Courseiva
hardMultiple ChoiceObjective-mapped

CISSP Practice Question: An organization's backup strategy includes daily…

An organization's backup strategy includes daily full backups and hourly incremental backups. The system suffers a ransomware attack that encrypts all data. Which backup set is essential to restore the most recent clean state?

⚠ Common exam trap

Test-takers frequently confuse incremental backups with differential backups, mistakenly thinking only the last incremental is needed, when in fact incremental backups require the entire chain from the last full backup to restore completely.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The last full backup plus all incremental backups after that

To restore the most recent clean state after a ransomware attack, you need the last full backup as the base and all subsequent incremental backups to apply every change made up to the moment before the attack. Incremental backups capture only data changed since the last backup (full or incremental), so skipping any breaks the chain and results in data loss. Option A correctly includes the full backup and every incremental backup after it, ensuring a complete restoration to the latest point before encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The last full backup plus all incremental backups after that

    Why this is correct

    When employing a daily full backup strategy combined with incremental backups, a complete restoration to the most recent state requires the last full backup as the foundational baseline. Subsequently, all incremental backups taken after that full backup must be applied sequentially. Each incremental backup captures only the changes since the *previous* backup, ensuring that every modification up to the point of failure is included for a comprehensive and accurate recovery.

  • The last full backup plus the last incremental backup

    Why it's wrong here

    Restoring using only the last full backup and the very last incremental backup is insufficient because incremental backups record changes since the *immediately preceding* backup, whether it was a full or another incremental. Omitting any intermediate incremental backups means that all data modifications and additions made between the last full backup and the final incremental, but not captured in that final incremental, would be permanently lost. This approach would result in an incomplete and potentially corrupted restoration, failing to achieve the desired recovery point.

  • The last full backup only

    Why it's wrong here

    Relying solely on the last full backup for restoration would lead to significant data loss, as it only captures the state of the data at the exact moment that full backup was completed. Any new files created, existing files modified, or data deleted after the full backup was performed would be entirely absent from the restored system. This method fails to meet typical recovery point objectives (RPOs) for active systems, as it discards all subsequent changes.

  • The last incremental backup only

    Why it's wrong here

    Attempting to restore using only the last incremental backup is fundamentally impossible because an incremental backup does not contain a complete copy of the data; it only stores the changes made since its parent backup. Without the preceding full backup, and potentially other intermediate incremental backups, there is no baseline from which to apply these recorded changes. This would result in an unrecoverable state, as the incremental data lacks the necessary context for reconstruction.

About these practice questions

Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.