SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
Search
Test your basic knowledge |
CISSP Business Continuity And Disaster Recovery
Start Test
Study First
Subjects
:
certifications
,
it-skills
,
cissp
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Reconstitution Phase
Responsibility: each individual involved should have their responsibilities spelled out in writing and the tasks should be assigned to the individual most situated to handle it - Authority: you need to know what leaders are going to step up to the pl
The business continuity process isn't integrated into the change management process - infrastructure and environment changes occur - reorganization of the company - layoffs - or mergers occur - changes in hardware - software - and applications occur
There is more than one disk controller - so if one fails - the other is ready and available
When it is time for the company to move back into its original site or a new site
2. Hot Site
One site is equipped and configured exactly like the primary site - which serves as a redundant environment. these sites are owned by the company and are mirrors of the original production environment... this is one of the most expensive backup facil
A facility that is leased or rented and is fully configured and ready to operate within a few hours... the only missing resources are usually the data - which will be retrieved from a backup site - and the people who are processing the data. The equi
The most intrusive test to regular operations and business productivity. the original site is shut down - and processing takes place at the alternate site. this test takes a lot of planning and coordination but it can reveal many holes in the plan. f
It's used when threats are identified that cannot be prevented. Taking on the full risk of these threats is often dangerous
3. Mean Time Between Failures (MTBF)
Representatives from at least each of the following departments must be involved with not only the planning stages but also the testing and implementation stages: - Business Units - Senior Management - IT Department - Security Department - Communicat
The estimated lifetime of a piece of equipment... calculated by the vendor of the equipment or a third party
A new type of coverage that insures losses caused by denial-of-service attacks - malware damages - hackers - electronic theft - privacy-related lawsuits and more
An estimate of how long it will take to fix a piece of equipment and get it back into production
4. What issues does a company need to look at when determining when it should move into Reconstitution Phase?
Each disk would have a corresponding mirrored disk that contains the exact same information
It needs to ensure the safety of employees - It needs to ensure an adequate environment is provided (power - facility infrastructure - water - HVAC) - It needs to ensure that the necessary equipment and supplies are present and in working order - It
Company A agrees to allow company B to use its facilities if company B is hit by a disaster - and vice versa. This is a cheaper way to go than the other offsite choices - but is not always the best choice because most environments are maxed out perta
They should make sure there are at least two copies of the company's operating system and critical applications
5. Full-Interruption Test
1. Select individuals to interview for data gathering 2. Create data-gathering techniques (surveys - questionnaires - qualitative and quantitative approaches) 3. Identify the company's critical business functions 4. Identify the resources these funct
The employees who carry out the most critical functions of the company who must be put back to work first
The most intrusive test to regular operations and business productivity. the original site is shut down - and processing takes place at the alternate site. this test takes a lot of planning and coordination but it can reveal many holes in the plan. f
Typically a copy is stored at the BCP coordinator's home - and another copy is stored at the offsite facility... when they are stored offsite - they need to be stored in a way that provides just as much protection as the primary site would provide
6. Checklist Test (Deckcheck Test)
Annually
Copies of the BCP are distributed to the different departments and functional areas for review
One site is equipped and configured exactly like the primary site - which serves as a redundant environment. these sites are owned by the company and are mirrors of the original production environment... this is one of the most expensive backup facil
Focuses on malware - hackers - intrusions - attacks - and other security issues. outlines procedures for incident response
7. Salvage Team
A document that outlines who should be contacted in the event of a disaster - in what order - and who is responsible for doing the calling
One person should be responsible... the authorities are the police department - security guards - fire department - emergency rescue - and management
Responsible for starting the recovery of the original site. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and install equipment and applicat
Includes getting critical systems to another environment while repair of the original facilities is under way - getting the right people to the right places - and performing business in a different mode until regular conditions are back in place
8. Disk Duplexing
After it has been tested
There is more than one disk controller - so if one fails - the other is ready and available
Responsible for getting the alternate site into a working and functioning environment. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and ins
Committing fully to the BCP - Setting policy and goals - Making available the necessary funds and resources - Taking responsibility for the outcome of the development of the BCP - Appointing a team for the process
9. What is the difference between preventive mechanisms and recovery strategies?
Management support
Preventive mechanisms are put into place to try to reduce the possibility of the company experiencing a disaster and - if a disaster does hit - to lessen the amount of damage that will take place - Recovery strategies are processes on how to rescue t
When it is time for the company to move back into its original site or a new site
A facility that is leased or rented and is fully configured and ready to operate within a few hours... the only missing resources are usually the data - which will be retrieved from a backup site - and the people who are processing the data. The equi
10. Emergency Response Procedures
Backup all the files that have changed since the last full or incremental backup. this process sets the archive bit to 0
It's used when threats are identified that cannot be prevented. Taking on the full risk of these threats is often dangerous
A document that outlines who should be contacted in the event of a disaster - in what order - and who is responsible for doing the calling
Prepared actions that are developed to help people in a crisis situation better cope with the disruption. Protection of life is of the utmost importance and should be dealt with first before looking to save material objects!
11. Where does the Recovery Time Objective sit on a chart that keeps track of cost and time?
At the intersection of the cost of disruption and the cost to recover
Define essential business functions and supporting departments - Identify interdependencies between these functions and departments - Discover all possible disruptions that could affect the mechanisms necessary to allow these departments to function
1. Develop the continuity planning policy statement 2. Conduct the business impact analysis (BIA) 3. Identify preventive controls 4. Develop recovery strategies 5. Develop the contingency plan 6. Test the plan and conduct training and exercises 7. Ma
Backing up business data to tapes that are then manually transferred to an offsite facility by a courier or an employee... with automatic tape vaulting - the data are sent over a serial line to a backup tape system at the offsite facility. Electronic
12. NIST Steps for Business Continuity
1. Develop the continuity planning policy statement 2. Conduct the business impact analysis (BIA) 3. Identify preventive controls 4. Develop recovery strategies 5. Develop the contingency plan 6. Test the plan and conduct training and exercises 7. Ma
65%
The least critical functions... it ensures that the critical operations of the company are not negatively affected
The plans that determine the steps needed to protect the company in the event that a senior executive retires - leaves the company - or is killed. also details the people who would step in and assume responsibility
13. Cyberinsurance
A document that outlines who should be contacted in the event of a disaster - in what order - and who is responsible for doing the calling
A new type of coverage that insures losses caused by denial-of-service attacks - malware damages - hackers - electronic theft - privacy-related lawsuits and more
It requires less resources and time
Backup all the files that have changed since the last full or incremental backup. this process sets the archive bit to 0
14. Asynchronous Replication
Backing up business data to tapes that are then manually transferred to an offsite facility by a courier or an employee... with automatic tape vaulting - the data are sent over a serial line to a backup tape system at the offsite facility. Electronic
Maximum tolerable downtime - Operational disruption and productivity - Financial considerations - Regulatory responsibilities - Reputation
The primary and secondary data volumes are only a few milliseconds out of sync - so the replication is nearly real-time
The client pays a monthly fee to retain the right to use the facility in a time of need and then incurs a large activation fee when the facility actually has to be used... most recovery site contracts do not promise to house the company in need at a
15. Once the project plan is completed - what should be done before further steps are taken?
1. Select individuals to interview for data gathering 2. Create data-gathering techniques (surveys - questionnaires - qualitative and quantitative approaches) 3. Identify the company's critical business functions 4. Identify the resources these funct
A leased or rented facility that usually partially configured with some equipment (peripheral devices) - but not the actual computers... it's usually a hot site without the expensive equipment. This is the most widely-used model... it is less expensi
Present it to management for written approval
All employees who participate in operational and support functions - or their representatives - come together to practice executing the disaster recovery plan based on a specific scenario. the scenario is used to test the reaction of each operational
16. Skeleton Crew
The primary and secondary data volumes are only a few milliseconds out of sync - so the replication is nearly real-time
Fortification of the facility in its construction materials - redundant servers and communications links - power lines coming in through different transformers - redundant vendor support - purchasing of insurance - purchasing of UPS and generators -
The employees who carry out the most critical functions of the company who must be put back to work first
All data are backed up and saved to some type of storage media. backup and restoration processes are very simplistic and straightforward with this method
17. What does the BCP team need to understand about critical business processes?
The plans that determine the steps needed to protect the company in the event that a senior executive retires - leaves the company - or is killed. also details the people who would step in and assume responsibility
Required roles - Required resources - Input and output mechanisms - Workflow steps - Required time for completion - How they interface with other processes
Typically a copy is stored at the BCP coordinator's home - and another copy is stored at the offsite facility... when they are stored offsite - they need to be stored in a way that provides just as much protection as the primary site would provide
The employees who carry out the most critical functions of the company who must be put back to work first
18. Disk Shadowing
A facility that is leased or rented and is fully configured and ready to operate within a few hours... the only missing resources are usually the data - which will be retrieved from a backup site - and the people who are processing the data. The equi
Data are dynamically created and maintained as images on two or more identical disks. this method is used to ensure the availability of data and to provide a fault-tolerant solution by duplicating hardware and maintaining more than one copy of the in
Representatives from at least each of the following departments must be involved with not only the planning stages but also the testing and implementation stages: - Business Units - Senior Management - IT Department - Security Department - Communicat
Annually
19. Redundant Site
One site is equipped and configured exactly like the primary site - which serves as a redundant environment. these sites are owned by the company and are mirrors of the original production environment... this is one of the most expensive backup facil
Maximum tolerable downtime - Operational disruption and productivity - Financial considerations - Regulatory responsibilities - Reputation
Preventive mechanisms are put into place to try to reduce the possibility of the company experiencing a disaster and - if a disaster does hit - to lessen the amount of damage that will take place - Recovery strategies are processes on how to rescue t
The estimated lifetime of a piece of equipment... calculated by the vendor of the equipment or a third party
20. Restoration Team
Since the software vendor provides its customers with only the compiled version of its applications - it's difficult for the customer to continue to use it if the vendor goes out of business. So the customer should set up a Software Escrow agreement
Backing up business data to tapes that are then manually transferred to an offsite facility by a courier or an employee... with automatic tape vaulting - the data are sent over a serial line to a backup tape system at the offsite facility. Electronic
They should make sure there are at least two copies of the company's operating system and critical applications
Responsible for getting the alternate site into a working and functioning environment. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and ins
21. What are management's responsibilities with regards to BCP planning?
A type of facility-backup option where the back of a large truck or a trailer is turned into a data processing or working area (typically used by military organizations and large insurance companies)
Committing fully to the BCP - Setting policy and goals - Making available the necessary funds and resources - Taking responsibility for the outcome of the development of the BCP - Appointing a team for the process
They want information stated in monetary - quantitative terms - not in subjective - qualitative terms.
Business process recovery - Facility recovery - Supply and technology recovery - User environment recovery - Data recovery
22. IT Contingency Plan
Data are dynamically created and maintained as images on two or more identical disks. this method is used to ensure the availability of data and to provide a fault-tolerant solution by duplicating hardware and maintaining more than one copy of the in
Plan for systems - networks - and major applications recovery procedures after disruptions. a contingency plan should be developed for each major system and application
Make business continuity a part of every business decision - Insert the maintenance responsibilities into job description - Include maintenance in personnel evaluations - Perform internal audits that include disaster recovery and continuity documenta
Includes internal and external communications structure and roles. identifies specific individuals who will communicate with external entities. contains predeveloped statements that are to be released
23. What is the main goal of business continuity?
They want information stated in monetary - quantitative terms - not in subjective - qualitative terms.
Backup all the files that have changed since the last full or incremental backup. this process sets the archive bit to 0
One person should be responsible... the authorities are the police department - security guards - fire department - emergency rescue - and management
To resume business as quickly as possible - spending the least amount of money
24. What is the most critical part of establishing and maintaining a current continuity plan?
Focuses on how to re-create the necessary business processes that need to be reestablished instead of focusing on IT components
It needs to ensure the safety of employees - It needs to ensure an adequate environment is provided (power - facility infrastructure - water - HVAC) - It needs to ensure that the necessary equipment and supplies are present and in working order - It
Management support
1. Select individuals to interview for data gathering 2. Create data-gathering techniques (surveys - questionnaires - qualitative and quantitative approaches) 3. Identify the company's critical business functions 4. Identify the resources these funct
25. What functions should be moved back first during the Reconstitution Phase?
Maximum tolerable downtime - Operational disruption and productivity - Financial considerations - Regulatory responsibilities - Reputation
Typically a copy is stored at the BCP coordinator's home - and another copy is stored at the offsite facility... when they are stored offsite - they need to be stored in a way that provides just as much protection as the primary site would provide
The least critical functions... it ensures that the critical operations of the company are not negatively affected
Reduce the risk of financial loss by improving the company's ability to recover and restore operations
26. Where should the business continuity and disaster recovery plans be stored when they're completed?
27. What are the three main types of leased or rented offsite facilities?
Hot Site - Warm Site - Colde Site
Typically a copy is stored at the BCP coordinator's home - and another copy is stored at the offsite facility... when they are stored offsite - they need to be stored in a way that provides just as much protection as the primary site would provide
To resume business as quickly as possible - spending the least amount of money
After it has been tested
28. How should a company - during the BIA phase - find out what the risks of its geographical location are? And how should they find out how to access emergency zones?
A document that outlines who should be contacted in the event of a disaster - in what order - and who is responsible for doing the calling
Typically a copy is stored at the BCP coordinator's home - and another copy is stored at the offsite facility... when they are stored offsite - they need to be stored in a way that provides just as much protection as the primary site would provide
Contact the local authorities
Preventive mechanisms are put into place to try to reduce the possibility of the company experiencing a disaster and - if a disaster does hit - to lessen the amount of damage that will take place - Recovery strategies are processes on how to rescue t
29. What are the BCP team's responsibilities with regards to BCP planning?
Make business continuity a part of every business decision - Insert the maintenance responsibilities into job description - Include maintenance in personnel evaluations - Perform internal audits that include disaster recovery and continuity documenta
It should be far enough away from the original site so one disaster does not take out both locations... alternate facilities should be at a bare minimum at least five miles away from the primary site - while 15 miles is recommended for most low-to-me
Data are dynamically created and maintained as images on two or more identical disks. this method is used to ensure the availability of data and to provide a fault-tolerant solution by duplicating hardware and maintaining more than one copy of the in
Identifying regulatory and legal requirements that must be met - Identifying all possible vulnerabilities and threats - Estimating the possibilities of these threats and the loss potential - Performing a BIA - Outlining which departments - systems -
30. What is the goal of Disaster Recovery?
To minimize the effects of a disaster and to take the necessary steps to ensure that the resources - personnel - and business processes are able to resume operation in a timely manner. A disaster recovery plan is carried out when everything is still
1. Initiation Phase: goal statements - overview of concepts - roles and teams definitions - task definitions 2. Activation Phase: notification steps - damage assessment - plan activation 3. Recovery Phase: move to alternate site - restore processes -
At the intersection of the cost of disruption and the cost to recover
When it is time for the company to move back into its original site or a new site
31. What are some appropriate and cost-effective preventative methods to better fortify a company from the impacts recognized in the BIA?
Maximum tolerable downtime - Operational disruption and productivity - Financial considerations - Regulatory responsibilities - Reputation
Business process recovery - Facility recovery - Supply and technology recovery - User environment recovery - Data recovery
Typically a copy is stored at the BCP coordinator's home - and another copy is stored at the offsite facility... when they are stored offsite - they need to be stored in a way that provides just as much protection as the primary site would provide
Fortification of the facility in its construction materials - redundant servers and communications links - power lines coming in through different transformers - redundant vendor support - purchasing of insurance - purchasing of UPS and generators -
32. How are offsite backup facility contracts usually established?
The business continuity process isn't integrated into the change management process - infrastructure and environment changes occur - reorganization of the company - layoffs - or mergers occur - changes in hardware - software - and applications occur
The client pays a monthly fee to retain the right to use the facility in a time of need and then incurs a large activation fee when the facility actually has to be used... most recovery site contracts do not promise to house the company in need at a
Contact the local authorities
The least critical functions... it ensures that the critical operations of the company are not negatively affected
33. Executive Succession Planning
The plans that determine the steps needed to protect the company in the event that a senior executive retires - leaves the company - or is killed. also details the people who would step in and assume responsibility
One site is equipped and configured exactly like the primary site - which serves as a redundant environment. these sites are owned by the company and are mirrors of the original production environment... this is one of the most expensive backup facil
Reduce the risk of financial loss by improving the company's ability to recover and restore operations
Use scenario-based exercises as a group to see what issues might crop up
34. What is one of the big issues with legacy equipment and disaster recovery?
35. How can an organization keep the BCP up to date?
Make business continuity a part of every business decision - Insert the maintenance responsibilities into job description - Include maintenance in personnel evaluations - Perform internal audits that include disaster recovery and continuity documenta
Define essential business functions and supporting departments - Identify interdependencies between these functions and departments - Discover all possible disruptions that could affect the mechanisms necessary to allow these departments to function
Object code - source code - libraries - patches and fixes
Establishes senior management and a headquarters after a disaster. outlines roles and authorities - orders of succession - and individual role tasks
36. What are the benefits of using the Differential or Incremental backup methods?
It requires less resources and time
The business continuity process isn't integrated into the change management process - infrastructure and environment changes occur - reorganization of the company - layoffs - or mergers occur - changes in hardware - software - and applications occur
Base it off of the probability of the threat becoming real and the loss potential. the goal is to make sure the insurance coverage fills in the gap of what the current preventative countermeasures cannot protect against
Focuses on how to recover various IT mechanisms after a disaster. whereas a contingency plan is usually for nondisasters - a disaster recover plan is for disasters that require IT processing to take place at another facility
37. In terms of software backups - what should your BCP team address?
38. Full Backup
All data are backed up and saved to some type of storage media. backup and restoration processes are very simplistic and straightforward with this method
A new type of coverage that insures losses caused by denial-of-service attacks - malware damages - hackers - electronic theft - privacy-related lawsuits and more
Responsible for getting the alternate site into a working and functioning environment. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and ins
To minimize the effects of a disaster and to take the necessary steps to ensure that the resources - personnel - and business processes are able to resume operation in a timely manner. A disaster recovery plan is carried out when everything is still
39. As a general rule of thumb - how far away should a backup facility be from the main facility?
It should be far enough away from the original site so one disaster does not take out both locations... alternate facilities should be at a bare minimum at least five miles away from the primary site - while 15 miles is recommended for most low-to-me
Before too many people come to their own conclusions about the company and begin to start false rumors
It has to figure out what the company needs to do to actually recover the items it has identified as being so important to the organization overall... the BIA provides the footprint
Focuses on how to recover various IT mechanisms after a disaster. whereas a contingency plan is usually for nondisasters - a disaster recover plan is for disasters that require IT processing to take place at another facility
40. Who should be responsible for notifying the appropriate authorities and who would those authorities be?
One person should be responsible... the authorities are the police department - security guards - fire department - emergency rescue - and management
Determines the cause of the disaster - Determines the potential for further damage - Identifies the affected business functions and areas - Identifies the level of functionality for the critical resources - Identifies the resources that must be repla
65%
Damage assessment team - legal team - media relations team - network recovery team - relocation team - restoration team - salvage team - security team - telecommunications team
41. Differential Backup
Back up the files that have been modified since the LAST FULL BACKUP. this process does not change the archive bit value
Committing fully to the BCP - Setting policy and goals - Making available the necessary funds and resources - Taking responsibility for the outcome of the development of the BCP - Appointing a team for the process
If the company does not practice due care - the insurance company may not be legally obligated to pay if a disaster hits... this is why it's important to read and understand the fine print
Responsible for getting the alternate site into a working and functioning environment. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and ins
42. Service Level Agreement (SLA)
When it is time for the company to move back into its original site or a new site
A promise that a service will be fulfilled within a certain timeframe
Business Resumption Plan - Continuity of Operations Plan (COOP) - IT Contingency Plan - Crisis Communications Plan - Cyber Incident Response Plan - Disaster Recovery Plan
Data are dynamically created and maintained as images on two or more identical disks. this method is used to ensure the availability of data and to provide a fault-tolerant solution by duplicating hardware and maintaining more than one copy of the in
43. What is one of the big issues with VoIP and disaster recovery?
44. What is the general structure of a BCP?
Representatives from at least each of the following departments must be involved with not only the planning stages but also the testing and implementation stages: - Business Units - Senior Management - IT Department - Security Department - Communicat
65%
1. Initiation Phase: goal statements - overview of concepts - roles and teams definitions - task definitions 2. Activation Phase: notification steps - damage assessment - plan activation 3. Recovery Phase: move to alternate site - restore processes -
Back up the files that have been modified since the LAST FULL BACKUP. this process does not change the archive bit value
45. At what point can a company have real confidence in a developed plan?
After it has been tested
Since the software vendor provides its customers with only the compiled version of its applications - it's difficult for the customer to continue to use it if the vendor goes out of business. So the customer should set up a Software Escrow agreement
Representatives from at least each of the following departments must be involved with not only the planning stages but also the testing and implementation stages: - Business Units - Senior Management - IT Department - Security Department - Communicat
A leased or rented facility that usually partially configured with some equipment (peripheral devices) - but not the actual computers... it's usually a hot site without the expensive equipment. This is the most widely-used model... it is less expensi
46. Business Impact Analysis (BIA)
To resume business as quickly as possible - spending the least amount of money
It has to figure out what the company needs to do to actually recover the items it has identified as being so important to the organization overall... the BIA provides the footprint
Responsible for starting the recovery of the original site. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and install equipment and applicat
A functional analysis in which a team collects data through interviews - workshops - and documentary sources; documents business functions - activities - and transactions (maybe in a set of flow charts); develops a hierarchy of business functions; an
47. Mean Time To Repair (MTTR)
An estimate of how long it will take to fix a piece of equipment and get it back into production
The least critical functions... it ensures that the critical operations of the company are not negatively affected
They should make sure there are at least two copies of the company's operating system and critical applications
Base it off of the probability of the threat becoming real and the loss potential. the goal is to make sure the insurance coverage fills in the gap of what the current preventative countermeasures cannot protect against
48. Electronic Vaulting
49. Rolling Hot Site (Mobile Hot Site)
Back up the files that have been modified since the LAST FULL BACKUP. this process does not change the archive bit value
A type of facility-backup option where the back of a large truck or a trailer is turned into a data processing or working area (typically used by military organizations and large insurance companies)
Prepared actions that are developed to help people in a crisis situation better cope with the disruption. Protection of life is of the utmost importance and should be dealt with first before looking to save material objects!
Maximum tolerable downtime - Operational disruption and productivity - Financial considerations - Regulatory responsibilities - Reputation
50. Business Resumption Plan
To minimize the effects of a disaster and to take the necessary steps to ensure that the resources - personnel - and business processes are able to resume operation in a timely manner. A disaster recovery plan is carried out when everything is still
Preventive mechanisms are put into place to try to reduce the possibility of the company experiencing a disaster and - if a disaster does hit - to lessen the amount of damage that will take place - Recovery strategies are processes on how to rescue t
Focuses on how to re-create the necessary business processes that need to be reestablished instead of focusing on IT components
Data are dynamically created and maintained as images on two or more identical disks. this method is used to ensure the availability of data and to provide a fault-tolerant solution by duplicating hardware and maintaining more than one copy of the in