SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISSP Business Continuity And Disaster Recovery
Start Test
Study First
Subjects
:
certifications
,
it-skills
,
cissp
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. When should a Damage Assessment Team change into Recovery mode?
When it detects danger to human life - When it detects danger to state or national security - When it detects damage to the facility - When it detects damage to critical systems
Define essential business functions and supporting departments - Identify interdependencies between these functions and departments - Discover all possible disruptions that could affect the mechanisms necessary to allow these departments to function
Before too many people come to their own conclusions about the company and begin to start false rumors
A promise that a service will be fulfilled within a certain timeframe
2. If a company loses computing capabilities for a week - what is the chance they will go out of business (on average)?
65%
A leased or rented facility that supplies the basic environment - electrical wiring - air conditioning - plumbing and flooring - but none of the equipment or additional services. It may take weeks to get the site activated and ready for work. This is
A functional analysis in which a team collects data through interviews - workshops - and documentary sources; documents business functions - activities - and transactions (maybe in a set of flow charts); develops a hierarchy of business functions; an
Define essential business functions and supporting departments - Identify interdependencies between these functions and departments - Discover all possible disruptions that could affect the mechanisms necessary to allow these departments to function
3. How are offsite backup facility contracts usually established?
Annually
Committing fully to the BCP - Setting policy and goals - Making available the necessary funds and resources - Taking responsibility for the outcome of the development of the BCP - Appointing a team for the process
It has to figure out what the company needs to do to actually recover the items it has identified as being so important to the organization overall... the BIA provides the footprint
The client pays a monthly fee to retain the right to use the facility in a time of need and then incurs a large activation fee when the facility actually has to be used... most recovery site contracts do not promise to house the company in need at a
4. Disaster Recovery Plan
A leased or rented facility that usually partially configured with some equipment (peripheral devices) - but not the actual computers... it's usually a hot site without the expensive equipment. This is the most widely-used model... it is less expensi
Focuses on how to recover various IT mechanisms after a disaster. whereas a contingency plan is usually for nondisasters - a disaster recover plan is for disasters that require IT processing to take place at another facility
Backup all the files that have changed since the last full or incremental backup. this process sets the archive bit to 0
A facility that is leased or rented and is fully configured and ready to operate within a few hours... the only missing resources are usually the data - which will be retrieved from a backup site - and the people who are processing the data. The equi
5. What information should a BCP and DR goal contain?
Responsibility: each individual involved should have their responsibilities spelled out in writing and the tasks should be assigned to the individual most situated to handle it - Authority: you need to know what leaders are going to step up to the pl
Loss in reputation and public confidence - Loss of competitive advantages - Increase in operational expenses - Violations of contract agreements - Violations of legal and regulatory requirements - Delayed income costs - Loss in revenue - Loss in pr
Base it off of the probability of the threat becoming real and the loss potential. the goal is to make sure the insurance coverage fills in the gap of what the current preventative countermeasures cannot protect against
There is more risk for the organization because replacement systems won't be available... that's why many organizations have moved to commercial off the shelf (COTS) products. they want to make sure replacement is possible
6. Continuity of Operations Plan (COOP)
Establishes senior management and a headquarters after a disaster. outlines roles and authorities - orders of succession - and individual role tasks
65%
To resume business as quickly as possible - spending the least amount of money
All employees who participate in operational and support functions - or their representatives - come together to practice executing the disaster recovery plan based on a specific scenario. the scenario is used to test the reaction of each operational
7. Full Backup
All data are backed up and saved to some type of storage media. backup and restoration processes are very simplistic and straightforward with this method
Loss in reputation and public confidence - Loss of competitive advantages - Increase in operational expenses - Violations of contract agreements - Violations of legal and regulatory requirements - Delayed income costs - Loss in revenue - Loss in pr
Hot Site - Warm Site - Colde Site
A document that lays out the scope of the BCP project - the team member roles - and the goals of the project. it outlines what needs to be accomplished after the team communicates with management and comes to agreement on the terms of the project
8. Business Interruption Insurance
To resume business as quickly as possible - spending the least amount of money
A type of policy in which the insurance company will pay for specified expenses and lost earnings in the event that a company is forced out of business for a certain length of time. another policy can be bought that insures accounts receivable - so i
Loss in reputation and public confidence - Loss of competitive advantages - Increase in operational expenses - Violations of contract agreements - Violations of legal and regulatory requirements - Delayed income costs - Loss in revenue - Loss in pr
When it is time for the company to move back into its original site or a new site
9. What functions should be moved back first during the Reconstitution Phase?
Loss in reputation and public confidence - Loss of competitive advantages - Increase in operational expenses - Violations of contract agreements - Violations of legal and regulatory requirements - Delayed income costs - Loss in revenue - Loss in pr
Reduce the risk of financial loss by improving the company's ability to recover and restore operations
Establishes personnel safety and evacuation procedures
The least critical functions... it ensures that the critical operations of the company are not negatively affected
10. What is one of the big issues with VoIP and disaster recovery?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
11. What are management's responsibilities with regards to BCP planning?
Computer systems - Personnel - Procedures - Tasks - Supplies - Vendor support
Fortification of the facility in its construction materials - redundant servers and communications links - power lines coming in through different transformers - redundant vendor support - purchasing of insurance - purchasing of UPS and generators -
Committing fully to the BCP - Setting policy and goals - Making available the necessary funds and resources - Taking responsibility for the outcome of the development of the BCP - Appointing a team for the process
The plans that determine the steps needed to protect the company in the event that a senior executive retires - leaves the company - or is killed. also details the people who would step in and assume responsibility
12. Crisis Communications Plan
A facility that is leased or rented and is fully configured and ready to operate within a few hours... the only missing resources are usually the data - which will be retrieved from a backup site - and the people who are processing the data. The equi
Includes internal and external communications structure and roles. identifies specific individuals who will communicate with external entities. contains predeveloped statements that are to be released
A document that outlines who should be contacted in the event of a disaster - in what order - and who is responsible for doing the calling
All employees who participate in operational and support functions - or their representatives - come together to practice executing the disaster recovery plan based on a specific scenario. the scenario is used to test the reaction of each operational
13. Where should the business continuity and disaster recovery plans be stored when they're completed?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
14. Electronic Vaulting
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
15. Redundant Site
One site is equipped and configured exactly like the primary site - which serves as a redundant environment. these sites are owned by the company and are mirrors of the original production environment... this is one of the most expensive backup facil
1. Develop the continuity planning policy statement 2. Conduct the business impact analysis (BIA) 3. Identify preventive controls 4. Develop recovery strategies 5. Develop the contingency plan 6. Test the plan and conduct training and exercises 7. Ma
Nondisaster: a disruption in service due to a device malfunction or failure - Disaster: an event that causes the entire facility to be unusable for a day or longer - Catastrophe: a major disruption that destroys the facility altogether --> requires b
It should be far enough away from the original site so one disaster does not take out both locations... alternate facilities should be at a bare minimum at least five miles away from the primary site - while 15 miles is recommended for most low-to-me
16. Continuity Planning Policy Statement
A document that outlines who should be contacted in the event of a disaster - in what order - and who is responsible for doing the calling
Committing fully to the BCP - Setting policy and goals - Making available the necessary funds and resources - Taking responsibility for the outcome of the development of the BCP - Appointing a team for the process
A document that lays out the scope of the BCP project - the team member roles - and the goals of the project. it outlines what needs to be accomplished after the team communicates with management and comes to agreement on the terms of the project
The primary and secondary data volumes are only a few milliseconds out of sync - so the replication is nearly real-time
17. Especially in a software development environment - what should be backed up?
Object code - source code - libraries - patches and fixes
A method of transmitting data offsite - but it usually only includes moving the journal or transaction logs to the offsite facility - not the actual files. these logs contain the changes that have taken place to the individual files. Journaling is ef
Makes copies of files as they are modified and periodically transmits them to an offsite backup site. The transmission doesn't happen in real time but is carried out in batches
A document that outlines who should be contacted in the event of a disaster - in what order - and who is responsible for doing the calling
18. What format does management want to see in the BCP?
The plans that determine the steps needed to protect the company in the event that a senior executive retires - leaves the company - or is killed. also details the people who would step in and assume responsibility
They want information stated in monetary - quantitative terms - not in subjective - qualitative terms.
Network and computer equipment - Voice and data communications resources - Human Resources - Transportation of equipment and personnel - Environment issues (HVAC) - Data and personnel security issues - Supplies (paper - forms - cabling - and so on) -
After it has been tested
19. Checklist Test (Deckcheck Test)
Copies of the BCP are distributed to the different departments and functional areas for review
It should be far enough away from the original site so one disaster does not take out both locations... alternate facilities should be at a bare minimum at least five miles away from the primary site - while 15 miles is recommended for most low-to-me
A type of facility-backup option where the back of a large truck or a trailer is turned into a data processing or working area (typically used by military organizations and large insurance companies)
A document that outlines who should be contacted in the event of a disaster - in what order - and who is responsible for doing the calling
20. Who should be responsible for notifying the appropriate authorities and who would those authorities be?
Data are dynamically created and maintained as images on two or more identical disks. this method is used to ensure the availability of data and to provide a fault-tolerant solution by duplicating hardware and maintaining more than one copy of the in
One person should be responsible... the authorities are the police department - security guards - fire department - emergency rescue - and management
The business continuity process isn't integrated into the change management process - infrastructure and environment changes occur - reorganization of the company - layoffs - or mergers occur - changes in hardware - software - and applications occur
A type of policy in which the insurance company will pay for specified expenses and lost earnings in the event that a company is forced out of business for a certain length of time. another policy can be bought that insures accounts receivable - so i
21. What are some of the things you have to consider when it comes to supply and tech recovery?
Network and computer equipment - Voice and data communications resources - Human Resources - Transportation of equipment and personnel - Environment issues (HVAC) - Data and personnel security issues - Supplies (paper - forms - cabling - and so on) -
A promise that a service will be fulfilled within a certain timeframe
Backing up business data to tapes that are then manually transferred to an offsite facility by a courier or an employee... with automatic tape vaulting - the data are sent over a serial line to a backup tape system at the offsite facility. Electronic
Identifying regulatory and legal requirements that must be met - Identifying all possible vulnerabilities and threats - Estimating the possibilities of these threats and the loss potential - Performing a BIA - Outlining which departments - systems -
22. Executive Succession Planning
The plans that determine the steps needed to protect the company in the event that a senior executive retires - leaves the company - or is killed. also details the people who would step in and assume responsibility
Define essential business functions and supporting departments - Identify interdependencies between these functions and departments - Discover all possible disruptions that could affect the mechanisms necessary to allow these departments to function
A set of interrelated steps linked through specific decision activities to accomplish a specific task... business processes have starting and ending points and are repeatable
Network and computer equipment - Voice and data communications resources - Human Resources - Transportation of equipment and personnel - Environment issues (HVAC) - Data and personnel security issues - Supplies (paper - forms - cabling - and so on) -
23. Where does the Recovery Time Objective sit on a chart that keeps track of cost and time?
At the intersection of the cost of disruption and the cost to recover
Data are dynamically created and maintained as images on two or more identical disks. this method is used to ensure the availability of data and to provide a fault-tolerant solution by duplicating hardware and maintaining more than one copy of the in
Determines the cause of the disaster - Determines the potential for further damage - Identifies the affected business functions and areas - Identifies the level of functionality for the critical resources - Identifies the resources that must be repla
When it detects danger to human life - When it detects danger to state or national security - When it detects damage to the facility - When it detects damage to critical systems
24. What are some appropriate and cost-effective preventative methods to better fortify a company from the impacts recognized in the BIA?
Maximum tolerable downtime - Operational disruption and productivity - Financial considerations - Regulatory responsibilities - Reputation
Fortification of the facility in its construction materials - redundant servers and communications links - power lines coming in through different transformers - redundant vendor support - purchasing of insurance - purchasing of UPS and generators -
1. Develop the continuity planning policy statement 2. Conduct the business impact analysis (BIA) 3. Identify preventive controls 4. Develop recovery strategies 5. Develop the contingency plan 6. Test the plan and conduct training and exercises 7. Ma
The primary and secondary data volumes are only a few milliseconds out of sync - so the replication is nearly real-time
25. What are the steps of a BIA?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
26. IT Contingency Plan
A leased or rented facility that usually partially configured with some equipment (peripheral devices) - but not the actual computers... it's usually a hot site without the expensive equipment. This is the most widely-used model... it is less expensi
There is more than one disk controller - so if one fails - the other is ready and available
Plan for systems - networks - and major applications recovery procedures after disruptions. a contingency plan should be developed for each major system and application
1. Develop the continuity planning policy statement 2. Conduct the business impact analysis (BIA) 3. Identify preventive controls 4. Develop recovery strategies 5. Develop the contingency plan 6. Test the plan and conduct training and exercises 7. Ma
27. What are some components required for the project plan?
To resume business as quickly as possible - spending the least amount of money
An estimate of how long it will take to fix a piece of equipment and get it back into production
Objective-to-task mapping - Resource-to-task mapping - Milestones - Budget estimates - Success factors - Deadlines
Define essential business functions and supporting departments - Identify interdependencies between these functions and departments - Discover all possible disruptions that could affect the mechanisms necessary to allow these departments to function
28. In terms of software backups - what should your BCP team address?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
29. What are the three main types of leased or rented offsite facilities?
Identifying regulatory and legal requirements that must be met - Identifying all possible vulnerabilities and threats - Estimating the possibilities of these threats and the loss potential - Performing a BIA - Outlining which departments - systems -
Object code - source code - libraries - patches and fixes
Loss in reputation and public confidence - Loss of competitive advantages - Increase in operational expenses - Violations of contract agreements - Violations of legal and regulatory requirements - Delayed income costs - Loss in revenue - Loss in pr
Hot Site - Warm Site - Colde Site
30. Parallel Test
One person should be responsible... the authorities are the police department - security guards - fire department - emergency rescue - and management
Management support
Done to ensure that the specific systems can actually perform adequately at the alternate offsite facility. some systems are moved to the alternate site and processing takes place. the results are compared with the regular processing that is done at
Company A agrees to allow company B to use its facilities if company B is hit by a disaster - and vice versa. This is a cheaper way to go than the other offsite choices - but is not always the best choice because most environments are maxed out perta
31. What is the most critical part of establishing and maintaining a current continuity plan?
To resume business as quickly as possible - spending the least amount of money
Lead the BCP team and oversee the development - implementation - and testing of the continuity and disaster recovery plans... this person needs to have direct access to management and have the credibility and authority to carry out leadership tasks
Management support
The estimated lifetime of a piece of equipment... calculated by the vendor of the equipment or a third party
32. Reciprocal Agreement (Mutual Aid)
Includes getting critical systems to another environment while repair of the original facilities is under way - getting the right people to the right places - and performing business in a different mode until regular conditions are back in place
Company A agrees to allow company B to use its facilities if company B is hit by a disaster - and vice versa. This is a cheaper way to go than the other offsite choices - but is not always the best choice because most environments are maxed out perta
Representatives from each department or functional area come together to over the plan to ensure its accuracy
There is more than one disk controller - so if one fails - the other is ready and available
33. Disk Mirroring
Since the software vendor provides its customers with only the compiled version of its applications - it's difficult for the customer to continue to use it if the vendor goes out of business. So the customer should set up a Software Escrow agreement
Each disk would have a corresponding mirrored disk that contains the exact same information
A type of policy in which the insurance company will pay for specified expenses and lost earnings in the event that a company is forced out of business for a certain length of time. another policy can be bought that insures accounts receivable - so i
Prepared actions that are developed to help people in a crisis situation better cope with the disruption. Protection of life is of the utmost importance and should be dealt with first before looking to save material objects!
34. Rolling Hot Site (Mobile Hot Site)
Required roles - Required resources - Input and output mechanisms - Workflow steps - Required time for completion - How they interface with other processes
Responsible for starting the recovery of the original site. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and install equipment and applicat
At the intersection of the cost of disruption and the cost to recover
A type of facility-backup option where the back of a large truck or a trailer is turned into a data processing or working area (typically used by military organizations and large insurance companies)
35. What is the main reason to develop Business Continuity and Disaster Recovery plans?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
36. Calling Tree
Done to ensure that the specific systems can actually perform adequately at the alternate offsite facility. some systems are moved to the alternate site and processing takes place. the results are compared with the regular processing that is done at
The business continuity process isn't integrated into the change management process - infrastructure and environment changes occur - reorganization of the company - layoffs - or mergers occur - changes in hardware - software - and applications occur
Before too many people come to their own conclusions about the company and begin to start false rumors
A document that outlines who should be contacted in the event of a disaster - in what order - and who is responsible for doing the calling
37. How do we know which data have changed and need to be backed up without having to look at every file's modification date?
Makes copies of files as they are modified and periodically transmits them to an offsite backup site. The transmission doesn't happen in real time but is carried out in batches
Identifying regulatory and legal requirements that must be met - Identifying all possible vulnerabilities and threats - Estimating the possibilities of these threats and the loss potential - Performing a BIA - Outlining which departments - systems -
The file system sets the archive bit of the file to 1 when a file is modified or created
A facility that is leased or rented and is fully configured and ready to operate within a few hours... the only missing resources are usually the data - which will be retrieved from a backup site - and the people who are processing the data. The equi
38. Reconstitution Phase
Maximum tolerable downtime - Operational disruption and productivity - Financial considerations - Regulatory responsibilities - Reputation
The employees who carry out the most critical functions of the company who must be put back to work first
When it is time for the company to move back into its original site or a new site
Determines the cause of the disaster - Determines the potential for further damage - Identifies the affected business functions and areas - Identifies the level of functionality for the critical resources - Identifies the resources that must be repla
39. Asynchronous Replication
The primary and secondary data volumes are only a few milliseconds out of sync - so the replication is nearly real-time
Responsible for getting the alternate site into a working and functioning environment. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and ins
There is more than one disk controller - so if one fails - the other is ready and available
Focuses on how to re-create the necessary business processes that need to be reestablished instead of focusing on IT components
40. What are some of the resources that would be required for individual business processes?
Typically a copy is stored at the BCP coordinator's home - and another copy is stored at the offsite facility... when they are stored offsite - they need to be stored in a way that provides just as much protection as the primary site would provide
A document that lays out the scope of the BCP project - the team member roles - and the goals of the project. it outlines what needs to be accomplished after the team communicates with management and comes to agreement on the terms of the project
Computer systems - Personnel - Procedures - Tasks - Supplies - Vendor support
Focuses on how to recover various IT mechanisms after a disaster. whereas a contingency plan is usually for nondisasters - a disaster recover plan is for disasters that require IT processing to take place at another facility
41. Business Resumption Plan
One person should be responsible... the authorities are the police department - security guards - fire department - emergency rescue - and management
Focuses on how to re-create the necessary business processes that need to be reestablished instead of focusing on IT components
Backup all the files that have changed since the last full or incremental backup. this process sets the archive bit to 0
Base it off of the probability of the threat becoming real and the loss potential. the goal is to make sure the insurance coverage fills in the gap of what the current preventative countermeasures cannot protect against
42. Differential Backup
After it has been tested
Back up the files that have been modified since the LAST FULL BACKUP. this process does not change the archive bit value
Fortification of the facility in its construction materials - redundant servers and communications links - power lines coming in through different transformers - redundant vendor support - purchasing of insurance - purchasing of UPS and generators -
Prepared actions that are developed to help people in a crisis situation better cope with the disruption. Protection of life is of the utmost importance and should be dealt with first before looking to save material objects!
43. How can an organization keep the BCP up to date?
Focuses on how to recover various IT mechanisms after a disaster. whereas a contingency plan is usually for nondisasters - a disaster recover plan is for disasters that require IT processing to take place at another facility
Define essential business functions and supporting departments - Identify interdependencies between these functions and departments - Discover all possible disruptions that could affect the mechanisms necessary to allow these departments to function
A document that lays out the scope of the BCP project - the team member roles - and the goals of the project. it outlines what needs to be accomplished after the team communicates with management and comes to agreement on the terms of the project
Make business continuity a part of every business decision - Insert the maintenance responsibilities into job description - Include maintenance in personnel evaluations - Perform internal audits that include disaster recovery and continuity documenta
44. Disk Duplexing
If the company does not practice due care - the insurance company may not be legally obligated to pay if a disaster hits... this is why it's important to read and understand the fine print
A promise that a service will be fulfilled within a certain timeframe
Backing up business data to tapes that are then manually transferred to an offsite facility by a courier or an employee... with automatic tape vaulting - the data are sent over a serial line to a backup tape system at the offsite facility. Electronic
There is more than one disk controller - so if one fails - the other is ready and available
45. Restoration Team
Representatives from each department or functional area come together to over the plan to ensure its accuracy
Since the software vendor provides its customers with only the compiled version of its applications - it's difficult for the customer to continue to use it if the vendor goes out of business. So the customer should set up a Software Escrow agreement
Responsible for getting the alternate site into a working and functioning environment. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and ins
Establishes senior management and a headquarters after a disaster. outlines roles and authorities - orders of succession - and individual role tasks
46. Business Process
Before too many people come to their own conclusions about the company and begin to start false rumors
A method of transmitting data offsite - but it usually only includes moving the journal or transaction logs to the offsite facility - not the actual files. these logs contain the changes that have taken place to the individual files. Journaling is ef
A leased or rented facility that supplies the basic environment - electrical wiring - air conditioning - plumbing and flooring - but none of the equipment or additional services. It may take weeks to get the site activated and ready for work. This is
A set of interrelated steps linked through specific decision activities to accomplish a specific task... business processes have starting and ending points and are repeatable
47. Synchronous Replication
Focuses on how to re-create the necessary business processes that need to be reestablished instead of focusing on IT components
The primary and secondary copies are always in sync - which provides true real-time duplication
If the company does not practice due care - the insurance company may not be legally obligated to pay if a disaster hits... this is why it's important to read and understand the fine print
When it is time for the company to move back into its original site or a new site
48. Hot Site
Back up the files that have been modified since the LAST FULL BACKUP. this process does not change the archive bit value
A facility that is leased or rented and is fully configured and ready to operate within a few hours... the only missing resources are usually the data - which will be retrieved from a backup site - and the people who are processing the data. The equi
Typically a copy is stored at the BCP coordinator's home - and another copy is stored at the offsite facility... when they are stored offsite - they need to be stored in a way that provides just as much protection as the primary site would provide
Before too many people come to their own conclusions about the company and begin to start false rumors
49. Warm Site
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
50. Role of the Business Continuity Coordinator
The estimated lifetime of a piece of equipment... calculated by the vendor of the equipment or a third party
1. Select individuals to interview for data gathering 2. Create data-gathering techniques (surveys - questionnaires - qualitative and quantitative approaches) 3. Identify the company's critical business functions 4. Identify the resources these funct
After it has been tested
Lead the BCP team and oversee the development - implementation - and testing of the continuity and disaster recovery plans... this person needs to have direct access to management and have the credibility and authority to carry out leadership tasks