Courseiva

SSCP Incident Response and Recovery Practice Question

A security incident response team is reviewing their disaster recovery plan. They need to ensure that their backup strategy supports recovery from a ransomware attack that encrypts critical files. Which TWO of the following are essential characteristics of an effective backup strategy for this scenario? (Choose two.)

⚠ Common exam trap

The trap here is focusing on backup frequency or retention rather than on protecting backups from being encrypted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Backups are stored offline or in an immutable format.

An effective backup strategy against ransomware must ensure that backups cannot be encrypted by the attacker and that they can be successfully restored. Offline or immutable backups provide protection from encryption, and regular testing verifies that restoration will work when needed. Other factors like retention period or encryption key management are important but not as directly critical for this specific threat.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Backups are stored offline or in an immutable format.

    Why this is correct

    Offline or immutable backups prevent ransomware from encrypting the backup data, ensuring that a clean copy is available for restoration. This is critical because ransomware often targets connected backups. Storing backups offline or using write-once-read-many (WORM) storage ensures that even if the network is compromised, the backups remain intact and can be used to recover.

  • ✓

    Backup restoration procedures are tested regularly.

    Why this is correct

    Regular testing of restoration procedures ensures that backups are usable and that the recovery process works within the required time frame. Without testing, organizations may discover that backups are corrupted or that the restoration process is too slow during an actual incident. Testing validates the integrity of backups and the efficiency of recovery, which is vital for ransomware recovery.

  • ✗

    Backups are encrypted with a key stored on the same server.

    Why it's wrong here

    Storing the encryption key on the same server means that if the server is compromised, the attacker can access the key and decrypt the backups. This defeats the purpose of encryption. For backups to be secure, encryption keys should be stored separately, such as in a hardware security module or offline. Thus, this is not an effective characteristic.

  • ✗

    Backups are retained for at least seven years.

    Why it's wrong here

    Retention period is driven by legal and business requirements, not specifically by ransomware recovery. While long retention might be useful, it does not address the immediate need to have a clean, accessible backup. The key characteristics for ransomware recovery are isolation and testability, not retention length. Therefore, this is not essential for this scenario.

  • ✗

    Backups are performed daily to the same network share.

    Why it's wrong here

    Backing up to a network share that is accessible from the infected network is risky because ransomware can encrypt those backups as well. Daily backups are good for recovery point objective, but the storage location must be secure. A network share is typically not sufficient protection against ransomware, as it can be targeted and encrypted.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.