CompTIA Security+ (SY0-701) · Free practice question 11 of 12
Offline backups for ransomware recovery
After a competitor's network backups were encrypted along with its servers, Ballater Freight wants to be sure it can recover from a ransomware attack. Which backup practice best supports this?
- A.Back up only the operating system files
- B.Keep a single backup copy and overwrite it nightly
- C.Keep backup copies offline or immutable so ransomware on the network cannot alter them
- D.Store backups only on a mapped network drive on the file server
Show answer and explanation
Correct answer: C. Keep backup copies offline or immutable so ransomware on the network cannot alter them
Why: Offline or immutable backups cannot be encrypted or deleted by ransomware that spreads across the network, so clean data remains available for recovery. A mapped drive is reachable by the same malware. Backing up only OS files misses business data, and a single nightly-overwritten copy may already contain encrypted files when the attack is noticed.
More free CompTIA Security+ (SY0-701) questions
- Access control vestibule stops tailgating
- Trusted Platform Module characteristics
- Blockchain open public ledger integrity
- Virtual machine escape vulnerability
- Jump server for administrative access
- OAuth delegated authorization without passwords
- Non-disclosure agreement for consultants
- Passive reconnaissance from public sources
- Mean time between failures reliability
- Gap analysis against a framework
- Steganography hiding data in images