ExamOpsPractice free

CompTIA Security+ SY0-701 · Free study guide

Objective 3.4 — Plan for resilience, recovery, and continuity

Resilience keeps important services within acceptable limits during disruption; recovery restores them after failure. Both require business targets. Recovery time objective (RTO) defines the maximum intended restoration interval, while recovery point objective (RPO) defines the maximum tolerable data-loss window. Architecture should be selected from those needs rather than from labels such as “high availability.”

Load balancing distributes work among service instances. Clustering coordinates nodes so another can continue a service after failure. Geographic dispersion reduces one-site exposure, while platform diversity can reduce common-mode failure. Multi-cloud may diversify providers but adds identity, networking, data, skills, and operational complexity.

Recovery facilities and capacity

A hot site has current infrastructure and data for rapid activation. A warm site has partial readiness and requires some restoration or configuration. A cold site provides facilities and basic utilities but needs substantial equipment and data recovery. Faster readiness usually costs more.

Capacity planning includes people, technology, facilities, power, network, suppliers, and time. A recovery platform sized for normal averages may fail during a regional event. A UPS bridges short interruptions and supports controlled shutdown; a generator handles longer outages but needs fuel, maintenance, safe operation, and testing.

Data recovery

Backup design specifies source, scope, frequency, retention, encryption, access, on-site and off-site placement, immutability where appropriate, and restore validation. A snapshot is a point-in-time representation; replication copies changes; journaling records changes that can support granular recovery. Replication can also reproduce deletion or corruption, so it is not a substitute for protected backups.

Testing must prove assumptions. Tabletop exercises walk stakeholders through decisions. Simulations exercise realistic actions without necessarily switching production. Failover tests move service to the alternate capability. Parallel processing runs both paths and compares results. Each test needs objectives, safety limits, evidence, findings, owners, and retesting.

Continuity of operations includes manual procedures, communication, alternate staff, vendor dependencies, and prioritization—not only technology. Recovery plans that rely on one unavailable administrator or an untested vendor portal are fragile.

Decision rule: translate RTO, RPO, criticality, and failure scenarios into architecture, backups, power, staffing, and exercises; do not accept replication status as proof of recoverability.

Practice and apply this objective

A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.

Start practicing free