SSCP Security Operations and Administration Practice Question
A security administrator is implementing the 3-2-1 backup rule. Which THREE actions are required to comply with this rule? (Select THREE.)
⚠ Common exam trap
SSCP often tests the exact components of the 3-2-1 rule, and candidates frequently confuse it with general backup best practices like encryption or daily full backups, which are not part of the rule.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store one copy offsite
The 3-2-1 backup rule requires three things: at least three copies of the data (option B), stored on two different media types (option C), with one copy kept offsite (option A). Option B is correct because the '3' means the original data plus two backup copies, totaling three copies. Option C is correct because the '2' means two distinct media or storage types, such as disk and tape, to avoid a single failure mode. Option A is correct because the '1' means at least one copy must be stored offsite for disaster recovery. Option D is not required by the rule, since backup frequency is a separate scheduling decision. Option E is also not part of the 3-2-1 rule, as encryption is a security control rather than a copy-count or media requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Store one copy offsite
Why this is correct
The 3-2-1 rule's final component requires one copy stored at a separate physical location, protecting against site-level loss such as fire, flood or theft destroying all on-premises backups simultaneously. Offsite storage satisfies that geographic-separation requirement.
- ✓
Maintain at least three copies of the data
Why this is correct
Maintaining at least three copies of the data satisfies the "3" in the 3-2-1 backup rule, which mandates three total copies: the original plus two backups. This count is the foundational constraint, ensuring redundancy before the "2" (distinct media) and "1" (offsite) requirements are applied.
- ✓
Use two different media types (e.g., disk and tape)
Why this is correct
Using two distinct media types satisfies the "2" in the 3-2-1 rule, which mandates two different media for redundancy. This guards against media-specific failures, such as a tape drive fault or disk controller corruption, ensuring one media type's weakness cannot compromise both backup copies simultaneously.
- ✗
Perform daily full backups
Why it's wrong here
Daily full backups describe a frequency, not one of the 3-2-1 requirements, which specify three copies, two media types and one offsite. Daily fulls would be chosen where recovery point objectives demand minimal data loss, independent of copy-count rules.
- ✗
Use encryption for all backup copies
Why it's wrong here
Encryption protects backup confidentiality but is not one of the 3-2-1 criteria, which count copies, media and offsite location. Encryption would be the right control when regulatory or data-classification requirements mandate protection of backup data at rest.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.