SUBJECTS
|
BROWSE
|
CAREER CENTER
|
POPULAR
|
JOIN
|
LOGIN
Business Skills
|
Soft Skills
|
Basic Literacy
|
Certifications
About
|
Help
|
Privacy
|
Terms
|
Email
Search
Test your basic knowledge |
CISSP Business Continuity And Disaster Recovery
Start Test
Study First
Subjects
:
certifications
,
it-skills
,
cissp
Instructions:
Answer 50 questions in 15 minutes.
If you are not ready to take this test, you can
study here
.
Match each statement with the correct term.
Don't refresh. All questions and answers are randomly picked and ordered every time you load a test.
This is a study tool. The 3 wrong answers for each question are randomly chosen from answers to other questions. So, you might find at times the answers obvious, but you will see it re-enforces your understanding as you take the test each time.
1. What is one of the big issues with VoIP and disaster recovery?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
2. How should a team break down recovery strategies?
Annually
Copies of the BCP are distributed to the different departments and functional areas for review
A promise that a service will be fulfilled within a certain timeframe
Business process recovery - Facility recovery - Supply and technology recovery - User environment recovery - Data recovery
3. Disk Shadowing
Committing fully to the BCP - Setting policy and goals - Making available the necessary funds and resources - Taking responsibility for the outcome of the development of the BCP - Appointing a team for the process
Makes copies of files as they are modified and periodically transmits them to an offsite backup site. The transmission doesn't happen in real time but is carried out in batches
Data are dynamically created and maintained as images on two or more identical disks. this method is used to ensure the availability of data and to provide a fault-tolerant solution by duplicating hardware and maintaining more than one copy of the in
Since the software vendor provides its customers with only the compiled version of its applications - it's difficult for the customer to continue to use it if the vendor goes out of business. So the customer should set up a Software Escrow agreement
4. What is the main goal of business continuity?
Before too many people come to their own conclusions about the company and begin to start false rumors
Business Resumption Plan - Continuity of Operations Plan (COOP) - IT Contingency Plan - Crisis Communications Plan - Cyber Incident Response Plan - Disaster Recovery Plan
To resume business as quickly as possible - spending the least amount of money
When it is time for the company to move back into its original site or a new site
5. At what point can a company have real confidence in a developed plan?
After it has been tested
Company A agrees to allow company B to use its facilities if company B is hit by a disaster - and vice versa. This is a cheaper way to go than the other offsite choices - but is not always the best choice because most environments are maxed out perta
The business continuity process isn't integrated into the change management process - infrastructure and environment changes occur - reorganization of the company - layoffs - or mergers occur - changes in hardware - software - and applications occur
Includes internal and external communications structure and roles. identifies specific individuals who will communicate with external entities. contains predeveloped statements that are to be released
6. Business Resumption Plan
Back up the files that have been modified since the LAST FULL BACKUP. this process does not change the archive bit value
Responsible for getting the alternate site into a working and functioning environment. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and ins
A type of facility-backup option where the back of a large truck or a trailer is turned into a data processing or working area (typically used by military organizations and large insurance companies)
Focuses on how to re-create the necessary business processes that need to be reestablished instead of focusing on IT components
7. What is the main reason to develop Business Continuity and Disaster Recovery plans?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
8. How do we know which data have changed and need to be backed up without having to look at every file's modification date?
Responsibility: each individual involved should have their responsibilities spelled out in writing and the tasks should be assigned to the individual most situated to handle it - Authority: you need to know what leaders are going to step up to the pl
The file system sets the archive bit of the file to 1 when a file is modified or created
Object code - source code - libraries - patches and fixes
Nondisaster: a disruption in service due to a device malfunction or failure - Disaster: an event that causes the entire facility to be unusable for a day or longer - Catastrophe: a major disruption that destroys the facility altogether --> requires b
9. What format does management want to see in the BCP?
Fortification of the facility in its construction materials - redundant servers and communications links - power lines coming in through different transformers - redundant vendor support - purchasing of insurance - purchasing of UPS and generators -
They want information stated in monetary - quantitative terms - not in subjective - qualitative terms.
Makes copies of files as they are modified and periodically transmits them to an offsite backup site. The transmission doesn't happen in real time but is carried out in batches
All employees who participate in operational and support functions - or their representatives - come together to practice executing the disaster recovery plan based on a specific scenario. the scenario is used to test the reaction of each operational
10. Remote Journaling
Annually
There is more risk for the organization because replacement systems won't be available... that's why many organizations have moved to commercial off the shelf (COTS) products. they want to make sure replacement is possible
One person should be responsible... the authorities are the police department - security guards - fire department - emergency rescue - and management
A method of transmitting data offsite - but it usually only includes moving the journal or transaction logs to the offsite facility - not the actual files. these logs contain the changes that have taken place to the individual files. Journaling is ef
11. If a company loses computing capabilities for a week - what is the chance they will go out of business (on average)?
Management support
65%
Preventive mechanisms are put into place to try to reduce the possibility of the company experiencing a disaster and - if a disaster does hit - to lessen the amount of damage that will take place - Recovery strategies are processes on how to rescue t
It has to figure out what the company needs to do to actually recover the items it has identified as being so important to the organization overall... the BIA provides the footprint
12. What are the three main types of threats?
A method of transmitting data offsite - but it usually only includes moving the journal or transaction logs to the offsite facility - not the actual files. these logs contain the changes that have taken place to the individual files. Journaling is ef
A new type of coverage that insures losses caused by denial-of-service attacks - malware damages - hackers - electronic theft - privacy-related lawsuits and more
Manmade: arsonist - terrorist - a simple mistake - Natural: tornadoes - floods - hurricanes - or earthquakes - Technical: data corruption - loss of power - device failure - or loss of a data communications line
A facility that is leased or rented and is fully configured and ready to operate within a few hours... the only missing resources are usually the data - which will be retrieved from a backup site - and the people who are processing the data. The equi
13. Who should be involved in the Business Continuity and Disaster Recovery plans? In what part of the process?
Copies of the BCP are distributed to the different departments and functional areas for review
Representatives from at least each of the following departments must be involved with not only the planning stages but also the testing and implementation stages: - Business Units - Senior Management - IT Department - Security Department - Communicat
Annually
When the power goes on the computers - it's also going to go out for the phones
14. Redundant Site
Annually
Done to ensure that the specific systems can actually perform adequately at the alternate offsite facility. some systems are moved to the alternate site and processing takes place. the results are compared with the regular processing that is done at
Damage assessment team - legal team - media relations team - network recovery team - relocation team - restoration team - salvage team - security team - telecommunications team
One site is equipped and configured exactly like the primary site - which serves as a redundant environment. these sites are owned by the company and are mirrors of the original production environment... this is one of the most expensive backup facil
15. What are the different types of recovery plans?
Business Resumption Plan - Continuity of Operations Plan (COOP) - IT Contingency Plan - Crisis Communications Plan - Cyber Incident Response Plan - Disaster Recovery Plan
65%
Lead the BCP team and oversee the development - implementation - and testing of the continuity and disaster recovery plans... this person needs to have direct access to management and have the credibility and authority to carry out leadership tasks
Responsible for starting the recovery of the original site. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and install equipment and applicat
16. What are the three types of disruptions that a facility can have and what does each mean?
Fortification of the facility in its construction materials - redundant servers and communications links - power lines coming in through different transformers - redundant vendor support - purchasing of insurance - purchasing of UPS and generators -
All employees who participate in operational and support functions - or their representatives - come together to practice executing the disaster recovery plan based on a specific scenario. the scenario is used to test the reaction of each operational
Nondisaster: a disruption in service due to a device malfunction or failure - Disaster: an event that causes the entire facility to be unusable for a day or longer - Catastrophe: a major disruption that destroys the facility altogether --> requires b
When it is time for the company to move back into its original site or a new site
17. Business Impact Analysis (BIA)
Base it off of the probability of the threat becoming real and the loss potential. the goal is to make sure the insurance coverage fills in the gap of what the current preventative countermeasures cannot protect against
A functional analysis in which a team collects data through interviews - workshops - and documentary sources; documents business functions - activities - and transactions (maybe in a set of flow charts); develops a hierarchy of business functions; an
A method of transmitting data offsite - but it usually only includes moving the journal or transaction logs to the offsite facility - not the actual files. these logs contain the changes that have taken place to the individual files. Journaling is ef
Use scenario-based exercises as a group to see what issues might crop up
18. Mean Time Between Failures (MTBF)
Hot Site - Warm Site - Colde Site
Establishes senior management and a headquarters after a disaster. outlines roles and authorities - orders of succession - and individual role tasks
Maximum tolerable downtime - Operational disruption and productivity - Financial considerations - Regulatory responsibilities - Reputation
The estimated lifetime of a piece of equipment... calculated by the vendor of the equipment or a third party
19. What does the BCP team need to understand about critical business processes?
The business continuity process isn't integrated into the change management process - infrastructure and environment changes occur - reorganization of the company - layoffs - or mergers occur - changes in hardware - software - and applications occur
Each disk would have a corresponding mirrored disk that contains the exact same information
Required roles - Required resources - Input and output mechanisms - Workflow steps - Required time for completion - How they interface with other processes
Plan for systems - networks - and major applications recovery procedures after disruptions. a contingency plan should be developed for each major system and application
20. What should an organization do to assure that they will always be able to get some kind of support for their specialized and critical applications (even in the event that the software vendor goes out of business)?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
21. What information should a BCP and DR goal contain?
When it detects danger to human life - When it detects danger to state or national security - When it detects damage to the facility - When it detects damage to critical systems
Annually
Responsibility: each individual involved should have their responsibilities spelled out in writing and the tasks should be assigned to the individual most situated to handle it - Authority: you need to know what leaders are going to step up to the pl
Lead the BCP team and oversee the development - implementation - and testing of the continuity and disaster recovery plans... this person needs to have direct access to management and have the credibility and authority to carry out leadership tasks
22. Hot Site
At the intersection of the cost of disruption and the cost to recover
Back up the files that have been modified since the LAST FULL BACKUP. this process does not change the archive bit value
When it is time for the company to move back into its original site or a new site
A facility that is leased or rented and is fully configured and ready to operate within a few hours... the only missing resources are usually the data - which will be retrieved from a backup site - and the people who are processing the data. The equi
23. Differential Backup
Contact the local authorities
Establishes senior management and a headquarters after a disaster. outlines roles and authorities - orders of succession - and individual role tasks
A leased or rented facility that supplies the basic environment - electrical wiring - air conditioning - plumbing and flooring - but none of the equipment or additional services. It may take weeks to get the site activated and ready for work. This is
Back up the files that have been modified since the LAST FULL BACKUP. this process does not change the archive bit value
24. Especially in a software development environment - what should be backed up?
The primary and secondary data volumes are only a few milliseconds out of sync - so the replication is nearly real-time
Object code - source code - libraries - patches and fixes
Nondisaster: a disruption in service due to a device malfunction or failure - Disaster: an event that causes the entire facility to be unusable for a day or longer - Catastrophe: a major disruption that destroys the facility altogether --> requires b
A new type of coverage that insures losses caused by denial-of-service attacks - malware damages - hackers - electronic theft - privacy-related lawsuits and more
25. What are management's responsibilities with regards to BCP planning?
There is more risk for the organization because replacement systems won't be available... that's why many organizations have moved to commercial off the shelf (COTS) products. they want to make sure replacement is possible
Committing fully to the BCP - Setting policy and goals - Making available the necessary funds and resources - Taking responsibility for the outcome of the development of the BCP - Appointing a team for the process
Define essential business functions and supporting departments - Identify interdependencies between these functions and departments - Discover all possible disruptions that could affect the mechanisms necessary to allow these departments to function
Before too many people come to their own conclusions about the company and begin to start false rumors
26. Why does Insurance exist?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
27. Business Process
A set of interrelated steps linked through specific decision activities to accomplish a specific task... business processes have starting and ending points and are repeatable
They want information stated in monetary - quantitative terms - not in subjective - qualitative terms.
Maximum tolerable downtime - Operational disruption and productivity - Financial considerations - Regulatory responsibilities - Reputation
Preventive mechanisms are put into place to try to reduce the possibility of the company experiencing a disaster and - if a disaster does hit - to lessen the amount of damage that will take place - Recovery strategies are processes on how to rescue t
28. Salvage Team
Responsible for starting the recovery of the original site. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and install equipment and applicat
Maximum tolerable downtime - Operational disruption and productivity - Financial considerations - Regulatory responsibilities - Reputation
All employees who participate in operational and support functions - or their representatives - come together to practice executing the disaster recovery plan based on a specific scenario. the scenario is used to test the reaction of each operational
No - but the team may recognize that the company is at risk because it does not have these procedures in place
29. Checklist Test (Deckcheck Test)
A leased or rented facility that supplies the basic environment - electrical wiring - air conditioning - plumbing and flooring - but none of the equipment or additional services. It may take weeks to get the site activated and ready for work. This is
Object code - source code - libraries - patches and fixes
A method of transmitting data offsite - but it usually only includes moving the journal or transaction logs to the offsite facility - not the actual files. these logs contain the changes that have taken place to the individual files. Journaling is ef
Copies of the BCP are distributed to the different departments and functional areas for review
30. What are some reasons why BCPs become outdated?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
31. Structured Walk-Through Test
Business Resumption Plan - Continuity of Operations Plan (COOP) - IT Contingency Plan - Crisis Communications Plan - Cyber Incident Response Plan - Disaster Recovery Plan
Preventive mechanisms are put into place to try to reduce the possibility of the company experiencing a disaster and - if a disaster does hit - to lessen the amount of damage that will take place - Recovery strategies are processes on how to rescue t
Representatives from each department or functional area come together to over the plan to ensure its accuracy
Before too many people come to their own conclusions about the company and begin to start false rumors
32. Disk Mirroring
Each disk would have a corresponding mirrored disk that contains the exact same information
There is more risk for the organization because replacement systems won't be available... that's why many organizations have moved to commercial off the shelf (COTS) products. they want to make sure replacement is possible
The least critical functions... it ensures that the critical operations of the company are not negatively affected
Focuses on how to re-create the necessary business processes that need to be reestablished instead of focusing on IT components
33. Warm Site
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
34. What issues does a company need to look at when determining when it should move into Reconstitution Phase?
It needs to ensure the safety of employees - It needs to ensure an adequate environment is provided (power - facility infrastructure - water - HVAC) - It needs to ensure that the necessary equipment and supplies are present and in working order - It
Representatives from at least each of the following departments must be involved with not only the planning stages but also the testing and implementation stages: - Business Units - Senior Management - IT Department - Security Department - Communicat
Provides methods and procedures for dealing with longer-term outages and disaster.
Company A agrees to allow company B to use its facilities if company B is hit by a disaster - and vice versa. This is a cheaper way to go than the other offsite choices - but is not always the best choice because most environments are maxed out perta
35. What are the steps of a BIA?
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
36. What are some of the characteristics you should look at when creating a BIA?
When the power goes on the computers - it's also going to go out for the phones
A leased or rented facility that supplies the basic environment - electrical wiring - air conditioning - plumbing and flooring - but none of the equipment or additional services. It may take weeks to get the site activated and ready for work. This is
Maximum tolerable downtime - Operational disruption and productivity - Financial considerations - Regulatory responsibilities - Reputation
Reduce the risk of financial loss by improving the company's ability to recover and restore operations
37. Business Interruption Insurance
They should make sure there are at least two copies of the company's operating system and critical applications
Includes getting critical systems to another environment while repair of the original facilities is under way - getting the right people to the right places - and performing business in a different mode until regular conditions are back in place
1. Select individuals to interview for data gathering 2. Create data-gathering techniques (surveys - questionnaires - qualitative and quantitative approaches) 3. Identify the company's critical business functions 4. Identify the resources these funct
A type of policy in which the insurance company will pay for specified expenses and lost earnings in the event that a company is forced out of business for a certain length of time. another policy can be bought that insures accounts receivable - so i
38. Parallel Test
65%
Use scenario-based exercises as a group to see what issues might crop up
Includes getting critical systems to another environment while repair of the original facilities is under way - getting the right people to the right places - and performing business in a different mode until regular conditions are back in place
Done to ensure that the specific systems can actually perform adequately at the alternate offsite facility. some systems are moved to the alternate site and processing takes place. the results are compared with the regular processing that is done at
39. Cyberinsurance
A new type of coverage that insures losses caused by denial-of-service attacks - malware damages - hackers - electronic theft - privacy-related lawsuits and more
Hot Site - Warm Site - Colde Site
It needs to ensure the safety of employees - It needs to ensure an adequate environment is provided (power - facility infrastructure - water - HVAC) - It needs to ensure that the necessary equipment and supplies are present and in working order - It
To resume business as quickly as possible - spending the least amount of money
40. What should the BCP team do in the recovery strategy stage?
The plans that determine the steps needed to protect the company in the event that a senior executive retires - leaves the company - or is killed. also details the people who would step in and assume responsibility
Contact the local authorities
It has to figure out what the company needs to do to actually recover the items it has identified as being so important to the organization overall... the BIA provides the footprint
Makes copies of files as they are modified and periodically transmits them to an offsite backup site. The transmission doesn't happen in real time but is carried out in batches
41. What are the benefits of using the Differential or Incremental backup methods?
It requires less resources and time
A set of interrelated steps linked through specific decision activities to accomplish a specific task... business processes have starting and ending points and are repeatable
Makes copies of files as they are modified and periodically transmits them to an offsite backup site. The transmission doesn't happen in real time but is carried out in batches
Objective-to-task mapping - Resource-to-task mapping - Milestones - Budget estimates - Success factors - Deadlines
42. What are some examples of teams a company may need to construct - train - and have available in the event of a disaster?
The file system sets the archive bit of the file to 1 when a file is modified or created
The outage time that can be endured by a company
Damage assessment team - legal team - media relations team - network recovery team - relocation team - restoration team - salvage team - security team - telecommunications team
Determines the cause of the disaster - Determines the potential for further damage - Identifies the affected business functions and areas - Identifies the level of functionality for the critical resources - Identifies the resources that must be repla
43. Electronic Vaulting
Warning
: Invalid argument supplied for foreach() in
/var/www/html/basicversity.com/show_quiz.php
on line
183
44. Incremental Backup
Damage assessment team - legal team - media relations team - network recovery team - relocation team - restoration team - salvage team - security team - telecommunications team
Backup all the files that have changed since the last full or incremental backup. this process sets the archive bit to 0
1. Develop the continuity planning policy statement 2. Conduct the business impact analysis (BIA) 3. Identify preventive controls 4. Develop recovery strategies 5. Develop the contingency plan 6. Test the plan and conduct training and exercises 7. Ma
Plan for systems - networks - and major applications recovery procedures after disruptions. a contingency plan should be developed for each major system and application
45. Mean Time To Repair (MTTR)
Establishes senior management and a headquarters after a disaster. outlines roles and authorities - orders of succession - and individual role tasks
An estimate of how long it will take to fix a piece of equipment and get it back into production
To minimize the effects of a disaster and to take the necessary steps to ensure that the resources - personnel - and business processes are able to resume operation in a timely manner. A disaster recovery plan is carried out when everything is still
Focuses on malware - hackers - intrusions - attacks - and other security issues. outlines procedures for incident response
46. What are some components required for the project plan?
Manmade: arsonist - terrorist - a simple mistake - Natural: tornadoes - floods - hurricanes - or earthquakes - Technical: data corruption - loss of power - device failure - or loss of a data communications line
Management support
Computer systems - Personnel - Procedures - Tasks - Supplies - Vendor support
Objective-to-task mapping - Resource-to-task mapping - Milestones - Budget estimates - Success factors - Deadlines
47. Skeleton Crew
The employees who carry out the most critical functions of the company who must be put back to work first
A document that outlines who should be contacted in the event of a disaster - in what order - and who is responsible for doing the calling
Plan for systems - networks - and major applications recovery procedures after disruptions. a contingency plan should be developed for each major system and application
Provides methods and procedures for dealing with longer-term outages and disaster.
48. Where does the Recovery Time Objective sit on a chart that keeps track of cost and time?
Establishes personnel safety and evacuation procedures
The most intrusive test to regular operations and business productivity. the original site is shut down - and processing takes place at the alternate site. this test takes a lot of planning and coordination but it can reveal many holes in the plan. f
At the intersection of the cost of disruption and the cost to recover
1. Develop the continuity planning policy statement 2. Conduct the business impact analysis (BIA) 3. Identify preventive controls 4. Develop recovery strategies 5. Develop the contingency plan 6. Test the plan and conduct training and exercises 7. Ma
49. Restoration Team
It needs to ensure the safety of employees - It needs to ensure an adequate environment is provided (power - facility infrastructure - water - HVAC) - It needs to ensure that the necessary equipment and supplies are present and in working order - It
Responsible for getting the alternate site into a working and functioning environment. Needs to know how to install OSes - configure workstations and servers - string wiring and cabling - set up the network and configure networking services - and ins
A type of policy in which the insurance company will pay for specified expenses and lost earnings in the event that a company is forced out of business for a certain length of time. another policy can be bought that insures accounts receivable - so i
Identifying regulatory and legal requirements that must be met - Identifying all possible vulnerabilities and threats - Estimating the possibilities of these threats and the loss potential - Performing a BIA - Outlining which departments - systems -
50. Should the BCP team be responsible for setting up and maintaining the company's data classification procedures?
Since the software vendor provides its customers with only the compiled version of its applications - it's difficult for the customer to continue to use it if the vendor goes out of business. So the customer should set up a Software Escrow agreement
No - but the team may recognize that the company is at risk because it does not have these procedures in place
Identifying regulatory and legal requirements that must be met - Identifying all possible vulnerabilities and threats - Estimating the possibilities of these threats and the loss potential - Performing a BIA - Outlining which departments - systems -
Network and computer equipment - Voice and data communications resources - Human Resources - Transportation of equipment and personnel - Environment issues (HVAC) - Data and personnel security issues - Supplies (paper - forms - cabling - and so on) -