Amazon AWS Certified Solutions Architect Associate SAA-C03 Disaster Recovery and Durable Data Architectures Practice Test

 

Topic 10 covers disaster recovery and durable data architectures for the AWS Certified Solutions Architect – Associate certification. These original practice questions apply the verified SAA-C03 objectives to practical decisions and troubleshooting. Select one answer unless a fixed number is requested. For broader preparation, visit the AWS Certified Solutions Architect Associate SAA-C03 Exam Dumps page. Each option includes an explanation of the relevant behavior and scenario constraints.

Question 1

A noncritical internal system can tolerate hours of downtime and several hours of data loss. The business wants the lowest-cost cross-Region DR approach. Which strategy fits best?

  1. Use multi-Region active-active.
  2. Use resilient multi-AZ design and protected backups inside the permitted Region.
  3. Use backup and restore.
  4. Use a pilot light strategy.
  5. Use warm standby.

Correct Answer: C

 

Correct Answer

Answer C is correct because Backup and restore has the lowest steady-state footprint but requires recreating infrastructure and restoring data during recovery. This directly satisfies the decisive requirement in the scenario: lowest steady-state cost.

Incorrect Answers

Answer A is incorrect because Active-active serves production traffic from multiple Regions and can provide the lowest RTO when the application and data model support it. It can be useful in other designs, but it does not satisfy the decisive requirement here: lowest steady-state cost.

Answer B is incorrect because When data cannot leave the Region, resilience must be built across in-Region failure domains rather than using cross-Region DR copies. It can be useful in other designs, but it does not satisfy the decisive requirement here: lowest steady-state cost.

Answer D is incorrect because Pilot light keeps core data and replication services running while much of the application infrastructure is created during recovery. It can be useful in other designs, but it does not satisfy the decisive requirement here: lowest steady-state cost.

Answer E is incorrect because Warm standby keeps a scaled-down but functional copy continuously running so it can scale up quickly during failover. It can be useful in other designs, but it does not satisfy the decisive requirement here: lowest steady-state cost.

 

Question 2

A critical database and replication layer must run continuously in the recovery Region, but application servers may be created only after a disaster. Which strategy is this?

  1. Use a pilot light strategy.
  2. Use backup and restore.
  3. Use warm standby.
  4. Use multi-Region active-active.
  5. Use resilient multi-AZ design and protected backups inside the permitted Region.

Correct Answer: A

 

Correct Answer

Answer A is correct because Pilot light keeps core data and replication services running while much of the application infrastructure is created during recovery. This directly satisfies the decisive requirement in the scenario: pilot light.

Incorrect Answers

Answer B is incorrect because Backup and restore has the lowest steady-state footprint but requires recreating infrastructure and restoring data during recovery. It can be useful in other designs, but it does not satisfy the decisive requirement here: pilot light.

Answer C is incorrect because Warm standby keeps a scaled-down but functional copy continuously running so it can scale up quickly during failover. It can be useful in other designs, but it does not satisfy the decisive requirement here: pilot light.

Answer D is incorrect because Active-active serves production traffic from multiple Regions and can provide the lowest RTO when the application and data model support it. It can be useful in other designs, but it does not satisfy the decisive requirement here: pilot light.

Answer E is incorrect because When data cannot leave the Region, resilience must be built across in-Region failure domains rather than using cross-Region DR copies. It can be useful in other designs, but it does not satisfy the decisive requirement here: pilot light.

 

Question 3

A customer-facing system needs recovery within minutes. A scaled-down but fully functional copy should always run in the recovery Region and scale up on failover. Which strategy fits?

  1. Use resilient multi-AZ design and protected backups inside the permitted Region.
  2. Use warm standby.
  3. Use backup and restore.
  4. Use multi-Region active-active.
  5. Use a pilot light strategy.

Correct Answer: B

 

Correct Answer

Answer B is correct because Warm standby keeps a scaled-down but functional copy continuously running so it can scale up quickly during failover. This directly satisfies the decisive requirement in the scenario: warm standby.

Incorrect Answers

Answer A is incorrect because When data cannot leave the Region, resilience must be built across in-Region failure domains rather than using cross-Region DR copies. It can be useful in other designs, but it does not satisfy the decisive requirement here: warm standby.

Answer C is incorrect because Backup and restore has the lowest steady-state footprint but requires recreating infrastructure and restoring data during recovery. It can be useful in other designs, but it does not satisfy the decisive requirement here: warm standby.

Answer D is incorrect because Active-active serves production traffic from multiple Regions and can provide the lowest RTO when the application and data model support it. It can be useful in other designs, but it does not satisfy the decisive requirement here: warm standby.

Answer E is incorrect because Pilot light keeps core data and replication services running while much of the application infrastructure is created during recovery. It can be useful in other designs, but it does not satisfy the decisive requirement here: warm standby.

 

Question 4

A global application must continue serving users from another Region with near-zero interruption and both Regions normally handle production traffic. Which strategy is required?

  1. Use warm standby.
  2. Use resilient multi-AZ design and protected backups inside the permitted Region.
  3. Use backup and restore.
  4. Use multi-Region active-active.
  5. Use a pilot light strategy.

Correct Answer: D

 

Correct Answer

Answer D is correct because Active-active serves production traffic from multiple Regions and can provide the lowest RTO when the application and data model support it. This directly satisfies the decisive requirement in the scenario: active-active.

Incorrect Answers

Answer A is incorrect because Warm standby keeps a scaled-down but functional copy continuously running so it can scale up quickly during failover. It can be useful in other designs, but it does not satisfy the decisive requirement here: active-active.

Answer B is incorrect because When data cannot leave the Region, resilience must be built across in-Region failure domains rather than using cross-Region DR copies. It can be useful in other designs, but it does not satisfy the decisive requirement here: active-active.

Answer C is incorrect because Backup and restore has the lowest steady-state footprint but requires recreating infrastructure and restoring data during recovery. It can be useful in other designs, but it does not satisfy the decisive requirement here: active-active.

Answer E is incorrect because Pilot light keeps core data and replication services running while much of the application infrastructure is created during recovery. It can be useful in other designs, but it does not satisfy the decisive requirement here: active-active.

 

Question 5

A regulated workload is prohibited from storing data outside one Region but must survive an Availability Zone failure. Which design best respects the boundary?

  1. Use backup and restore.
  2. Use warm standby.
  3. Use multi-Region active-active.
  4. Use resilient multi-AZ design and protected backups inside the permitted Region.
  5. Use a pilot light strategy.

Correct Answer: D

 

Correct Answer

Answer D is correct because When data cannot leave the Region, resilience must be built across in-Region failure domains rather than using cross-Region DR copies. This directly satisfies the decisive requirement in the scenario: multi-AZ architecture plus in-Region backups.

Incorrect Answers

Answer A is incorrect because Backup and restore has the lowest steady-state footprint but requires recreating infrastructure and restoring data during recovery. It can be useful in other designs, but it does not satisfy the decisive requirement here: multi-AZ architecture plus in-Region backups.

Answer B is incorrect because Warm standby keeps a scaled-down but functional copy continuously running so it can scale up quickly during failover. It can be useful in other designs, but it does not satisfy the decisive requirement here: multi-AZ architecture plus in-Region backups.

Answer C is incorrect because Active-active serves production traffic from multiple Regions and can provide the lowest RTO when the application and data model support it. It can be useful in other designs, but it does not satisfy the decisive requirement here: multi-AZ architecture plus in-Region backups.

Answer E is incorrect because Pilot light keeps core data and replication services running while much of the application infrastructure is created during recovery. It can be useful in other designs, but it does not satisfy the decisive requirement here: multi-AZ architecture plus in-Region backups.

 

Question 6

A database is backed up every 12 hours, but the business can lose at most 15 minutes of transactions. Which change addresses the RPO gap?

  1. Run regular recovery tests that measure actual failover time and validate the full dependency chain.
  2. Preprovision or automate application recovery so required compute can be restored inside the RTO.
  3. Increase restore throughput and parallelize recovery operations where the service supports it.
  4. Use a replication or backup cadence that is frequent enough to meet the 15-minute RPO.
  5. Increase the frequency of backups or continuous replication according to the required RPO.

Correct Answer: D

 

Correct Answer

Answer D is correct because RPO is the maximum acceptable data-loss interval, so protection points must be created at least frequently enough to stay within that window. This directly satisfies the decisive requirement in the scenario: increase replication or backup frequency.

Incorrect Answers

Answer A is incorrect because A theoretical design does not prove the RTO until the recovery procedure is exercised and measured. It can be useful in other designs, but it does not satisfy the decisive requirement here: increase replication or backup frequency.

Answer B is incorrect because RTO measures time to restore service; data protection alone does not shorten infrastructure recreation. It can be useful in other designs, but it does not satisfy the decisive requirement here: increase replication or backup frequency.

Answer C is incorrect because A current backup still misses the RTO if the restore path cannot move and reconstruct data quickly enough. It can be useful in other designs, but it does not satisfy the decisive requirement here: increase replication or backup frequency.

Answer E is incorrect because More frequent recovery points reduce the amount of recent change that can be lost after a failure. It can be useful in other designs, but it does not satisfy the decisive requirement here: increase replication or backup frequency.

 

Question 7

Backups meet the RPO, but rebuilding 100 application instances takes six hours and the RTO is one hour. Which part of the plan must improve?

  1. Increase the frequency of backups or continuous replication according to the required RPO.
  2. Preprovision or automate application recovery so required compute can be restored inside the RTO.
  3. Use a replication or backup cadence that is frequent enough to meet the 15-minute RPO.
  4. Run regular recovery tests that measure actual failover time and validate the full dependency chain.
  5. Increase restore throughput and parallelize recovery operations where the service supports it.

Correct Answer: B

 

Correct Answer

Answer B is correct because RTO measures time to restore service; data protection alone does not shorten infrastructure recreation. This directly satisfies the decisive requirement in the scenario: preprovision or automate faster compute recovery.

Incorrect Answers

Answer A is incorrect because More frequent recovery points reduce the amount of recent change that can be lost after a failure. It can be useful in other designs, but it does not satisfy the decisive requirement here: preprovision or automate faster compute recovery.

Answer C is incorrect because RPO is the maximum acceptable data-loss interval, so protection points must be created at least frequently enough to stay within that window. It can be useful in other designs, but it does not satisfy the decisive requirement here: preprovision or automate faster compute recovery.

Answer D is incorrect because A theoretical design does not prove the RTO until the recovery procedure is exercised and measured. It can be useful in other designs, but it does not satisfy the decisive requirement here: preprovision or automate faster compute recovery.

Answer E is incorrect because A current backup still misses the RTO if the restore path cannot move and reconstruct data quickly enough. It can be useful in other designs, but it does not satisfy the decisive requirement here: preprovision or automate faster compute recovery.

 

Question 8

A 20 TB restore is too slow to meet the recovery deadline even though the backup is current. Which dimension must be improved?

  1. Preprovision or automate application recovery so required compute can be restored inside the RTO.
  2. Run regular recovery tests that measure actual failover time and validate the full dependency chain.
  3. Use a replication or backup cadence that is frequent enough to meet the 15-minute RPO.
  4. Increase restore throughput and parallelize recovery operations where the service supports it.
  5. Increase the frequency of backups or continuous replication according to the required RPO.

Correct Answer: D

 

Correct Answer

Answer D is correct because A current backup still misses the RTO if the restore path cannot move and reconstruct data quickly enough. This directly satisfies the decisive requirement in the scenario: restore throughput and parallelism.

Incorrect Answers

Answer A is incorrect because RTO measures time to restore service; data protection alone does not shorten infrastructure recreation. It can be useful in other designs, but it does not satisfy the decisive requirement here: restore throughput and parallelism.

Answer B is incorrect because A theoretical design does not prove the RTO until the recovery procedure is exercised and measured. It can be useful in other designs, but it does not satisfy the decisive requirement here: restore throughput and parallelism.

Answer C is incorrect because RPO is the maximum acceptable data-loss interval, so protection points must be created at least frequently enough to stay within that window. It can be useful in other designs, but it does not satisfy the decisive requirement here: restore throughput and parallelism.

Answer E is incorrect because More frequent recovery points reduce the amount of recent change that can be lost after a failure. It can be useful in other designs, but it does not satisfy the decisive requirement here: restore throughput and parallelism.

 

Question 9

A failover environment is fully deployed but has never been exercised, and the business assumes it can meet a 20-minute RTO. What is missing?

  1. Run regular recovery tests that measure actual failover time and validate the full dependency chain.
  2. Increase the frequency of backups or continuous replication according to the required RPO.
  3. Increase restore throughput and parallelize recovery operations where the service supports it.
  4. Preprovision or automate application recovery so required compute can be restored inside the RTO.
  5. Use a replication or backup cadence that is frequent enough to meet the 15-minute RPO.

Correct Answer: A

 

Correct Answer

Answer A is correct because A theoretical design does not prove the RTO until the recovery procedure is exercised and measured. This directly satisfies the decisive requirement in the scenario: regular failover testing.

Incorrect Answers

Answer B is incorrect because More frequent recovery points reduce the amount of recent change that can be lost after a failure. It can be useful in other designs, but it does not satisfy the decisive requirement here: regular failover testing.

Answer C is incorrect because A current backup still misses the RTO if the restore path cannot move and reconstruct data quickly enough. It can be useful in other designs, but it does not satisfy the decisive requirement here: regular failover testing.

Answer D is incorrect because RTO measures time to restore service; data protection alone does not shorten infrastructure recreation. It can be useful in other designs, but it does not satisfy the decisive requirement here: regular failover testing.

Answer E is incorrect because RPO is the maximum acceptable data-loss interval, so protection points must be created at least frequently enough to stay within that window. It can be useful in other designs, but it does not satisfy the decisive requirement here: regular failover testing.

 

Question 10

A file system changes throughout the day. A daily backup creates unacceptable data-loss exposure. Which planning variable should be shortened?

  1. Increase the frequency of backups or continuous replication according to the required RPO.
  2. Run regular recovery tests that measure actual failover time and validate the full dependency chain.
  3. Preprovision or automate application recovery so required compute can be restored inside the RTO.
  4. Use a replication or backup cadence that is frequent enough to meet the 15-minute RPO.
  5. Increase restore throughput and parallelize recovery operations where the service supports it.

Correct Answer: A

 

Correct Answer

Answer A is correct because More frequent recovery points reduce the amount of recent change that can be lost after a failure. This directly satisfies the decisive requirement in the scenario: backup or replication cadence.

Incorrect Answers

Answer B is incorrect because A theoretical design does not prove the RTO until the recovery procedure is exercised and measured. It can be useful in other designs, but it does not satisfy the decisive requirement here: backup or replication cadence.

Answer C is incorrect because RTO measures time to restore service; data protection alone does not shorten infrastructure recreation. It can be useful in other designs, but it does not satisfy the decisive requirement here: backup or replication cadence.

Answer D is incorrect because RPO is the maximum acceptable data-loss interval, so protection points must be created at least frequently enough to stay within that window. It can be useful in other designs, but it does not satisfy the decisive requirement here: backup or replication cadence.

Answer E is incorrect because A current backup still misses the RTO if the restore path cannot move and reconstruct data quickly enough. It can be useful in other designs, but it does not satisfy the decisive requirement here: backup or replication cadence.

 

Question 11

An RDS database needs a point-in-time recovery copy for operational mistakes without running a second database continuously. Which protection mechanism is most appropriate?

  1. Use Amazon S3 Cross-Region Replication for the designated objects.
  2. Store protected recovery copies in a separate account or appropriately isolated backup vault.
  3. Enable S3 Versioning.
  4. Maintain a required recovery copy in a different AWS Region.
  5. Use service-native backups or snapshots with point-in-time recovery where supported.

Correct Answer: E

 

Correct Answer

Answer E is correct because Backups and snapshots provide recovery points without requiring a continuously serving second database. This directly satisfies the decisive requirement in the scenario: backup/snapshot capability.

Incorrect Answers

Answer A is incorrect because S3 replication can maintain copies of eligible objects in a destination bucket in another Region. It can be useful in other designs, but it does not satisfy the decisive requirement here: backup/snapshot capability.

Answer B is incorrect because Account or vault isolation reduces the chance that production credentials can destroy both live data and its only backup. It can be useful in other designs, but it does not satisfy the decisive requirement here: backup/snapshot capability.

Answer C is incorrect because Versioning preserves multiple object versions so accidental overwrites and deletes can be reversed when prior versions remain available. It can be useful in other designs, but it does not satisfy the decisive requirement here: backup/snapshot capability.

Answer D is incorrect because A cross-Region copy provides a data copy outside the failure boundary of a single regional event. It can be useful in other designs, but it does not satisfy the decisive requirement here: backup/snapshot capability.

 

Question 12

An application must keep a continuously updated copy of critical objects in another Region for regional recovery. Which S3 feature best matches?

  1. Maintain a required recovery copy in a different AWS Region.
  2. Enable S3 Versioning.
  3. Use service-native backups or snapshots with point-in-time recovery where supported.
  4. Store protected recovery copies in a separate account or appropriately isolated backup vault.
  5. Use Amazon S3 Cross-Region Replication for the designated objects.

Correct Answer: E

 

Correct Answer

Answer E is correct because S3 replication can maintain copies of eligible objects in a destination bucket in another Region. This directly satisfies the decisive requirement in the scenario: replication.

Incorrect Answers

Answer A is incorrect because A cross-Region copy provides a data copy outside the failure boundary of a single regional event. It can be useful in other designs, but it does not satisfy the decisive requirement here: replication.

Answer B is incorrect because Versioning preserves multiple object versions so accidental overwrites and deletes can be reversed when prior versions remain available. It can be useful in other designs, but it does not satisfy the decisive requirement here: replication.

Answer C is incorrect because Backups and snapshots provide recovery points without requiring a continuously serving second database. It can be useful in other designs, but it does not satisfy the decisive requirement here: replication.

Answer D is incorrect because Account or vault isolation reduces the chance that production credentials can destroy both live data and its only backup. It can be useful in other designs, but it does not satisfy the decisive requirement here: replication.

 

Question 13

Users sometimes overwrite or delete S3 objects accidentally and need prior object versions restored. Which S3 feature should be enabled?

  1. Maintain a required recovery copy in a different AWS Region.
  2. Store protected recovery copies in a separate account or appropriately isolated backup vault.
  3. Use Amazon S3 Cross-Region Replication for the designated objects.
  4. Use service-native backups or snapshots with point-in-time recovery where supported.
  5. Enable S3 Versioning.

Correct Answer: E

 

Correct Answer

Answer E is correct because Versioning preserves multiple object versions so accidental overwrites and deletes can be reversed when prior versions remain available. This directly satisfies the decisive requirement in the scenario: versioning.

Incorrect Answers

Answer A is incorrect because A cross-Region copy provides a data copy outside the failure boundary of a single regional event. It can be useful in other designs, but it does not satisfy the decisive requirement here: versioning.

Answer B is incorrect because Account or vault isolation reduces the chance that production credentials can destroy both live data and its only backup. It can be useful in other designs, but it does not satisfy the decisive requirement here: versioning.

Answer C is incorrect because S3 replication can maintain copies of eligible objects in a destination bucket in another Region. It can be useful in other designs, but it does not satisfy the decisive requirement here: versioning.

Answer D is incorrect because Backups and snapshots provide recovery points without requiring a continuously serving second database. It can be useful in other designs, but it does not satisfy the decisive requirement here: versioning.

 

Question 14

Administrators in the production account must not be able to delete the only recovery copy. Which backup design improves isolation?

  1. Enable S3 Versioning.
  2. Store protected recovery copies in a separate account or appropriately isolated backup vault.
  3. Use service-native backups or snapshots with point-in-time recovery where supported.
  4. Maintain a required recovery copy in a different AWS Region.
  5. Use Amazon S3 Cross-Region Replication for the designated objects.

Correct Answer: B

 

Correct Answer

Answer B is correct because Account or vault isolation reduces the chance that production credentials can destroy both live data and its only backup. This directly satisfies the decisive requirement in the scenario: cross-account protected backup.

Incorrect Answers

Answer A is incorrect because Versioning preserves multiple object versions so accidental overwrites and deletes can be reversed when prior versions remain available. It can be useful in other designs, but it does not satisfy the decisive requirement here: cross-account protected backup.

Answer C is incorrect because Backups and snapshots provide recovery points without requiring a continuously serving second database. It can be useful in other designs, but it does not satisfy the decisive requirement here: cross-account protected backup.

Answer D is incorrect because A cross-Region copy provides a data copy outside the failure boundary of a single regional event. It can be useful in other designs, but it does not satisfy the decisive requirement here: cross-account protected backup.

Answer E is incorrect because S3 replication can maintain copies of eligible objects in a destination bucket in another Region. It can be useful in other designs, but it does not satisfy the decisive requirement here: cross-account protected backup.

 

Question 15

A regional disaster must not remove both the production copy and the disaster-recovery copy. Which placement decision is required?

  1. Use service-native backups or snapshots with point-in-time recovery where supported.
  2. Store protected recovery copies in a separate account or appropriately isolated backup vault.
  3. Enable S3 Versioning.
  4. Maintain a required recovery copy in a different AWS Region.
  5. Use Amazon S3 Cross-Region Replication for the designated objects.

Correct Answer: D

 

Correct Answer

Answer D is correct because A cross-Region copy provides a data copy outside the failure boundary of a single regional event. This directly satisfies the decisive requirement in the scenario: cross-Region copy.

Incorrect Answers

Answer A is incorrect because Backups and snapshots provide recovery points without requiring a continuously serving second database. It can be useful in other designs, but it does not satisfy the decisive requirement here: cross-Region copy.

Answer B is incorrect because Account or vault isolation reduces the chance that production credentials can destroy both live data and its only backup. It can be useful in other designs, but it does not satisfy the decisive requirement here: cross-Region copy.

Answer C is incorrect because Versioning preserves multiple object versions so accidental overwrites and deletes can be reversed when prior versions remain available. It can be useful in other designs, but it does not satisfy the decisive requirement here: cross-Region copy.

Answer E is incorrect because S3 replication can maintain copies of eligible objects in a destination bucket in another Region. It can be useful in other designs, but it does not satisfy the decisive requirement here: cross-Region copy.

 

Question 16

A standby database has caught up and is ready to take writes after a regional outage. Which action establishes the new writer before application traffic is redirected?

  1. Resynchronize the repaired environment from the current authoritative data source before failback.
  2. Use explicit writer ownership and fencing so only one Region can accept writes for a single-writer data model.
  3. Promote the designated standby or otherwise establish it as the authoritative writer before directing write traffic.
  4. Update or fail over DNS/routing to the healthy recovery endpoint.
  5. Delay promotion until replication catches up to the required recovery point, unless the business explicitly accepts the resulting data loss.

Correct Answer: C

 

Correct Answer

Answer C is correct because Failover requires an explicit writer transition so applications do not send writes to an unprepared or read-only secondary. This directly satisfies the decisive requirement in the scenario: promote or designate writer.

Incorrect Answers

Answer A is incorrect because Failing back to a stale environment can discard or conflict with changes that occurred while the recovery Region was active. It can be useful in other designs, but it does not satisfy the decisive requirement here: promote or designate writer.

Answer B is incorrect because Fencing prevents split-brain writes when both environments become reachable during failover. It can be useful in other designs, but it does not satisfy the decisive requirement here: promote or designate writer.

Answer D is incorrect because Client traffic must be directed to the recovery environment after its dependencies are ready. It can be useful in other designs, but it does not satisfy the decisive requirement here: promote or designate writer.

Answer E is incorrect because The failover decision must honor the defined RPO rather than promoting an arbitrarily stale copy. It can be useful in other designs, but it does not satisfy the decisive requirement here: promote or designate writer.

 

Question 17

The recovery application is healthy but users still resolve the failed primary endpoint. Which control should be changed as part of failover?

  1. Delay promotion until replication catches up to the required recovery point, unless the business explicitly accepts the resulting data loss.
  2. Resynchronize the repaired environment from the current authoritative data source before failback.
  3. Promote the designated standby or otherwise establish it as the authoritative writer before directing write traffic.
  4. Use explicit writer ownership and fencing so only one Region can accept writes for a single-writer data model.
  5. Update or fail over DNS/routing to the healthy recovery endpoint.

Correct Answer: E

 

Correct Answer

Answer E is correct because Client traffic must be directed to the recovery environment after its dependencies are ready. This directly satisfies the decisive requirement in the scenario: DNS routing.

Incorrect Answers

Answer A is incorrect because The failover decision must honor the defined RPO rather than promoting an arbitrarily stale copy. It can be useful in other designs, but it does not satisfy the decisive requirement here: DNS routing.

Answer B is incorrect because Failing back to a stale environment can discard or conflict with changes that occurred while the recovery Region was active. It can be useful in other designs, but it does not satisfy the decisive requirement here: DNS routing.

Answer C is incorrect because Failover requires an explicit writer transition so applications do not send writes to an unprepared or read-only secondary. It can be useful in other designs, but it does not satisfy the decisive requirement here: DNS routing.

Answer D is incorrect because Fencing prevents split-brain writes when both environments become reachable during failover. It can be useful in other designs, but it does not satisfy the decisive requirement here: DNS routing.

 

Question 18

Two Regions both start accepting writes after an unplanned failover even though the data layer is not multi-writer safe. Which runbook control is missing?

  1. Resynchronize the repaired environment from the current authoritative data source before failback.
  2. Delay promotion until replication catches up to the required recovery point, unless the business explicitly accepts the resulting data loss.
  3. Use explicit writer ownership and fencing so only one Region can accept writes for a single-writer data model.
  4. Promote the designated standby or otherwise establish it as the authoritative writer before directing write traffic.
  5. Update or fail over DNS/routing to the healthy recovery endpoint.

Correct Answer: C

 

Correct Answer

Answer C is correct because Fencing prevents split-brain writes when both environments become reachable during failover. This directly satisfies the decisive requirement in the scenario: explicit write ownership/fencing.

Incorrect Answers

Answer A is incorrect because Failing back to a stale environment can discard or conflict with changes that occurred while the recovery Region was active. It can be useful in other designs, but it does not satisfy the decisive requirement here: explicit write ownership/fencing.

Answer B is incorrect because The failover decision must honor the defined RPO rather than promoting an arbitrarily stale copy. It can be useful in other designs, but it does not satisfy the decisive requirement here: explicit write ownership/fencing.

Answer D is incorrect because Failover requires an explicit writer transition so applications do not send writes to an unprepared or read-only secondary. It can be useful in other designs, but it does not satisfy the decisive requirement here: explicit write ownership/fencing.

Answer E is incorrect because Client traffic must be directed to the recovery environment after its dependencies are ready. It can be useful in other designs, but it does not satisfy the decisive requirement here: explicit write ownership/fencing.

 

Question 19

After the primary Region is repaired, it is several hours behind the active recovery Region. What must happen before failing back?

  1. Use explicit writer ownership and fencing so only one Region can accept writes for a single-writer data model.
  2. Update or fail over DNS/routing to the healthy recovery endpoint.
  3. Promote the designated standby or otherwise establish it as the authoritative writer before directing write traffic.
  4. Delay promotion until replication catches up to the required recovery point, unless the business explicitly accepts the resulting data loss.
  5. Resynchronize the repaired environment from the current authoritative data source before failback.

Correct Answer: E

 

Correct Answer

Answer E is correct because Failing back to a stale environment can discard or conflict with changes that occurred while the recovery Region was active. This directly satisfies the decisive requirement in the scenario: resynchronize data before return.

Incorrect Answers

Answer A is incorrect because Fencing prevents split-brain writes when both environments become reachable during failover. It can be useful in other designs, but it does not satisfy the decisive requirement here: resynchronize data before return.

Answer B is incorrect because Client traffic must be directed to the recovery environment after its dependencies are ready. It can be useful in other designs, but it does not satisfy the decisive requirement here: resynchronize data before return.

Answer C is incorrect because Failover requires an explicit writer transition so applications do not send writes to an unprepared or read-only secondary. It can be useful in other designs, but it does not satisfy the decisive requirement here: resynchronize data before return.

Answer D is incorrect because The failover decision must honor the defined RPO rather than promoting an arbitrarily stale copy. It can be useful in other designs, but it does not satisfy the decisive requirement here: resynchronize data before return.

 

Question 20

A standby database has not applied the latest replicated changes and is behind the RPO target. Which action is appropriate?

  1. Use explicit writer ownership and fencing so only one Region can accept writes for a single-writer data model.
  2. Delay promotion until replication catches up to the required recovery point, unless the business explicitly accepts the resulting data loss.
  3. Resynchronize the repaired environment from the current authoritative data source before failback.
  4. Promote the designated standby or otherwise establish it as the authoritative writer before directing write traffic.
  5. Update or fail over DNS/routing to the healthy recovery endpoint.

Correct Answer: B

 

Correct Answer

Answer B is correct because The failover decision must honor the defined RPO rather than promoting an arbitrarily stale copy. This directly satisfies the decisive requirement in the scenario: do not promote until recovery point is acceptable or business accepts loss.

Incorrect Answers

Answer A is incorrect because Fencing prevents split-brain writes when both environments become reachable during failover. It can be useful in other designs, but it does not satisfy the decisive requirement here: do not promote until recovery point is acceptable or business accepts loss.

Answer C is incorrect because Failing back to a stale environment can discard or conflict with changes that occurred while the recovery Region was active. It can be useful in other designs, but it does not satisfy the decisive requirement here: do not promote until recovery point is acceptable or business accepts loss.

Answer D is incorrect because Failover requires an explicit writer transition so applications do not send writes to an unprepared or read-only secondary. It can be useful in other designs, but it does not satisfy the decisive requirement here: do not promote until recovery point is acceptable or business accepts loss.

Answer E is incorrect because Client traffic must be directed to the recovery environment after its dependencies are ready. It can be useful in other designs, but it does not satisfy the decisive requirement here: do not promote until recovery point is acceptable or business accepts loss.

 

Question 21

A DR stack template is correct, but deployment fails because the target Region has a low EC2 quota. Which readiness check should have caught this?

  1. Exercise the complete dependency chain, including identity, DNS, secrets, networking, and external integrations.
  2. Validate required service quotas and available capacity in the recovery Region before a disaster.
  3. Test that recovery identities can decrypt data and use all required KMS keys.
  4. Define and test the recovery infrastructure as code.
  5. Run regular recovery exercises and record actual restore and failover results.

Correct Answer: B

 

Correct Answer

Answer B is correct because Recovery infrastructure cannot be created if the target account or Region lacks quota for required resources. This directly satisfies the decisive requirement in the scenario: quota parity/readiness.

Incorrect Answers

Answer A is incorrect because A partial component restore does not prove the application can deliver its end-to-end business function. It can be useful in other designs, but it does not satisfy the decisive requirement here: quota parity/readiness.

Answer C is incorrect because Encrypted backups are unusable during recovery if the recovery principals cannot perform the required cryptographic operations. It can be useful in other designs, but it does not satisfy the decisive requirement here: quota parity/readiness.

Answer D is incorrect because Infrastructure as code makes network, compute, and supporting resources reproducible instead of relying on manual reconstruction. It can be useful in other designs, but it does not satisfy the decisive requirement here: quota parity/readiness.

Answer E is incorrect because Execution evidence demonstrates whether the written procedure works and whether real RTO/RPO outcomes match the targets. It can be useful in other designs, but it does not satisfy the decisive requirement here: quota parity/readiness.

 

Question 22

Encrypted backups exist in another Region, but the recovery role cannot use the KMS key. Which validation should be added?

  1. Exercise the complete dependency chain, including identity, DNS, secrets, networking, and external integrations.
  2. Test that recovery identities can decrypt data and use all required KMS keys.
  3. Define and test the recovery infrastructure as code.
  4. Run regular recovery exercises and record actual restore and failover results.
  5. Validate required service quotas and available capacity in the recovery Region before a disaster.

Correct Answer: B

 

Correct Answer

Answer B is correct because Encrypted backups are unusable during recovery if the recovery principals cannot perform the required cryptographic operations. This directly satisfies the decisive requirement in the scenario: validate key and IAM access.

Incorrect Answers

Answer A is incorrect because A partial component restore does not prove the application can deliver its end-to-end business function. It can be useful in other designs, but it does not satisfy the decisive requirement here: validate key and IAM access.

Answer C is incorrect because Infrastructure as code makes network, compute, and supporting resources reproducible instead of relying on manual reconstruction. It can be useful in other designs, but it does not satisfy the decisive requirement here: validate key and IAM access.

Answer D is incorrect because Execution evidence demonstrates whether the written procedure works and whether real RTO/RPO outcomes match the targets. It can be useful in other designs, but it does not satisfy the decisive requirement here: validate key and IAM access.

Answer E is incorrect because Recovery infrastructure cannot be created if the target account or Region lacks quota for required resources. It can be useful in other designs, but it does not satisfy the decisive requirement here: validate key and IAM access.

 

Question 23

Engineers can restore the database but cannot recreate the application network consistently. Which capability should be part of the DR plan?

  1. Exercise the complete dependency chain, including identity, DNS, secrets, networking, and external integrations.
  2. Validate required service quotas and available capacity in the recovery Region before a disaster.
  3. Define and test the recovery infrastructure as code.
  4. Run regular recovery exercises and record actual restore and failover results.
  5. Test that recovery identities can decrypt data and use all required KMS keys.

Correct Answer: C

 

Correct Answer

Answer C is correct because Infrastructure as code makes network, compute, and supporting resources reproducible instead of relying on manual reconstruction. This directly satisfies the decisive requirement in the scenario: infrastructure as code.

Incorrect Answers

Answer A is incorrect because A partial component restore does not prove the application can deliver its end-to-end business function. It can be useful in other designs, but it does not satisfy the decisive requirement here: infrastructure as code.

Answer B is incorrect because Recovery infrastructure cannot be created if the target account or Region lacks quota for required resources. It can be useful in other designs, but it does not satisfy the decisive requirement here: infrastructure as code.

Answer D is incorrect because Execution evidence demonstrates whether the written procedure works and whether real RTO/RPO outcomes match the targets. It can be useful in other designs, but it does not satisfy the decisive requirement here: infrastructure as code.

Answer E is incorrect because Encrypted backups are unusable during recovery if the recovery principals cannot perform the required cryptographic operations. It can be useful in other designs, but it does not satisfy the decisive requirement here: infrastructure as code.

 

Question 24

A recovered application passes host checks but fails because an external identity provider and DNS dependency were not included in the exercise. What should change?

  1. Test that recovery identities can decrypt data and use all required KMS keys.
  2. Run regular recovery exercises and record actual restore and failover results.
  3. Validate required service quotas and available capacity in the recovery Region before a disaster.
  4. Exercise the complete dependency chain, including identity, DNS, secrets, networking, and external integrations.
  5. Define and test the recovery infrastructure as code.

Correct Answer: D

 

Correct Answer

Answer D is correct because A partial component restore does not prove the application can deliver its end-to-end business function. This directly satisfies the decisive requirement in the scenario: validate full dependency chain.

Incorrect Answers

Answer A is incorrect because Encrypted backups are unusable during recovery if the recovery principals cannot perform the required cryptographic operations. It can be useful in other designs, but it does not satisfy the decisive requirement here: validate full dependency chain.

Answer B is incorrect because Execution evidence demonstrates whether the written procedure works and whether real RTO/RPO outcomes match the targets. It can be useful in other designs, but it does not satisfy the decisive requirement here: validate full dependency chain.

Answer C is incorrect because Recovery infrastructure cannot be created if the target account or Region lacks quota for required resources. It can be useful in other designs, but it does not satisfy the decisive requirement here: validate full dependency chain.

Answer E is incorrect because Infrastructure as code makes network, compute, and supporting resources reproducible instead of relying on manual reconstruction. It can be useful in other designs, but it does not satisfy the decisive requirement here: validate full dependency chain.

 

Question 25

The company has a documented recovery procedure but has never executed it. Which activity provides the strongest readiness evidence?

  1. Run regular recovery exercises and record actual restore and failover results.
  2. Validate required service quotas and available capacity in the recovery Region before a disaster.
  3. Define and test the recovery infrastructure as code.
  4. Exercise the complete dependency chain, including identity, DNS, secrets, networking, and external integrations.
  5. Test that recovery identities can decrypt data and use all required KMS keys.

Correct Answer: A

 

Correct Answer

Answer A is correct because Execution evidence demonstrates whether the written procedure works and whether real RTO/RPO outcomes match the targets. This directly satisfies the decisive requirement in the scenario: scheduled restore/failover exercise.

Incorrect Answers

Answer B is incorrect because Recovery infrastructure cannot be created if the target account or Region lacks quota for required resources. It can be useful in other designs, but it does not satisfy the decisive requirement here: scheduled restore/failover exercise.

Answer C is incorrect because Infrastructure as code makes network, compute, and supporting resources reproducible instead of relying on manual reconstruction. It can be useful in other designs, but it does not satisfy the decisive requirement here: scheduled restore/failover exercise.

Answer D is incorrect because A partial component restore does not prove the application can deliver its end-to-end business function. It can be useful in other designs, but it does not satisfy the decisive requirement here: scheduled restore/failover exercise.

Answer E is incorrect because Encrypted backups are unusable during recovery if the recovery principals cannot perform the required cryptographic operations. It can be useful in other designs, but it does not satisfy the decisive requirement here: scheduled restore/failover exercise.

 

Question 26

A continuously replicated database copy receives the same logical corruption as the primary within seconds. Which additional protection is needed?

  1. Add a tested cross-Region recovery capability.
  2. Define a degraded-service recovery mode that prioritizes critical functions until standby capacity is scaled up.
  3. Keep independent point-in-time recovery copies in addition to continuous replication.
  4. Use measured results from a realistic recovery exercise.
  5. Use isolated, immutable, or strongly protected backup copies that production administrators cannot readily delete.

Correct Answer: C

 

Correct Answer

Answer C is correct because Replication improves freshness but can also propagate logical corruption, so older protected recovery points remain necessary. This directly satisfies the decisive requirement in the scenario: point-in-time backups/versioned recovery points.

Incorrect Answers

Answer A is incorrect because Multi-AZ design stays within one Region and therefore does not address a failure that removes the entire Region. It can be useful in other designs, but it does not satisfy the decisive requirement here: point-in-time backups/versioned recovery points.

Answer B is incorrect because Warm standby can intentionally start smaller than production, so the runbook should state which services are guaranteed during the initial recovery period. It can be useful in other designs, but it does not satisfy the decisive requirement here: point-in-time backups/versioned recovery points.

Answer D is incorrect because A timed exercise provides direct evidence of actual recovery duration and exposes hidden dependencies. It can be useful in other designs, but it does not satisfy the decisive requirement here: point-in-time backups/versioned recovery points.

Answer E is incorrect because Backup isolation protects the recovery copy from the same credential compromise or destructive action that affects production. It can be useful in other designs, but it does not satisfy the decisive requirement here: point-in-time backups/versioned recovery points.

 

Question 27

A ransomware event compromises production administrator credentials. Which backup characteristic most improves recoverability?

  1. Use measured results from a realistic recovery exercise.
  2. Keep independent point-in-time recovery copies in addition to continuous replication.
  3. Define a degraded-service recovery mode that prioritizes critical functions until standby capacity is scaled up.
  4. Add a tested cross-Region recovery capability.
  5. Use isolated, immutable, or strongly protected backup copies that production administrators cannot readily delete.

Correct Answer: E

 

Correct Answer

Answer E is correct because Backup isolation protects the recovery copy from the same credential compromise or destructive action that affects production. This directly satisfies the decisive requirement in the scenario: isolated or immutable backup.

Incorrect Answers

Answer A is incorrect because A timed exercise provides direct evidence of actual recovery duration and exposes hidden dependencies. It can be useful in other designs, but it does not satisfy the decisive requirement here: isolated or immutable backup.

Answer B is incorrect because Replication improves freshness but can also propagate logical corruption, so older protected recovery points remain necessary. It can be useful in other designs, but it does not satisfy the decisive requirement here: isolated or immutable backup.

Answer C is incorrect because Warm standby can intentionally start smaller than production, so the runbook should state which services are guaranteed during the initial recovery period. It can be useful in other designs, but it does not satisfy the decisive requirement here: isolated or immutable backup.

Answer D is incorrect because Multi-AZ design stays within one Region and therefore does not address a failure that removes the entire Region. It can be useful in other designs, but it does not satisfy the decisive requirement here: isolated or immutable backup.

 

Question 28

A workload already spans three AZs but the business must survive loss of the entire Region. Which added failure boundary is necessary?

  1. Keep independent point-in-time recovery copies in addition to continuous replication.
  2. Add a tested cross-Region recovery capability.
  3. Use measured results from a realistic recovery exercise.
  4. Use isolated, immutable, or strongly protected backup copies that production administrators cannot readily delete.
  5. Define a degraded-service recovery mode that prioritizes critical functions until standby capacity is scaled up.

Correct Answer: B

 

Correct Answer

Answer B is correct because Multi-AZ design stays within one Region and therefore does not address a failure that removes the entire Region. This directly satisfies the decisive requirement in the scenario: cross-Region recovery environment.

Incorrect Answers

Answer A is incorrect because Replication improves freshness but can also propagate logical corruption, so older protected recovery points remain necessary. It can be useful in other designs, but it does not satisfy the decisive requirement here: cross-Region recovery environment.

Answer C is incorrect because A timed exercise provides direct evidence of actual recovery duration and exposes hidden dependencies. It can be useful in other designs, but it does not satisfy the decisive requirement here: cross-Region recovery environment.

Answer D is incorrect because Backup isolation protects the recovery copy from the same credential compromise or destructive action that affects production. It can be useful in other designs, but it does not satisfy the decisive requirement here: cross-Region recovery environment.

Answer E is incorrect because Warm standby can intentionally start smaller than production, so the runbook should state which services are guaranteed during the initial recovery period. It can be useful in other designs, but it does not satisfy the decisive requirement here: cross-Region recovery environment.

 

Question 29

Management wants to know whether the DR plan meets its 45-minute RTO. Which evidence is most persuasive?

  1. Add a tested cross-Region recovery capability.
  2. Define a degraded-service recovery mode that prioritizes critical functions until standby capacity is scaled up.
  3. Keep independent point-in-time recovery copies in addition to continuous replication.
  4. Use isolated, immutable, or strongly protected backup copies that production administrators cannot readily delete.
  5. Use measured results from a realistic recovery exercise.

Correct Answer: E

 

Correct Answer

Answer E is correct because A timed exercise provides direct evidence of actual recovery duration and exposes hidden dependencies. This directly satisfies the decisive requirement in the scenario: measured recovery exercise.

Incorrect Answers

Answer A is incorrect because Multi-AZ design stays within one Region and therefore does not address a failure that removes the entire Region. It can be useful in other designs, but it does not satisfy the decisive requirement here: measured recovery exercise.

Answer B is incorrect because Warm standby can intentionally start smaller than production, so the runbook should state which services are guaranteed during the initial recovery period. It can be useful in other designs, but it does not satisfy the decisive requirement here: measured recovery exercise.

Answer C is incorrect because Replication improves freshness but can also propagate logical corruption, so older protected recovery points remain necessary. It can be useful in other designs, but it does not satisfy the decisive requirement here: measured recovery exercise.

Answer D is incorrect because Backup isolation protects the recovery copy from the same credential compromise or destructive action that affects production. It can be useful in other designs, but it does not satisfy the decisive requirement here: measured recovery exercise.

 

Question 30

A warm-standby environment is intentionally smaller than production. During failover, it can support critical APIs but not batch reporting. Which runbook behavior best reflects the design?

  1. Define a degraded-service recovery mode that prioritizes critical functions until standby capacity is scaled up.
  2. Use isolated, immutable, or strongly protected backup copies that production administrators cannot readily delete.
  3. Keep independent point-in-time recovery copies in addition to continuous replication.
  4. Use measured results from a realistic recovery exercise.
  5. Add a tested cross-Region recovery capability.

Correct Answer: A

 

Correct Answer

Answer A is correct because Warm standby can intentionally start smaller than production, so the runbook should state which services are guaranteed during the initial recovery period. This directly satisfies the decisive requirement in the scenario: document and enforce recovery service priorities.

Incorrect Answers

Answer B is incorrect because Backup isolation protects the recovery copy from the same credential compromise or destructive action that affects production. It can be useful in other designs, but it does not satisfy the decisive requirement here: document and enforce recovery service priorities.

Answer C is incorrect because Replication improves freshness but can also propagate logical corruption, so older protected recovery points remain necessary. It can be useful in other designs, but it does not satisfy the decisive requirement here: document and enforce recovery service priorities.

Answer D is incorrect because A timed exercise provides direct evidence of actual recovery duration and exposes hidden dependencies. It can be useful in other designs, but it does not satisfy the decisive requirement here: document and enforce recovery service priorities.

Answer E is incorrect because Multi-AZ design stays within one Region and therefore does not address a failure that removes the entire Region. It can be useful in other designs, but it does not satisfy the decisive requirement here: document and enforce recovery service priorities.

img