CompTIA SecurityX (CAS-005)Security ArchitectureHard

A security architect is designing a new system for a utility company that manages critical national infrastructure. The system must maintain continuous operation even if a data center goes completely offline due to a major natural disaster. Data loss tolerance is near zero, and recovery time must be minimal. Which architectural pattern is MOST appropriate for ensuring both high availability and disaster recovery for this scenario?

  1. AActive-active deployment with synchronous replication across geographically dispersed data centers.
  2. BAsynchronous replication to a cold standby site.
  3. CActive-passive failover with daily backups.
  4. DSnapshot-based replication to a warm standby site.
Show answer & explanation

Correct answer: A. Active-active deployment with synchronous replication across geographically dispersed data centers.

Active-active deployment with synchronous replication across geographically dispersed data centers provides the highest level of availability and near-zero data loss (RPO=0) with minimal recovery time (RTO close to zero). Both sites handle traffic, and data is written simultaneously to both, ensuring immediate failover in case of a disaster.

Why the other options are wrong

  • B. Asynchronous replication introduces potential data loss (RPO) and a cold standby requires substantial time to become operational (RTO).
  • C. Daily backups imply data loss of up to 24 hours (RPO) and significant recovery time (RTO) to restore.
  • D. Snapshot-based replication introduces a recovery point objective (RPO) related to the snapshot frequency and requires time to bring the warm standby online.

Active-Active Synchronous Replication

An architectural pattern where multiple geographically separated instances of an application or database are simultaneously active and processing requests. Data changes are synchronously replicated between all active instances, ensuring near-zero data loss (RPO) and immediate failover capabilities (RTO).

  • Both sites are active and serve traffic.
  • Data is written to all sites concurrently (synchronously).
  • Provides RPO (Recovery Point Objective) of zero or near-zero.
  • Enables RTO (Recovery Time Objective) of near-zero, ensuring continuous operation.
  • Higher complexity and cost compared to other DR strategies.

Memory trick: Always on, always synced, always ready for disaster.

More Security Architecture questions