CCSP Cloud Concepts, Architecture, and Design Practice Question
A logistics firm runs a customer portal on a public cloud provider. The board wants assurance that a provider outage will not halt order intake. The architect proposes an active-passive deployment in a second region of the same provider. Which design element is MOST critical to validate the recovery time objective?
⚠ Common exam trap
The trap here is treating a provider availability commitment or a configured replication link as proof of business continuity, when only an executed failover measures real recovery time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Regularly scheduled failover tests that measure actual recovery time and data loss
Recovery objectives are validated by measurement, not by documentation or provider guarantees. Scheduled failover exercises reveal the real elapsed time to restore service and the true data loss window, accounting for DNS time-to-live, database promotion, and application reconnection. Replication and agreements enable recovery, but only testing produces the evidence that the stated recovery time objective is achievable.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A documented failover runbook that has never been executed
Why it's wrong here
Documentation alone does not prove that the recovery time objective is achievable. Untested steps frequently hide wrong DNS targets, missing credentials, or quota limits that surface only during a real event. A runbook is a necessary artifact but provides no evidence of elapsed recovery time, so it cannot validate the objective the board is asking about.
- ✓
Regularly scheduled failover tests that measure actual recovery time and data loss
Why this is correct
The only credible way to validate a recovery time objective and recovery point objective is to exercise the failover and measure how long the standby region takes to serve production traffic and how much data is missing. Scheduled game days expose stale DNS records, replication lag, and capacity shortfalls, and the measured results become the evidence the board needs.
- ✗
A service level agreement from the provider guaranteeing 99.99 percent regional availability
Why it's wrong here
A provider service level agreement covers the provider's own commitments and typically remedies outages with service credits, not with restored order intake. It says nothing about the customer's application dependencies, DNS propagation, or operator response time, which dominate the recovery time objective. Relying on the agreement conflates provider availability with business continuity.
- ✗
Cross-region replication of the database with asynchronous commit enabled
Why it's wrong here
Replication is a prerequisite for recovery, but configuring it does not demonstrate that the objective is met. Replication lag, promotion procedures, and application reconnection behavior all add time that must be measured. Without a test, the architect cannot state the true recovery point or recovery time, so this element is necessary but not sufficient.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.