SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISSP Business Continuity And Disaster Recovery
Start Test
Study First
Subjects
:
certifications
,
it-skills
,
cissp
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. Mean Time Between Failures (MTBF)
The estimated lifetime of a piece of equipment... calculated by the vendor of the equipment or a third party
Computer systems - Personnel - Procedures - Tasks - Supplies - Vendor support
Back up the files that have been modified since the LAST FULL BACKUP. this process does not change the archive bit value
The most intrusive test to regular operations and business productivity. the original site is shut down - and processing takes place at the alternate site. this test takes a lot of planning and coordination but it can reveal many holes in the plan. f
2. Cyberinsurance
Prepared actions that are developed to help people in a crisis situation better cope with the disruption. Protection of life is of the utmost importance and should be dealt with first before looking to save material objects!
A new type of coverage that insures losses caused by denial-of-service attacks - malware damages - hackers - electronic theft - privacy-related lawsuits and more
Each disk would have a corresponding mirrored disk that contains the exact same information
Focuses on how to re-create the necessary business processes that need to be reestablished instead of focusing on IT components
3. How can an organization keep the BCP up to date?
The client pays a monthly fee to retain the right to use the facility in a time of need and then incurs a large activation fee when the facility actually has to be used... most recovery site contracts do not promise to house the company in need at a
At the intersection of the cost of disruption and the cost to recover
Make business continuity a part of every business decision - Insert the maintenance responsibilities into job description - Include maintenance in personnel evaluations - Perform internal audits that include disaster recovery and continuity documenta
Each disk would have a corresponding mirrored disk that contains the exact same information
4. Electronic Vaulting
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
5. IT Contingency Plan
Plan for systems - networks - and major applications recovery procedures after disruptions. a contingency plan should be developed for each major system and application
Damage assessment team - legal team - media relations team - network recovery team - relocation team - restoration team - salvage team - security team - telecommunications team
Includes getting critical systems to another environment while repair of the original facilities is under way - getting the right people to the right places - and performing business in a different mode until regular conditions are back in place
1. Select individuals to interview for data gathering 2. Create data-gathering techniques (surveys - questionnaires - qualitative and quantitative approaches) 3. Identify the company's critical business functions 4. Identify the resources these funct
6. Tape Vaulting
Reduce the risk of financial loss by improving the company's ability to recover and restore operations
Includes getting critical systems to another environment while repair of the original facilities is under way - getting the right people to the right places - and performing business in a different mode until regular conditions are back in place
Backing up business data to tapes that are then manually transferred to an offsite facility by a courier or an employee... with automatic tape vaulting - the data are sent over a serial line to a backup tape system at the offsite facility. Electronic
No - but the team may recognize that the company is at risk because it does not have these procedures in place
7. What is one of the big issues with VoIP and disaster recovery?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
8. Where should the business continuity and disaster recovery plans be stored when they're completed?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
9. Checklist Test (Deckcheck Test)
Computer systems - Personnel - Procedures - Tasks - Supplies - Vendor support
Contact the local authorities
Copies of the BCP are distributed to the different departments and functional areas for review
Plan for systems - networks - and major applications recovery procedures after disruptions. a contingency plan should be developed for each major system and application
10. Role of the Business Continuity Coordinator
They should make sure there are at least two copies of the company's operating system and critical applications
Focuses on how to recover various IT mechanisms after a disaster. whereas a contingency plan is usually for nondisasters - a disaster recover plan is for disasters that require IT processing to take place at another facility
Lead the BCP team and oversee the development - implementation - and testing of the continuity and disaster recovery plans... this person needs to have direct access to management and have the credibility and authority to carry out leadership tasks
A set of interrelated steps linked through specific decision activities to accomplish a specific task... business processes have starting and ending points and are repeatable
11. What is the most critical part of establishing and maintaining a current continuity plan?
A document that lays out the scope of the BCP project - the team member roles - and the goals of the project. it outlines what needs to be accomplished after the team communicates with management and comes to agreement on the terms of the project
Representatives from each department or functional area come together to over the plan to ensure its accuracy
Data are dynamically created and maintained as images on two or more identical disks. this method is used to ensure the availability of data and to provide a fault-tolerant solution by duplicating hardware and maintaining more than one copy of the in
Management support
12. What are the benefits of using the Differential or Incremental backup methods?
Manmade: arsonist - terrorist - a simple mistake - Natural: tornadoes - floods - hurricanes - or earthquakes - Technical: data corruption - loss of power - device failure - or loss of a data communications line
It requires less resources and time
Required roles - Required resources - Input and output mechanisms - Workflow steps - Required time for completion - How they interface with other processes
When it is time for the company to move back into its original site or a new site
13. What are the three types of disruptions that a facility can have and what does each mean?
Nondisaster: a disruption in service due to a device malfunction or failure - Disaster: an event that causes the entire facility to be unusable for a day or longer - Catastrophe: a major disruption that destroys the facility altogether --> requires b
Objective-to-task mapping - Resource-to-task mapping - Milestones - Budget estimates - Success factors - Deadlines
A method of transmitting data offsite - but it usually only includes moving the journal or transaction logs to the offsite facility - not the actual files. these logs contain the changes that have taken place to the individual files. Journaling is ef
A promise that a service will be fulfilled within a certain timeframe
14. Warm Site
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
15. Who should be involved in the Business Continuity and Disaster Recovery plans? In what part of the process?
A functional analysis in which a team collects data through interviews - workshops - and documentary sources; documents business functions - activities - and transactions (maybe in a set of flow charts); develops a hierarchy of business functions; an
Preventive mechanisms are put into place to try to reduce the possibility of the company experiencing a disaster and - if a disaster does hit - to lessen the amount of damage that will take place - Recovery strategies are processes on how to rescue t
Representatives from at least each of the following departments must be involved with not only the planning stages but also the testing and implementation stages: - Business Units - Senior Management - IT Department - Security Department - Communicat
A facility that is leased or rented and is fully configured and ready to operate within a few hours... the only missing resources are usually the data - which will be retrieved from a backup site - and the people who are processing the data. The equi
16. Continuity of Operations Plan (COOP)
Backup all the files that have changed since the last full or incremental backup. this process sets the archive bit to 0
Company A agrees to allow company B to use its facilities if company B is hit by a disaster - and vice versa. This is a cheaper way to go than the other offsite choices - but is not always the best choice because most environments are maxed out perta
A type of policy in which the insurance company will pay for specified expenses and lost earnings in the event that a company is forced out of business for a certain length of time. another policy can be bought that insures accounts receivable - so i
Establishes senior management and a headquarters after a disaster. outlines roles and authorities - orders of succession - and individual role tasks
17. What is the main reason to develop Business Continuity and Disaster Recovery plans?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
18. Restoration Team
Responsible for getting the alternate site into a working and functioning environment. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and ins
Since the software vendor provides its customers with only the compiled version of its applications - it's difficult for the customer to continue to use it if the vendor goes out of business. So the customer should set up a Software Escrow agreement
Required roles - Required resources - Input and output mechanisms - Workflow steps - Required time for completion - How they interface with other processes
Annually
19. Should the BCP team be responsible for setting up and maintaining the company's data classification procedures?
When it is time for the company to move back into its original site or a new site
No - but the team may recognize that the company is at risk because it does not have these procedures in place
A facility that is leased or rented and is fully configured and ready to operate within a few hours... the only missing resources are usually the data - which will be retrieved from a backup site - and the people who are processing the data. The equi
Company A agrees to allow company B to use its facilities if company B is hit by a disaster - and vice versa. This is a cheaper way to go than the other offsite choices - but is not always the best choice because most environments are maxed out perta
20. Business Process
A set of interrelated steps linked through specific decision activities to accomplish a specific task... business processes have starting and ending points and are repeatable
The most intrusive test to regular operations and business productivity. the original site is shut down - and processing takes place at the alternate site. this test takes a lot of planning and coordination but it can reveal many holes in the plan. f
A facility that is leased or rented and is fully configured and ready to operate within a few hours... the only missing resources are usually the data - which will be retrieved from a backup site - and the people who are processing the data. The equi
No - but the team may recognize that the company is at risk because it does not have these procedures in place
21. Rolling Hot Site (Mobile Hot Site)
The plans that determine the steps needed to protect the company in the event that a senior executive retires - leaves the company - or is killed. also details the people who would step in and assume responsibility
A type of facility-backup option where the back of a large truck or a trailer is turned into a data processing or working area (typically used by military organizations and large insurance companies)
There is more than one disk controller - so if one fails - the other is ready and available
It's used when threats are identified that cannot be prevented. Taking on the full risk of these threats is often dangerous
22. What issues does a company need to look at when determining when it should move into Reconstitution Phase?
A document that outlines who should be contacted in the event of a disaster - in what order - and who is responsible for doing the calling
It needs to ensure the safety of employees - It needs to ensure an adequate environment is provided (power - facility infrastructure - water - HVAC) - It needs to ensure that the necessary equipment and supplies are present and in working order - It
Responsible for starting the recovery of the original site. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and install equipment and applicat
There is more than one disk controller - so if one fails - the other is ready and available
23. What are some appropriate and cost-effective preventative methods to better fortify a company from the impacts recognized in the BIA?
Fortification of the facility in its construction materials - redundant servers and communications links - power lines coming in through different transformers - redundant vendor support - purchasing of insurance - purchasing of UPS and generators -
The outage time that can be endured by a company
It has to figure out what the company needs to do to actually recover the items it has identified as being so important to the organization overall... the BIA provides the footprint
Backing up business data to tapes that are then manually transferred to an offsite facility by a courier or an employee... with automatic tape vaulting - the data are sent over a serial line to a backup tape system at the offsite facility. Electronic
24. As a general rule of thumb - how far away should a backup facility be from the main facility?
It should be far enough away from the original site so one disaster does not take out both locations... alternate facilities should be at a bare minimum at least five miles away from the primary site - while 15 miles is recommended for most low-to-me
Each disk would have a corresponding mirrored disk that contains the exact same information
When it is time for the company to move back into its original site or a new site
Company A agrees to allow company B to use its facilities if company B is hit by a disaster - and vice versa. This is a cheaper way to go than the other offsite choices - but is not always the best choice because most environments are maxed out perta
25. Emergency Response Procedures
Prepared actions that are developed to help people in a crisis situation better cope with the disruption. Protection of life is of the utmost importance and should be dealt with first before looking to save material objects!
Business process recovery - Facility recovery - Supply and technology recovery - User environment recovery - Data recovery
Done to ensure that the specific systems can actually perform adequately at the alternate offsite facility. some systems are moved to the alternate site and processing takes place. the results are compared with the regular processing that is done at
Backing up business data to tapes that are then manually transferred to an offsite facility by a courier or an employee... with automatic tape vaulting - the data are sent over a serial line to a backup tape system at the offsite facility. Electronic
26. Full-Interruption Test
The most intrusive test to regular operations and business productivity. the original site is shut down - and processing takes place at the alternate site. this test takes a lot of planning and coordination but it can reveal many holes in the plan. f
1. Develop the continuity planning policy statement 2. Conduct the business impact analysis (BIA) 3. Identify preventive controls 4. Develop recovery strategies 5. Develop the contingency plan 6. Test the plan and conduct training and exercises 7. Ma
Done to ensure that the specific systems can actually perform adequately at the alternate offsite facility. some systems are moved to the alternate site and processing takes place. the results are compared with the regular processing that is done at
Damage assessment team - legal team - media relations team - network recovery team - relocation team - restoration team - salvage team - security team - telecommunications team
27. What is the goal of Disaster Recovery?
Hot Site - Warm Site - Colde Site
To minimize the effects of a disaster and to take the necessary steps to ensure that the resources - personnel - and business processes are able to resume operation in a timely manner. A disaster recovery plan is carried out when everything is still
A type of policy in which the insurance company will pay for specified expenses and lost earnings in the event that a company is forced out of business for a certain length of time. another policy can be bought that insures accounts receivable - so i
Back up the files that have been modified since the LAST FULL BACKUP. this process does not change the archive bit value
28. If a company loses computing capabilities for a week - what is the chance they will go out of business (on average)?
Network and computer equipment - Voice and data communications resources - Human Resources - Transportation of equipment and personnel - Environment issues (HVAC) - Data and personnel security issues - Supplies (paper - forms - cabling - and so on) -
It should be far enough away from the original site so one disaster does not take out both locations... alternate facilities should be at a bare minimum at least five miles away from the primary site - while 15 miles is recommended for most low-to-me
Backup all the files that have changed since the last full or incremental backup. this process sets the archive bit to 0
65%
29. Reciprocal Agreement (Mutual Aid)
Reduce the risk of financial loss by improving the company's ability to recover and restore operations
A type of policy in which the insurance company will pay for specified expenses and lost earnings in the event that a company is forced out of business for a certain length of time. another policy can be bought that insures accounts receivable - so i
All data are backed up and saved to some type of storage media. backup and restoration processes are very simplistic and straightforward with this method
Company A agrees to allow company B to use its facilities if company B is hit by a disaster - and vice versa. This is a cheaper way to go than the other offsite choices - but is not always the best choice because most environments are maxed out perta
30. What are management's responsibilities with regards to BCP planning?
They want information stated in monetary - quantitative terms - not in subjective - qualitative terms.
All data are backed up and saved to some type of storage media. backup and restoration processes are very simplistic and straightforward with this method
Objective-to-task mapping - Resource-to-task mapping - Milestones - Budget estimates - Success factors - Deadlines
Committing fully to the BCP - Setting policy and goals - Making available the necessary funds and resources - Taking responsibility for the outcome of the development of the BCP - Appointing a team for the process
31. Cyber Incident Response Plan
Provides methods and procedures for dealing with longer-term outages and disaster.
All employees who participate in operational and support functions - or their representatives - come together to practice executing the disaster recovery plan based on a specific scenario. the scenario is used to test the reaction of each operational
Preventive mechanisms are put into place to try to reduce the possibility of the company experiencing a disaster and - if a disaster does hit - to lessen the amount of damage that will take place - Recovery strategies are processes on how to rescue t
Focuses on malware - hackers - intrusions - attacks - and other security issues. outlines procedures for incident response
32. How are offsite backup facility contracts usually established?
The client pays a monthly fee to retain the right to use the facility in a time of need and then incurs a large activation fee when the facility actually has to be used... most recovery site contracts do not promise to house the company in need at a
Object code - source code - libraries - patches and fixes
Representatives from each department or functional area come together to over the plan to ensure its accuracy
Nondisaster: a disruption in service due to a device malfunction or failure - Disaster: an event that causes the entire facility to be unusable for a day or longer - Catastrophe: a major disruption that destroys the facility altogether --> requires b
33. Disk Shadowing
Object code - source code - libraries - patches and fixes
Data are dynamically created and maintained as images on two or more identical disks. this method is used to ensure the availability of data and to provide a fault-tolerant solution by duplicating hardware and maintaining more than one copy of the in
One site is equipped and configured exactly like the primary site - which serves as a redundant environment. these sites are owned by the company and are mirrors of the original production environment... this is one of the most expensive backup facil
Establishes senior management and a headquarters after a disaster. outlines roles and authorities - orders of succession - and individual role tasks
34. Service Level Agreement (SLA)
The primary and secondary data volumes are only a few milliseconds out of sync - so the replication is nearly real-time
A promise that a service will be fulfilled within a certain timeframe
Copies of the BCP are distributed to the different departments and functional areas for review
Representatives from each department or functional area come together to over the plan to ensure its accuracy
35. Full Backup
The primary and secondary copies are always in sync - which provides true real-time duplication
After it has been tested
Plan for systems - networks - and major applications recovery procedures after disruptions. a contingency plan should be developed for each major system and application
All data are backed up and saved to some type of storage media. backup and restoration processes are very simplistic and straightforward with this method
36. Disk Duplexing
The primary and secondary copies are always in sync - which provides true real-time duplication
There is more than one disk controller - so if one fails - the other is ready and available
Nondisaster: a disruption in service due to a device malfunction or failure - Disaster: an event that causes the entire facility to be unusable for a day or longer - Catastrophe: a major disruption that destroys the facility altogether --> requires b
After it has been tested
37. Skeleton Crew
It should be far enough away from the original site so one disaster does not take out both locations... alternate facilities should be at a bare minimum at least five miles away from the primary site - while 15 miles is recommended for most low-to-me
Provides methods and procedures for dealing with longer-term outages and disaster.
The employees who carry out the most critical functions of the company who must be put back to work first
A new type of coverage that insures losses caused by denial-of-service attacks - malware damages - hackers - electronic theft - privacy-related lawsuits and more
38. What is the main goal of business continuity?
Before too many people come to their own conclusions about the company and begin to start false rumors
To resume business as quickly as possible - spending the least amount of money
A facility that is leased or rented and is fully configured and ready to operate within a few hours... the only missing resources are usually the data - which will be retrieved from a backup site - and the people who are processing the data. The equi
Reduce the risk of financial loss by improving the company's ability to recover and restore operations
39. Simulation Test
The least critical functions... it ensures that the critical operations of the company are not negatively affected
It should be far enough away from the original site so one disaster does not take out both locations... alternate facilities should be at a bare minimum at least five miles away from the primary site - while 15 miles is recommended for most low-to-me
All employees who participate in operational and support functions - or their representatives - come together to practice executing the disaster recovery plan based on a specific scenario. the scenario is used to test the reaction of each operational
A set of interrelated steps linked through specific decision activities to accomplish a specific task... business processes have starting and ending points and are repeatable
40. What are some examples of teams a company may need to construct - train - and have available in the event of a disaster?
A type of facility-backup option where the back of a large truck or a trailer is turned into a data processing or working area (typically used by military organizations and large insurance companies)
A promise that a service will be fulfilled within a certain timeframe
The least critical functions... it ensures that the critical operations of the company are not negatively affected
Damage assessment team - legal team - media relations team - network recovery team - relocation team - restoration team - salvage team - security team - telecommunications team
41. Remote Journaling
The client pays a monthly fee to retain the right to use the facility in a time of need and then incurs a large activation fee when the facility actually has to be used... most recovery site contracts do not promise to house the company in need at a
Focuses on how to recover various IT mechanisms after a disaster. whereas a contingency plan is usually for nondisasters - a disaster recover plan is for disasters that require IT processing to take place at another facility
It needs to ensure the safety of employees - It needs to ensure an adequate environment is provided (power - facility infrastructure - water - HVAC) - It needs to ensure that the necessary equipment and supplies are present and in working order - It
A method of transmitting data offsite - but it usually only includes moving the journal or transaction logs to the offsite facility - not the actual files. these logs contain the changes that have taken place to the individual files. Journaling is ef
42. How frequently should a company's insurance be reviewed?
Representatives from each department or functional area come together to over the plan to ensure its accuracy
Responsible for getting the alternate site into a working and functioning environment. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and ins
Annually
When it is time for the company to move back into its original site or a new site
43. Redundant Site
One site is equipped and configured exactly like the primary site - which serves as a redundant environment. these sites are owned by the company and are mirrors of the original production environment... this is one of the most expensive backup facil
After it has been tested
The client pays a monthly fee to retain the right to use the facility in a time of need and then incurs a large activation fee when the facility actually has to be used... most recovery site contracts do not promise to house the company in need at a
An estimate of how long it will take to fix a piece of equipment and get it back into production
44. Continuity Planning Policy Statement
A new type of coverage that insures losses caused by denial-of-service attacks - malware damages - hackers - electronic theft - privacy-related lawsuits and more
Since the software vendor provides its customers with only the compiled version of its applications - it's difficult for the customer to continue to use it if the vendor goes out of business. So the customer should set up a Software Escrow agreement
A document that lays out the scope of the BCP project - the team member roles - and the goals of the project. it outlines what needs to be accomplished after the team communicates with management and comes to agreement on the terms of the project
Copies of the BCP are distributed to the different departments and functional areas for review
45. Maximum Tolerable Downtime (MTD)
The primary and secondary data volumes are only a few milliseconds out of sync - so the replication is nearly real-time
A new type of coverage that insures losses caused by denial-of-service attacks - malware damages - hackers - electronic theft - privacy-related lawsuits and more
The outage time that can be endured by a company
To minimize the effects of a disaster and to take the necessary steps to ensure that the resources - personnel - and business processes are able to resume operation in a timely manner. A disaster recovery plan is carried out when everything is still
46. Incremental Backup
Backup all the files that have changed since the last full or incremental backup. this process sets the archive bit to 0
If the company does not practice due care - the insurance company may not be legally obligated to pay if a disaster hits... this is why it's important to read and understand the fine print
Object code - source code - libraries - patches and fixes
1. Select individuals to interview for data gathering 2. Create data-gathering techniques (surveys - questionnaires - qualitative and quantitative approaches) 3. Identify the company's critical business functions 4. Identify the resources these funct
47. In terms of software backups - what should your BCP team address?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
48. What functions should be moved back first during the Reconstitution Phase?
An estimate of how long it will take to fix a piece of equipment and get it back into production
The least critical functions... it ensures that the critical operations of the company are not negatively affected
A method of transmitting data offsite - but it usually only includes moving the journal or transaction logs to the offsite facility - not the actual files. these logs contain the changes that have taken place to the individual files. Journaling is ef
When the power goes on the computers - it's also going to go out for the phones
49. How do you determine how much coverage to obtain?
A promise that a service will be fulfilled within a certain timeframe
Focuses on malware - hackers - intrusions - attacks - and other security issues. outlines procedures for incident response
Base it off of the probability of the threat becoming real and the loss potential. the goal is to make sure the insurance coverage fills in the gap of what the current preventative countermeasures cannot protect against
Lead the BCP team and oversee the development - implementation - and testing of the continuity and disaster recovery plans... this person needs to have direct access to management and have the credibility and authority to carry out leadership tasks
50. Where does the Recovery Time Objective sit on a chart that keeps track of cost and time?
If the company does not practice due care - the insurance company may not be legally obligated to pay if a disaster hits... this is why it's important to read and understand the fine print
The estimated lifetime of a piece of equipment... calculated by the vendor of the equipment or a third party
To resume business as quickly as possible - spending the least amount of money
At the intersection of the cost of disruption and the cost to recover