SY0-701 exam dumps

SY0-701 practice question 9 of 490

Security+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

SY0-701 Question 9

Single answerConfidentiality, Integrity, and Availability (CIA)

A regional healthcare provider stores patient records in an internal application used by clinics around the clock. After a recent ransomware incident at another hospital, the security manager is asked to recommend the single BEST control improvement to ensure doctors can still access patient records during a similar attack, while also preserving the trustworthiness of restored data. Which of the following should the manager implement first?

  1. A

    Deploy immutable, offline backups and routinely test restoration procedures

  2. B

    Enable full-disk encryption on all database servers

  3. C

    Require multifactor authentication for all staff who access the application

  4. D

    Implement file integrity monitoring on the patient records database

Show answer and explanation

Correct answer: A

Explanation

This question maps directly to the CIA triad. The scenario prioritizes availability first, because clinicians must continue accessing patient records, and integrity second, because restored data must be trustworthy. Backups that are offline or otherwise isolated from production are a widely accepted best practice against ransomware, since attackers often try to encrypt or delete reachable backups. Immutability further reduces the chance that backup data can be altered. Routine restoration testing is equally important because many organizations discover backup failures only during an incident. Guidance from sources such as NIST's contingency planning and ransomware-focused recommendations consistently emphasizes tested backups and recovery procedures as foundational resilience measures. The other options are valid security controls, but they align more closely to confidentiality, preventive access control, or detective integrity monitoring rather than the primary recovery and continuity need described in the scenario.

  • A. Correct.

    Correct. Immutable, offline backups directly support availability by allowing recovery if ransomware encrypts production systems, and they also support integrity because clean backup copies can be restored and validated. Regular restoration testing is critical; backups that cannot be restored do not meaningfully improve resilience. This is the best first control because the scenario emphasizes continued access to records during a ransomware event and confidence in restored data.

  • B. Incorrect.

    Incorrect. Full-disk encryption primarily protects confidentiality of data at rest if a server or drive is lost or stolen. It does not meaningfully ensure that patient records remain available during ransomware, because ransomware can encrypt data after the system is running and the disk is already unlocked. It also does not provide a recovery path for restoring trusted data.

  • C. Incorrect.

    Incorrect. Multifactor authentication is a strong preventive control that helps reduce the risk of unauthorized access and some forms of account compromise. However, it does not by itself ensure availability of patient records during a ransomware attack, nor does it provide a trusted source for recovery. Candidates may choose this because MFA is broadly recommended, but it is not the best answer for the stated objective.

  • D. Incorrect.

    Incorrect. File integrity monitoring helps detect unauthorized changes and can support integrity objectives by alerting administrators to tampering. However, it is primarily detective, not restorative. It does not ensure continued access to records during a ransomware incident and does not replace a tested backup and recovery capability.

Timed practice exam

Take a SY0-701 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam