ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
While updating the company's Business Continuity Plan (BCP), the security lead discovers that the organization's public-facing SaaS platform is deployed only in a single cloud region. To best ensure this critical service remains available if that region suffers a prolonged outage, which measure should be added to the BCP?
Schedule quarterly phishing-awareness training sessions for all software engineers.
Provision a secondary cloud region with automated failover and document Recovery Time Objectives for the service.
Incorporate detailed secure-coding guidelines for input validation used by the development team.
Expand the incident response escalation matrix to include additional contacts for data breach scenarios only.
A sound BCP must provide a means to keep essential business services running during a disruptive event. For a cloud-hosted application located in one region, the most effective safeguard is to define and provision an alternate processing site-such as a secondary cloud region-with automated failover and clearly documented Recovery Time Objectives (RTOs). This directly addresses service continuity by ensuring workload relocation within an acceptable downtime window. Coding standards and developer training improve security and quality but do not guarantee service availability during a regional outage. An escalation path limited to data breaches handles only one incident type and does not by itself sustain operations. Therefore, establishing cross-region redundancy with specified RTOs is the correct addition to the BCP.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Recovery Time Objective (RTO)?
Open an interactive chat with Bash
How does automated failover work in cloud environments?
Open an interactive chat with Bash
Why is cross-region redundancy important for business continuity?
Open an interactive chat with Bash
What is a cloud region?
Open an interactive chat with Bash
What is a Recovery Time Objective (RTO)?
Open an interactive chat with Bash
What is automated failover?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)