During a ransomware playbook review, an attacker is assumed to have every Data Domain admin credential. Which protection pattern is most defensible?
Select an answer to reveal the explanation.
Short Explanation
Think of it like this: if the attacker already has every key, you can't rely on access control alone. Retention lock keeps data from being deleted or shortened, while an air-gapped replica gives you a copy that isn't reachable until you deliberately reconnect it. The trap is trusting one control; stack them so credential compromise doesn't erase your recovery option.
Full Explanation
Retention lock is a Data Domain control that makes a defined retention period non-erasable: privileged users cannot delete or shorten protected data before it expires. An air-gapped or disconnected replica adds a separate copy whose connectivity is removed, so an attacker who already holds every management credential cannot reach it continuously. The combination is defensible because each control covers the other's weakness: retention lock preserves the primary against malicious deletion, while isolation protects a clean copy even if credentials are abused. A networked replica with retention lock can still be exposed to credential misuse, because the replica remains reachable and may accept replication traffic or become corrupted. Immutable snapshots plus credential rotation are useful hygiene, but rotation does not neutralize stolen active credentials, and snapshots that remain online may still be affected by an attacker. An air-gapped replica without retention lock can be deleted, modified, or replaced once the isolation is broken, so it lacks the enforceable immutability needed for a ransomware playbook. Exam caveat: choose the pattern that survives a full credential compromise, not the feature that merely looks secure. Operational check: confirm retention lock is applied to the relevant MTrees and document the disconnected replica's isolation, recovery, and reconnection procedure.