CISSP Security Operations Practice Question
A company plans to implement a disaster recovery site that can be operational within 2 hours of a failure. Which type of DR site best meets this requirement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hot site
Hot sites are fully operational and can be activated within minutes to a few hours.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Hot site
Why this is correct
A hot site represents a fully operational, mirror image of the primary production environment, complete with all necessary hardware, software, and up-to-date data. This configuration allows for near-instantaneous failover and activation, typically within 1-2 hours, minimizing both downtime (RTO) and data loss (RPO). Its readiness ensures business continuity for critical systems requiring the lowest possible recovery times.
- ✗
Warm site
Why it's wrong here
A warm site is a partially equipped disaster recovery facility that includes essential hardware and network connectivity, but may lack current data or all necessary applications. While it offers a faster recovery than a cold site, it still requires several hours, often more than two, for data restoration, application configuration, and system validation before becoming fully operational. This extended setup time makes it unsuitable for systems demanding immediate failover capabilities.
- ✗
Cold site
Why it's wrong here
A cold site provides only the basic infrastructure, such as space, power, and cooling, without any pre-installed hardware, software, or data. Activating a cold site involves procuring and installing all necessary equipment, configuring systems, and restoring data, a process that can take days or even weeks. This extensive lead time for setup and operational readiness makes it impractical for organizations with stringent recovery time objectives.
- ✗
Reciprocal agreement
Why it's wrong here
A reciprocal agreement involves two organizations mutually agreeing to provide backup facilities to each other in the event of a disaster. However, this strategy inherently carries significant risks, as it relies entirely on the other organization's availability and capacity, which may be compromised during a widespread regional disaster or when their own operational needs conflict. Such agreements typically lack guaranteed activation times and dedicated resources, making them unreliable for critical systems requiring predictable and rapid recovery.
Go deeper
Related to this question
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.