CompTIA SecurityX (CAS-005)Security ArchitectureMedium

A security architect is designing a new financial transaction processing system that requires near-zero downtime and must be able to withstand the failure of an entire data center. The system needs to ensure that all committed transactions are never lost, even in a disaster scenario. Which replication strategy should be implemented for the database component to meet these stringent requirements?

  1. AActive-Passive Replication
  2. BSynchronous Replication
  3. CAsynchronous Replication
  4. DSnapshot Replication
Show answer & explanation

Correct answer: B. Synchronous Replication

Synchronous replication ensures that a transaction is not considered committed until it has been successfully written to both the primary and at least one secondary replica. This guarantees zero data loss (RPO=0) even if the primary data center fails, which is critical for financial transactions.

Why the other options are wrong

  • A. Active-Passive replication primarily addresses high availability but doesn't inherently guarantee zero data loss without synchronous replication between sites.
  • C. Asynchronous replication allows for potential data loss (non-zero RPO) because data is acknowledged on the primary before being written to the secondary.
  • D. Snapshot replication creates point-in-time copies, which is not suitable for near-zero downtime and zero data loss requirements for continuous transaction processing.

Synchronous Replication

A data replication method where data is written to both the primary and replica storage locations simultaneously, ensuring zero data loss (RPO=0) but potentially introducing latency.

  • Guarantees data consistency across replicas.
  • Transaction is only committed after confirmation from all replicas.
  • Essential for applications with zero RPO (Recovery Point Objective) requirements.

Memory trick: Sync for Zero Loss, Async for Speed, Snap for Point-in-Time.

More Security Architecture questions