Courseiva
hardMultiple Choice

CISSP Practice Question: Your organization, a multinational e-commerce…

Your organization, a multinational e-commerce company, has suffered a ransomware attack that encrypted critical database servers and file shares. The ransom note demands payment in cryptocurrency within 48 hours or the data will be permanently destroyed. The company has a backup strategy that includes daily full backups and hourly incremental backups, stored both on-site and off-site. However, during the incident response, you discover that the most recent on-site backups are also encrypted because the backup server was connected to the network and affected by the same ransomware. Off-site backups are on tape and were last rotated out 72 hours ago. The CEO is pressuring to pay the ransom to restore operations quickly. Which option should the incident response team prioritize to minimize data loss and reputational damage?

⚠ Common exam trap

CISSP often tests the misconception that paying the ransom or negotiating is a legitimate incident response priority, when the correct answer is always restoring from a verified clean backup that minimizes data loss.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restore data from the off-site tape backups taken 72 hours ago.

Restoring from the off-site tape backups taken 72 hours ago is the only option that recovers data from a known-clean source unaffected by the ransomware, bounding data loss to at most 72 hours. Paying the ransom is discouraged by law enforcement and does not guarantee decryption, and rebuilding without data would cause total data loss. The off-site tapes were rotated out before the compromise, so they are the most reliable recovery point.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pay the ransom and hope the attackers provide a working decryption key.

    Why it's wrong here

    Paying ransom directly funds criminal enterprises, encouraging further attacks and perpetuating the ransomware ecosystem. There is no guarantee that attackers will provide a functional decryption key, or that the key will fully restore all data without corruption or backdoors. Furthermore, paying the ransom does not prevent future attacks and can mark the organization as a willing payer, making it a target for subsequent extortion attempts. This approach offers no certainty of recovery and exacerbates the overall risk posture.

  • ✓

    Restore data from the off-site tape backups taken 72 hours ago.

    Why this is correct

    Restoring from off-site tape backups is the most reliable and recommended strategy for ransomware recovery, leveraging a fundamental principle of data availability and disaster recovery. Off-site backups are physically or logically isolated from the production network, ensuring they are unaffected by the encryption event and remain uncompromised. While accepting a 72-hour data loss is a business decision, it is a controlled and predictable recovery method that avoids funding criminals and provides a clean slate for operations. This minimizes long-term impact by restoring known good data.

  • ✗

    Rebuild servers from scratch using latest known good configurations without restoring data.

    Why it's wrong here

    Rebuilding servers from scratch without restoring any data would result in catastrophic and irreversible data loss for an e-commerce company. All customer transaction history, product catalogs, order details, and user accounts would be permanently erased, rendering the business inoperable. This would destroy customer trust and lead to immense financial and reputational damage far exceeding the impact of a ransomware attack, making it an unacceptable recovery option.

  • ✗

    Attempt to negotiate with the attackers for a lower ransom and more time.

    Why it's wrong here

    Attempting to negotiate with attackers for a lower ransom or more time is generally an ineffective and risky strategy that prolongs the incident. It extends the downtime, increases operational losses, and provides no guarantee of a successful outcome, as attackers are criminals with no obligation to honor agreements. Furthermore, engaging in negotiations can signal desperation, potentially emboldening attackers to demand more or delay providing a key, thereby extending the business interruption and increasing overall risk exposure.

About these practice questions

This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.