Pre-stage CloudFormation templates in S3 and rely on cross-Region replication for images and Aurora backups

Answer Correct answer: B — stage the CloudFormation templates in S3 and use cross-Region replication for the ECR images and Aurora backups so no rebuild is needed during recovery.

A company runs a web application that extends across multiple Availability Zones. The company uses an Application Load Balancer (ALB) for routing, AWS Fargate for the application, and Amazon Aurora for the application data. The company uses AWS CloudFormation templates to deploy the application. The company stores all Docker images in an Amazon Elastic Container Registry (Amazon ECR) repository in the same AWS account and AWS Region. A DevOps engineer needs to establish a disaster recovery (DR) process in another Region. The solution must meet an RPO of 8 hours and an RTO of 2 hours. The company sometimes needs more than 2 hours to build the Docker images from the Dockerfile. Which solution will meet the RTO and RPO requirements MOST cost-effectively?

  1. Copy the CloudFormation templates and the Dockerfile to an Amazon S3 bucket in the DR Region. Use AWS Backup to configure automated Aurora cross-Region hourly snapshots. In case of DR, build the most recent Docker image and upload the Docker image to an ECR repository in the DR Region. Use the CloudFormation template that has the most recent Aurora snapshot and the Docker image from the ECR repository to launch a new CloudFormation stack in the DR Region. Update the application DNS records to point to the new ALB.
  2. Copy the CloudFormation templates to an Amazon S3 bucket in the DR Region. Configure Aurora automated backup Cross-Region Replication. Configure ECR Cross-Region Replication. In case of DR, use the CloudFormation template with the most recent Aurora snapshot and the Docker image from the local ECR repository to launch a new CloudFormation stack in the DR Region. Update the application DNS records to point to the new ALB. Correct Answer
  3. Copy the CloudFormation templates to an Amazon S3 bucket in the DR Region. Use Amazon EventBridge to schedule an AWS Lambda function to take an hourly snapshot of the Aurora database and of the most recent Docker image in the ECR repository. Copy the snapshot and the Docker image to the DR Region. In case of DR, use the CloudFormation template with the most recent Aurora snapshot and the Docker image from the local ECR repository to launch a new CloudFormation stack in the DR Region.
  4. Copy the CloudFormation templates to an Amazon S3 bucket in the DR Region. Deploy a second application CloudFormation stack in the DR Region. Reconfigure Aurora to be a global database. Update both CloudFormation stacks when a new application release in the current Region is needed. In case of DR, update the application DNS records to point to the new ALB.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The binding constraint is that image builds can exceed the 2-hour RTO, so the image must be pre-replicated; ECR cross-Region replication does that continuously and hands the DR Region a ready image (B). Option A fails outright because it rebuilds the Docker image during recovery, which can breach the RTO. Option D's Global Database gives excellent RPO but requires standing up and continuously updating a second stack, which is neither the cheapest nor the most time-efficient path for this recovery objective.

With an RPO of 8 hours and an RTO of 2 hours, and image builds sometimes exceeding 2 hours, the DR artifacts must already exist in the secondary Region before a failure. Copying the CloudFormation templates to an S3 bucket in the DR Region, turning on ECR cross-Region replication so images are continuously mirrored, and having Aurora backups replicated so the latest snapshot is available lets the team launch a stack from the newest image and repoint DNS well inside the RTO without ever rebuilding an image.

Building the Docker image during recovery (A)—the question explicitly says builds sometimes take more than 2 hours, which is the entire RTO, so rebuilding on demand cannot meet the objective. Standing up a Global Database with a second always-running stack and updating both stacks on every release (D)—it delivers a much better RPO but adds permanent cost and release-management overhead that the requirements do not demand. Driving snapshots through a scheduled Lambda that copies the image separately (C) is custom automation with more moving parts than native replication.

Community Discussion (9 comments)

thanhnv142 👍 6 Selected: B
B is correct: A: < build the most recent Docker image and upload the Docker image to an ECR repository in the DR Region>: This process might take longer than 2 hours, which does not meet the RTO B: correct C: <AWS Lambda function to take an hourly snapshot of the Aurora database>: lambda has a maximum running time of 15 minutes. Cannot do an hourly task D: No mention about the docker image for the ECS
Srikantha 👍 1 Selected: B
The best option in this case is Option B because it: Ensures both Aurora database and Docker images are replicated to the DR Region, meeting the RPO requirement of 8 hours. Eliminates the need to rebuild Docker images in the DR Region, thus ensuring the RTO of 2 hours is met, which is crucial during the disaster recovery process. Provides a straightforward, cost-effective solution with minimal operational overhead by leveraging AWS native features like cross-Region replication for both Aurora and ECR.
spring21 👍 2 Selected: B
Yes, Amazon Aurora supports cross-Region automated backups:
teo2157 👍 1 Selected: C
B is not correct as Amazon Aurora doesn´t support cross-Region automated backups: https://repost.aws/questions/QUPm9L8amQTTKkz1RXU7EqWA/unable-to-enable-cross-region-automated-backups-in-rds Have anyone that has responded B tried to enable cross-Region automated backups in an Aurora RDS?
dkp 👍 3 Selected: B
answer is B
DanShone 👍 4 Selected: B
B: Least operational overhead, lower cost and meets RPO and RTO
fdoxxx 👍 4 Selected: B
B provides a cost-effective solution that meets the RTO and RPO
LeoSantos121212121212121 👍 2
I also go with B
Chelseajcole 👍 2
B. Most cost effective

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Because image builds can exceed the 2-hour RTO, the Docker image must already be present in the recovery Region before an incident, which ECR cross-Region replication provides continuously and without custom code. Combined with Aurora backup replication and CloudFormation templates staged in S3 in the DR Region, recovery consists of launching a stack from the newest replicated image and updating DNS, which fits inside the RTO while the replicated backups satisfy the 8-hour RPO.

Why the Other Options Are Wrong

A rebuilds the Docker image during recovery; since the question states builds can take more than two hours, this cannot meet the 2-hour RTO, which is the decisive constraint. C replaces native replication with a scheduled Lambda that takes hourly snapshots and copies images, adding custom automation and a copy step that must be maintained and monitored. D reconfigures Aurora as a global database and keeps a second stack running at all times, providing a far better RPO but at higher ongoing cost and with double the release-management work. Note: Aurora's automated backups are Region-local by design, so the cross-Region backup path in practice relies on Global Database or automated snapshot-copy automation rather than a native setting. B is the intended and most cost-effective answer given the stated objectives.

Community Comment Notes

Community voted B (95). Commenters agreed that A fails the RTO because it rebuilds images during recovery, and that replication of both data and images is what makes the 2-hour objective achievable. One commenter correctly noted that Aurora does not support cross-Region automated backup replication natively, which matches the AWS documentation; in practice that piece is satisfied with Global Database or snapshot-copy automation.

Official Reference

Related Analysis

Practice All DOP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full DOP-C02 Practice Test →

← Back to DOP-C02 Study Guide