SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISSP Business Continuity And Disaster Recovery
Start Test
Study First
Subjects
:
certifications
,
it-skills
,
cissp
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Business Process
Plan for systems - networks - and major applications recovery procedures after disruptions. a contingency plan should be developed for each major system and application
When the power goes on the computers - it's also going to go out for the phones
Establishes personnel safety and evacuation procedures
A set of interrelated steps linked through specific decision activities to accomplish a specific task... business processes have starting and ending points and are repeatable
2. Why do you need a combination of consultants and employees on the BCP team?
Responsible for getting the alternate site into a working and functioning environment. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and ins
Consultants are experts in the field and know the necessary steps - questions to ask - and issues to look for - and they can also offer general reasonable advice. In-house employees know their company intimately and have a full understanding of how c
Plan for systems - networks - and major applications recovery procedures after disruptions. a contingency plan should be developed for each major system and application
Includes getting critical systems to another environment while repair of the original facilities is under way - getting the right people to the right places - and performing business in a different mode until regular conditions are back in place
3. Business Continuity Plan (BCP)
Includes getting critical systems to another environment while repair of the original facilities is under way - getting the right people to the right places - and performing business in a different mode until regular conditions are back in place
The file system sets the archive bit of the file to 1 when a file is modified or created
Each disk would have a corresponding mirrored disk that contains the exact same information
Focuses on how to re-create the necessary business processes that need to be reestablished instead of focusing on IT components
4. Why does Insurance exist?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
5. If a company loses computing capabilities for a week - what is the chance they will go out of business (on average)?
Reduce the risk of financial loss by improving the company's ability to recover and restore operations
Plan for systems - networks - and major applications recovery procedures after disruptions. a contingency plan should be developed for each major system and application
65%
Focuses on how to re-create the necessary business processes that need to be reestablished instead of focusing on IT components
6. What are the benefits of using the Differential or Incremental backup methods?
Management support
Provides methods and procedures for dealing with longer-term outages and disaster.
When it detects danger to human life - When it detects danger to state or national security - When it detects damage to the facility - When it detects damage to critical systems
It requires less resources and time
7. What are some reasons why BCPs become outdated?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
8. What are the three types of disruptions that a facility can have and what does each mean?
It should be far enough away from the original site so one disaster does not take out both locations... alternate facilities should be at a bare minimum at least five miles away from the primary site - while 15 miles is recommended for most low-to-me
Nondisaster: a disruption in service due to a device malfunction or failure - Disaster: an event that causes the entire facility to be unusable for a day or longer - Catastrophe: a major disruption that destroys the facility altogether --> requires b
Before too many people come to their own conclusions about the company and begin to start false rumors
No - but the team may recognize that the company is at risk because it does not have these procedures in place
9. What are the steps of a BIA?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
10. What are some components required for the project plan?
The primary and secondary data volumes are only a few milliseconds out of sync - so the replication is nearly real-time
Focuses on malware - hackers - intrusions - attacks - and other security issues. outlines procedures for incident response
Computer systems - Personnel - Procedures - Tasks - Supplies - Vendor support
Objective-to-task mapping - Resource-to-task mapping - Milestones - Budget estimates - Success factors - Deadlines
11. Damage Assessment Team
Establishes senior management and a headquarters after a disaster. outlines roles and authorities - orders of succession - and individual role tasks
1. Develop the continuity planning policy statement 2. Conduct the business impact analysis (BIA) 3. Identify preventive controls 4. Develop recovery strategies 5. Develop the contingency plan 6. Test the plan and conduct training and exercises 7. Ma
Focuses on how to recover various IT mechanisms after a disaster. whereas a contingency plan is usually for nondisasters - a disaster recover plan is for disasters that require IT processing to take place at another facility
Determines the cause of the disaster - Determines the potential for further damage - Identifies the affected business functions and areas - Identifies the level of functionality for the critical resources - Identifies the resources that must be repla
12. Structured Walk-Through Test
Management support
At the intersection of the cost of disruption and the cost to recover
Representatives from each department or functional area come together to over the plan to ensure its accuracy
Since the software vendor provides its customers with only the compiled version of its applications - it's difficult for the customer to continue to use it if the vendor goes out of business. So the customer should set up a Software Escrow agreement
13. What are loss criteria that can be applied to individual threats that were identified in the BIA?
Loss in reputation and public confidence - Loss of competitive advantages - Increase in operational expenses - Violations of contract agreements - Violations of legal and regulatory requirements - Delayed income costs - Loss in revenue - Loss in pr
A promise that a service will be fulfilled within a certain timeframe
The employees who carry out the most critical functions of the company who must be put back to work first
Business Resumption Plan - Continuity of Operations Plan (COOP) - IT Contingency Plan - Crisis Communications Plan - Cyber Incident Response Plan - Disaster Recovery Plan
14. How frequently should a company's insurance be reviewed?
Data are dynamically created and maintained as images on two or more identical disks. this method is used to ensure the availability of data and to provide a fault-tolerant solution by duplicating hardware and maintaining more than one copy of the in
Annually
A set of interrelated steps linked through specific decision activities to accomplish a specific task... business processes have starting and ending points and are repeatable
They want information stated in monetary - quantitative terms - not in subjective - qualitative terms.
15. When should a company be prepared to interface with the press - customers - shareholders - and civic officials after a crisis?
Before too many people come to their own conclusions about the company and begin to start false rumors
Contact the local authorities
Object code - source code - libraries - patches and fixes
They want information stated in monetary - quantitative terms - not in subjective - qualitative terms.
16. What is one of the big issues with VoIP and disaster recovery?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
17. Business Resumption Plan
Focuses on how to re-create the necessary business processes that need to be reestablished instead of focusing on IT components
Network and computer equipment - Voice and data communications resources - Human Resources - Transportation of equipment and personnel - Environment issues (HVAC) - Data and personnel security issues - Supplies (paper - forms - cabling - and so on) -
Loss in reputation and public confidence - Loss of competitive advantages - Increase in operational expenses - Violations of contract agreements - Violations of legal and regulatory requirements - Delayed income costs - Loss in revenue - Loss in pr
Backing up business data to tapes that are then manually transferred to an offsite facility by a courier or an employee... with automatic tape vaulting - the data are sent over a serial line to a backup tape system at the offsite facility. Electronic
18. What are some of the things you have to consider when it comes to supply and tech recovery?
Preventive mechanisms are put into place to try to reduce the possibility of the company experiencing a disaster and - if a disaster does hit - to lessen the amount of damage that will take place - Recovery strategies are processes on how to rescue t
Network and computer equipment - Voice and data communications resources - Human Resources - Transportation of equipment and personnel - Environment issues (HVAC) - Data and personnel security issues - Supplies (paper - forms - cabling - and so on) -
Since the software vendor provides its customers with only the compiled version of its applications - it's difficult for the customer to continue to use it if the vendor goes out of business. So the customer should set up a Software Escrow agreement
Done to ensure that the specific systems can actually perform adequately at the alternate offsite facility. some systems are moved to the alternate site and processing takes place. the results are compared with the regular processing that is done at
19. Role of the Business Continuity Coordinator
Lead the BCP team and oversee the development - implementation - and testing of the continuity and disaster recovery plans... this person needs to have direct access to management and have the credibility and authority to carry out leadership tasks
Required roles - Required resources - Input and output mechanisms - Workflow steps - Required time for completion - How they interface with other processes
Each disk would have a corresponding mirrored disk that contains the exact same information
When it is time for the company to move back into its original site or a new site
20. Cyberinsurance
Make business continuity a part of every business decision - Insert the maintenance responsibilities into job description - Include maintenance in personnel evaluations - Perform internal audits that include disaster recovery and continuity documenta
Company A agrees to allow company B to use its facilities if company B is hit by a disaster - and vice versa. This is a cheaper way to go than the other offsite choices - but is not always the best choice because most environments are maxed out perta
A new type of coverage that insures losses caused by denial-of-service attacks - malware damages - hackers - electronic theft - privacy-related lawsuits and more
There is more risk for the organization because replacement systems won't be available... that's why many organizations have moved to commercial off the shelf (COTS) products. they want to make sure replacement is possible
21. At what point can a company have real confidence in a developed plan?
After it has been tested
Copies of the BCP are distributed to the different departments and functional areas for review
Determines the cause of the disaster - Determines the potential for further damage - Identifies the affected business functions and areas - Identifies the level of functionality for the critical resources - Identifies the resources that must be repla
Focuses on how to re-create the necessary business processes that need to be reestablished instead of focusing on IT components
22. What is one of the big issues with legacy equipment and disaster recovery?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
23. Where does the Recovery Time Objective sit on a chart that keeps track of cost and time?
They should make sure there are at least two copies of the company's operating system and critical applications
At the intersection of the cost of disruption and the cost to recover
They want information stated in monetary - quantitative terms - not in subjective - qualitative terms.
Business process recovery - Facility recovery - Supply and technology recovery - User environment recovery - Data recovery
24. What are some of the resources that would be required for individual business processes?
An estimate of how long it will take to fix a piece of equipment and get it back into production
The primary and secondary copies are always in sync - which provides true real-time duplication
It has to figure out what the company needs to do to actually recover the items it has identified as being so important to the organization overall... the BIA provides the footprint
Computer systems - Personnel - Procedures - Tasks - Supplies - Vendor support
25. Restoration Team
Network and computer equipment - Voice and data communications resources - Human Resources - Transportation of equipment and personnel - Environment issues (HVAC) - Data and personnel security issues - Supplies (paper - forms - cabling - and so on) -
Representatives from each department or functional area come together to over the plan to ensure its accuracy
A document that outlines who should be contacted in the event of a disaster - in what order - and who is responsible for doing the calling
Responsible for getting the alternate site into a working and functioning environment. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and ins
26. Where should the business continuity and disaster recovery plans be stored when they're completed?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
27. What does the BCP team need to understand about critical business processes?
To resume business as quickly as possible - spending the least amount of money
Data are dynamically created and maintained as images on two or more identical disks. this method is used to ensure the availability of data and to provide a fault-tolerant solution by duplicating hardware and maintaining more than one copy of the in
Required roles - Required resources - Input and output mechanisms - Workflow steps - Required time for completion - How they interface with other processes
1. Select individuals to interview for data gathering 2. Create data-gathering techniques (surveys - questionnaires - qualitative and quantitative approaches) 3. Identify the company's critical business functions 4. Identify the resources these funct
28. Continuity of Operations Plan (COOP)
Includes getting critical systems to another environment while repair of the original facilities is under way - getting the right people to the right places - and performing business in a different mode until regular conditions are back in place
Focuses on how to recover various IT mechanisms after a disaster. whereas a contingency plan is usually for nondisasters - a disaster recover plan is for disasters that require IT processing to take place at another facility
Focuses on malware - hackers - intrusions - attacks - and other security issues. outlines procedures for incident response
Establishes senior management and a headquarters after a disaster. outlines roles and authorities - orders of succession - and individual role tasks
29. Differential Backup
There is more than one disk controller - so if one fails - the other is ready and available
Includes getting critical systems to another environment while repair of the original facilities is under way - getting the right people to the right places - and performing business in a different mode until regular conditions are back in place
Back up the files that have been modified since the LAST FULL BACKUP. this process does not change the archive bit value
A functional analysis in which a team collects data through interviews - workshops - and documentary sources; documents business functions - activities - and transactions (maybe in a set of flow charts); develops a hierarchy of business functions; an
30. How are offsite backup facility contracts usually established?
The client pays a monthly fee to retain the right to use the facility in a time of need and then incurs a large activation fee when the facility actually has to be used... most recovery site contracts do not promise to house the company in need at a
Required roles - Required resources - Input and output mechanisms - Workflow steps - Required time for completion - How they interface with other processes
To resume business as quickly as possible - spending the least amount of money
There is more than one disk controller - so if one fails - the other is ready and available
31. Skeleton Crew
Establishes senior management and a headquarters after a disaster. outlines roles and authorities - orders of succession - and individual role tasks
The employees who carry out the most critical functions of the company who must be put back to work first
Reduce the risk of financial loss by improving the company's ability to recover and restore operations
Back up the files that have been modified since the LAST FULL BACKUP. this process does not change the archive bit value
32. What is the main reason to develop Business Continuity and Disaster Recovery plans?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
33. Emergency Response Procedures
Back up the files that have been modified since the LAST FULL BACKUP. this process does not change the archive bit value
Use scenario-based exercises as a group to see what issues might crop up
The business continuity process isn't integrated into the change management process - infrastructure and environment changes occur - reorganization of the company - layoffs - or mergers occur - changes in hardware - software - and applications occur
Prepared actions that are developed to help people in a crisis situation better cope with the disruption. Protection of life is of the utmost importance and should be dealt with first before looking to save material objects!
34. Especially in a software development environment - what should be backed up?
It has to figure out what the company needs to do to actually recover the items it has identified as being so important to the organization overall... the BIA provides the footprint
Present it to management for written approval
Lead the BCP team and oversee the development - implementation - and testing of the continuity and disaster recovery plans... this person needs to have direct access to management and have the credibility and authority to carry out leadership tasks
Object code - source code - libraries - patches and fixes
35. Once the project plan is completed - what should be done before further steps are taken?
Since the software vendor provides its customers with only the compiled version of its applications - it's difficult for the customer to continue to use it if the vendor goes out of business. So the customer should set up a Software Escrow agreement
A new type of coverage that insures losses caused by denial-of-service attacks - malware damages - hackers - electronic theft - privacy-related lawsuits and more
Present it to management for written approval
They should make sure there are at least two copies of the company's operating system and critical applications
36. What should an organization do to assure that they will always be able to get some kind of support for their specialized and critical applications (even in the event that the software vendor goes out of business)?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
37. NIST Steps for Business Continuity
They should make sure there are at least two copies of the company's operating system and critical applications
1. Develop the continuity planning policy statement 2. Conduct the business impact analysis (BIA) 3. Identify preventive controls 4. Develop recovery strategies 5. Develop the contingency plan 6. Test the plan and conduct training and exercises 7. Ma
A document that lays out the scope of the BCP project - the team member roles - and the goals of the project. it outlines what needs to be accomplished after the team communicates with management and comes to agreement on the terms of the project
Consultants are experts in the field and know the necessary steps - questions to ask - and issues to look for - and they can also offer general reasonable advice. In-house employees know their company intimately and have a full understanding of how c
38. Remote Journaling
A method of transmitting data offsite - but it usually only includes moving the journal or transaction logs to the offsite facility - not the actual files. these logs contain the changes that have taken place to the individual files. Journaling is ef
One person should be responsible... the authorities are the police department - security guards - fire department - emergency rescue - and management
The primary and secondary copies are always in sync - which provides true real-time duplication
Consultants are experts in the field and know the necessary steps - questions to ask - and issues to look for - and they can also offer general reasonable advice. In-house employees know their company intimately and have a full understanding of how c
39. Crisis Communications Plan
No - but the team may recognize that the company is at risk because it does not have these procedures in place
Includes internal and external communications structure and roles. identifies specific individuals who will communicate with external entities. contains predeveloped statements that are to be released
Company A agrees to allow company B to use its facilities if company B is hit by a disaster - and vice versa. This is a cheaper way to go than the other offsite choices - but is not always the best choice because most environments are maxed out perta
It should be far enough away from the original site so one disaster does not take out both locations... alternate facilities should be at a bare minimum at least five miles away from the primary site - while 15 miles is recommended for most low-to-me
40. What is the main limitation of insurance coverage?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
41. What is one of the best ways to work through the details of a BIA?
A type of policy in which the insurance company will pay for specified expenses and lost earnings in the event that a company is forced out of business for a certain length of time. another policy can be bought that insures accounts receivable - so i
The estimated lifetime of a piece of equipment... calculated by the vendor of the equipment or a third party
Use scenario-based exercises as a group to see what issues might crop up
Representatives from at least each of the following departments must be involved with not only the planning stages but also the testing and implementation stages: - Business Units - Senior Management - IT Department - Security Department - Communicat
42. What is the most critical part of establishing and maintaining a current continuity plan?
Management support
1. Select individuals to interview for data gathering 2. Create data-gathering techniques (surveys - questionnaires - qualitative and quantitative approaches) 3. Identify the company's critical business functions 4. Identify the resources these funct
Loss in reputation and public confidence - Loss of competitive advantages - Increase in operational expenses - Violations of contract agreements - Violations of legal and regulatory requirements - Delayed income costs - Loss in revenue - Loss in pr
Computer systems - Personnel - Procedures - Tasks - Supplies - Vendor support
43. Who should be involved in the Business Continuity and Disaster Recovery plans? In what part of the process?
A functional analysis in which a team collects data through interviews - workshops - and documentary sources; documents business functions - activities - and transactions (maybe in a set of flow charts); develops a hierarchy of business functions; an
Representatives from at least each of the following departments must be involved with not only the planning stages but also the testing and implementation stages: - Business Units - Senior Management - IT Department - Security Department - Communicat
It should be far enough away from the original site so one disaster does not take out both locations... alternate facilities should be at a bare minimum at least five miles away from the primary site - while 15 miles is recommended for most low-to-me
Responsibility: each individual involved should have their responsibilities spelled out in writing and the tasks should be assigned to the individual most situated to handle it - Authority: you need to know what leaders are going to step up to the pl
44. What format does management want to see in the BCP?
They want information stated in monetary - quantitative terms - not in subjective - qualitative terms.
Preventive mechanisms are put into place to try to reduce the possibility of the company experiencing a disaster and - if a disaster does hit - to lessen the amount of damage that will take place - Recovery strategies are processes on how to rescue t
Focuses on malware - hackers - intrusions - attacks - and other security issues. outlines procedures for incident response
Consultants are experts in the field and know the necessary steps - questions to ask - and issues to look for - and they can also offer general reasonable advice. In-house employees know their company intimately and have a full understanding of how c
45. Cyber Incident Response Plan
1. Initiation Phase: goal statements - overview of concepts - roles and teams definitions - task definitions 2. Activation Phase: notification steps - damage assessment - plan activation 3. Recovery Phase: move to alternate site - restore processes -
A document that lays out the scope of the BCP project - the team member roles - and the goals of the project. it outlines what needs to be accomplished after the team communicates with management and comes to agreement on the terms of the project
Focuses on malware - hackers - intrusions - attacks - and other security issues. outlines procedures for incident response
Establishes senior management and a headquarters after a disaster. outlines roles and authorities - orders of succession - and individual role tasks
46. What functions should be moved back first during the Reconstitution Phase?
The least critical functions... it ensures that the critical operations of the company are not negatively affected
The primary and secondary data volumes are only a few milliseconds out of sync - so the replication is nearly real-time
All data are backed up and saved to some type of storage media. backup and restoration processes are very simplistic and straightforward with this method
1. Select individuals to interview for data gathering 2. Create data-gathering techniques (surveys - questionnaires - qualitative and quantitative approaches) 3. Identify the company's critical business functions 4. Identify the resources these funct
47. Reconstitution Phase
When it is time for the company to move back into its original site or a new site
All data are backed up and saved to some type of storage media. backup and restoration processes are very simplistic and straightforward with this method
A document that lays out the scope of the BCP project - the team member roles - and the goals of the project. it outlines what needs to be accomplished after the team communicates with management and comes to agreement on the terms of the project
The business continuity process isn't integrated into the change management process - infrastructure and environment changes occur - reorganization of the company - layoffs - or mergers occur - changes in hardware - software - and applications occur
48. What is the goal of Disaster Recovery?
Each disk would have a corresponding mirrored disk that contains the exact same information
To minimize the effects of a disaster and to take the necessary steps to ensure that the resources - personnel - and business processes are able to resume operation in a timely manner. A disaster recovery plan is carried out when everything is still
The most intrusive test to regular operations and business productivity. the original site is shut down - and processing takes place at the alternate site. this test takes a lot of planning and coordination but it can reveal many holes in the plan. f
1. Select individuals to interview for data gathering 2. Create data-gathering techniques (surveys - questionnaires - qualitative and quantitative approaches) 3. Identify the company's critical business functions 4. Identify the resources these funct
49. As a general rule of thumb - how far away should a backup facility be from the main facility?
Define essential business functions and supporting departments - Identify interdependencies between these functions and departments - Discover all possible disruptions that could affect the mechanisms necessary to allow these departments to function
The primary and secondary data volumes are only a few milliseconds out of sync - so the replication is nearly real-time
It should be far enough away from the original site so one disaster does not take out both locations... alternate facilities should be at a bare minimum at least five miles away from the primary site - while 15 miles is recommended for most low-to-me
It needs to ensure the safety of employees - It needs to ensure an adequate environment is provided (power - facility infrastructure - water - HVAC) - It needs to ensure that the necessary equipment and supplies are present and in working order - It
50. What tasks should the BCP team carry out and have addressed in the resulting plan?
Define essential business functions and supporting departments - Identify interdependencies between these functions and departments - Discover all possible disruptions that could affect the mechanisms necessary to allow these departments to function
Backup all the files that have changed since the last full or incremental backup. this process sets the archive bit to 0
The client pays a monthly fee to retain the right to use the facility in a time of need and then incurs a large activation fee when the facility actually has to be used... most recovery site contracts do not promise to house the company in need at a
Damage assessment team - legal team - media relations team - network recovery team - relocation team - restoration team - salvage team - security team - telecommunications team