SY0-701 exam dumps

SY0-701 practice question 242 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 242

Single answerContinuity of operations

A regional healthcare provider is hit by ransomware that encrypts several on-premises application servers in its primary data center. Patient care cannot stop, so leadership directs the IT team to restore the electronic health record (EHR) system at an alternate site within four hours and with no more than 15 minutes of data loss. The team has documented backups, an alternate processing site, and a continuity plan, but they have never performed a full failover test. Which action would BEST support continuity of operations while meeting the stated business requirements?

  1. A

    Activate the alternate site and restore the EHR from replicated data that is synchronized at least every 15 minutes, following the continuity plan's recovery procedures

  2. B

    Keep production offline until forensic analysis is complete, then rebuild the primary site to avoid any risk of operating from a secondary location

  3. C

    Restore the EHR from the previous night's full backup at the primary site because backups are the most reliable recovery method during malware incidents

  4. D

    Wait for executive approval to rewrite the continuity plan before initiating recovery, since the plan has not yet been validated through testing

Show answer and explanation

Correct answer: A

Explanation

Continuity of operations focuses on sustaining or rapidly restoring mission-essential functions during and after a disruption. In this scenario, the key requirements are an RTO of four hours and an RPO of 15 minutes. The best option is to fail over to the alternate site and recover using replication that meets the data-loss requirement. This reflects standard business continuity and disaster recovery practices: define critical services, identify recovery objectives, maintain alternate processing capability, and execute documented recovery procedures. Security+ expects candidates to distinguish among backups, replication, alternate sites, and incident response priorities. While testing the continuity plan is an important best practice, the lack of testing should be documented and corrected after the incident through exercises such as tabletop or full interruption tests. Relevant guidance includes NIST SP 800-34 Contingency Planning Guide for Federal Information Systems, which emphasizes recovery strategies, alternate processing sites, backup strategies, and testing of contingency plans.

  • A. Correct.

    This is the best answer because it aligns directly to continuity of operations objectives and the stated recovery targets. Restoring service at an alternate processing site supports continued mission-essential operations when the primary site is unavailable. Using replicated data synchronized at least every 15 minutes supports the 15-minute recovery point objective (RPO), and activating the alternate site supports the four-hour recovery time objective (RTO). Following documented recovery procedures is also consistent with business continuity and disaster recovery best practices.

  • B. Incorrect.

    This is incorrect because delaying restoration until forensic work is finished prioritizes investigation over continuity of operations. In a real incident, organizations often perform containment and investigation in parallel with service restoration using clean systems or an alternate site. For patient care systems, prolonged downtime can create operational and safety risks. The misconception is that recovery must wait for the incident response process to be fully completed.

  • C. Incorrect.

    This is incorrect because a previous night's backup would likely exceed the stated maximum tolerable data loss. If the organization can lose no more than 15 minutes of data, a nightly backup does not meet the required RPO. In addition, restoring only at the compromised primary site does not best support continuity if the primary environment is impacted by ransomware. The misconception is assuming that any backup-based recovery is sufficient without comparing it to RTO and RPO requirements.

  • D. Incorrect.

    This is incorrect because an untested plan is a weakness, but it is not a reason to delay activation during an actual outage. The purpose of a continuity plan is to guide response during disruptive events, even if the organization later improves it through exercises and lessons learned. Waiting to rewrite the plan would increase downtime and undermine continuity objectives. The misconception is treating plan validation as a prerequisite for emergency execution rather than an ongoing improvement activity.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam