A county’s HA program documents only application failover. Database failover is assumed to ‘just work’ and has never been tested. What operating practice should architects enforce?
Select an answer to reveal the explanation.
Short Explanation
App failover and database failover are different plays—write both runbooks and practice them. Hoping the database ‘just works’ is how silent gaps show up on incident day.
Full Explanation
Operating HA architectures requires distinct, tested procedures for application and database failover because failure modes and recovery steps differ. Untested combined checklists, app-only documentation, or marketing substitutes leave recovery gaps. Scheduled drills validate RTO assumptions for civic systems. Separate tested runbooks are the professional operations pattern.