SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
Search
Test your basic knowledge |
CISSP Business Continuity And Disaster Recovery
Start Test
Study First
Subjects
:
certifications
,
it-skills
,
cissp
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. What is the main goal of business continuity?
Network and computer equipment - Voice and data communications resources - Human Resources - Transportation of equipment and personnel - Environment issues (HVAC) - Data and personnel security issues - Supplies (paper - forms - cabling - and so on) -
To resume business as quickly as possible - spending the least amount of money
The business continuity process isn't integrated into the change management process - infrastructure and environment changes occur - reorganization of the company - layoffs - or mergers occur - changes in hardware - software - and applications occur
Fortification of the facility in its construction materials - redundant servers and communications links - power lines coming in through different transformers - redundant vendor support - purchasing of insurance - purchasing of UPS and generators -
2. Structured Walk-Through Test
Representatives from each department or functional area come together to over the plan to ensure its accuracy
Reduce the risk of financial loss by improving the company's ability to recover and restore operations
At the intersection of the cost of disruption and the cost to recover
A document that outlines who should be contacted in the event of a disaster - in what order - and who is responsible for doing the calling
3. Checklist Test (Deckcheck Test)
Responsible for starting the recovery of the original site. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and install equipment and applicat
At the intersection of the cost of disruption and the cost to recover
Copies of the BCP are distributed to the different departments and functional areas for review
The primary and secondary copies are always in sync - which provides true real-time duplication
4. How should a company - during the BIA phase - find out what the risks of its geographical location are? And how should they find out how to access emergency zones?
Responsible for starting the recovery of the original site. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and install equipment and applicat
No - but the team may recognize that the company is at risk because it does not have these procedures in place
Contact the local authorities
The client pays a monthly fee to retain the right to use the facility in a time of need and then incurs a large activation fee when the facility actually has to be used... most recovery site contracts do not promise to house the company in need at a
5. Redundant Site
When the power goes on the computers - it's also going to go out for the phones
Before too many people come to their own conclusions about the company and begin to start false rumors
One site is equipped and configured exactly like the primary site - which serves as a redundant environment. these sites are owned by the company and are mirrors of the original production environment... this is one of the most expensive backup facil
Management support
6. Disk Shadowing
Data are dynamically created and maintained as images on two or more identical disks. this method is used to ensure the availability of data and to provide a fault-tolerant solution by duplicating hardware and maintaining more than one copy of the in
A document that outlines who should be contacted in the event of a disaster - in what order - and who is responsible for doing the calling
Plan for systems - networks - and major applications recovery procedures after disruptions. a contingency plan should be developed for each major system and application
Contact the local authorities
7. What should the BCP team do in the recovery strategy stage?
It has to figure out what the company needs to do to actually recover the items it has identified as being so important to the organization overall... the BIA provides the footprint
A functional analysis in which a team collects data through interviews - workshops - and documentary sources; documents business functions - activities - and transactions (maybe in a set of flow charts); develops a hierarchy of business functions; an
One site is equipped and configured exactly like the primary site - which serves as a redundant environment. these sites are owned by the company and are mirrors of the original production environment... this is one of the most expensive backup facil
The primary and secondary data volumes are only a few milliseconds out of sync - so the replication is nearly real-time
8. Tape Vaulting
Each disk would have a corresponding mirrored disk that contains the exact same information
Before too many people come to their own conclusions about the company and begin to start false rumors
Typically a copy is stored at the BCP coordinator's home - and another copy is stored at the offsite facility... when they are stored offsite - they need to be stored in a way that provides just as much protection as the primary site would provide
Backing up business data to tapes that are then manually transferred to an offsite facility by a courier or an employee... with automatic tape vaulting - the data are sent over a serial line to a backup tape system at the offsite facility. Electronic
9. Continuity Planning Policy Statement
Fortification of the facility in its construction materials - redundant servers and communications links - power lines coming in through different transformers - redundant vendor support - purchasing of insurance - purchasing of UPS and generators -
65%
A document that lays out the scope of the BCP project - the team member roles - and the goals of the project. it outlines what needs to be accomplished after the team communicates with management and comes to agreement on the terms of the project
A new type of coverage that insures losses caused by denial-of-service attacks - malware damages - hackers - electronic theft - privacy-related lawsuits and more
10. What does the BCP team need to understand about critical business processes?
There is more risk for the organization because replacement systems won't be available... that's why many organizations have moved to commercial off the shelf (COTS) products. they want to make sure replacement is possible
Each disk would have a corresponding mirrored disk that contains the exact same information
One site is equipped and configured exactly like the primary site - which serves as a redundant environment. these sites are owned by the company and are mirrors of the original production environment... this is one of the most expensive backup facil
Required roles - Required resources - Input and output mechanisms - Workflow steps - Required time for completion - How they interface with other processes
11. What should an organization do to assure that they will always be able to get some kind of support for their specialized and critical applications (even in the event that the software vendor goes out of business)?
12. Simulation Test
All employees who participate in operational and support functions - or their representatives - come together to practice executing the disaster recovery plan based on a specific scenario. the scenario is used to test the reaction of each operational
A leased or rented facility that supplies the basic environment - electrical wiring - air conditioning - plumbing and flooring - but none of the equipment or additional services. It may take weeks to get the site activated and ready for work. This is
Representatives from each department or functional area come together to over the plan to ensure its accuracy
The primary and secondary copies are always in sync - which provides true real-time duplication
13. Disaster Recovery Plan
The business continuity process isn't integrated into the change management process - infrastructure and environment changes occur - reorganization of the company - layoffs - or mergers occur - changes in hardware - software - and applications occur
It's used when threats are identified that cannot be prevented. Taking on the full risk of these threats is often dangerous
Makes copies of files as they are modified and periodically transmits them to an offsite backup site. The transmission doesn't happen in real time but is carried out in batches
Focuses on how to recover various IT mechanisms after a disaster. whereas a contingency plan is usually for nondisasters - a disaster recover plan is for disasters that require IT processing to take place at another facility
14. IT Contingency Plan
Each disk would have a corresponding mirrored disk that contains the exact same information
Plan for systems - networks - and major applications recovery procedures after disruptions. a contingency plan should be developed for each major system and application
Object code - source code - libraries - patches and fixes
Establishes senior management and a headquarters after a disaster. outlines roles and authorities - orders of succession - and individual role tasks
15. Especially in a software development environment - what should be backed up?
A leased or rented facility that supplies the basic environment - electrical wiring - air conditioning - plumbing and flooring - but none of the equipment or additional services. It may take weeks to get the site activated and ready for work. This is
Backup all the files that have changed since the last full or incremental backup. this process sets the archive bit to 0
There is more risk for the organization because replacement systems won't be available... that's why many organizations have moved to commercial off the shelf (COTS) products. they want to make sure replacement is possible
Object code - source code - libraries - patches and fixes
16. How can an organization keep the BCP up to date?
Nondisaster: a disruption in service due to a device malfunction or failure - Disaster: an event that causes the entire facility to be unusable for a day or longer - Catastrophe: a major disruption that destroys the facility altogether --> requires b
If the company does not practice due care - the insurance company may not be legally obligated to pay if a disaster hits... this is why it's important to read and understand the fine print
Focuses on how to recover various IT mechanisms after a disaster. whereas a contingency plan is usually for nondisasters - a disaster recover plan is for disasters that require IT processing to take place at another facility
Make business continuity a part of every business decision - Insert the maintenance responsibilities into job description - Include maintenance in personnel evaluations - Perform internal audits that include disaster recovery and continuity documenta
17. Reciprocal Agreement (Mutual Aid)
Company A agrees to allow company B to use its facilities if company B is hit by a disaster - and vice versa. This is a cheaper way to go than the other offsite choices - but is not always the best choice because most environments are maxed out perta
Make business continuity a part of every business decision - Insert the maintenance responsibilities into job description - Include maintenance in personnel evaluations - Perform internal audits that include disaster recovery and continuity documenta
It should be far enough away from the original site so one disaster does not take out both locations... alternate facilities should be at a bare minimum at least five miles away from the primary site - while 15 miles is recommended for most low-to-me
Typically a copy is stored at the BCP coordinator's home - and another copy is stored at the offsite facility... when they are stored offsite - they need to be stored in a way that provides just as much protection as the primary site would provide
18. What is the most critical part of establishing and maintaining a current continuity plan?
The most intrusive test to regular operations and business productivity. the original site is shut down - and processing takes place at the alternate site. this test takes a lot of planning and coordination but it can reveal many holes in the plan. f
Make business continuity a part of every business decision - Insert the maintenance responsibilities into job description - Include maintenance in personnel evaluations - Perform internal audits that include disaster recovery and continuity documenta
65%
Management support
19. What are some of the resources that would be required for individual business processes?
When it detects danger to human life - When it detects danger to state or national security - When it detects damage to the facility - When it detects damage to critical systems
Object code - source code - libraries - patches and fixes
All data are backed up and saved to some type of storage media. backup and restoration processes are very simplistic and straightforward with this method
Computer systems - Personnel - Procedures - Tasks - Supplies - Vendor support
20. What are some components required for the project plan?
Objective-to-task mapping - Resource-to-task mapping - Milestones - Budget estimates - Success factors - Deadlines
65%
The plans that determine the steps needed to protect the company in the event that a senior executive retires - leaves the company - or is killed. also details the people who would step in and assume responsibility
Management support
21. Mean Time To Repair (MTTR)
An estimate of how long it will take to fix a piece of equipment and get it back into production
Responsible for getting the alternate site into a working and functioning environment. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and ins
Hot Site - Warm Site - Colde Site
It's used when threats are identified that cannot be prevented. Taking on the full risk of these threats is often dangerous
22. What are loss criteria that can be applied to individual threats that were identified in the BIA?
Contact the local authorities
Responsible for getting the alternate site into a working and functioning environment. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and ins
Focuses on how to re-create the necessary business processes that need to be reestablished instead of focusing on IT components
Loss in reputation and public confidence - Loss of competitive advantages - Increase in operational expenses - Violations of contract agreements - Violations of legal and regulatory requirements - Delayed income costs - Loss in revenue - Loss in pr
23. Full-Interruption Test
The most intrusive test to regular operations and business productivity. the original site is shut down - and processing takes place at the alternate site. this test takes a lot of planning and coordination but it can reveal many holes in the plan. f
A leased or rented facility that usually partially configured with some equipment (peripheral devices) - but not the actual computers... it's usually a hot site without the expensive equipment. This is the most widely-used model... it is less expensi
Includes getting critical systems to another environment while repair of the original facilities is under way - getting the right people to the right places - and performing business in a different mode until regular conditions are back in place
A set of interrelated steps linked through specific decision activities to accomplish a specific task... business processes have starting and ending points and are repeatable
24. What format does management want to see in the BCP?
Present it to management for written approval
65%
They want information stated in monetary - quantitative terms - not in subjective - qualitative terms.
The client pays a monthly fee to retain the right to use the facility in a time of need and then incurs a large activation fee when the facility actually has to be used... most recovery site contracts do not promise to house the company in need at a
25. Salvage Team
Responsible for starting the recovery of the original site. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and install equipment and applicat
Make business continuity a part of every business decision - Insert the maintenance responsibilities into job description - Include maintenance in personnel evaluations - Perform internal audits that include disaster recovery and continuity documenta
A new type of coverage that insures losses caused by denial-of-service attacks - malware damages - hackers - electronic theft - privacy-related lawsuits and more
A document that outlines who should be contacted in the event of a disaster - in what order - and who is responsible for doing the calling
26. What is the difference between preventive mechanisms and recovery strategies?
Preventive mechanisms are put into place to try to reduce the possibility of the company experiencing a disaster and - if a disaster does hit - to lessen the amount of damage that will take place - Recovery strategies are processes on how to rescue t
A type of facility-backup option where the back of a large truck or a trailer is turned into a data processing or working area (typically used by military organizations and large insurance companies)
Includes getting critical systems to another environment while repair of the original facilities is under way - getting the right people to the right places - and performing business in a different mode until regular conditions are back in place
Objective-to-task mapping - Resource-to-task mapping - Milestones - Budget estimates - Success factors - Deadlines
27. Occupant Emergency Plan
When it detects danger to human life - When it detects danger to state or national security - When it detects damage to the facility - When it detects damage to critical systems
Focuses on malware - hackers - intrusions - attacks - and other security issues. outlines procedures for incident response
When the power goes on the computers - it's also going to go out for the phones
Establishes personnel safety and evacuation procedures
28. Executive Succession Planning
Business Resumption Plan - Continuity of Operations Plan (COOP) - IT Contingency Plan - Crisis Communications Plan - Cyber Incident Response Plan - Disaster Recovery Plan
Required roles - Required resources - Input and output mechanisms - Workflow steps - Required time for completion - How they interface with other processes
The plans that determine the steps needed to protect the company in the event that a senior executive retires - leaves the company - or is killed. also details the people who would step in and assume responsibility
Provides methods and procedures for dealing with longer-term outages and disaster.
29. What are some reasons why BCPs become outdated?
30. What are the steps of a BIA?
31. Business Interruption Insurance
The estimated lifetime of a piece of equipment... calculated by the vendor of the equipment or a third party
A type of policy in which the insurance company will pay for specified expenses and lost earnings in the event that a company is forced out of business for a certain length of time. another policy can be bought that insures accounts receivable - so i
Annually
Base it off of the probability of the threat becoming real and the loss potential. the goal is to make sure the insurance coverage fills in the gap of what the current preventative countermeasures cannot protect against
32. What are management's responsibilities with regards to BCP planning?
Present it to management for written approval
The most intrusive test to regular operations and business productivity. the original site is shut down - and processing takes place at the alternate site. this test takes a lot of planning and coordination but it can reveal many holes in the plan. f
When the power goes on the computers - it's also going to go out for the phones
Committing fully to the BCP - Setting policy and goals - Making available the necessary funds and resources - Taking responsibility for the outcome of the development of the BCP - Appointing a team for the process
33. Skeleton Crew
Use scenario-based exercises as a group to see what issues might crop up
Business process recovery - Facility recovery - Supply and technology recovery - User environment recovery - Data recovery
The employees who carry out the most critical functions of the company who must be put back to work first
Identifying regulatory and legal requirements that must be met - Identifying all possible vulnerabilities and threats - Estimating the possibilities of these threats and the loss potential - Performing a BIA - Outlining which departments - systems -
34. What are some examples of teams a company may need to construct - train - and have available in the event of a disaster?
Damage assessment team - legal team - media relations team - network recovery team - relocation team - restoration team - salvage team - security team - telecommunications team
A new type of coverage that insures losses caused by denial-of-service attacks - malware damages - hackers - electronic theft - privacy-related lawsuits and more
Reduce the risk of financial loss by improving the company's ability to recover and restore operations
It needs to ensure the safety of employees - It needs to ensure an adequate environment is provided (power - facility infrastructure - water - HVAC) - It needs to ensure that the necessary equipment and supplies are present and in working order - It
35. Where should the business continuity and disaster recovery plans be stored when they're completed?
36. Why do you need a combination of consultants and employees on the BCP team?
Consultants are experts in the field and know the necessary steps - questions to ask - and issues to look for - and they can also offer general reasonable advice. In-house employees know their company intimately and have a full understanding of how c
Back up the files that have been modified since the LAST FULL BACKUP. this process does not change the archive bit value
Business Resumption Plan - Continuity of Operations Plan (COOP) - IT Contingency Plan - Crisis Communications Plan - Cyber Incident Response Plan - Disaster Recovery Plan
Backing up business data to tapes that are then manually transferred to an offsite facility by a courier or an employee... with automatic tape vaulting - the data are sent over a serial line to a backup tape system at the offsite facility. Electronic
37. Parallel Test
The business continuity process isn't integrated into the change management process - infrastructure and environment changes occur - reorganization of the company - layoffs - or mergers occur - changes in hardware - software - and applications occur
Maximum tolerable downtime - Operational disruption and productivity - Financial considerations - Regulatory responsibilities - Reputation
Done to ensure that the specific systems can actually perform adequately at the alternate offsite facility. some systems are moved to the alternate site and processing takes place. the results are compared with the regular processing that is done at
Business Resumption Plan - Continuity of Operations Plan (COOP) - IT Contingency Plan - Crisis Communications Plan - Cyber Incident Response Plan - Disaster Recovery Plan
38. Business Resumption Plan
Includes internal and external communications structure and roles. identifies specific individuals who will communicate with external entities. contains predeveloped statements that are to be released
Focuses on how to re-create the necessary business processes that need to be reestablished instead of focusing on IT components
Done to ensure that the specific systems can actually perform adequately at the alternate offsite facility. some systems are moved to the alternate site and processing takes place. the results are compared with the regular processing that is done at
An estimate of how long it will take to fix a piece of equipment and get it back into production
39. Maximum Tolerable Downtime (MTD)
The outage time that can be endured by a company
Done to ensure that the specific systems can actually perform adequately at the alternate offsite facility. some systems are moved to the alternate site and processing takes place. the results are compared with the regular processing that is done at
There is more than one disk controller - so if one fails - the other is ready and available
All employees who participate in operational and support functions - or their representatives - come together to practice executing the disaster recovery plan based on a specific scenario. the scenario is used to test the reaction of each operational
40. If a company loses computing capabilities for a week - what is the chance they will go out of business (on average)?
65%
To minimize the effects of a disaster and to take the necessary steps to ensure that the resources - personnel - and business processes are able to resume operation in a timely manner. A disaster recovery plan is carried out when everything is still
Computer systems - Personnel - Procedures - Tasks - Supplies - Vendor support
When it is time for the company to move back into its original site or a new site
41. What are some of the characteristics you should look at when creating a BIA?
Maximum tolerable downtime - Operational disruption and productivity - Financial considerations - Regulatory responsibilities - Reputation
Establishes personnel safety and evacuation procedures
Nondisaster: a disruption in service due to a device malfunction or failure - Disaster: an event that causes the entire facility to be unusable for a day or longer - Catastrophe: a major disruption that destroys the facility altogether --> requires b
Base it off of the probability of the threat becoming real and the loss potential. the goal is to make sure the insurance coverage fills in the gap of what the current preventative countermeasures cannot protect against
42. Why does Insurance exist?
43. When should a company be prepared to interface with the press - customers - shareholders - and civic officials after a crisis?
1. Initiation Phase: goal statements - overview of concepts - roles and teams definitions - task definitions 2. Activation Phase: notification steps - damage assessment - plan activation 3. Recovery Phase: move to alternate site - restore processes -
One site is equipped and configured exactly like the primary site - which serves as a redundant environment. these sites are owned by the company and are mirrors of the original production environment... this is one of the most expensive backup facil
The outage time that can be endured by a company
Before too many people come to their own conclusions about the company and begin to start false rumors
44. Crisis Communications Plan
The employees who carry out the most critical functions of the company who must be put back to work first
All data are backed up and saved to some type of storage media. backup and restoration processes are very simplistic and straightforward with this method
Object code - source code - libraries - patches and fixes
Includes internal and external communications structure and roles. identifies specific individuals who will communicate with external entities. contains predeveloped statements that are to be released
45. How do we know which data have changed and need to be backed up without having to look at every file's modification date?
When it detects danger to human life - When it detects danger to state or national security - When it detects damage to the facility - When it detects damage to critical systems
At the intersection of the cost of disruption and the cost to recover
The client pays a monthly fee to retain the right to use the facility in a time of need and then incurs a large activation fee when the facility actually has to be used... most recovery site contracts do not promise to house the company in need at a
The file system sets the archive bit of the file to 1 when a file is modified or created
46. What are the BCP team's responsibilities with regards to BCP planning?
Makes copies of files as they are modified and periodically transmits them to an offsite backup site. The transmission doesn't happen in real time but is carried out in batches
Identifying regulatory and legal requirements that must be met - Identifying all possible vulnerabilities and threats - Estimating the possibilities of these threats and the loss potential - Performing a BIA - Outlining which departments - systems -
The outage time that can be endured by a company
Company A agrees to allow company B to use its facilities if company B is hit by a disaster - and vice versa. This is a cheaper way to go than the other offsite choices - but is not always the best choice because most environments are maxed out perta
47. Mean Time Between Failures (MTBF)
Base it off of the probability of the threat becoming real and the loss potential. the goal is to make sure the insurance coverage fills in the gap of what the current preventative countermeasures cannot protect against
Use scenario-based exercises as a group to see what issues might crop up
The estimated lifetime of a piece of equipment... calculated by the vendor of the equipment or a third party
Fortification of the facility in its construction materials - redundant servers and communications links - power lines coming in through different transformers - redundant vendor support - purchasing of insurance - purchasing of UPS and generators -
48. Who should be involved in the Business Continuity and Disaster Recovery plans? In what part of the process?
Business Resumption Plan - Continuity of Operations Plan (COOP) - IT Contingency Plan - Crisis Communications Plan - Cyber Incident Response Plan - Disaster Recovery Plan
Objective-to-task mapping - Resource-to-task mapping - Milestones - Budget estimates - Success factors - Deadlines
Representatives from at least each of the following departments must be involved with not only the planning stages but also the testing and implementation stages: - Business Units - Senior Management - IT Department - Security Department - Communicat
Object code - source code - libraries - patches and fixes
49. Continuity of Operations Plan (COOP)
They should make sure there are at least two copies of the company's operating system and critical applications
There is more than one disk controller - so if one fails - the other is ready and available
Provides methods and procedures for dealing with longer-term outages and disaster.
Establishes senior management and a headquarters after a disaster. outlines roles and authorities - orders of succession - and individual role tasks
50. What issues does a company need to look at when determining when it should move into Reconstitution Phase?
It needs to ensure the safety of employees - It needs to ensure an adequate environment is provided (power - facility infrastructure - water - HVAC) - It needs to ensure that the necessary equipment and supplies are present and in working order - It
No - but the team may recognize that the company is at risk because it does not have these procedures in place
A leased or rented facility that supplies the basic environment - electrical wiring - air conditioning - plumbing and flooring - but none of the equipment or additional services. It may take weeks to get the site activated and ready for work. This is
To resume business as quickly as possible - spending the least amount of money