Module 5 - Risk, Response and Recovery

Pataasin ang iyong marka sa homework at exams ngayon gamit ang Quizwiz!

Kim is the risk manager for a large organization. She is evaluating whether the organization should purchase a fire suppression system. She consulted a variety of subject matter experts and determined that there is a 1 percent chance that a fire will occur in a given year. If a fire occurred, it would likely cause $2 million in damage to the facility, which has a $10 million value. Given this scenario, what is the single loss expectancy (SLE)?

$2,000,000

Kim is the risk manager for a large organization. She is evaluating whether the organization should purchase a fire suppression system. She consulted a variety of subject matter experts and determined that there is a 1 percent chance that a fire will occur in a given year. If a fire occurred, it would likely cause $2 million in damage to the facility, which has a $10 million value. Given this scenario, what is the annualized loss expectancy (ALE)?

$20,000

Nancy performs a full backup of her server every Sunday at 1 A.M. and differential backups on Mondays through Fridays at 1 A.M. Her server fails at 9 A.M. Wednesday. How many backups does Nancy need to restore?

2

Kim is the risk manager for a large organization. She is evaluating whether the organization should purchase a fire suppression system. She consulted a variety of subject matter experts and determined that there is a 1 percent chance that a fire will occur in a given year. If a fire occurred, it would likely cause $2 million in damage to the facility, which has a $10 million value. Given this scenario, what is the exposure factor?

20 percent

What a key principle of risk management programs?

Don't spend more to protect an asset than it is worth.

A structured walk-through test is a review of a business continuity plan to ensure that contact numbers are current and that the plan reflects the company's priorities and structure.

False. A structured walk-through test is a tabletop exercise. During this test, a team of representatives from each department should do the following: • Present their portion of the plan to the other teams. • Review the goals of the plan for completeness and correctness. • Affirm the scope of the plan as well as any assumptions made. • Look for overlaps and gaps. • Review the structure of the organization as well as the reporting/communications structure. • Evaluate the testing, maintenance, and training requirements. • Conduct a number of scenario-based exercises to evaluate the plan's effectiveness. • Meet to step through the plan together in a structured manner.

A business impact analysis (BIA) details the steps to recover from a disruption and restore the infrastructure necessary for normal business operations.

False. Business impact analysis (BIA) - A prerequisite analysis for a business continuity plan that prioritizes business operations and functions and their associated IT systems, applications, and data and the impact of an outage or downtime.

Deterrent controls identify that a threat has landed in your system.

False. Deterrent control - A control that warns the user that completing a requested action could result in a violation or threat.

The first step in the risk management process is to monitor and control deployed countermeasures.

False. Identify risks — The first step to managing risk is identifying risks.

Jake has been asked to help test the business continuity plan at an offsite location while the system at the main location is shut down. He is participating in a parallel test.

False. Parallel Test - The same as a full-interruption test, except that processing does not stop at the primary site.

Risk refers to the amount of harm a threat exploiting a vulnerability can cause.

False. Risk - The likelihood that something, generally something bad, will happen to an asset.

With adequate security controls and defenses, an organization can often reduce its risk to zero.

False. You can never reduce risk to zero.

Which recovery site option provides readiness in minutes to hours?

Hot site

Adam's company recently suffered an attack where hackers exploited an SQL injection issue on their web server and stole sensitive information from a database. What term describes this activity?

Incident

Brian needs to design a control that prevents piggybacking, only allowing one person to enter a facility at a time. What type of control would best meet this need?

Mantraps

What term describes the longest period of time that a business can survive without a particular critical system?

Maximum tolerable downtime (MTD)

Violet deploys an intrusion prevention system (IPS) on her network as a security control. What type of control has Violet deployed?

Preventive

Beth is conducting a risk assessment. She is trying to determine the impact a security incident will have on the reputation of her company. What type of risk assessment is best suited to this type of analysis?

Qualitative

Which data source comes first in the order of volatility when conducting a forensic investigation?

RAM

Alan is the security manager for a mid-sized business. The company has suffered several serious data losses when mobile devices were stolen. Alan decides to implement full disk encryption on all mobile devices. What risk response did Alan take?

Reduce

What term describes the risk that exists after an organization has performed all planned countermeasures and controls?

Residual risk

Joe is responsible for the security of the industrial control systems for a power plant. What type of environment does Joe administer?

Supervisory Control and Data Acquisition (SCADA)

A control limits or constrains behavior.

True.

A personnel safety plan should include an escape plan.

True.

A successful business impact analysis (BIA) maps the context, the critical business functions, and the processes on which they rely.

True.

Administrative controls develop and ensure compliance with policy and procedures.

True.

Any component that, if it fails, could interrupt business processing is called a single point of failure (SPoF).

True.

Examples of major disruptions include extreme weather, application failure, and criminal activity.

True.

Fencing and mantraps are examples of physical controls.

True.

Implementing and monitoring risk responses are part of the risk management process.

True.

In an incremental backup, you start with a full backup when network traffic is light. Then, each night, you back up only that day's changes.

True.

In remote journaling, a system writes a log of online transactions to an offsite location.

True.

Organizations should seek a balance between the utility and cost of various risk management options.

True.

The recovery point objective (RPO) can come from the business impact analysis or sometimes from a government mandate, such as banking laws.

True.

While running business operations at an alternate site, you must continue to make backups of data and systems.

True.

Adam is evaluating the security of a web server before it goes live. He believes that an issue in the code allows an SQL injection attack against the server. What term describes the issue that Adam discovered?

Vulnerability

Which control is NOT an example of a fault tolerance technique designed to avoid interruptions that would cause downtime?

Warm site

Forensics and incident response are examples of __________ controls.

corrective

A(n) _________ is an event that prevents a critical business function (CBF) from operating for a period greater than the maximum tolerable downtime.

disaster

Purchasing an insurance policy is an example of the ____________ risk management strategy.

transfer


Kaugnay na mga set ng pag-aaral

Chapter 8: Families and Teachers: Partners in Education

View Set

Chapter 5 Small Business, Entrepreneurship and Franchises

View Set

008 - Networking - C9.1.5 SAN Facts

View Set

Research Methods & Statistics Exam 2

View Set

P1L2 - Introduction to Operating Systems

View Set

Zoology Ch. 7, 8, & 9 Study Guide

View Set

Porth Patho Chapter 39: Disorders of the Male Genitourinary System

View Set