hardMultiple ChoiceObjective-mapped
CISSP Practice Question: Your organization, a multinational e-commerce…
Your organization, a multinational e-commerce company, has suffered a ransomware attack that encrypted critical database servers and file shares. The ransom note demands payment in cryptocurrency within 48 hours or the data will be permanently destroyed. The company has a backup strategy that includes daily full backups and hourly incremental backups, stored both on-site and off-site. However, during the incident response, you discover that the most recent on-site backups are also encrypted because the backup server was connected to the network and affected by the same ransomware. Off-site backups are on tape and were last rotated out 72 hours ago. The CEO is pressuring to pay the ransom to restore operations quickly. Which option should the incident response team prioritize to minimize data loss and reputational damage?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restore data from the off-site tape backups taken 72 hours ago.
Restoring from off-site tape backups taken 72 hours ago is the best course because they are not encrypted and provide a viable recovery point. Option A (pay ransom) is risky—no guarantee of decryption and encourages attackers. Option C (rebuild servers from scratch without restoring data) would result in significant data loss and is not efficient. Option D (negotiate) wastes valuable time and does not guarantee recovery.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pay the ransom and hope the attackers provide a working decryption key.
Why it's wrong here
Paying ransom directly funds criminal enterprises, encouraging further attacks and perpetuating the ransomware ecosystem. There is no guarantee that attackers will provide a functional decryption key, or that the key will fully restore all data without corruption or backdoors. Furthermore, paying the ransom does not prevent future attacks and can mark the organization as a willing payer, making it a target for subsequent extortion attempts. This approach offers no certainty of recovery and exacerbates the overall risk posture.
- ✓
Restore data from the off-site tape backups taken 72 hours ago.
Why this is correct
Restoring from off-site tape backups is the most reliable and recommended strategy for ransomware recovery, leveraging a fundamental principle of data availability and disaster recovery. Off-site backups are physically or logically isolated from the production network, ensuring they are unaffected by the encryption event and remain uncompromised. While accepting a 72-hour data loss is a business decision, it is a controlled and predictable recovery method that avoids funding criminals and provides a clean slate for operations. This minimizes long-term impact by restoring known good data.
- ✗
Rebuild servers from scratch using latest known good configurations without restoring data.
Why it's wrong here
Rebuilding servers from scratch without restoring any data would result in catastrophic and irreversible data loss for an e-commerce company. All customer transaction history, product catalogs, order details, and user accounts would be permanently erased, rendering the business inoperable. This would destroy customer trust and lead to immense financial and reputational damage far exceeding the impact of a ransomware attack, making it an unacceptable recovery option.
- ✗
Attempt to negotiate with the attackers for a lower ransom and more time.
Why it's wrong here
Attempting to negotiate with attackers for a lower ransom or more time is generally an ineffective and risky strategy that prolongs the incident. It extends the downtime, increases operational losses, and provides no guarantee of a successful outcome, as attackers are criminals with no obligation to honor agreements. Furthermore, engaging in negotiations can signal desperation, potentially emboldening attackers to demand more or delay providing a key, thereby extending the business interruption and increasing overall risk exposure.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
Key term
Incident response
Incident response is the structured approach an organization uses to identify, contain, and recover from cybersecurity incidents like data breaches or ransomware attacks.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.