Lesson 27: Backup, Recovery Strategies, Disaster Recovery, and Business Continuity Operations

Lesson 28/28 | Study Time: 15 Min

Lesson Twenty-Seven

Backup, Recovery Strategies, Disaster Recovery, and Business Continuity Operations

SierraTec Secure CISSP Certification Preparation Course


Lesson Overview

Organizations dependenue;

  • communications;

  • safety;

  • customer services;

  • logistics;

  • regulatory obligations;

  • critical business processes.

Eventually, something will fail.

The failure may result from:

  • ransomware;

  • hardware failure;

  • power loss;

  • fire;

  • flood;

  • human error;

  • software corruption;

  • telecommunications failure;

  • cloud outage;

  • supply-chain disruption;

  • natural disaster;

  • malicious attack.

Security therefore cannot focus only on:

preventing disruption.

It must also answer:

How will the organization continue critical operations and recover when disruption occurs?

That requires several related but distinct disciplines:

BACKUP
↓
RECOVERY
↓
DISASTER RECOVERY
↓
BUSINESS CONTINUITY
↓
ORGANIZATIONAL RESILIENCE

The current CISSP Examination Outline places this lesson primarily under Domain 7 β€” Security Operations, Objectives 7.10 through 7.13.

7.10 β€” Implement recovery strategies

Including:

  • backup storage strategies such as cloud, onsite, and offsite;

  • recovery-site strategies such as cold and hot sites and resource-capacity agreements;

  • multiple processing sites;

  • system resilience;

  • high availability;

  • Quality of Service;

  • fault tolerance.

7.11 β€” Implement Disaster Recovery processes

Including:

  • response;

  • personnel;

  • communications;

  • assessment;

  • restoration;

  • training and awareness;

  • lessons learned.

7.12 β€” Test Disaster Recovery Plans

Including:

  • read-through/tabletop;

  • walkthrough;

  • simulation;

  • parallel;

  • full interruption;

  • stakeholder, test-status, and regulator communications.

7.13 β€” Participate in Business Continuity planning and exercises.

NIST continues to list SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems, as its final contingency-planning guide. It connects contingency planning with the Business Impact Analysis, preventive controls, recovery strategies, plan development, testing/training/exercises, and plan maintenance.

NIST SP 800-184 further emphasizes recovery planning, resource prioritization, realistic recovery exercises, recovery playbooks, and continual improvement after cybersecurity events.

The central Lesson Twenty-Seven question is:

How should an organization design, implement, test, and continuously improve backup, recovery, disaster-recovery, and business-continuity capabilities so critical operations can survive disruption and return to a trusted state within defined business requirements?


CISSP Exam Objective Alignment

Lesson TopicPrimary Alignment
Recovery strategies7.10
Backup strategy7.10
Cloud backup7.10
Onsite backup7.10
Offsite backup7.10
Offline backup7.10 supporting concept
Immutable backup7.10 supporting concept
Backup testing7.10 / 7.12
Recovery sites7.10
Cold site7.10
Warm site7.10 supporting concept
Hot site7.10
Resource-capacity agreement7.10
Multiple processing sites7.10
High availability7.10
Fault tolerance7.10
QoS7.10
Redundancy7.10
Failover7.10
Replication7.10
RTO7.10 / BIA bridge
RPO7.10 / BIA bridge
Disaster Recovery7.11
DR activation7.11
Personnel7.11
DR communications7.11
Damage assessment7.11
Restoration7.11
Recovery validation7.11
Failback7.11
DR training7.11
Lessons learned7.11
Read-through/tabletop7.12
Walkthrough7.12
Simulation7.12
Parallel test7.12
Full interruption7.12
DR test communications7.12
Business Continuity7.13
Manual workarounds7.13
Alternate staffing7.13
Critical suppliers7.13
Alternate facilities7.13
BC exercises7.13
Organizational resilience7.10–7.13

Learning Objectives

After completing this lesson, you should be able to:

  1. Define resilience.

  2. Distinguish backup, recovery, DR, and BC.

  3. Explain the relationship between the BIA and recovery strategy.

  4. Define RTO.

  5. Define RPO.

  6. Explain maximum tolerable downtime conceptually.

  7. Explain recovery priorities.

  8. Define a backup.

  9. Explain full backups.

  10. Explain incremental backups.

  11. Explain differential backups.

  12. Compare incremental and differential restoration.

  13. Explain snapshots.

  14. Explain replication.

  15. Distinguish replication from backup.

  16. Explain onsite backup.

  17. Explain offsite backup.

  18. Explain cloud backup.

  19. Explain online backup.

  20. Explain offline backup.

  21. Explain immutable backup.

  22. Explain air-gapped backup conceptually.

  23. Explain the 3-2-1 backup concept.

  24. Explain backup encryption.

  25. Explain backup-key protection.

  26. Explain backup integrity.

  27. Explain restoration testing.

  28. Explain why backup-job success does not prove recoverability.

  29. Explain backup retention.

  30. Explain backup accounts and least privilege.

  31. Explain ransomware-resistant backup design.

  32. Explain recovery sites.

  33. Define a cold site.

  34. Define a warm site.

  35. Define a hot site.

  36. Compare recovery-site cost and recovery speed.

  37. Explain reciprocal agreements.

  38. Explain resource-capacity agreements.

  39. Explain multiple processing sites.

  40. Explain active-active architecture.

  41. Explain active-passive architecture.

  42. Explain failover.

  43. Explain failback.

  44. Explain high availability.

  45. Explain fault tolerance.

  46. Distinguish HA from fault tolerance.

  47. Explain redundancy.

  48. Explain common-mode failure.

  49. Explain geographic diversity.

  50. Explain QoS.

  51. Explain DR-plan activation.

  52. Explain damage assessment.

  53. Explain personnel requirements.

  54. Explain emergency communications.

  55. Explain restoration priorities.

  56. Explain system dependencies.

  57. Explain clean recovery.

  58. Explain recovery validation.

  59. Explain DR training.

  60. Explain lessons learned.

  61. Explain DR read-through/tabletop testing.

  62. Explain walkthrough testing.

  63. Explain simulation testing.

  64. Explain parallel testing.

  65. Explain full-interruption testing.

  66. Compare DR testing risk and realism.

  67. Explain DR-test communications.

  68. Explain BC.

  69. Distinguish BC from DR.

  70. Distinguish Incident Response from DR.

  71. Explain manual business workarounds.

  72. Explain alternate staffing.

  73. Explain supplier continuity.

  74. Explain business-process dependencies.

  75. Apply CISSP FIRST/BEST/MOST reasoning to recovery scenarios.


Part I β€” Organizational Resilience

1. Resilience

Resilience is the ability of an organization or system to:

  • withstand disruption;

  • continue essential functions;

  • recover;

  • adapt.


2. Security Is Not Only Prevention

An organization can invest heavily in prevention and still experience disruption.

Therefore:

PREVENTION
+
DETECTION
+
RESPONSE
+
RECOVERY
=
RESILIENCE

Part II β€” Backup, Recovery, DR, and BC

3. Backup

A backup is a retained copy of information or system state intended to support restoration.


4. Recovery

Recovery restores:

  • information;

  • applications;

  • systems;

  • services

after disruption.


5. Disaster Recovery

Disaster Recovery focuses primarily on restoring:

information technology capabilities and supporting infrastructure after a significant disruption.


6. Business Continuity

Business Continuity focuses on:

continuing critical business functions during and after disruption.


Part III β€” Key Distinction

7.

BACKUP
"Do we have recoverable copies?"

RECOVERY
"Can we restore?"

DR
"Can technology operations be restored?"

BC
"Can critical business operations continue?"

Part IV β€” DR Is Not the Same as BC

8. Example

A hurricane destroys the primary office.

IT successfully activates systems in another region.

But:

  • staff cannot work;

  • supplier cannot deliver;

  • customer call center is unavailable.

Technology recovered.

Business continuity did not.


Part V β€” Incident Response vs DR

9. Incident Response

Incident response focuses on:

  • detecting;

  • containing;

  • investigating;

  • remediating

security incidents.


10. Disaster Recovery

DR focuses on:

restoring disrupted technology capability.


11. Relationship

SECURITY INCIDENT
↓
INCIDENT RESPONSE
↓
MAJOR SERVICE DISRUPTION?
β”œβ”€β”€ NO β†’ Normal remediation
└── YES
↓
DISASTER RECOVERY
↓
BUSINESS CONTINUITY

Part VI β€” Business Impact Analysis

12. Recovery Priorities Must Come From Business Need

Do not begin DR planning by asking:

β€œWhich server is technically most powerful?”

Ask:

Which business functions are most critical?


13. BIA Relationship

The Business Impact Analysis helps determine:

  • critical processes;

  • dependencies;

  • acceptable disruption;

  • recovery priorities.


14. Strategy Flow

BUSINESS PROCESS
↓
BIA
↓
RECOVERY REQUIREMENTS
↓
RTO / RPO
↓
RECOVERY STRATEGY
↓
TECHNOLOGY

Part VII β€” Recovery Time Objective

15. RTO

NIST defines the Recovery Time Objective as the overall length of time system components can remain in the recovery phase before negatively affecting organizational mission or business processes.

Simplified CISSP memory:

How quickly must the service be recovered?


16. Example

RTO:

4 hours.

The organization designs recovery capability intended to restore the required service within that target.


Part VIII β€” Recovery Point Objective

17. RPO

NIST defines RPO as:

the point in time to which data must be recovered after an outage.

Simplified exam memory:

How much data loss in time can the organization tolerate?


18. Example

RPO:

30 minutes.

Recovery should ideally restore information to no more than approximately 30 minutes before the disruption, subject to the defined strategy.


Part IX β€” RTO vs RPO

19.

ObjectiveMain Question
RTOHow long can recovery take?
RPOHow far back can recovered data go?

20. Memory Diagram

FAILURE OCCURS
β”‚
│◄──── RPO ────► Previous recoverable point
β”‚
└─────► RTO ─────► Service restored

Part X β€” RTO Does Not Equal RPO

21. Example

RPO:

15 minutes.

RTO:

8 hours.

The organization may tolerate only 15 minutes of data loss while accepting up to eight hours to restore the service.


Part XI β€” Maximum Tolerable Downtime

22. MTD / MTD-Like Concepts

Organizations may use terms such as:

  • Maximum Tolerable Downtime;

  • Maximum Allowable Downtime.

Terminology can vary.

Conceptually:

At what point does the outage create unacceptable harm to the business?


23. CISSP Relationship

The recovery design should ensure:

RTO does not exceed the organization's maximum tolerable outage requirement.


Part XII β€” Recovery Objectives Are Business Decisions

24. Important Principle

The system administrator should not independently decide:

β€œRTO is 10 minutes.”

Recovery objectives should originate from:

  • business need;

  • BIA;

  • risk;

  • management.


Part XIII β€” Cost of Recovery

25. Faster Recovery Usually Costs More

LONGER RTO
Lower-cost recovery may be acceptable

↓

VERY SHORT RTO
Higher-cost resilience may be required

Part XIV β€” Backup Fundamentals

26. Backup Purpose

Backups protect against:

  • accidental deletion;

  • corruption;

  • ransomware;

  • hardware failure;

  • disaster.


Part XV β€” Backup Is Not the Same as Availability

27. Example

You have a perfect backup.

Production database fails.

Restore time:

16 hours.

If the business requires:

5-minute availability,

backup alone is insufficient.

You may need:

  • replication;

  • clustering;

  • fault tolerance;

  • HA.


Part XVI β€” Full Backup

28. Full Backup

A full backup copies the complete defined backup set.


29. Advantages

  • simple restoration;

  • fewer backup sets required during recovery.


30. Disadvantages

Typically requires:

  • more storage;

  • more backup time.


Part XVII β€” Incremental Backup

31. Incremental

Copies data changed since the most recent backup of the relevant sequence, whether full or incremental.


32. Example

SUNDAY
Full

MONDAY
Changes since Sunday

TUESDAY
Changes since Monday

WEDNESDAY
Changes since Tuesday

Part XVIII β€” Incremental Restore

33. Restore Requirements

To restore Wednesday:

SUNDAY FULL
+
MONDAY INCREMENTAL
+
TUESDAY INCREMENTAL
+
WEDNESDAY INCREMENTAL

34. Advantage

Generally:

smaller/faster daily backup operations.


35. Disadvantage

Recovery can be:

more complex and potentially slower.


Part XIX β€” Differential Backup

36. Differential

Copies data changed since the most recent full backup.


37. Example

SUNDAY
FULL

MONDAY
Changes since Sunday

TUESDAY
All changes since Sunday

WEDNESDAY
All changes since Sunday

Part XX β€” Differential Restore

38. Restore Wednesday

Requires:

SUNDAY FULL
+
WEDNESDAY DIFFERENTIAL

Part XXI β€” Incremental vs Differential

39.

IncrementalDifferential
Changes since latest backupChanges since latest full
Smaller daily backupGrows during cycle
More restore setsFewer restore sets
Restore can be slowerRestore often simpler

Part XXII β€” Exam Trap

40.

Incremental:

full + all required incrementals.

Differential:

full + latest differential.


Part XXIII β€” Snapshot

41. Snapshot

A snapshot captures a point-in-time state of a storage or computing resource.


42. Snapshot Benefits

Can support:

  • rapid rollback;

  • quick recovery;

  • testing.


Part XXIV β€” Snapshot Limitation

43. Snapshot β‰  Automatically Independent Backup

If a snapshot depends on the same:

  • storage system;

  • administrator;

  • cloud account

as production, compromise of that environment may affect both.


Part XXV β€” Replication

44. Replication

Replication maintains copies of data or services across multiple locations or systems.


Part XXVI β€” Replication Advantage

45. It Can Reduce

  • recovery time;

  • service interruption.


Part XXVII β€” Replication Risk

46. Corruption Can Replicate

Suppose ransomware encrypts:

Production Database A.

Real-time replication may faithfully replicate:

encrypted/corrupted data

to Database B.


47. Key Principle

Replication β‰  Backup

Replication improves:

availability.

Backup provides:

recoverable historical copies.


Part XXVIII β€” Onsite Backups

48. Onsite

Stored near or within the primary facility.

Advantages:

  • fast access;

  • potentially rapid restoration.


49. Risk

A single event could affect:

  • production;

  • onsite backup.

Examples:

  • fire;

  • flood;

  • theft;

  • ransomware.


Part XXIX β€” Offsite Backups

50. Offsite

Stored geographically separate from production.

Helps reduce:

common-site disaster risk.


Part XXX β€” Cloud Backup

51. Cloud Storage

Current CISSP Objective 7.10 explicitly includes cloud backup/storage strategies.

Benefits may include:

  • geographic separation;

  • scalability;

  • managed storage.


Part XXXI β€” Cloud Backup Risks

52. Consider

  • shared responsibility;

  • cloud identity compromise;

  • provider availability;

  • vendor dependence;

  • deletion privileges;

  • recovery bandwidth.


Part XXXII β€” Online Backup

53. Online Backup

Continuously or routinely accessible through the operating environment or network.

Advantage:

convenient recovery.

Risk:

attackers may reach it.


Part XXXIII β€” Offline Backup

54. Offline Backup

Not continuously accessible from production.

This can reduce exposure to ransomware.

CISA recommends maintaining offline, encrypted backups of critical data and regularly testing backup availability and integrity during disaster-recovery scenarios.


Part XXXIV β€” Immutable Backups

55. Immutable

An immutable backup is designed so stored backup data cannot be altered or deleted during the defined retention period.


56. Security Value

This may reduce the attacker's ability to:

  • encrypt;

  • delete;

  • modify

recovery data.

CISA ransomware guidance also emphasizes encrypted, protected, and where appropriate immutable backup capabilities.


Part XXXV β€” Immutable Does Not Mean Invulnerable

57. Possible Problems

  • misconfiguration;

  • compromised administrative controls;

  • corrupted source data;

  • insufficient retention.


Part XXXVI β€” Air Gap

58. Air-Gapped Backup Concept

An air gap creates strong separation between:

backup resources

and:

production systems.

This may be:

  • physical;

  • logical,

depending on architecture.


Part XXXVII β€” Separation Is the Point

59.

PRODUCTION
β”‚
X
β”‚
PROTECTED BACKUP

The objective is to prevent the same attacker or failure from easily compromising both environments.


Part XXXVIII β€” 3-2-1 Backup Concept

60. Common Strategy

A commonly referenced resilience strategy is:

  • 3 copies of data;

  • 2 different media/storage forms;

  • 1 copy offsite.

CISA advisories have referenced the 3-2-1 approach through allied cyber-security guidance.


61. Exam Qualification

Do not treat 3-2-1 as:

the only valid CISSP recovery architecture.

The exam principle is:

eliminate single points of failure and protect recovery copies from the same event that compromises production.


Part XXXIX β€” Enhanced Modern Backup Thinking

62. Strong Recovery Design May Add

  • offline copy;

  • immutable copy;

  • geographic separation;

  • separate administrative credentials;

  • tested restoration.


Part XL β€” Backup Encryption

63. Backups Contain Real Data

A backup can contain:

  • sensitive customer records;

  • passwords or hashes;

  • intellectual property;

  • regulated data.

Protect confidentiality appropriately.


Part XLI β€” Backup Key Management

64. Critical Trap

Encrypted backup with lost encryption key:

unusable backup.


65. Recovery Design Must Protect

BACKUP DATA
+
DECRYPTION KEY
+
RESTORE SOFTWARE
+
DOCUMENTATION

Part XLII β€” Separate Backup Administration

66. Privilege Risk

If the same compromised administrator account can:

  • modify production;

  • delete backup;

  • alter retention,

ransomware impact can increase.


67. Better Principle

Use:

  • least privilege;

  • separate roles;

  • strong authentication;

  • protected administrative paths.


Part XLIII β€” Backup Integrity

68. Successful Copy Does Not Guarantee Integrity

A backup may contain:

  • corrupted data;

  • malware;

  • incomplete application state.


Part XLIV β€” Backup Verification

69. Better Process

BACKUP
↓
VERIFY CREATION
↓
VERIFY INTEGRITY
↓
RESTORE TEST
↓
VALIDATE APPLICATION / DATA

Part XLV β€” Restoration Testing

70. Most Important Backup Question

Not:

β€œDid backup software say success?”

But:

Can the organization actually restore the required service and data?

CISA specifically recommends regular testing of backup procedures and backup availability/integrity.


Part XLVI β€” Restore Test Levels

71. Possible Tests

  • restore single file;

  • restore database;

  • restore server;

  • rebuild critical service;

  • recover complete environment.


Part XLVII β€” Test Against RTO and RPO

72.

A backup may restore successfully but:

  • take too long;

  • contain data too old.

Therefore test:

restoration and business recovery objectives.


Part XLVIII β€” Backup Retention

73. Retention

Determines how long recovery versions remain available.

Factors include:

  • recovery needs;

  • regulation;

  • legal requirements;

  • ransomware dwell time;

  • storage cost.


Part XLIX β€” Long-Dwell Attackers

74. Example

Attacker gains persistence:

January 1.

Ransomware activates:

March 1.

If backups retain only:

seven days,

all retained images might already contain attacker persistence.


Part L β€” Recovery Point Diversity

75. Value of Historical Recovery Points

Multiple generations can help recover from:

  • delayed discovery;

  • corruption;

  • ransomware.


Part LI β€” Backup Monitoring

76. Monitor

  • job failures;

  • missed assets;

  • deletion attempts;

  • administrative changes;

  • capacity.


Part LII β€” Backup Scope

77. What Must Be Backed Up?

Not only user files.

Potentially:

  • configuration;

  • databases;

  • system images;

  • encryption-related information;

  • application binaries;

  • infrastructure definitions;

  • critical documentation.

CISA's ransomware guidance recommends maintaining golden images and protected copies of critical rebuilding resources, including infrastructure-as-code templates where applicable.


Part LIII β€” Recovery Documentation

78. During Major Outage

Do not assume teams can access:

documentation stored only on the failed network.

Maintain appropriate protected copies.


Part LIV β€” Recovery Sites

79. Alternate Processing Site

A recovery site provides facilities or resources for restoring operations when the primary site is unavailable.


Part LV β€” Cold Site

80. Cold Site

Typically provides:

  • physical facility;

  • power;

  • basic environmental capability;

  • communications potential.

But limited preinstalled operational systems.


81. Advantages

  • lower recurring cost.


82. Disadvantages

  • longer recovery time;

  • equipment/configuration must be established.


Part LVI β€” Warm Site

83. Warm Site

Typically represents an intermediate option.

May include:

  • some equipment;

  • connectivity;

  • partial configuration.


84. Tradeoff

COLD
Low cost / Slow recovery

WARM
Medium cost / Medium recovery

HOT
High cost / Fast recovery

Part LVII β€” Hot Site

85. Hot Site

Provides a highly prepared alternate environment with:

  • hardware;

  • network connectivity;

  • system capability;

  • supporting infrastructure.


86. Advantage

Can support:

much faster recovery.


87. Disadvantage

Typically:

significantly more expensive.


Part LVIII β€” Site Comparison

88.

SiteReadinessCostRecovery Speed
ColdLowLowerSlow
WarmModerateMediumMedium
HotHighHigherFast

Exact designs vary.


Part LIX β€” Exam Trap

89. Hot Site Does Not Mean Zero Recovery Work

Teams may still need to:

  • synchronize data;

  • validate systems;

  • redirect users;

  • test applications.


Part LX β€” Reciprocal Agreement

90. Reciprocal Arrangement

Two organizations agree to provide recovery capability to each other.


Part LXI β€” Advantage

91.

Can reduce:

cost.


Part LXII β€” Risks

92.

Questions include:

  • Do systems have compatible capacity?

  • What if both experience the same disaster?

  • Will resources actually be available?

  • Is the agreement tested?


Part LXIII β€” Resource-Capacity Agreements

93. Current Exam Topic

Current Objective 7.10 specifically lists resource capacity agreements as a recovery-site strategy.


94. Concept

A contractual arrangement ensures defined processing or infrastructure resources can be made available during a recovery event.


Part LXIV β€” Capacity Matters

95. Example

Provider has recovery facility.

But contract guarantees only:

20 virtual machines.

Organization requires:

The site exists.

The required recovery capability does not.


Part LXV β€” Multiple Processing Sites

96. Current CISSP Topic

Objective 7.10 explicitly includes multiple processing sites.


Part LXVI β€” Active-Active

97. Active-Active

Multiple locations actively process production workloads.

SITE A  ◄────►  SITE B

Both serving production

98. Benefit

Can provide:

  • rapid failover;

  • load distribution;

  • high availability.


Part LXVII β€” Active-Passive

99. Active-Passive

One site handles production while another is prepared to assume service.

SITE A
ACTIVE
β”‚
β”œβ”€β”€ replication
β–Ό
SITE B
PASSIVE / STANDBY

Part LXVIII β€” Failover

100. Failover

Movement of service from:

failed or degraded component

to:

alternate component or site.


Part LXIX β€” Automatic vs Manual Failover

101.

Automatic:

  • faster;

  • more complex;

  • poor detection logic can cause unnecessary failover.

Manual:

  • slower;

  • more operator control.


Part LXX β€” Failback

102. Failback

Moving operations from the alternate environment back to the repaired/preferred environment.


Part LXXI β€” Failback Can Be Risky

103.

It may require:

  • data synchronization;

  • downtime;

  • validation;

  • careful sequencing.


Part LXXII β€” High Availability

104. HA

High availability attempts to minimize service interruption through:

  • redundancy;

  • clustering;

  • failover;

  • resilient design.


Part LXXIII β€” High Availability Goal

105.

COMPONENT FAILURE
↓
ALTERNATE CAPACITY
↓
SERVICE CONTINUES

Part LXXIV β€” Fault Tolerance

106. Fault Tolerance

Fault tolerance allows a system to continue operating despite failure of one or more components within its design tolerance.


Part LXXV β€” Fault Tolerance vs HA

107.

High Availability:

minimize downtime.

Fault Tolerance:

continue operation through certain failures, often with little or no service interruption.


Part LXXVI β€” Example

108.

HA:

Server fails β†’ cluster fails over after brief interruption.

Fault tolerance:

Component fails β†’ redundant component immediately continues operation without meaningful loss of service.


Part LXXVII β€” Redundancy

109. Redundancy

Provides additional components such as:

  • power supplies;

  • network paths;

  • servers;

  • storage.


Part LXXVIII β€” Redundancy Is Not Enough

110. Common-Mode Failure

Two redundant systems may depend on the same:

  • power source;

  • network carrier;

  • building;

  • cloud region;

  • administrator account.

One event can then affect both.


Part LXXIX β€” Diversity

111. Better Design

PRIMARY SITE
β”‚
POWER A
CARRIER A
REGION A

ALTERNATE SITE
β”‚
POWER B
CARRIER B
REGION B

where business requirements justify that level of diversity.


Part LXXX β€” Geographic Diversity

112. Distance Matters

Alternate environments located too close together may both be affected by:

  • hurricane;

  • earthquake;

  • regional outage;

  • civil emergency.


Part LXXXI β€” Distance Tradeoff

113.

Too close:

common disaster risk.

Too far:

latency, staffing, cost, data-replication challenges.


Part LXXXII β€” Quality of Service

114. QoS

Quality of Service mechanisms prioritize network/service resources according to defined requirements.

Current Objective 7.10 explicitly includes QoS as a resilience concept.


Part LXXXIII β€” DR Use Case

115.

During reduced recovery capacity:

  • emergency voice traffic;

  • critical database replication;

  • business-critical applications

may receive priority over:

  • streaming;

  • nonessential transfers.


Part LXXXIV β€” QoS Is Not Additional Bandwidth

116. Important Trap

QoS prioritizes available resources.

It does not magically create:

unlimited capacity.


Part LXXXV β€” Disaster Recovery Process

117. Objective 7.11

Current CISSP Objective 7.11 specifically includes:

  • response;

  • personnel;

  • communications;

  • assessment;

  • restoration;

  • training/awareness;

  • lessons learned.


Part LXXXVI β€” DR Plan Activation

118. Activation Criteria

The DR plan should identify:

when and by whom it may be activated.


Part LXXXVII β€” Not Every Outage Is a Disaster

119.

Single workstation failure:

normal support process.

Entire primary data center unavailable:

possible DR activation.


Part LXXXVIII β€” Declaration Authority

120. Important

Declaring a disaster can trigger:

  • contracts;

  • alternate facilities;

  • major spending;

  • communications.

Authority should be defined in advance.


Part LXXXIX β€” DR Response

121.

DISRUPTION
↓
ASSESS
↓
DECLARE / ACTIVATE?
↓
MOBILIZE
↓
RECOVER

Part XC β€” Personnel

122. Technology Does Not Recover Itself

Plans should define:

  • roles;

  • alternates;

  • decision authority;

  • contact information.


Part XCI β€” Succession

123. Critical Role

What happens if the primary recovery manager is:

unavailable?

Assign:

  • backups;

  • alternates;

  • succession.


Part XCII β€” Personnel Welfare

124. Safety First

After major disasters:

people may be injured, displaced, or unable to work.

Human safety precedes equipment recovery.


Part XCIII β€” Communications

125. DR Communication

Current Objective 7.11 explicitly includes communications.


126. Communication Questions

  • Who contacts staff?

  • How?

  • What if email is down?

  • Who contacts suppliers?

  • Who informs customers?


Part XCIV β€” Alternate Communication Methods

127.

Possible methods:

  • mobile;

  • alternate messaging;

  • emergency notification platform;

  • phone trees.

Avoid relying on:

the system that is currently unavailable.


Part XCV β€” Contact Lists

128. Keep Current

An emergency list containing:

former employees

can delay response.


Part XCVI β€” Damage Assessment

129. Assessment

Determine:

  • what failed;

  • extent of damage;

  • expected duration;

  • recovery options.


Part XCVII β€” Technical + Business Assessment

130.

TECHNICAL:
What systems are down?

BUSINESS:
What critical processes are affected?

Both matter.


Part XCVIII β€” Restoration

131. Restoration

Restore systems according to:

approved recovery priority.


Part XCIX β€” Do Not Restore Randomly

132. Example

You restore:

employee cafeteria application

before:

enterprise identity service.

The cafeteria application still cannot operate.

Dependency planning matters.


Part C β€” Dependency Mapping

133.

BUSINESS APPLICATION
↓
DATABASE
↓
IDENTITY
↓
DNS
↓
NETWORK
↓
POWER

Recovery order must respect dependencies.


Part CI β€” Foundational Services

134. Common Dependencies

Depending on environment:

  • power;

  • network;

  • DNS;

  • authentication;

  • storage;

  • time services;

  • databases.


Part CII β€” Recovery Priority

135. BIA Drives Order

The most technically expensive system is not necessarily:

the most important system to restore first.


Part CIII β€” Clean Recovery Environment

136. Cyber Disaster

Recovery from ransomware must consider:

reinfection.

CISA recommends restoring from protected offline backups based on critical-service priority and ensuring clean systems are not reconnected to contaminated recovery environments.


Part CIV β€” Recovery Network

137. Example

CLEAN RECOVERY VLAN
β”‚
β”œβ”€β”€ Validated system A
β”œβ”€β”€ Validated system B
└── Validated system C

COMPROMISED SYSTEMS
X

Part CV β€” Credential Recovery

138. Major Compromise

If identity infrastructure was compromised, recovery may require:

  • privileged credential reset;

  • token revocation;

  • certificate/key review;

  • administrative trust rebuilding.


Part CVI β€” Recovery Validation

139. Before Production

Confirm:

  • security baseline;

  • patch state;

  • application integrity;

  • authentication;

  • monitoring;

  • data consistency.


Part CVII β€” Restoration Is Not Recovery Completion

140.

RESTORE FILES
↓
VALIDATE DATA
↓
VALIDATE SYSTEM
↓
VALIDATE SECURITY
↓
VALIDATE BUSINESS PROCESS

Part CVIII β€” Training and Awareness

141. Objective 7.11

DR processes explicitly include training and awareness.


142. Why?

A perfect plan that nobody understands is:

operationally weak.


Part CIX β€” DR Roles Need Practice

143. Staff Should Know

  • where to report;

  • what authority they have;

  • alternate communication paths;

  • required procedures.


Part CX β€” Lessons Learned

144. After Recovery

Ask:

  • Did RTO hold?

  • Did RPO hold?

  • Did communications work?

  • Were contact details accurate?

  • Were dependencies correct?

  • Did backups restore?


Part CXI β€” Improvement Loop

145.

DISASTER
↓
RECOVERY
↓
REVIEW
↓
LESSONS
↓
UPDATE PLAN
↓
RETEST

NIST SP 800-184 emphasizes learning from recovery events and tests to continually improve recovery planning and organizational resilience.


Part CXII β€” Disaster Recovery Testing

146. Why Test?

A DR plan that has never been tested is:

an assumption.


Part CXIII β€” Current Test Types

147. CISSP Objective 7.12 explicitly lists:

  1. read-through/tabletop;

  2. walkthrough;

  3. simulation;

  4. parallel;

  5. full interruption.


Part CXIV β€” Test Continuum

148.

LOW OPERATIONAL RISK
↓
READ-THROUGH / TABLETOP
↓
WALKTHROUGH
↓
SIMULATION
↓
PARALLEL
↓
FULL INTERRUPTION
↓
HIGHER REALISM / RISK

Part CXV β€” Read-Through

149. Read-Through

Participants review:

the DR plan and procedures.

Goal:

  • identify missing;

  • outdated;

  • contradictory

information.


Part CXVI β€” Tabletop

150. Tabletop

Participants discuss their response to a scenario.

Example:

Primary data center is unavailable for 72 hours.


Part CXVII β€” Tabletop Advantages

151.

  • low operational disruption;

  • exercises decision making;

  • reveals role confusion.


Part CXVIII β€” Tabletop Limitation

152.

Participants saying:

β€œWe would restore the database”

does not prove:

they can actually restore it.


Part CXIX β€” Walkthrough

153. Walkthrough

Personnel walk through recovery procedures, locations, systems, or steps with greater operational detail.


Part CXX β€” Example

154.

Team:

  • travels to recovery location;

  • identifies equipment;

  • reviews connections;

  • confirms procedural steps.


Part CXXI β€” Simulation

155. Simulation

Participants respond to a simulated disaster scenario with more realistic activities while avoiding actual production interruption.


Part CXXII β€” Example

156.

Scenario:

Primary site is declared unavailable.

Teams execute:

  • communications;

  • coordination;

  • recovery decisions

without actually shutting production down.


Part CXXIII β€” Parallel Test

157. Parallel

Recovery systems are activated and tested while:

normal production continues.


Part CXXIV β€” Example

158.

PRODUCTION
Still operating

+

RECOVERY SITE
Restores copies and processes test workload

Part CXXV β€” Parallel Advantage

159.

Provides stronger technical evidence without intentionally interrupting production.


Part CXXVI β€” Parallel Limitation

160.

Does not fully prove:

production can be cut over to the alternate environment during a real disaster.


Part CXXVII β€” Full Interruption

161. Full Interruption

Actual production operations are interrupted and recovery capability assumes the workload.


Part CXXVIII β€” Highest Realism

162.

This provides powerful evidence.

But also:

highest operational risk.


Part CXXIX β€” Full Interruption Risk

163.

If recovery fails:

the test itself can create a real outage.


Part CXXX β€” Exam Test Comparison

164.

TestProduction ImpactRealism
Read-throughVery LowLow
TabletopVery LowLow/Moderate
WalkthroughLowModerate
SimulationLow/ModerateModerate
ParallelModerateHigh
Full InterruptionHighHighest

Part CXXXI β€” Which Test Is Best?

165. CISSP Answer

There is no universal:

β€œalways perform full interruption.”

Choose according to:

  • criticality;

  • risk;

  • maturity;

  • business tolerance;

  • regulatory needs.


Part CXXXII β€” Testing Should Progress

166. Mature Strategy

An organization may progress from:

TABLETOP
↓
WALKTHROUGH
↓
SIMULATION
↓
PARALLEL
↓
FULL INTERRUPTION

as confidence and requirements justify.


Part CXXXIII β€” Test Communications

167. Objective 7.12

Communications during DR testing may include:

  • stakeholders;

  • test status;

  • regulators.


Part CXXXIV β€” Why Communicate Test Status?

168. Prevent Confusion

Monitoring teams may see:

  • failovers;

  • unusual traffic;

  • systems going offline.

They should know:

this is an authorized exercise.


Part CXXXV β€” But Do Not Over-Script Every Test

169. Depending on Objective

Some participants may intentionally receive:

limited advance information

to test real response behavior.

Management still needs appropriate authorization.


Part CXXXVI β€” Test Success Criteria

170. Before Testing

Define:

  • what is being tested;

  • expected recovery time;

  • expected data recovery;

  • required functionality.


Part CXXXVII β€” Example

171.

Test objective:

Restore payroll application within four hours using offsite backup and process a validated test payroll transaction.

This is stronger than:

β€œTest DR.”


Part CXXXVIII β€” Measure RTO

172.

If recovery target:

4 hours

actual result:

6 hours

the test did not meet the RTO.


Part CXXXIX β€” Measure RPO

173.

Required RPO:

1 hour.

Recovered data:

5 hours old.

The recovery technically worked.

The business requirement failed.


Part CXL β€” DR Test Evidence

174. Capture

  • start time;

  • completion time;

  • systems restored;

  • failures;

  • dependencies;

  • decisions;

  • corrective actions.


Part CXLI β€” Test Failure Is Useful

175. Better to Discover

backup cannot be restored

during:

controlled testing

than during:

ransomware recovery.


Part CXLII β€” Retest Corrective Action

176.

TEST
↓
FAILURE
↓
ROOT CAUSE
↓
CORRECT
↓
RETEST

Part CXLIII β€” Business Continuity

177. Objective 7.13

Current CISSP Domain 7 requires candidates to participate in Business Continuity planning and exercises.


Part CXLIV β€” BC Focus

178. Business Continuity Asks

How will the organization continue delivering critical services despite disruption?


Part CXLV β€” BC May Not Require Technology Recovery First

179. Example

Online ordering platform unavailable.

Temporary BC procedure:

accept orders through a controlled manual process.

Technology remains unavailable.

Business continues at reduced capacity.


Part CXLVI β€” Manual Workaround

180. Manual Workaround

Temporary human process used when automated capability is unavailable.


Part CXLVII β€” Example

181.

Electronic badge system fails.

Approved emergency procedure may use:

  • guard verification;

  • manual visitor log.


Part CXLVIII β€” Manual Process Risk

182.

Manual processes can create:

  • errors;

  • fraud;

  • security bypass.

They require:

  • procedures;

  • authorization;

  • reconciliation afterward.


Part CXLIX β€” Business Continuity Resources

183. Critical Resources May Include

  • people;

  • technology;

  • facilities;

  • communications;

  • suppliers;

  • records;

  • utilities.


Part CL β€” People Dependency

184. Example

Only one employee knows how to execute a critical recovery procedure.

That is:

a key-person dependency.


Part CLI β€” Cross-Training

185. Control

Use:

  • documentation;

  • training;

  • alternates;

  • succession.


Part CLII β€” Facility Continuity

186. Primary Office Unavailable

Potential approaches:

  • alternate site;

  • remote work;

  • distributed workforce.


Part CLIII β€” Telecommunications

187. Continuity Requires Communications

Consider:

  • Internet;

  • voice;

  • mobile;

  • alternate carriers.


Part CLIV β€” Supplier Continuity

188. Third Parties Matter

A company may recover its systems but still fail because:

critical supplier is unavailable.


Part CLV β€” Supplier Questions

189.

  • Does supplier have BC/DR?

  • Does contract define recovery capability?

  • Are alternates available?

  • Is geographic concentration understood?


Part CLVI β€” Cloud Provider Dependency

190. Cloud Is Not Automatic BC

Cloud platforms can also experience:

  • region failure;

  • identity outage;

  • provider incident.


Part CLVII β€” Multi-Region

191. Multi-Region Architecture

Can reduce:

regional single points of failure.

But increases:

  • complexity;

  • cost;

  • data-management challenges.


Part CLVIII β€” Multi-Cloud

192. Multi-Cloud

May reduce some provider concentration risks.

But it can create:

  • operational complexity;

  • inconsistent controls;

  • skill requirements.

CISA's ransomware guidance notes that multi-cloud approaches may be considered for certain backup-resilience scenarios, while also emphasizing careful design.


Part CLIX β€” Cloud Snapshot Trap

193.

Production:

Cloud Account A.

Snapshots:

same Cloud Account A.

Attacker compromises account and deletes both.

The backups were logically separate objects.

They were not:

administratively independent.


Part CLX β€” Administrative Separation

194. Stronger Model

PRODUCTION ADMIN
X
β”‚
BACKUP ADMIN

SEPARATE CREDENTIALS
SEPARATE POLICY
SEPARATE DELETION AUTHORITY

Part CLXI β€” Recovery Account

195. Recovery Access Must Be Tested

Do not discover during disaster that:

  • recovery credential expired;

  • MFA device unavailable;

  • emergency vault cannot be opened.


Part CLXII β€” Break-Glass Recovery

196. Emergency Credentials

May be necessary for:

  • identity outage;

  • cloud lockout;

  • major infrastructure failure.

Protect and test them carefully.


Part CLXIII β€” Backup Malware Scanning

197. Recovery Concern

A backup may contain malware that was present before detection.

Recovery teams may need:

  • validation;

  • scanning;

  • known-clean recovery points.


Part CLXIV β€” Golden Images

198. Clean Rebuilding

CISA recommends maintaining updated golden images of critical systems to support rapid rebuilding after ransomware incidents.


Part CLXV β€” Infrastructure as Code Recovery

199.

In cloud environments:

VERSION-CONTROLLED IaC
↓
NEW CLEAN ENVIRONMENT
↓
RESTORE VALIDATED DATA
↓
TEST

This can support rapid clean recovery when templates themselves are trusted.


Part CLXVI β€” Recovery Dependency: Software

200. Backup Data Alone May Be Insufficient

You may also need:

  • software;

  • licenses;

  • installation media;

  • keys;

  • documentation.


Part CLXVII β€” Recovery Dependency: Hardware

201. Example

Backup created from old platform.

Replacement hardware does not support:

old operating system.

Recovery fails due to compatibility.


Part CLXVIII β€” Recovery Dependency: People

202. Scenario

Recovery documentation exists.

Only administrator who knows encryption key process is:

unreachable.

This is a continuity failure.


Part CLXIX β€” Recovery Dependency: DNS

203.

Application restored successfully.

Users cannot access it because:

DNS recovery was omitted.


Part CLXX β€” Dependency Thinking

204.

CRITICAL SERVICE
β”‚
β”œβ”€β”€ PEOPLE
β”œβ”€β”€ APPLICATION
β”œβ”€β”€ DATABASE
β”œβ”€β”€ IDENTITY
β”œβ”€β”€ NETWORK
β”œβ”€β”€ DNS
β”œβ”€β”€ POWER
└── SUPPLIERS

Part CLXXI β€” Common-Mode Backup Failure

205.

Three copies stored on:

three disks in same building.

Fire destroys building.

You had:

multiple copies,

but not sufficient:

risk diversity.


Part CLXXII β€” Common-Mode Cloud Failure

206.

Primary and backup both depend on:

  • same region;

  • same identity tenant;

  • same administrator.

That can create:

hidden common dependencies.


Part CLXXIII β€” High Availability β‰  Disaster Recovery

207. Critical Trap

HA handles certain:

component/service failures.

DR addresses:

significant disruptive events.


Part CLXXIV β€” Example

208.

Two servers in one data center:

high availability.

Building burns down:

both unavailable.

HA did not provide adequate site-level DR.


Part CLXXV β€” Backup β‰  DR

209.

Having tapes stored offsite does not mean:

the organization has a complete DR program.

You also need:

  • people;

  • procedures;

  • systems;

  • facilities;

  • communications;

  • testing.


Part CLXXVI β€” DR β‰  BC

210.

DR may restore IT.

BC ensures critical business operation continues.


Part CLXXVII β€” BC β‰  Crisis Management

211. Relationship

Business Continuity:

maintain critical processes.

Crisis management:

coordinate major organizational consequences and strategic decisions.

They can overlap.


Part CLXXVIII β€” Recovery Prioritization

212. First Question

Not:

β€œWhat is easiest to restore?”

But:

What business capability is most critical?


Part CLXXIX β€” Dependency-Based Priority

213.

Even if payroll is critical, first restore:

  • identity;

  • databases;

  • network dependencies

if payroll depends on them.


Part CLXXX β€” Tiered Recovery

214. Example

TIER 0
Foundational infrastructure

TIER 1
Mission-critical services

TIER 2
Important business systems

TIER 3
Noncritical services

Exact tiers are organization-specific.


Part CLXXXI β€” Recovery Validation by Business Owner

215. IT May Say

β€œServer is up.”

Business owner must confirm:

β€œBusiness function actually works.”


Part CLXXXII β€” Technical Recovery vs Business Recovery

216.

SERVER ONLINE
β‰ 
BUSINESS PROCESS RESTORED

Part CLXXXIII β€” Data Reconciliation

217. After Manual Workaround

Transactions processed manually during outage may need:

reconciliation

after automated systems return.


Part CLXXXIV β€” Failback Planning

218. Failback Is a Change

Treat it with:

  • planning;

  • testing;

  • synchronization;

  • authorization;

  • monitoring.


Part CLXXXV β€” Premature Failback

219.

Primary site appears operational.

Moving back too soon may create:

  • another outage;

  • data inconsistency.


Part CLXXXVI β€” Recovery Communications

220. Different Audiences

Executives

Need:

  • impact;

  • expected restoration;

  • decisions.

Technical teams

Need:

  • tasks;

  • dependencies;

  • status.

Customers

Need:

  • service status;

  • approved communications.


Part CLXXXVII β€” Regulator Communications

221. During Tests or Incidents

Some sectors may require:

  • notification;

  • evidence;

  • exercise participation.

Current CISSP Objective 7.12 explicitly recognizes regulator communications as a DR-test consideration.


Part CLXXXVIII β€” Recovery Security

222. Security Controls Must Not Be Forgotten

Under pressure, teams may bypass:

  • MFA;

  • segmentation;

  • logging.


Part CLXXXIX β€” Recovery Shortcuts

223. Dangerous Mindset

β€œSecurity can be turned off until systems come back.”

Recovery environments are attractive attacker targets.


Part CXC β€” Minimum Secure Recovery

224.

Recovered environment should restore critical protections such as:

  • identity;

  • logging;

  • endpoint protection;

  • network segmentation;

  • backup protection.


Part CXCI β€” SierraTec Secure BACKUP Model

225. BACKUP

Use BACKUP for backup-strategy questions.

B β€” Base on Business Requirements

RTO and RPO drive the design.

A β€” Add Independent Copies

Avoid one storage location or common failure domain.

C β€” Control Access and Cryptography

Protect backup credentials, data, and keys.

K β€” Keep Recovery Versions Protected

Use appropriate offsite, offline, or immutable capabilities.

U β€” Understand Dependencies

Include applications, configurations, licenses, and documentation.

P β€” Prove Restoration

Test recovery instead of trusting job-success messages.


Part CXCII β€” BACKUP Diagram

226.

B
BUSINESS REQUIREMENTS
β”‚
β–Ό
A
ADD COPIES
β”‚
β–Ό
C
CONTROL ACCESS
β”‚
β–Ό
K
KEEP PROTECTED
β”‚
β–Ό
U
UNDERSTAND DEPENDENCIES
β”‚
β–Ό
P
PROVE RESTORATION

Part CXCIII β€” SierraTec Secure RESTORE Model

227. RESTORE

Use RESTORE for disaster-recovery questions.

R β€” Recovery Requirements

Know RTO, RPO, and business priorities.

E β€” Establish Alternate Resources

Sites, people, communications, and capacity.

S β€” Sequence Dependencies

Restore foundational capabilities in the correct order.

T β€” Test the Plan

Move from discussion-based exercises toward stronger validation where appropriate.

O β€” Operate the Recovery Environment

Restore services in a trusted state.

R β€” Return Carefully

Plan failback and reconciliation.

E β€” Evaluate and Improve

Capture lessons and update the plan.


Part CXCIV β€” RESTORE Diagram

228.

R
RECOVERY REQUIREMENTS
β”‚
β–Ό
E
ESTABLISH ALTERNATIVES
β”‚
β–Ό
S
SEQUENCE DEPENDENCIES
β”‚
β–Ό
T
TEST
β”‚
β–Ό
O
OPERATE RECOVERY
β”‚
β–Ό
R
RETURN / FAILBACK
β”‚
β–Ό
E
EVALUATE

Part CXCV β€” SierraTec Secure CONTINUE Model

229. CONTINUE

Use CONTINUE for Business Continuity scenarios.

C β€” Critical Processes

Identify what must continue.

O β€” Owners and Alternates

Assign responsible personnel and backups.

N β€” Necessary Resources

Technology, people, facilities, suppliers, records.

T β€” Temporary Workarounds

Prepare alternate processes.

I β€” Interdependencies

Understand internal and external dependencies.

N β€” Notify and Communicate

Maintain alternate communications.

U β€” Undertake Exercises

Practice BC procedures.

E β€” Enhance Through Lessons

Update plans after tests and events.


Part CXCVI β€” Worked Scenario 1: RTO

230.

A critical application must return to service within four hours after an outage.

Which recovery measurement does this MOST directly establish?

A. RTO
B. RPO
C. ALE
D. SLE

Correct Answer

A


Part CXCVII β€” Scenario 2: RPO

231.

Management determines that no more than 30 minutes of transaction data can be lost.

Which requirement is this?

A. RPO
B. RTO
C. MTTD
D. MTBF

Correct Answer

A


Part CXCVIII β€” Scenario 3: Incremental

232.

A company performs a full backup Sunday and incremental backups each day.

To restore Thursday's state, what is generally required?

A. Sunday's full backup and each applicable incremental through Thursday.
B. Thursday incremental only.
C. Sunday's full only.
D. Latest differential.

Correct Answer

A


Part CXCIX β€” Scenario 4: Differential

233.

A full backup was completed Sunday and differential backups run daily.

What is generally needed to restore Wednesday?

A. Sunday full plus Wednesday differential.
B. Every differential from Monday through Wednesday.
C. Wednesday differential only.
D. Sunday full only.

Correct Answer

A


Part CC β€” Scenario 5: Replication

234.

A ransomware infection encrypts data on the primary server and the encrypted files immediately replicate to the secondary server.

What principle is MOST clearly demonstrated?

A. Replication is not a substitute for backup.
B. Replication always prevents ransomware.
C. Secondary servers cannot be corrupted.
D. Backup is unnecessary with HA.

Correct Answer

A


Part CCI β€” Scenario 6: Offline Backup

235.

The organization wants recovery copies that ransomware cannot easily reach from the compromised production network.

Which approach MOST directly helps?

A. Properly protected offline backup.
B. Only another writable network share.
C. Same-account snapshot only.
D. Browser cache.

Correct Answer

A


Part CCII β€” Scenario 7: Backup Test

236.

Backup software shows 100% success for six months, but nobody has attempted a restore.

What is the MOST important concern?

A. Recoverability has not been demonstrated.
B. Backup testing is unnecessary.
C. Successful jobs guarantee RTO.
D. RPO automatically equals zero.

Correct Answer

A


Part CCIII β€” Scenario 8: Encryption Keys

237.

The organization has encrypted offsite backups, but the only copy of the decryption key was destroyed with the primary data center.

What failed?

A. Recovery key-management planning.
B. Backup confidentiality.
C. Fire suppression.
D. QoS.

Correct Answer

A


Part CCIV β€” Scenario 9: Cold Site

238.

Management wants the lowest-cost alternate facility and accepts a long recovery time.

Which recovery-site strategy is MOST appropriate?

A. Cold site.
B. Hot site.
C. Active-active.
D. Fault-tolerant cluster.

Correct Answer

A


Part CCV β€” Scenario 10: Hot Site

239.

A financial service requires very rapid restoration and is willing to pay substantially for a highly prepared alternate environment.

Which is MOST appropriate?

A. Hot site.
B. Cold site.
C. Empty warehouse.
D. File archive.

Correct Answer

A


Part CCVI β€” Scenario 11: Common-Mode Failure

240.

Two redundant data centers rely on the same electrical substation and telecommunications conduit.

What is the PRIMARY concern?

A. Common-mode failure.
B. Too much geographic diversity.
C. Excessive fault tolerance.
D. Data classification.

Correct Answer

A


Part CCVII β€” Scenario 12: HA vs DR

241.

An application uses two clustered servers in the same building.

What is the MOST accurate conclusion?

A. This can improve availability but does not necessarily provide site-level disaster recovery.
B. It guarantees disaster recovery.
C. Backups are no longer required.
D. The building cannot fail.

Correct Answer

A


Part CCVIII β€” Scenario 13: Parallel Test

242.

The organization starts recovery systems and processes test workloads while production continues normally.

Which DR test is this?

A. Parallel test.
B. Full interruption.
C. Read-through.
D. Cold-site declaration.

Correct Answer

A


Part CCIX β€” Scenario 14: Full Interruption

243.

Management deliberately shuts down primary production and requires the alternate site to assume the real workload.

Which test is this?

A. Full interruption.
B. Tabletop.
C. Walkthrough.
D. Documentation review.

Correct Answer

A


Part CCX β€” Scenario 15: Tabletop

244.

Managers and technical personnel discuss how they would respond to a simulated data-center fire without actually moving production.

Which test is this?

A. Tabletop.
B. Full interruption.
C. Parallel.
D. Failback.

Correct Answer

A


Part CCXI β€” Scenario 16: Test Failure

245.

A DR test fails to restore the database within its required RTO.

What should happen NEXT?

A. Analyze the cause, correct the recovery capability, and retest.
B. Change the test result to pass.
C. Ignore it because production was unaffected.
D. Eliminate the RTO.

Correct Answer

A


Part CCXII β€” Scenario 17: BC

246.

A cyberattack disables the order-management platform. Staff use a documented manual procedure to continue accepting high-priority orders.

What is MOST clearly demonstrated?

A. Business Continuity.
B. Disk sanitization.
C. Penetration testing.
D. Configuration baselining.

Correct Answer

A


Part CCXIII β€” Scenario 18: Key Person

247.

Only one administrator knows how to restore the organization's encrypted database.

What is the PRIMARY continuity concern?

A. Key-person dependency.
B. Too many backups.
C. High availability.
D. Excessive redundancy.

Correct Answer

A


Part CCXIV β€” Scenario 19: Supplier

248.

All internal systems recover successfully, but the business cannot operate because its only payment provider remains offline.

What did the plan fail to address?

A. External dependency/supplier continuity.
B. Local server configuration.
C. Disk encryption.
D. Media sanitization.

Correct Answer

A


Part CCXV β€” Scenario 20: Failback

249.

Production has been running at the alternate site for one week. The primary site is repaired.

What should happen before returning operations?

A. Plan and validate synchronization, security, dependencies, and controlled failback.
B. Immediately move systems without analysis.
C. Delete alternate-site data.
D. Disable monitoring.

Correct Answer

A


Part CCXVI β€” Common CISSP Exam Traps

250. Trap β€” Backup Equals Disaster Recovery

No.

Backup is:

one component of recovery.


251. Trap β€” Disaster Recovery Equals Business Continuity

No.

DR primarily restores technology.

BC maintains critical business functions.


252. Trap β€” Incident Response Equals DR

No.

IR handles the incident.

DR restores disrupted technology capability when necessary.


253. Trap β€” RTO Means Acceptable Data Loss

No.

That is primarily RPO.

RTO concerns:

recovery time.


254. Trap β€” RPO Means Service Restoration Time

No.

RPO concerns:

recoverable data point.


255. Trap β€” RTO Should Be Set by IT Alone

No.

Business requirements and the BIA should drive recovery objectives.


256. Trap β€” Full Backup Is Always Best

Not necessarily.

Backup architecture depends on:

  • recovery objectives;

  • storage;

  • performance;

  • operational requirements.


257. Trap β€” Incremental Restore Needs Only Latest Incremental

No.

Normally you need:

full + required incremental chain.


258. Trap β€” Differential Restore Needs Every Differential

No.

Generally:

full + latest required differential.


259. Trap β€” Snapshot Always Equals Independent Backup

No.

Snapshots can share the same failure and administrative domain as production.


260. Trap β€” Replication Is Backup

No.

Replication may copy corruption or ransomware.


261. Trap β€” Cloud Backup Automatically Means Offsite Resilience

Not necessarily.

Examine:

  • region;

  • tenant;

  • account;

  • provider;

  • deletion authority.


262. Trap β€” Immutable Backup Cannot Fail

No.

Incorrect configuration or corrupted input can still create problems.


263. Trap β€” Offline Backup Needs No Testing

False.

An offline backup can still be:

  • corrupted;

  • incomplete;

  • unusable.


264. Trap β€” Backup Encryption Is Enough

No.

You must be able to recover:

the keys.


265. Trap β€” Hot Site Means Zero Downtime

No.

Recovery actions and synchronization may still be required.


266. Trap β€” Cold Site Is Better Because It Costs Less

Not if the required RTO cannot be met.


267. Trap β€” Hot Site Is Always Best

Not if the additional cost cannot be justified by business recovery requirements.


268. Trap β€” Two Systems Means No Single Point of Failure

They may share:

  • power;

  • network;

  • location;

  • administration.


269. Trap β€” High Availability Equals Fault Tolerance

They are related but not identical.


270. Trap β€” High Availability Eliminates Need for DR

No.

HA may not protect against:

  • site failure;

  • ransomware;

  • large-scale disaster.


271. Trap β€” QoS Adds Capacity

No.

QoS prioritizes available capacity.


272. Trap β€” Restore Servers in Any Order

No.

Dependencies matter.


273. Trap β€” Most Expensive Server Is Restored First

Not necessarily.

Recovery priority is driven by:

business criticality and dependencies.


274. Trap β€” The Newest Backup Is Always Cleanest

Not during long-dwell compromise.


275. Trap β€” Tabletop Proves Technical Recovery

No.

It primarily tests:

  • plans;

  • roles;

  • decisions.


276. Trap β€” Parallel Test Interrupts Production

Normally production continues while recovery capability is tested.


277. Trap β€” Full Interruption Has Lowest Risk

No.

It generally has the highest operational risk and realism.


278. Trap β€” Failed DR Test Is Bad and Should Be Hidden

No.

A controlled failure provides valuable improvement information.


279. Trap β€” BC Is an IT-Only Activity

No.

Business continuity involves:

  • people;

  • facilities;

  • suppliers;

  • technology;

  • communications;

  • business processes.


280. Trap β€” Cloud Automatically Solves BC

No.

Cloud dependencies can fail too.


Part CCXVII β€” Knowledge Check

281. Question 1

What is the PRIMARY purpose of Business Continuity?

A. Maintain critical business operations during disruption.
B. Only restore servers.
C. Perform penetration tests.
D. Manage source code.

Correct Answer

A


282. Question 2

What is Disaster Recovery primarily concerned with?

A. Restoring technology capability after significant disruption.
B. Hiring employees.
C. Data classification only.
D. Software development.

Correct Answer

A


283. Question 3

What does RTO measure?

A. Required recovery time.
B. Acceptable data-loss point.
C. Vulnerability severity.
D. Password age.

Correct Answer

A


284. Question 4

What does RPO measure?

A. The point in time to which data must be recovered.
B. Restoration labor cost.
C. Service availability percentage.
D. Network throughput.

Correct Answer

A


285. Question 5

Which backup generally requires the longest restore chain?

A. Incremental.
B. Differential.
C. Full.
D. None.

Correct Answer

A


286. Question 6

Which generally requires full backup plus the latest differential?

A. Differential recovery.
B. Incremental recovery.
C. RAID recovery only.
D. Replication.

Correct Answer

A


287. Question 7

Why is replication not sufficient as the only backup strategy?

A. Corruption or malicious changes can replicate.
B. Replication always stores historical generations.
C. Replication is always offline.
D. Replication cannot copy data.

Correct Answer

A


288. Question 8

Why are offline backups valuable against ransomware?

A. They reduce continuous attacker access to recovery copies.
B. They guarantee zero data loss.
C. They eliminate restoration testing.
D. They replace access control.

Correct Answer

A


289. Question 9

What is an immutable backup designed to resist?

A. Unauthorized alteration or deletion during the retention period.
B. Power loss only.
C. Network latency.
D. User authentication.

Correct Answer

A


290. Question 10

Which site normally offers the fastest recovery?

A. Hot site.
B. Cold site.
C. Empty office.
D. Archive facility.

Correct Answer

A


291. Question 11

Which site generally has the lowest ongoing cost?

A. Cold site.
B. Hot site.
C. Active-active.
D. Fault-tolerant site.

Correct Answer

A


292. Question 12

What is failover?

A. Moving service to alternate capacity following failure.
B. Destroying backup media.
C. Changing data classification.
D. Ending an audit.

Correct Answer

A


293. Question 13

What is failback?

A. Returning service from alternate capacity to the preferred environment.
B. Deleting backup data.
C. Disabling DR.
D. Starting a tabletop.

Correct Answer

A


294. Question 14

What is the major purpose of fault tolerance?

A. Continue operation despite supported component failure.
B. Increase audit scope.
C. Increase data loss.
D. Replace BC.

Correct Answer

A


295. Question 15

What does QoS primarily do?

A. Prioritize available service/network resources.
B. Create unlimited bandwidth.
C. Encrypt backups.
D. Replace fault tolerance.

Correct Answer

A


296. Question 16

Which DR test runs recovery capability while production remains operational?

A. Parallel.
B. Full interruption.
C. Read-through.
D. None.

Correct Answer

A


297. Question 17

Which DR test normally creates the greatest production risk?

A. Full interruption.
B. Tabletop.
C. Read-through.
D. Documentation review.

Correct Answer

A


298. Question 18

What is a primary purpose of DR lessons learned?

A. Improve plans and future recovery capability.
B. Hide failures.
C. Eliminate testing.
D. Increase RTO automatically.

Correct Answer

A


299. Question 19

Which should determine system-restoration priorities?

A. Business criticality and dependencies.
B. Hardware price alone.
C. Server age alone.
D. Administrator preference.

Correct Answer

A


300. Question 20

Which statement is MOST accurate?

A. Resilience combines preparation, redundancy, recoverability, tested DR, and business continuity.
B. Backups alone guarantee resilience.
C. HA eliminates the need for DR.
D. BC is solely an IT responsibility.

Correct Answer

A


Part CCXVIII β€” Original CISSP-Style Practice Questions

301. Practice Question 1

A company's business impact analysis determines that its payment-processing application can be unavailable for no more than two hours and may lose no more than five minutes of transactions.

Which pair is correct?

A. RTO = 2 hours; RPO = 5 minutes.
B. RTO = 5 minutes; RPO = 2 hours.
C. Both are RTOs.
D. Both are RPOs.

Correct Answer

A


302. Practice Question 2

A company maintains continuous replication of a database to another server in the same cloud account. A compromised administrator deletes both databases.

What is the BEST improvement?

A. Add recovery copies protected through separate failure and administrative boundaries.
B. Increase replication speed.
C. Eliminate backups.
D. Use the same administrator everywhere.

Correct Answer

A


303. Practice Question 3

A backup is encrypted, stored offsite, and retained for one year. During a DR test, nobody can locate the required decryption key.

What is the PRIMARY lesson?

A. Backup strategy must include recoverable key-management procedures.
B. Encryption should never be used.
C. Offsite storage caused the failure.
D. Retention was too long.

Correct Answer

A


304. Practice Question 4

An organization has a four-hour RTO but its cold site requires two days to acquire and configure hardware.

What is the BEST conclusion?

A. The recovery strategy cannot satisfy the business requirement.
B. Cold sites always meet every RTO.
C. Change the BIA to two days automatically.
D. RTO does not affect site selection.

Correct Answer

A


305. Practice Question 5

Two active data centers are geographically separated but rely on the same identity-provider tenant. The identity service fails globally.

What risk was underestimated?

A. Common dependency/common-mode failure.
B. Excessive backup retention.
C. Physical media exposure.
D. Incremental backup complexity.

Correct Answer

A


306. Practice Question 6

During a ransomware recovery, the organization discovers that all online backups were encrypted by the attacker.

Which prior control would have MOST directly reduced the impact?

A. Protected offline or appropriately immutable recovery copies.
B. Faster Internet service.
C. More local administrator accounts.
D. Shorter password length.

Correct Answer

A


307. Practice Question 7

A DR team restores an application server before restoring its authentication and database services. The application remains unusable.

What planning issue is demonstrated?

A. Recovery dependencies were not sequenced correctly.
B. RPO was too low.
C. Backups should be removed.
D. QoS failed.

Correct Answer

A


308. Practice Question 8

Management wants to validate the alternate processing site technically without deliberately taking down production.

Which DR test BEST fits?

A. Parallel test.
B. Full interruption.
C. Read-through only.
D. No testing.

Correct Answer

A


309. Practice Question 9

An organization has never exercised its DR plan and management proposes beginning with a full-interruption test of the payment platform.

What is the BEST recommendation?

A. Use a risk-based progression of exercises before undertaking a high-impact full interruption unless requirements justify otherwise.
B. Full interruption is always the safest first test.
C. Do not test DR.
D. Only test after a real disaster.

Correct Answer

A


310. Practice Question 10

During a BC exercise, a critical supplier says it cannot deliver for 30 days after a regional disaster.

What should the organization do?

A. Evaluate alternate suppliers and continuity strategies for that dependency.
B. Ignore external dependencies.
C. Increase backup frequency.
D. Replace the SIEM.

Correct Answer

A


311. Practice Question 11

A business unit manually processes transactions during a six-hour system outage. After recovery, the transactions are not entered into the restored system.

What is the PRIMARY problem?

A. The BC workaround lacked reconciliation procedures.
B. The backup was too encrypted.
C. DR testing is unnecessary.
D. The RTO was too short.

Correct Answer

A


312. Practice Question 12

A company successfully restores every server within the RTO but cannot perform customer transactions because an external API remains unavailable.

What is the BEST conclusion?

A. Technical recovery alone did not restore the complete business service.
B. DR is automatically successful whenever servers boot.
C. Supplier dependencies do not affect BC.
D. RPO eliminates third-party risk.

Correct Answer

A


313. Practice Question 13

A DR test restores the database within two hours, but the required RTO is one hour.

How should the result be recorded?

A. The recovery worked technically but failed the required RTO.
B. Full success.
C. RTO is irrelevant after restoration.
D. Change the measured time to one hour.

Correct Answer

A


314. Practice Question 14

A backup administrator can modify production systems, disable immutable retention, and delete all backup copies.

What security principle should be strengthened?

A. Separation of duties and least privilege.
B. QoS.
C. RPO.
D. Warm-site capacity.

Correct Answer

A


315. Practice Question 15

A company uses a highly available cluster across two racks in one data center and believes a DR site is unnecessary.

What is the BEST response?

A. HA addresses certain failures, but site-level disasters can still require DR capability.
B. Clustering eliminates every disaster scenario.
C. Backups are no longer required.
D. Business Continuity becomes irrelevant.

Correct Answer

A


Part CCXIX β€” Recovery Objectives Memory Table

ConceptQuestion
RTOHow quickly must service return?
RPOTo what point must data be recovered?
MTD/MAD conceptHow long before business impact becomes unacceptable?
Recovery PriorityWhat should be restored first?
DependencyWhat must exist first for the service to work?

Part CCXX β€” Backup Type Memory Table

Backup TypeCapturesRestore Requirement
FullEntire defined datasetFull
IncrementalChanges since previous relevant backupFull + all needed incrementals
DifferentialChanges since last fullFull + latest differential
SnapshotPoint-in-time statePlatform dependent
ReplicationCopy of current/near-current stateAlternate live/standby copy

Part CCXXI β€” Backup Architecture Memory Table

StrategyMain BenefitMain Concern
OnsiteFast accessSame-site disaster
OffsiteGeographic separationRecovery logistics
CloudScalability/geographic optionsProvider/tenant dependency
OnlineConvenientRansomware reachability
OfflineIsolationSlower/manual access
ImmutableResists alteration/deletionConfiguration and retention design
Air-gappedStrong separationOperational complexity

Part CCXXII β€” Recovery Site Memory Table

SiteCostReadinessTypical Recovery
ColdLowerLowSlow
WarmMediumModerateModerate
HotHigherHighFast
Active-ActiveHighest/complexOperationalVery fast
Active-PassiveHigh/mediumStandbyFast, depending design

Part CCXXIII β€” DR Test Memory Table

TestProduction Interrupted?Primary Value
Read-throughNoDocument review
TabletopNoDecision/role testing
WalkthroughUsually noProcedure/facility validation
SimulationUsually noRealistic coordination
ParallelNoTechnical recovery validation
Full InterruptionYesHighest end-to-end realism

Part CCXXIV β€” BC Resource Table

ResourceContinuity Question
PeopleAre trained alternates available?
FacilityWhere will work occur?
TechnologyCan systems be restored?
DataCan required information be recovered?
CommunicationsHow will teams coordinate?
SuppliersCan dependencies continue?
UtilitiesAre power/connectivity available?
RecordsCan critical documentation be accessed?

Part CCXXV β€” Key Terms

Backup

Copy of data or system information retained for restoration purposes.

Recovery

Restoration of information, systems, or services following disruption.

Disaster Recovery

Activities used to restore information-system capabilities following significant disruption.

Business Continuity

Capability to continue critical business functions during disruption.

Resilience

Ability to withstand, recover from, and adapt to disruption.

Recovery Time Objective

Time-related target describing how long recovery may take before unacceptable mission/business impact occurs.

Recovery Point Objective

Point in time to which data must be recovered after disruption.

Full Backup

Backup containing the entire defined backup dataset.

Incremental Backup

Backup of changes since the previous relevant backup.

Differential Backup

Backup of changes since the latest full backup.

Snapshot

Point-in-time representation of system or storage state.

Replication

Maintenance of copies of data or services across systems or locations.

Offline Backup

Backup not continuously accessible from production systems.

Immutable Backup

Backup protected against alteration or deletion during a defined retention period.

Air Gap

Separation intended to prevent direct access between production and protected recovery resources.

Cold Site

Alternate facility with limited preinstalled computing capability.

Warm Site

Partially equipped alternate facility.

Hot Site

Highly prepared alternate facility capable of comparatively rapid recovery.

Reciprocal Agreement

Arrangement between organizations to provide recovery resources to one another.

Resource-Capacity Agreement

Contractual arrangement reserving or providing processing/recovery capacity.

Failover

Transfer of workload to alternate capability after failure.

Failback

Controlled return from alternate capability to the primary/preferred environment.

High Availability

Architecture intended to minimize service downtime.

Fault Tolerance

Ability to continue operation through supported component failures.

Redundancy

Provision of additional components or paths to reduce single points of failure.

Common-Mode Failure

Single event or dependency capable of defeating multiple supposedly redundant components.

Quality of Service

Mechanisms used to prioritize available network or service resources.

Disaster Recovery Plan

Documented strategy and procedures for recovering technology capability after disruptive events.

Parallel Test

DR test in which recovery resources are activated while production remains operational.

Full-Interruption Test

DR test involving actual interruption of production and transition to recovery capability.

Manual Workaround

Temporary non-automated method used to continue a business process during technology unavailability.

Golden Image

Known system build or template used to rebuild systems into an approved state.


CISSP Exam Focus

For recovery questions, use this sequence:

WHAT BUSINESS PROCESS MATTERS?
↓
WHAT DOES THE BIA REQUIRE?
↓
WHAT ARE RTO AND RPO?
↓
WHAT DEPENDENCIES EXIST?
↓
WHICH STRATEGY CAN MEET THEM?
↓
IS THERE A COMMON FAILURE DOMAIN?
↓
HAS RECOVERY BEEN TESTED?
↓
CAN THE BUSINESS ACTUALLY OPERATE?

Remember:

  • Current CISSP Objective 7.10 includes cloud/onsite/offsite backup strategies, recovery sites, capacity agreements, multiple processing sites, resilience, HA, QoS, and fault tolerance.

  • Objective 7.11 covers DR response, personnel, communications, assessment, restoration, training, and lessons learned.

  • Objective 7.12 explicitly includes read-through/tabletop, walkthrough, simulation, parallel, full interruption, and communications.

  • Objective 7.13 covers participation in BC planning and exercises.

  • RTO is time to required recovery.

  • RPO is the required recovered-data point.

  • Business requirements drive RTO and RPO.

  • Faster recovery generally costs more.

  • Backup does not equal availability.

  • Backup does not equal DR.

  • DR does not equal BC.

  • Incremental recovery normally requires the full backup plus the required sequence of incrementals.

  • Differential recovery generally requires the full backup plus the latest required differential.

  • Snapshots are not automatically independent backups.

  • Replication can replicate corruption.

  • Replication improves availability but does not necessarily provide historical recoverability.

  • Offsite protection reduces same-location risk.

  • CISA recommends offline, encrypted backups and regular recovery testing as part of ransomware resilience.

  • Immutable storage can strengthen backup protection but must still be properly configured and tested.

  • Protected recovery copies should not share every administrative failure domain with production.

  • Encryption requires recoverable key management.

  • A successful backup job does not prove restoration capability.

  • Test actual restores.

  • CISA recommends restoring from protected offline backups according to critical-service priorities and avoiding reinfection during recovery.

  • Cold sites cost less but normally recover more slowly.

  • Hot sites cost more but support faster recovery.

  • Site selection should follow required recovery objectives rather than preference.

  • Multiple processing sites can support resilience but may still share hidden dependencies.

  • High availability does not automatically equal disaster recovery.

  • Fault tolerance and high availability are related but distinct.

  • Redundancy without diversity can leave common-mode failures.

  • QoS prioritizes available resources; it does not create unlimited resources.

  • DR restoration sequence must respect technical and business dependencies.

  • Recovery is not complete merely because a server boots.

  • Business owners should validate restored business functionality.

  • The newest backup may contain attacker persistence.

  • Recovery environments must remain secure.

  • DR testing should use measurable success criteria.

  • Tabletop testing provides low-risk plan validation but does not prove technical recovery.

  • Parallel testing provides stronger recovery evidence without intentionally interrupting production.

  • Full-interruption testing provides high realism at high operational risk.

  • Failed DR tests are opportunities for improvement.

  • BC includes people, facilities, technology, communications, suppliers, utilities, and critical information.

  • Manual workarounds require later reconciliation.

  • External suppliers and cloud services are part of continuity dependencies.

  • NIST SP 800-184 emphasizes recovery planning, prioritization, realistic testing, and continual improvement.

  • NIST continues to list SP 800-34 Rev. 1 as its final contingency-planning guide and provides BIA and contingency-plan resources with it.


Lesson Summary

Lesson Twenty-Seven connected the four layers of organizational recovery:

BACKUP
↓
RECOVERY
↓
DISASTER RECOVERY
↓
BUSINESS CONTINUITY

You learned that effective recovery begins not with technology but with:

business requirements.

The BIA establishes criticality.

RTO establishes:

how quickly capability must return.

RPO establishes:

how far back recovered information may go.

NIST's current glossary defines RTO and RPO in these mission/business recovery terms.

You then examined the backup lifecycle:

IDENTIFY CRITICAL DATA
↓
CREATE BACKUPS
↓
PROTECT COPIES
↓
SEPARATE FAILURE DOMAINS
↓
VERIFY INTEGRITY
↓
RESTORE TEST
↓
MEASURE RTO / RPO

Modern ransomware resilience requires more than a second writable copy of production. CISA recommends offline, encrypted backups, regular restoration testing, protected golden images, and recovery practices designed to prevent reinfection.

You compared:

FULL
INCREMENTAL
DIFFERENTIAL
SNAPSHOT
REPLICATION

and learned the critical principle:

Replication is not automatically backup because replication may reproduce corruption or malicious changes.

You then examined alternate processing strategies:

COLD SITE
↓
WARM SITE
↓
HOT SITE
↓
MULTIPLE PROCESSING SITES
↓
HIGH AVAILABILITY / FAULT TOLERANCE

The correct solution is determined by:

  • business criticality;

  • RTO;

  • RPO;

  • cost;

  • risk;

  • dependencies.

You also studied the current CISSP disaster-recovery testing sequence:

READ-THROUGH / TABLETOP
↓
WALKTHROUGH
↓
SIMULATION
↓
PARALLEL
↓
FULL INTERRUPTION

with increasing realism generally accompanied by increasing operational exposure. The current CISSP outline explicitly lists these test approaches.

Finally, you distinguished technology restoration from actual business continuity:

SERVER RESTORED
↓
APPLICATION RESTORED
↓
DEPENDENCIES RESTORED
↓
BUSINESS PROCESS VALIDATED
↓
BUSINESS CONTINUITY ACHIEVED

The three SierraTec Secure models for this lesson are:

BACKUP

Base on business requirements β†’ Add copies β†’ Control access β†’ Keep protected β†’ Understand dependencies β†’ Prove restoration

RESTORE

Recovery requirements β†’ Establish alternatives β†’ Sequence dependencies β†’ Test β†’ Operate recovery β†’ Return β†’ Evaluate

CONTINUE

Critical processes β†’ Owners β†’ Necessary resources β†’ Temporary workarounds β†’ Interdependencies β†’ Notify β†’ Undertake exercises β†’ Enhance

The central Lesson Twenty-Seven principle is:

Recovery capability is not proven by possessing backup files or writing a disaster-recovery plan. True resilience requires business-defined recovery objectives, independently protected and recoverable data, resilient processing capacity, dependency-aware restoration, trained personnel, alternate communications, repeated testing, validated business functionality, and continuous improvement based on evidence.


Exam Readiness Check

Before moving to Lesson Twenty-Eight, make sure you can explain without reviewing:

  • Backup versus recovery.

  • Recovery versus DR.

  • DR versus BC.

  • Incident Response versus DR.

  • Organizational resilience.

  • The relationship between the BIA and recovery design.

  • RTO.

  • RPO.

  • RTO versus RPO.

  • Maximum tolerable downtime conceptually.

  • Why faster recovery generally costs more.

  • What a full backup is.

  • What an incremental backup is.

  • What a differential backup is.

  • Incremental restore requirements.

  • Differential restore requirements.

  • What a snapshot is.

  • Why a snapshot may not be an independent backup.

  • What replication is.

  • Why replication does not replace backup.

  • Why ransomware corruption can replicate.

  • Onsite versus offsite backups.

  • Cloud backup considerations.

  • Online versus offline backup.

  • Why offline copies improve ransomware resilience.

  • What immutable storage means.

  • Why immutable does not mean invulnerable.

  • What an air gap represents.

  • What the 3-2-1 concept represents.

  • Why 3-2-1 is a strategy rather than a universal CISSP mandate.

  • Why backup encryption matters.

  • Why encryption-key recovery matters.

  • Why backup administrators should follow least privilege.

  • Why successful backup jobs do not prove recoverability.

  • Why restore testing matters.

  • Why backup retention matters during long-dwell compromise.

  • Why application/configuration/software recovery resources matter.

  • What a cold site is.

  • What a warm site is.

  • What a hot site is.

  • Cold versus warm versus hot tradeoffs.

  • What a reciprocal agreement is.

  • What a resource-capacity agreement is.

  • What multiple processing sites are.

  • Active-active versus active-passive.

  • What failover is.

  • What failback is.

  • Why failback requires planning.

  • What high availability means.

  • What fault tolerance means.

  • HA versus fault tolerance.

  • Why HA does not automatically equal DR.

  • What redundancy means.

  • What common-mode failure means.

  • Why geographic diversity matters.

  • Why diverse telecommunications/power may matter.

  • What QoS does.

  • Why QoS does not create bandwidth.

  • What triggers DR activation.

  • Why declaration authority should be defined.

  • Why personnel alternates are required.

  • Why life safety comes before technology recovery.

  • Why alternate communications matter.

  • What damage assessment means.

  • Why recovery priorities come from business requirements.

  • Why dependencies determine restoration order.

  • Why DNS, identity, network, and storage may be foundational.

  • What clean recovery means.

  • Why recovery from ransomware can reinfect systems.

  • Why credentials may need rebuilding during recovery.

  • What recovery validation means.

  • Why β€œserver online” does not automatically mean β€œbusiness recovered.”

  • Why DR personnel need training.

  • What DR lessons learned should accomplish.

  • Read-through testing.

  • Tabletop testing.

  • Walkthrough testing.

  • Simulation testing.

  • Parallel testing.

  • Full-interruption testing.

  • Which DR tests have lower versus higher operational risk.

  • Why a parallel test does not intentionally interrupt production.

  • Why full interruption provides strong evidence but significant risk.

  • Why test success criteria should be established beforehand.

  • Why RTO and RPO should be measured during exercises.

  • Why failed exercises provide useful evidence.

  • What Business Continuity means.

  • What a manual workaround is.

  • Why manual work must be reconciled after recovery.

  • Why key-person dependencies matter.

  • Why supplier continuity matters.

  • Why cloud platforms do not eliminate continuity risk.

  • Why administrative separation can protect backups.

  • Why golden images and IaC can support clean recovery.

  • Why recovery documentation must remain accessible during a disaster.

  • Why business owners should validate restored services.


Coming Next

Lesson Twenty-Eight: Physical Security Operations, Personnel Safety, and Emergency Management

Lesson Twenty-Eight will complete the remaining major CISSP Domain 7 objectives by focusing primarily on:

7.14 β€” Implement and Manage Physical Security

Including:

  • perimeter security controls;

  • internal security controls.

7.15 β€” Address Personnel Safety and Security Concerns

Including:

  • travel;

  • security training and awareness;

  • insider threats;

  • social-media impacts;

  • two-factor/MFA fatigue;

  • emergency management;

  • duress.

The lesson will cover:

  • physical-security operations;

  • defense in depth;

  • site perimeter;

  • fencing;

  • gates;

  • bollards;

  • lighting;

  • CCTV;

  • guards;

  • access badges;

  • visitor management;

  • mantraps/access vestibules;

  • tailgating;

  • piggybacking;

  • secure areas;

  • server-room controls;

  • equipment security;

  • environmental monitoring;

  • fire;

  • water;

  • HVAC;

  • power;

  • physical intrusion detection;

  • key management;

  • badge lifecycle;

  • travel security;

  • laptop/mobile-device travel protections;

  • hotel/public-network risk;

  • international travel considerations;

  • insider threat;

  • behavioral reporting;

  • social-media exposure;

  • social engineering;

  • MFA fatigue;

  • emergency management;

  • evacuation;

  • shelter-in-place;

  • muster/accountability;

  • duress alarms;

  • panic mechanisms;

  • personnel safety;

  • original SierraTec operational-security models;

  • exam traps;

  • knowledge checks;

  • CISSP-style scenarios.

The central Lesson Twenty-Eight question will be:

How should organizations operate physical and personnel security controls so facilities, equipment, information, and people remain protected during normal operations, travel, emergencies, insider-threat situations, and physical-security incidents?


Publication and Independence Notice

This lesson is independently developed educational material for the SierraTec Secure CISSP Certification Preparation Course.

CISSP is administered by ISC2. SierraTec Secure's course is independent certification-preparation material and should not be represented as official ISC2 training unless separately authorized.

The primary exam alignment was verified against the current official CISSP Certification Exam Outline. Objectives 7.10–7.13 currently address recovery strategies, DR implementation, DR testing, and BC planning/exercises.

NIST SP 800-34 Rev. 1 remains listed by NIST as its final contingency-planning guide and provides guidance connecting BIA, recovery strategies, contingency plans, testing/training/exercises, and plan maintenance.

Cyber-event recovery concepts were supplemented with NIST SP 800-184, which emphasizes recovery planning, resource prioritization, testing, playbooks, metrics, and continuous improvement.

Current ransomware-oriented backup practices were supplemented with CISA guidance recommending offline, encrypted backups, routine restore testing, protected golden images, and clean recovery processes designed to avoid reinfection.

The SierraTec Secure BACKUP, RESTORE, and CONTINUE frameworks, diagrams, examples, comparison tables, knowledge checks, and practice questions are original instructional material and are not actual, recalled, leaked, or official CISSP examination questions.

Sallieu Kanu

Sallieu Kanu

Product Designer
0
Best Seller
Faithful User
Expert Vendor
King Seller

Class Sessions

1- Introduction to CISSP 2- Thinking Like a CISSP: Security Principles, Risk, and Professional Decision-Making 3- Lesson 1 4- Lesson 3 5- Lesson 4: Risk Management, Risk Assessment, and Risk Treatment 6- Lesson 5: Threat Modeling, Supply-Chain Risk, and Third-Party Risk 7- Lesson 6: Legal, Regulatory, Privacy, Compliance, and Investigation Foundations 8- Lesson 7: Asset Security and Information Lifecycle Management 9- Lesson 8: Security Architecture Foundations and Protection Mechanisms 10- Lesson 9: Security Models, Trusted Systems, and Secure Design 11- Lesson 10: Cryptography and Cryptographic Solutions 12- Lesson 11: Cryptographic Attacks and Public Key Infrastructure 13- Lesson 12: Physical and Facility Security Architecture 14- Lesson 13: Information System Lifecycle and Secure Engineering 15- Lesson 14: Communication and Network Security Foundations 16- Lesson 15: Secure Network Components and Infrastructure Protection 17- Lesson 16: Secure Communication Channels, Remote Access, and Third-Party Connectivity 18- Lesson 17: Identity and Access Management Foundations 19- Lesson 18: Authentication Systems, Federation, SSO, and Identity Protocols 20- Lesson 19: Authorization Models and Access-Control Enforcement 21- Lesson 20: Identity Provisioning, Access Reviews, Privileged Access, and Account Lifecycle 22- Lesson 21: Security Assessment and Testing Foundations 23- Lesson 22: Advanced Security Control Testing and Vulnerability Management 24- Lesson 23: Security Metrics, Test Analysis, Reporting, and Audit Assurance 25- Lesson 24: Security Operations, Investigations, Evidence, and Logging Foundations 26- Lesson 25: Configuration Management, Resource Protection, Patch Management, and Change Control 27- Lesson 26: Incident Management and Operational Detection and Prevention 28- Lesson 27: Backup, Recovery Strategies, Disaster Recovery, and Business Continuity Operations

Join Us Today

We'll send the best deals and offers to your email. No spam, ever.

GDPR

When you visit any of our websites, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. Click on the different category headings to find out more and manage your preferences. Please note, that blocking some types of cookies may impact your experience of the site and the services we are able to offer.