The correct answer is D because effective recovery from many security incidents depends on the ability to restore reliable data and systems. Offsite backups are especially important when primary systems or data are corrupted, encrypted, destroyed, or otherwise unavailable. Security incidents such as ransomware, destructive malware, insider misuse, or system compromise may require restoration from clean backups. Response team cross-training improves operational flexibility, but it does not directly restore lost or damaged data. Network architecture reviews may improve security design and reduce future exposure, but they are not the most important recovery enabler. Penetration testing helps identify weaknesses before an incident occurs, but it does not support restoration after an incident. CISM incident management includes recovery as a key phase, and recovery requires tested, available, and protected backup capabilities aligned with recovery objectives. Offsite backups reduce dependence on compromised local infrastructure and support business resilience. Therefore, offsite data backups are the most important recovery enabler.
[Reference: CISM Information Security Incident Management; recovery, backup strategy, resilience, disaster recovery, and restoration principles., , ]
Submit