312-76 Disaster Recovery Professional (EDRP) Practice Questions
Prepare for 312-76 with more than an answer.
- Exam fee
- $250 USD
- Level
- Professional
Domains covered on the exam 7
- Introduction to Disaster Recovery and Business Continuity9%
- Risk Assessment7%
- Business Impact Analysis and Business Continuity Plan12%
- Data Backup Strategies17%
- Data Recovery Strategies37%
- Disaster Recovery Planning Process10%
- BCP Testing, Maintenance, and Training8%
- 1
An organization is considering a Disaster Recovery strategy for its Tier-2 applications. Management wants a solution that provides a recovery site with all necessary infrastructure (power, cooling, network connectivity) but does not want to pay for dedicated server hardware that will sit idle. The IT staff will be responsible for installing and configuring servers and restoring data when a disaster is declared. Which type of recovery site BEST fits these requirements?
Show answer details
Correct answer: C
A cold site is the correct answer. It is an environmentally controlled space with power, cooling, and network connectivity, but it does not contain any IT hardware. The organization is responsible for providing and installing all servers and storage. This model is the least expensive option and aligns perfectly with the requirement to avoid paying for idle hardware. Hot sites are fully equipped and ready for immediate failover, while warm sites have hardware but may require software and data restoration.
- 2
Which RAID level provides the highest write performance and storage utilization but offers no fault tolerance?
Show answer details
Correct answer: A
RAID 0, also known as striping, writes data across multiple disks simultaneously. This significantly increases read and write performance and utilizes 100% of the disks' capacity for storage. However, it does not include any parity or mirroring, so if a single disk in the array fails, all data on the entire array is lost. It is used for high-performance needs where data loss is not a concern, such as video editing scratch disks.
- 3
A business continuity planner is developing a training program for employees. The goal is to ensure that all staff, not just the technical recovery teams, understand their roles during a disruptive event. Which type of training is MOST appropriate for this broad audience?
Show answer details
Correct answer: C
General awareness training is designed for all employees to provide a high-level understanding of the business continuity plan. It covers topics like how to report an incident, where to find information during an event (e.g., emergency notification system), and basic safety procedures. It ensures everyone knows the plan exists and their part in it, without getting into deep technical details, which are reserved for role-based training for specific teams.
- 4
A project manager is tasked with creating the initial Disaster Recovery Plan for a new startup. Which of the following represents the correct logical sequence of activities in the DR planning process?
flowchart TD A[Risk Assessment] --> B[Business Impact Analysis]; B --> C[Strategy Selection]; C --> D[Plan Development]; D --> E[Testing & Maintenance];Show answer details
Correct answer: C
The correct sequence starts with the Business Impact Analysis (BIA) to identify critical functions and recovery objectives (RTO/RPO). This is followed by a Risk Assessment to identify threats to these critical functions. Based on the BIA and Risk Assessment, a suitable recovery Strategy is Selected. Only then can the detailed Plan be Developed. Finally, the plan must undergo regular Testing and maintenance.
- 5
Case Study:
HealthFirst Corp, a regional healthcare provider, was recently hit by a ransomware attack that encrypted servers in their primary data center, including their primary domain controllers and backup server. The attack rendered their production environment unusable. Their DR plan called for restoring from backups stored on a NAS device within the same data center network segment.
Upon investigation, the incident response team found that the ransomware had propagated to the NAS and encrypted all backup files as well. The only viable backups were on tapes that had been sent offsite one week prior, resulting in a one-week RPO, far exceeding the 24-hour RPO defined in their BIA. The recovery process took over 10 days, causing massive disruption.
A post-incident review has been convened to identify the key failures in their data recovery strategy that allowed this catastrophic outcome. The CISO wants to implement changes to prevent a recurrence.
Which of the following is the MOST critical strategic failure that needs to be addressed?
Show answer details
Correct answer: B
The most critical failure was the lack of a secure, isolated backup copy. By storing their primary backups on an online, network-accessible NAS in the same security domain as the production servers, they created a single point of failure for a ransomware attack. A modern DR strategy against ransomware requires at least one copy of the backups to be either air-gapped (like the offsite tapes, but with better RPO) or immutable (unable to be changed or deleted, even by an administrator). This prevents the attacker from destroying the recovery mechanism. While tape frequency and network segmentation are issues, the core strategic flaw is the absence of a survivable backup copy.
- 6
A manufacturing firm uses a legacy SCADA system that runs on a physical server with a specialized PCI card. The Business Impact Analysis (BIA) has established a Recovery Time Objective (RTO) of 4 hours. The current DR plan involves shipping tape backups to a cold site. During a recent test, the team discovered that sourcing and configuring a compatible server with the required PCI card would take at least 48 hours. Which of the following is the MOST cost-effective solution to meet the RTO?
Show answer details
Correct answer: B
The most effective solution is to perform a P2V conversion. This decouples the legacy operating system and application from the specific underlying hardware. Once virtualized, the VM can be replicated to a warm site. This allows for rapid failover to dissimilar hardware, easily meeting the 4-hour RTO without the high cost of a full platform migration or a dedicated hot site. Migrating to a cloud-native platform is a major, expensive project, not a DR solution. A hot site would work but is very expensive. Improving logistics for the cold site doesn't solve the fundamental hardware dependency issue.
- 7
A DR planner is designing a backup strategy for a distributed environment with multiple remote offices connected via high-latency WAN links. The goal is to minimize WAN traffic while ensuring data can be recovered efficiently at a central data center. Which combination of technologies would be MOST suitable for this scenario? (Select TWO)
Show answer details
Correct answer: A, C
Source-side deduplication reduces the amount of data that needs to be sent over the WAN by eliminating redundant blocks before transmission. This directly addresses the goal of minimizing WAN traffic.
A centralized backup server allows for the consolidation and management of backups from all remote offices, meeting the requirement for efficient recovery at a central data center.
- 8
During a tabletop exercise for a business continuity plan, the facilitator presents a scenario where the primary data center has been rendered inaccessible due to a regional power outage. The DR team lead immediately instructs the technical staff to initiate the failover to the secondary site. Which critical step in the BCP activation process was missed?
Show answer details
Correct answer: C
Before any technical failover procedures are initiated, a formal disaster declaration must be made by authorized executive management. This is a critical governance step that authorizes the significant resources, costs, and operational changes associated with activating the DR plan. The DR team lead does not typically have the authority to make this declaration independently. This step ensures the decision is made at the appropriate business level.
- 9
A DR consultant is reviewing a company's data recovery strategy. The company uses virtualization extensively and has implemented VM replication to a secondary site with a 15-minute Recovery Point Objective (RPO). The consultant notes that while the virtual machines are replicated, the virtual network configurations, including VLANs, firewall rules, and IP addressing schemes, are managed manually and are not documented in the DR plan. What is the primary risk associated with this finding?
Show answer details
Correct answer: B
While the VM data is available (meeting the RPO), the inability to quickly and accurately restore the network environment will significantly delay the process of bringing services back online. Manually reconfiguring complex network settings under pressure is time-consuming and error-prone, which directly impacts and extends the recovery time, making it highly likely that the RTO will be missed. The RPO is related to data loss, which is handled by replication, whereas RTO is about the time to restore service.
- 10
True or False: In a Business Continuity Management System (BCMS) compliant with ISO 22301, the Business Impact Analysis (BIA) and risk assessment are independent activities that can be performed in any order.
Show answer details
Correct answer: B
False. According to ISO 22301, the BIA and risk assessment are related and sequential activities. The BIA is conducted first to identify critical business activities and their recovery timeframes (RTOs). The results of the BIA then inform the risk assessment, which focuses on identifying risks to these specific critical activities. The BIA determines 'what' is important, and the risk assessment determines 'what' can harm it.
