During a cyber-recovery drill, the disconnected Data Domain copy is stale. You need to bring it current and restore protection without weakening the air-gap posture. What should the procedure require?
Select an answer to reveal the explanation.
Short Explanation
Think of an air gap like a fire door: closing it only helps if someone checks it on schedule. You want a planned window to sync, prove the copy is fresh, then shut it again. If you just leave it open and hope immutability saves you, you've traded protection for convenience.
Full Explanation
A disconnected copy is only as useful as its last successful synchronization. In an air-gapped or immutable design, the safe pattern is a planned connection window: bring the copy online, let replication or recovery validation run, confirm the data is fresh and readable, then disconnect it again. This preserves the isolation while giving the organization a current copy to test and, if needed, restore from. A permanently online immutable copy still exposes the data to operational mistakes, compromised credentials, and network-borne ransomware; immutability reduces deletion and overwrite risk, but it is not an air gap. Reconnecting only after a failed replication report creates an uncontrolled, unplanned window and may miss ransomware that silently corrupts backups. Leaving the copy disconnected until an annual test makes the data stale, so the recovery point may be unusable and the drill proves little. Exam caveat: Air-gap posture is a lifecycle, not a one-time cable removal; scheduled sync and re-sever must be part of the policy. Operational check: Document the sync window, validation command or report used to prove freshness, and the person responsible for disconnecting the copy after the drill.