Regularly backing up all data is a required part of a disaster recovery plan. Disaster recovery focuses on restoring systems, services, data, and business operations after a disruptive event such as ransomware, data corruption, hardware failure, natural disaster, or a major network security incident. Without reliable backups, an organization may be unable to recover lost or encrypted data, rebuild critical systems, or meet recovery time and recovery point objectives.
The CompTIA Network+ N10-009 objectives include disaster recovery, business continuity, backups, recovery planning, and operational resilience. A proper DR plan should include backup frequency, backup location, retention policy, restoration testing, access control, encryption, and procedures for recovering critical network services.
Vulnerability scans are useful for identifying weaknesses before an incident occurs, but they are part of risk management and security assessment rather than the core recovery process. Antivirus software helps prevent or detect malware, but it does not guarantee recovery after an incident. An IDS can detect suspicious activity, but it does not restore data or services. Therefore, regular data backups are the required disaster recovery step.