Certified Information Security Manager (CISM)Incident ManagementEasy
A CISO is developing a disaster recovery plan (DRP) for a cloud-native application. The application relies on managed services from the cloud provider, including serverless functions and managed databases. Which of the following is the MOST important consideration for ensuring the DRP's effectiveness for this architecture?
- ALeveraging the cloud provider's native disaster recovery capabilities and multi-region deployments.
- BImplementing a traditional backup and restore strategy using tape drives.
- CDeveloping on-premises recovery infrastructure as a primary failover.
- DNegotiating a separate, dedicated physical infrastructure for recovery.
Show answer & explanationAnswer & explanation
Correct answer: A. Leveraging the cloud provider's native disaster recovery capabilities and multi-region deployments.
For cloud-native applications relying on managed services, the most effective DRP leverages the inherent capabilities of the cloud provider, such as multi-region deployments and native DR features, which are designed for scalability and resilience in that environment.
Why the other options are wrong
- B. Tape drives are outdated and unsuitable for cloud-native, high-availability applications.
- C. Developing on-premises infrastructure for cloud-native applications creates a hybrid, complex, and often less efficient DR solution.
- D. Negotiating dedicated physical infrastructure contradicts the benefits and architecture of cloud-native applications.
Cloud-Native DR Strategy
A disaster recovery approach specifically designed for applications built and deployed using cloud computing principles and services.
- Leverages cloud provider's inherent resilience and global infrastructure.
- Utilizes features like multi-region deployment, auto-scaling, and managed services.
- Focuses on automation and infrastructure-as-code for rapid recovery.
Memory trick: Use the cloud's own tools for cloud problems.