Multi-Region and Geo-Distributed Systems Questions

Running a system across regions and continents: multi-region replication, data residency and sovereignty, geo-routing and CDN edge distribution, cross-region consistency and quorum placement, and conflict resolution when two regions accept writes. Covers regional failover and split-brain prevention, recovery objectives (RTO/RPO), region-by-region rollout and blast-radius containment, and the latency, cost, and consistency tradeoffs of going global. Global distribution strategy across the service and data tiers.

HardTechnical
21 practiced

Design cross-border encryption key management for an international SaaS product: customers in EU, US, and APAC. Requirements: customer data must remain within region, keys must rotate regularly, revocation must be auditable, and customers may request key deletion. Propose KMS topology, HSM usage, key replication or isolation strategy, access control, and legal implications.

HardTechnical
19 practiced

Design identity federation and authorization for a multi-tenant SaaS spanning regions with local regulatory constraints. Include token issuance models, central vs regional identity providers, cross-region token validation, key rotation, privacy considerations, and approaches to minimize authentication latency.

MediumTechnical
34 practiced

Describe cross-region key management and encryption options: a single global KMS, regional KMS with federation, customer-managed keys with HSM, and bring-your-own-key. Discuss rotation, access controls, cross-region replication (if allowed), performance impact, and compliance trade-offs.

That is every published Multi-Region and Geo-Distributed Systems question for Security Architect so far. Browse the other topics in this category, or practice this one interactively.