Pre-stage CloudFormation templates in S3 and rely on cross-Region replication for images and Aurora backups
A company runs a web application that extends across multiple Availability Zones. The company uses an Application Load Balancer (ALB) for routing, AWS Fargate for the application, and Amazon Aurora for the application data. The company uses AWS CloudFormation templates to deploy the application. The company stores all Docker images in an Amazon Elastic Container Registry (Amazon ECR) repository in the same AWS account and AWS Region. A DevOps engineer needs to establish a disaster recovery (DR) process in another Region. The solution must meet an RPO of 8 hours and an RTO of 2 hours. The company sometimes needs more than 2 hours to build the Docker images from the Dockerfile. Which solution will meet the RTO and RPO requirements MOST cost-effectively?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The binding constraint is that image builds can exceed the 2-hour RTO, so the image must be pre-replicated; ECR cross-Region replication does that continuously and hands the DR Region a ready image (B). Option A fails outright because it rebuilds the Docker image during recovery, which can breach the RTO. Option D's Global Database gives excellent RPO but requires standing up and continuously updating a second stack, which is neither the cheapest nor the most time-efficient path for this recovery objective.
With an RPO of 8 hours and an RTO of 2 hours, and image builds sometimes exceeding 2 hours, the DR artifacts must already exist in the secondary Region before a failure. Copying the CloudFormation templates to an S3 bucket in the DR Region, turning on ECR cross-Region replication so images are continuously mirrored, and having Aurora backups replicated so the latest snapshot is available lets the team launch a stack from the newest image and repoint DNS well inside the RTO without ever rebuilding an image.
Building the Docker image during recovery (A)—the question explicitly says builds sometimes take more than 2 hours, which is the entire RTO, so rebuilding on demand cannot meet the objective. Standing up a Global Database with a second always-running stack and updating both stacks on every release (D)—it delivers a much better RPO but adds permanent cost and release-management overhead that the requirements do not demand. Driving snapshots through a scheduled Lambda that copies the image separately (C) is custom automation with more moving parts than native replication.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Because image builds can exceed the 2-hour RTO, the Docker image must already be present in the recovery Region before an incident, which ECR cross-Region replication provides continuously and without custom code. Combined with Aurora backup replication and CloudFormation templates staged in S3 in the DR Region, recovery consists of launching a stack from the newest replicated image and updating DNS, which fits inside the RTO while the replicated backups satisfy the 8-hour RPO.Why the Other Options Are Wrong
A rebuilds the Docker image during recovery; since the question states builds can take more than two hours, this cannot meet the 2-hour RTO, which is the decisive constraint. C replaces native replication with a scheduled Lambda that takes hourly snapshots and copies images, adding custom automation and a copy step that must be maintained and monitored. D reconfigures Aurora as a global database and keeps a second stack running at all times, providing a far better RPO but at higher ongoing cost and with double the release-management work. Note: Aurora's automated backups are Region-local by design, so the cross-Region backup path in practice relies on Global Database or automated snapshot-copy automation rather than a native setting. B is the intended and most cost-effective answer given the stated objectives.Community Comment Notes
Community voted B (95). Commenters agreed that A fails the RTO because it rebuilds images during recovery, and that replication of both data and images is what makes the 2-hour objective achievable. One commenter correctly noted that Aurora does not support cross-Region automated backup replication natively, which matches the AWS documentation; in practice that piece is satisfied with Global Database or snapshot-copy automation.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →