CISA · Question #264
A national bank recently migrated a large number of business-critical applications to the cloud. Which of the following is MOST important to ensuring the resiliency of the applications?
The correct answer is B. Negotiating a service level agreement (SLA) with the provider. For business-critical applications migrated to the cloud, negotiating a comprehensive Service Level Agreement (SLA) with the provider is most important for ensuring application resiliency, as it contractually defines availability and performance commitments.
Question
A national bank recently migrated a large number of business-critical applications to the cloud. Which of the following is MOST important to ensuring the resiliency of the applications?
Options
- AConducting periodic system stress testing
- BNegotiating a service level agreement (SLA) with the provider
- CUsing a monitoring tool to assess uptime
- DCreating restore points for critical applications
How the community answered
(37 responses)- A3% (1)
- B78% (29)
- C5% (2)
- D14% (5)
Why each option
For business-critical applications migrated to the cloud, negotiating a comprehensive Service Level Agreement (SLA) with the provider is most important for ensuring application resiliency, as it contractually defines availability and performance commitments.
Conducting periodic system stress testing is important for understanding application limits and behavior under load, but it's an internal operational activity, not the primary contractual mechanism for outsourced resiliency.
When critical applications are outsourced to a cloud provider, an SLA is a legally binding contract that defines the expected levels of service, including uptime, performance, and recovery objectives. It holds the provider accountable for maintaining the resiliency of the applications and specifies remedies if these levels are not met, making it the most critical foundational element for ensuring resiliency in an outsourced context.
Using a monitoring tool to assess uptime is a means of observing and verifying service levels, but it doesn't establish the commitment or provide recourse in the same way an SLA does with an external provider.
Creating restore points for critical applications is an important part of data protection and recovery, contributing to resiliency, but an SLA provides the overarching contractual framework for the provider's responsibility in maintaining the entire application's resilience in the cloud environment.
Concept tested: Cloud outsourcing resiliency and SLAs
Topics
Community Discussion
No community discussion yet for this question.