A company is designing a multi-cloud disaster recovery solution. They need to ensure RPO of 15 minutes and RTO of 1 hour for critical workloads. Which of the following should be implemented?
Trap 1: Asynchronous replication to a secondary cloud with a 30-minute delay
A 30-minute replication delay exceeds the 15-minute RPO, so up to half an hour of data could be lost. Asynchronous replication is tempting because it avoids latency penalties on the primary, and would suit workloads tolerating RPOs of 30 minutes or more.
Trap 2: Pilot light environment that is started manually during a disaster
Manual start-up cannot reliably complete within the one-hour RTO, since detection, decision-making and bootstrapping all consume time. A pilot light is tempting because it minimises ongoing compute cost, and would be correct where RTOs stretch to hours rather than minutes.
Trap 3: Daily backups to object storage in a different region
Daily backups give a 24-hour RPO, far exceeding the 15-minute target, and full restoration typically breaches the one-hour RTO. Backups are tempting because they are cheap and simple, and would be correct for non-critical workloads with relaxed recovery objectives.
- A
Asynchronous replication to a secondary cloud with a 30-minute delay
Why it fails: A 30-minute replication delay exceeds the 15-minute RPO, so up to half an hour of data could be lost. Asynchronous replication is tempting because it avoids latency penalties on the primary, and would suit workloads tolerating RPOs of 30 minutes or more.
- B
Synchronous replication to a standby environment in another cloud provider
Synchronous replication writes to both sites before acknowledging, giving near-zero RPO, which satisfies the 15-minute target. A standby environment in another provider delivers cross-cloud redundancy, and automated failover meets the one-hour RTO. Asynchronous replication would risk exceeding the RPO.
- C
Pilot light environment that is started manually during a disaster
Why it fails: Manual start-up cannot reliably complete within the one-hour RTO, since detection, decision-making and bootstrapping all consume time. A pilot light is tempting because it minimises ongoing compute cost, and would be correct where RTOs stretch to hours rather than minutes.
- D
Daily backups to object storage in a different region
Why it fails: Daily backups give a 24-hour RPO, far exceeding the 15-minute target, and full restoration typically breaches the one-hour RTO. Backups are tempting because they are cheap and simple, and would be correct for non-critical workloads with relaxed recovery objectives.