Posts

Showing posts with the label Resilience

MTBF and MTTF Explained: Reliability Metrics for the Server+ Exam

MTBF and MTTF measure how reliable something is. They appear on Server+ under hardware planning and on Security+ under availability, and the pair is almost always tested together with MTTR. The three metrics MTBF — mean time between failures. The average operating time between failures of a repairable system. A server that can be fixed and returned to service has an MTBF. MTTF — mean time to failure. The average operating time until failure of a non-repairable item, one that is replaced rather than repaired. A hard drive or a power supply has an MTTF. MTTR — mean time to repair. The average time to restore a failed system to service. Note that in a security context MTTR more often means respond, repair or remediate depending on the stem — read carefully. The distinction that gets tested: repairable takes MTBF, replaceable takes MTTF . In practice vendors use MTBF loosely for components too, but on an exam the repairable/non-repairable split is the discriminator. How they fit...

RTO vs RPO Explained: Recovery Objectives for the Security+ Exam

RTO and RPO are the two numbers that turn "we need good backups" into an engineering specification. They are constantly confused, and the exam tests the difference directly. The two objectives Recovery time objective — the maximum acceptable time a function may be unavailable. It looks forward from the moment of failure to the moment service resumes. Recovery point objective — the maximum acceptable amount of data loss, expressed as time. It looks backward from the failure to the last usable copy. A clean way to hold it: RTO is "how long can we be down", RPO is "how much work can we afford to lose". Worked example. Failure occurs at 14:00. RPO of one hour means the last good copy must be no older than 13:00, so at most an hour of work is lost. RTO of four hours means service must be back by 18:00. What each one drives This is the practical value, and where exam scenarios land. RPO drives backup frequency and replication. A 24-hour RPO is satis...

Geographic Dispersion of Backups Explained for the Security+ Exam

Geographic dispersion means keeping copies of your data far enough apart that no single event can destroy all of them. The Security+ exam frames it under resilience, and the questions usually turn on one idea: a backup that shares a fate with the original is not a backup. The fate-sharing problem A nightly backup written to a second server in the same rack survives a disk failure. It does not survive a fire, a flood, a power event that takes out the room, or ransomware that reaches every share the backup account can write to. Distance is the control. The further apart the copies, the smaller the set of events that can take both. That is the whole argument, and everything else is working out how far is far enough and what it costs. The 3-2-1 rule The rule the exam expects you to recite: 3 copies of the data — the production copy and two backups. 2 different media or storage types. 1 copy offsite. You will also meet 3-2-1-1-0 : one copy immutable or offline (air-gapped), and ...

Business Continuity Planning Explained: BIA, RTO and DRP for Security+

A business continuity plan keeps the organisation operating through a disruption. It is broader than a disaster recovery plan, and the exam tests the distinction directly. BCP versus DRP Business continuity planning covers the whole organisation: how does the business keep functioning? That includes people, premises, suppliers, communications and manual workarounds, not just technology. Disaster recovery planning is the IT subset: how do we restore systems and data? DRP sits inside BCP. If a building is destroyed, the DRP restores the systems at another site; the BCP covers where staff work, how customers are told, how orders are taken while systems are down, and which functions are restored first. A clean exam framing: BCP keeps the business running, DRP brings the technology back. The business impact analysis The BIA is the foundation, and it comes first. You cannot decide what to protect until you know what losing it costs. It identifies critical business functions, determ...

Mission Essential Functions Explained: BIA Prioritisation for Security+

A mission essential function is an activity the organisation cannot stop doing without failing at its core purpose. Identifying them is the first substantive step of a business impact analysis, because everything downstream — recovery objectives, spending, recovery order — depends on knowing which functions actually matter. Function first, system second The distinction the exam tests. A function is something the business does: taking orders, paying staff, dispatching ambulances, settling trades. A system is technology that supports it. Starting from systems produces the wrong answer, because IT tends to rank systems by how much it costs to run them or how loudly people complain. Starting from functions produces a ranking the business recognises, and it reveals that some expensive systems support nothing essential while some neglected one is load-bearing. The sequence is: identify functions, rank them by impact of loss over time, then map each function to the systems, data, people...