CTO Business Continuity & Disaster Recovery 2 — Questions and Answers
Question 1: What characterizes a 'warm standby' disaster recovery configuration?
- A fully operational duplicate with real-time data replication and immediate failover capability
- An empty facility with only basic utilities available for equipment setup
- A scaled-down but functional replica that can be scaled up rapidly when needed (Correct answer)
- A cloud-based snapshot of production systems refreshed on a weekly schedule
Correct answer: A scaled-down but functional replica that can be scaled up rapidly when needed
A warm standby maintains a scaled-down but operational replica of the production environment that can be quickly scaled up during a disaster, balancing recovery speed and ongoing cost.
Question 2: In cloud-based DR architectures, what does the 'pilot light' approach refer to?
- A real-time mirroring of all production systems to a cloud region
- A notification system that alerts recovery teams when disasters are detected
- A full duplicate environment kept in a powered-off state in the cloud
- A minimal core infrastructure kept running that can be rapidly scaled during recovery (Correct answer)
Correct answer: A minimal core infrastructure kept running that can be rapidly scaled during recovery
Pilot light keeps only the most critical, minimal core infrastructure continuously running in the cloud, which can be rapidly expanded to full production capacity when a disaster strikes.
Question 3: What does Mean Time To Recovery (MTTR) measure in IT operations and BC/DR programs?
- The maximum acceptable period of disruption for a critical business function
- The interval between scheduled preventive maintenance windows
- The frequency of backup creation and validation cycles
- The average time required to restore a failed system to normal operation (Correct answer)
Correct answer: The average time required to restore a failed system to normal operation
MTTR measures the average time it takes to diagnose, repair, and restore a failed system to full functionality, reflecting the real-world efficiency of an organization's recovery operations.
Question 4: What is the CTO's primary responsibility in enterprise BC/DR planning and governance?
- Writing detailed step-by-step technical recovery runbooks for all systems
- Negotiating cyber insurance policies and determining coverage limits
- Ensuring technology resilience strategies align with business continuity requirements and risk tolerance (Correct answer)
- Managing physical security protocols at all backup and recovery sites
Correct answer: Ensuring technology resilience strategies align with business continuity requirements and risk tolerance
The CTO ensures that technology DR strategies align with the organization's business continuity requirements, risk appetite, and strategic objectives, operating at the governance and alignment level.
Question 5: What is the key objective of a tabletop exercise in an organization's BC/DR testing program?
- To physically test the failover of production systems to backup infrastructure under load
- To identify gaps and weaknesses in recovery plans through scenario-based discussion (Correct answer)
- To verify the integrity of backup data through full restoration to a test environment
- To formally certify that all recovery team members meet qualification requirements
Correct answer: To identify gaps and weaknesses in recovery plans through scenario-based discussion
Tabletop exercises enable teams to walk through disaster scenarios and identify plan weaknesses and role ambiguities without risking operational disruption or activating recovery systems.
Question 6: Which international standard specifically addresses the requirements for Business Continuity Management Systems (BCMS)?
- ISO 27001 — Information Security Management Systems
- NIST SP 800-53 — Security and Privacy Controls
- ISO 9001 — Quality Management Systems
- ISO 22301 — Business Continuity Management Systems (Correct answer)
Correct answer: ISO 22301 — Business Continuity Management Systems
ISO 22301 is the international standard specifically designed for Business Continuity Management Systems, providing requirements for planning, implementing, maintaining, and improving continuity capabilities.
Question 7: What is the correct distinction between 'failover' and 'failback' in disaster recovery operations?
- Failover switches workloads to backup systems; failback returns operations to the primary system after recovery (Correct answer)
- Failover applies to hardware failures only; failback applies to software or application failures
- Failover is always an automated process; failback is always performed manually
- Failover is used for planned maintenance windows; failback is used for unplanned outage recovery
Correct answer: Failover switches workloads to backup systems; failback returns operations to the primary system after recovery
Failover redirects workloads to backup systems during a disruption, while failback is the subsequent process of returning operations to the restored primary environment once it is validated.
What characterizes a 'warm standby' disaster recovery configuration?