ExamRange

CND (312-38) Network Defense Simulation

In this simulation, you will analyze a post-incident Business Continuity and Disaster Recovery (BC/DR) scenario. Understanding the correct sequence of bringing systems back online is critical for minimizing downtime and maintaining organizational resilience.

01. Network Scenario

A severe ransomware infection has completely compromised the primary data center. The incident response team has severed all external connections to contain the spread. The primary site is deemed temporarily unusable for the next 72 hours.

The Network Defense team is now coordinating with the DR (Disaster Recovery) site (a warm standby location) to bring services back online based strictly on the Business Impact Analysis (BIA) prioritization.

Primary Site Status
  • • Network: ISOLATED (Air-gapped)
  • • Storage: ENCRYPTED / COMPROMISED
  • • Phase: Containment/Eradication
DR Site Activation
  • • Priority 1: IAM / Active Directory
  • • Priority 2: Core Database Clusters
  • • Priority 3: Internal ERP Systems

02. Traffic & Logs

[DR ORCHESTRATOR] 14:02:11 - Initiating BC/DR Failover Sequence
[INFO] Primary Site Heartbeat: TIMEOUT
[ACTION] Activating Warm Site VMs...
[INFO] BIA Tier 1 Startup - Domain Controllers (dc-dr-01): ONLINE
[INFO] BIA Tier 1 Startup - VPN Gateway (vpn-dr-01): ONLINE
[INFO] BIA Tier 2 Startup - App Servers pending DB synchronization...
[WARNING] Non-critical systems (Marketing web, Dev environment) halted until Tier 1/2 are verified.
[STATUS] Operations transitioning to alternate location based on criticality.
                

03. Question

Which BC/DR activity works on the assumption that the most critical processes are brought back from a remote location first, followed by the less critical functions?