certslothcertsloth
AZ-120/Topic 04

Azure / Specialty

High availability and disaster recovery

2 min read5 recall promptsReviewed 2026-10-10

Memory hook: Fence before failover; restore before trusting.

Must remember

  • Availability sets and zones reduce particular infrastructure failure risks; clustering coordinates application/database failover. Design HANA, SAP Central Services and SQL HA using supported cluster patterns.
  • Pacemaker on Linux and Windows clustering have different configuration requirements. STONITH/fencing prevents a failed or isolated node from continuing as a conflicting owner; use supported Azure fence agents or SBD patterns.
  • Load balancers, health probes, cluster virtual IPs and storage/replication must agree. A reachable VM is not proof that the SAP service owns the resource safely.
  • Use HANA System Replication or the appropriate database-native replication for supported database DR. Azure Site Recovery can protect supported infrastructure tiers but is not a universal replacement for database-aware replication.
  • Define RPO/RTO, backup schedules, snapshots, regional placement, DNS and dependency recovery. Test restoration and failover with application validation and a planned failback.
  • Document restart order across database, central services and application instances. DR requires credentials, keys, interfaces and capacity in the target region, not only copied disks.

Choose under exam pressure

Requirement Choice and reason
Prevent two isolated nodes acting as primary Correct fencing and quorum/cluster design.
Recover from a regional outage A rehearsed cross-region plan combining suitable replication, backups and application recovery.

Traps

  • HA protects against some failures; it does not replace backup history.
  • Disabling fencing to make a cluster start can risk data corruption.

Active recall

1. What is STONITH for?

Ensuring an unsafe node cannot continue writing or owning resources during failover.

2. Why define restart order?

SAP tiers have dependencies that must be ready before higher layers start.

3. What does RPO describe?

Acceptable lost data measured in time.

4. Why test failback?

Returning service can create new outages or divergent data if not planned.

5. What must a DR test validate?

Business function, data consistency, interfaces and achieved RPO/RTO.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.