After last year's ransomware incident, the customer demands a backup copy that an attacker holding production administrative credentials can never reach from the production network. Which pre-deployment response is correct?
Select an answer to reveal the explanation.
Short Explanation
A lock on the door means nothing when the burglar already has the key—that's the thinking behind an air gap. Your customer wants a copy that is logically or physically unreachable, and that is a topology decision: how the copy is isolated, when it's connected, and what licensing makes the schedule repeatable. Write it down now, because it redraws the design.
Full Explanation
An air-gap requirement is a topology decision: it defines which copy of the data is logically or physically beyond reach of production credentials, how and when that copy connects for ingestion or restore, and what licensing, automation, and schedules make the isolation repeatable. Because those choices alter the site's physical and logical design, they belong in pre-deployment requirement gathering alongside replication distance and tenancy. Equating immutability with air-gapping conflates two mechanisms: retention lock makes data undeletable on a connected system, while an air gap removes the reachable path an attacker uses, and the requirement explicitly demands unreachability. Declaring disk-based air gaps impossible fails because modern backup designs deliver disconnected or isolated copies on disk through controlled, scheduled connectivity. Relying on VLAN segmentation alone fails by concept because a segmented but still reachable target remains attackable by credential theft—reachability, not visibility, is what must change. Exam caveat: the design should name who is allowed to connect the copy and how emergency restores traverse the gap. Operational check: draw the data path from production to the protected copy, mark where an administrator cannot cross, and have security approve that diagram before ordering.