chapter 11 350
Susan performs a full backup of her server every Sunday at 1:00 a.m. and differential backups on Mondays through Fridays at 1:00 a.m. Her server fails at 9:00 a.m. on Wednesday. How many backups does Susan need to restore? A. 3 B. 2 C. 4 D. 1
2
Hajar is responsible for keeping her banking institution's servers operating 24/7/365. Her recovery strategy is to have fully redundant or duplicate operations and synchronized data and to operate the site continuously. Which strategy has she selected? A. Mobile site B. Hot site C. Alternate processing center or mirrored site D. Warm site
Alternate processing center or mirrored site
During which step of the incident-handling process does triage take place? A. Response B. Recovery and follow-up C. Notification D. Identification
Identification
Isabella is an IT security manager for a state agency. The agency can survive for nine hours without a functioning data center. If the power goes out in her data center, Isabella estimates it will take six hours to move data center operations to an alternate site. Which of the following describes how long the agency can survive without a functioning data center? A. Recovery time objective (RTO) B. Recovery point objective (RPO) C. Maximum tolerable downtime (MTD) D. Critical business function (CBF)
Maximum tolerable downtime (MTD)
During which step of the incident-handling process do you develop a formal communication plan and identify all key stakeholders? A. Documentation B. Notification C. Preparation D. Identification
Preparation
Arturo is an IT manager for a school district. He is planning recovery options for a small data center that supports teacher and classroom activities for 5 of the 21 schools in his district. Many school districts in his state use similar classroom technology. Arturo is looking for a temporary alternate site that would be easy to cut over to and is affordable. Which option is most likely to fit Arturo's needs? A. Reciprocal center B. Service provider that has extra capacity C. Reciprocal agreement with another school district D. Contingency carrier
Reciprocal agreement with another school district
During which step of the incident-handling process should a lessons-learned review of the incident be conducted? A. Recovery and follow-up B. Response C. Documentation D. Notification
Recovery and follow-up
Isabella is an IT security manager for a state agency. The agency can survive for nine hours without a functioning data center. The power goes out in her data center. It takes six hours to move data center operations to an alternate site. Which of the following describes the time it takes for the move? A. Mean time to failure (MTTF) B. Critical business function (CBF) C. Recovery time objective (RTO) D. Recovery point objective (RPO)
Recovery time objective (RTO)
A(n) _________ is an event that prevents a critical business function (CBF) from operating for a period greater than the maximum tolerable downtime (MTD). A. incident B. contingency C. violation D. disaster
disaster
True or False? A business impact analysis (BIA) details the steps to recover from a disruption and restore the infrastructure necessary for normal business operations.
false
True or False? All types of disaster recovery sites are available in the cloud.
false
True or False? Clustering comprises multiple disk drives that appear as a single disk drive but actually store multiple copies of data in case a disk drive in the array fails.
false
True or False? During a simulation test of a contingency plan, you must shut down the original system at the primary site for the duration.
false
True or False? A parallel test of a contingency plan is the same as a full-interruption test except that processing does not stop at the primary site.
true
True or False? A successful business impact analysis (BIA) maps the context, the critical business functions (CBFs), and the processes on which they rely.
true
True or False? An organization can maintain a cloud-based disaster recovery site for a fraction of the cost of a physical site.
true
True or False? Any component that, if it fails, could interrupt business processing is called a single point of failure (SPOF).
true
True or False? Business continuity management includes business continuity planning, disaster recovery planning, crisis management, incident response management, and risk management.
true
True or False? Examples of major disruptions include extreme weather, application failure, and criminal activity
true
True or False? Fault-tolerance options are not replacements for data backups
true
True or False? Generally, once evidence becomes inadmissible, it cannot be fixed.
true
True or False? In an incremental backup, you start with a full backup when network traffic is light. Then, each night, you back up only that day's changes.
true
During which step of the incident-handling process is the goal to contain the incident? A. Response B. Notification C. Identification D. Recovery and follow-up
Response
Carl has assembled a team of representatives from each department to test a new business continuity plan (BCP). During the test, the representatives meet in a room and review many aspects of the plan, such as the goals, scope, assumptions, and the structure of the organization. They also conduct scenario-based exercises as though they are executing the plan for a certain type of incident to find errors, such as gaps or overlaps. What type of plan is being conducted? A. Parallel B. Simulation C. Structured walk-through D. Checklist
Structured walk-through
Joe is responsible for the security of the systems that control and monitor devices for a power plant. What type of system does Joe likely administer? A. Mainframe B. Mobile fleet C. Embedded robotic systems D. Supervisory Control and Data Acquisition (SCADA)
Supervisory Control and Data Acquisition (SCADA)
