712-50 exam dumps

712-50 practice question 289 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 289

Single answerDesign Backup and disaster recovery strategies for cloud computing

A global SaaS company is moving its customer analytics platform to a public cloud provider. The platform processes regulated customer data and supports business units in North America, Europe, and Asia. The board has approved a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 15 minutes for the production database tier. The CISO is concerned about ransomware, accidental deletion, and a regional cloud outage. Budget is available for critical systems, but leadership wants to avoid unnecessary complexity and uncontrolled storage growth. Which approach is the MOST appropriate backup and disaster recovery strategy?

  1. A

    Use only the cloud provider's standard availability features within a single region, such as multi-zone deployment and storage replication, because they provide sufficient resilience and eliminate the need for separate backups.

  2. B

    Implement cross-region disaster recovery for the production environment, use frequent point-in-time database backups or continuous log shipping to meet the 15-minute RPO, and store backup copies in logically isolated immutable storage with defined retention and regular recovery testing.

  3. C

    Rely on nightly full backups copied to the same cloud account and region, and document a manual rebuild procedure for application servers to control cost while accepting some data loss during major incidents.

  4. D

    Create snapshots of virtual machines and databases every 24 hours and replicate them to a secondary region, because snapshots alone provide complete protection against ransomware, corruption, and operator error.

Show answer and explanation

Correct answer: B

Explanation

The best answer is the strategy that maps technical controls to business recovery objectives and the actual risk scenarios. In cloud environments, chief information security officers should distinguish between high availability, backup, and disaster recovery. High availability within a region reduces downtime from localized failures, but it does not replace offline or logically isolated backups and does not adequately address region-wide failures. To meet a 15-minute RPO, organizations commonly use point-in-time recovery, database transaction log backups, or continuous replication mechanisms appropriate to the platform. To meet a 4-hour RTO, they should predefine recovery runbooks, automate failover or restoration steps where possible, and test them regularly. For ransomware resilience, industry best practices emphasize immutable storage, separation of backup administrative control from production, least privilege, and periodic restore testing. This aligns with guidance from NIST contingency planning and system recovery practices, the shared responsibility model used by major cloud providers, and widely accepted resilience practices such as the 3-2-1 backup principle adapted for cloud environments.

  • A. Incorrect.

    Incorrect. High availability features within one region, such as multi-zone deployment, improve resilience against localized infrastructure failures but are not a complete backup or disaster recovery strategy. They typically do not protect adequately against regional outages, ransomware-driven deletion or encryption of data, insider misuse, or corruption that is replicated across the environment. A common misconception is to equate availability architecture with backup and recovery capability.

  • B. Correct.

    Correct. This option aligns with the stated business requirements and threat model. A 15-minute RPO generally requires frequent backups, point-in-time recovery, transaction log backups, or continuous replication/log shipping depending on the database platform. Cross-region disaster recovery addresses regional cloud outages, while logically isolated and immutable backup storage helps reduce the impact of ransomware and accidental or malicious deletion. Defined retention helps manage storage growth, and regular recovery testing validates that the design actually achieves the 4-hour RTO. This is the most balanced strategy from a chief information security and business resilience perspective.

  • C. Incorrect.

    Incorrect. Nightly full backups cannot realistically meet a 15-minute RPO, and keeping backups in the same account and region leaves the organization exposed to regional disruption and account compromise. Although cost control is a valid consideration, the approach does not satisfy the approved recovery objectives for a critical regulated workload. Candidates may choose this option if they focus too heavily on cost rather than board-approved resilience requirements.

  • D. Incorrect.

    Incorrect. Replicated snapshots can be useful as one recovery mechanism, but snapshots taken every 24 hours do not meet the required 15-minute RPO. In addition, snapshots alone are not sufficient protection against ransomware or corruption if the compromised state is also replicated or if snapshots can be altered or deleted by the same administrative boundary. The misconception here is that replication and snapshots automatically equal secure backup.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam