712-50 exam dumps

712-50 practice question 277 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 277

Single answerDisaster Recovery and Business Continuity Planning (5 questions)

A global manufacturing company has just completed a business impact analysis (BIA). The BIA shows that the ERP system supporting procurement, production scheduling, and shipping has a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 15 minutes. During a leadership review, the CIO proposes using nightly backups stored offsite and rebuilding the ERP environment in the secondary data center if the primary site fails. The CFO supports this approach because it is significantly cheaper than real-time replication. As the CISO, you must advise executive management on whether the proposed disaster recovery strategy is acceptable. What is the BEST response?

  1. A

    Approve the proposal because offsite backups satisfy disaster recovery requirements as long as the data can eventually be restored at the alternate site.

  2. B

    Approve the proposal if the secondary data center has sufficient compute capacity, because infrastructure readiness is the main factor in meeting the ERP recovery objectives.

  3. C

    Reject the proposal because nightly backups and rebuild procedures are unlikely to meet the defined RTO and RPO for the ERP system, and recommend a recovery strategy aligned to the BIA requirements.

  4. D

    Reject the proposal because all tier-1 systems should use identical hot sites regardless of business impact analysis results.

Show answer and explanation

Correct answer: C

Explanation

The best answer is to reject the proposal because disaster recovery planning must be aligned with business continuity requirements established through the BIA. The BIA defines the operational impact of downtime and data loss, which is then translated into RTO and RPO targets. In this case, a 4-hour RTO and 15-minute RPO indicate a highly critical system that likely requires a warm-to-hot recovery capability, rapid failover processes, and replication frequency far greater than nightly backups. Nightly backups are more consistent with less demanding RPOs and do not adequately address the risk of significant transaction loss in an ERP environment. Best practices from NIST SP 800-34 Contingency Planning Guide for Federal Information Systems and ISO 22301 emphasize that recovery strategies must be selected based on business requirements, resource dependencies, and validated recovery capabilities. Executive leadership may consider cost, but governance requires that cost decisions be made with clear understanding of residual risk and business impact. The CISO's role is to ensure management understands that a lower-cost backup-and-rebuild approach is not acceptable when it cannot meet documented recovery objectives.

  • A. Incorrect.

    This is incorrect because simply having offsite backups does not mean the organization can meet the required recovery objectives. Nightly backups imply a potential data loss of up to 24 hours, which conflicts with the 15-minute RPO. In addition, rebuilding systems after a site failure is typically too slow for a 4-hour RTO for a complex ERP platform. This option reflects the common misconception that any backup strategy is sufficient for disaster recovery, when recovery capability must be evaluated against business-defined RTO and RPO targets.

  • B. Incorrect.

    This is incorrect because compute capacity at the secondary site is only one component of disaster recovery readiness. Even if the alternate site has enough infrastructure, nightly backups still fail the 15-minute RPO, and a rebuild-based recovery process may not satisfy the 4-hour RTO. This option is plausible because infrastructure limitations often do cause DR failures, but in this scenario the larger issue is the mismatch between the proposed recovery method and the BIA-defined recovery objectives.

  • C. Correct.

    This is correct because the proposed strategy does not align with the recovery requirements established by the BIA. A nightly backup schedule cannot reasonably support a 15-minute RPO, and rebuilding a complex ERP environment after a disaster introduces significant delay that may exceed a 4-hour RTO. The CISO should ensure that disaster recovery investments are driven by business impact and risk tolerance, not solely by cost. A more appropriate strategy may include near-real-time replication, pre-built recovery environments, and tested failover procedures designed specifically to meet the ERP system's criticality.

  • D. Incorrect.

    This is incorrect because disaster recovery strategy should be risk-based and guided by the BIA, not by a blanket rule that all tier-1 systems require identical hot sites. While a hot site or similar high-availability recovery design may be justified here, different critical systems can have different recovery needs, architectures, and cost-benefit considerations. This option represents the misconception that one standardized recovery model is universally required for all critical assets.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam