SSCP Incident Response and Recovery Practice Question
A security incident response team is reviewing their disaster recovery plan. They need to ensure that their backup strategy supports recovery from a ransomware attack that encrypts critical files. Which TWO of the following are essential characteristics of an effective backup strategy for this scenario? (Choose two.)
⚠ Common exam trap
The trap here is focusing on backup frequency or retention rather than on protecting backups from being encrypted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Backups are stored offline or in an immutable format.
An effective backup strategy against ransomware must ensure that backups cannot be encrypted by the attacker and that they can be successfully restored. Offline or immutable backups provide protection from encryption, and regular testing verifies that restoration will work when needed. Other factors like retention period or encryption key management are important but not as directly critical for this specific threat.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Backups are stored offline or in an immutable format.
Why this is correct
Offline or immutable backups prevent ransomware from encrypting the backup data, ensuring that a clean copy is available for restoration. This is critical because ransomware often targets connected backups. Storing backups offline or using write-once-read-many (WORM) storage ensures that even if the network is compromised, the backups remain intact and can be used to recover.
- ✓
Backup restoration procedures are tested regularly.
Why this is correct
Regular testing of restoration procedures ensures that backups are usable and that the recovery process works within the required time frame. Without testing, organizations may discover that backups are corrupted or that the restoration process is too slow during an actual incident. Testing validates the integrity of backups and the efficiency of recovery, which is vital for ransomware recovery.
- ✗
Backups are encrypted with a key stored on the same server.
Why it's wrong here
Storing the encryption key on the same server means that if the server is compromised, the attacker can access the key and decrypt the backups. This defeats the purpose of encryption. For backups to be secure, encryption keys should be stored separately, such as in a hardware security module or offline. Thus, this is not an effective characteristic.
- ✗
Backups are retained for at least seven years.
Why it's wrong here
Retention period is driven by legal and business requirements, not specifically by ransomware recovery. While long retention might be useful, it does not address the immediate need to have a clean, accessible backup. The key characteristics for ransomware recovery are isolation and testability, not retention length. Therefore, this is not essential for this scenario.
- ✗
Backups are performed daily to the same network share.
Why it's wrong here
Backing up to a network share that is accessible from the infected network is risky because ransomware can encrypt those backups as well. Daily backups are good for recovery point objective, but the storage location must be secure. A network share is typically not sufficient protection against ransomware, as it can be targeted and encrypted.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.