Post-Class Quiz: Business Continuity & Disaster Recovery Planning Domain



Similar documents
Business Continuity Planning and Disaster Recovery Planning. Ed Crowley IAM/IEM

Business Continuity Planning and Disaster Recovery Planning

Domain 3 Business Continuity and Disaster Recovery Planning

Business Continuity Planning (BCP) & Disaster Recovery Planning (DRP).

CISSP Common Body of Knowledge: Business Continuity & Disaster Recovery Planning Domain Version: 5.9.2

Assessing Your Disaster. Andrews Hooper Pavlik PLC. Andrews Hooper Pavlik PLC

CISM Certified Information Security Manager

Business Continuity Planning and Disaster Recovery Planning

Business Continuity Plan

Disaster Recovery Plan (DRP) / Business Continuity Plan (BCP)

Disaster Recovery Planning. Marcus Bendtsen Institutionen för Datavetenskap (IDA) Avdelningen för Databas- och Informationsteknik (ADIT)

Temple university. Auditing a business continuity management BCM. November, 2015

Disaster Recovery Planning Process

DISASTER RECOVERY AND CONTINGENCY PLANNING CHECKLIST FOR ICT SYSTEMS

BCP and DR. P K Patel AGM, MoF

EMERGENCY PREPAREDNESS PLAN Business Continuity Plan

Desktop Scenario Self Assessment Exercise Page 1

Business Continuity and Disaster Recovery Planning

Business Continuity Glossary

Table of Contents... 1

BUSINESS CONTINUITY PLAN

PAPER-6 PART-4 OF 5 CA A.RAFEQ, FCA

How to write a DISASTER RECOVERY PLAN. To print to A4, print at 75%.

Information Services IT Security Policies B. Business continuity management and planning

Unit Guide to Business Continuity/Resumption Planning

INSIDE. Preventing Data Loss. > Disaster Recovery Types and Categories. > Disaster Recovery Site Types. > Disaster Recovery Procedure Lists

Disaster Recovery & Business Continuity Related, but NOT the Same! Teri Stokes, Ph.D., Director GXP International

NEEDS BASED PLANNING FOR IT DISASTER RECOVERY

Contingency Planning Guide

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Three

Audit, Finance and Legislative Committee Mayor Craig Lowe, Chair Mayor-Commissioner Pro Tem Thomas Hawkins, Member

Business Continuity Planning (800)

Protecting your Enterprise

Business Continuity Management

PAPER-6 PART-1 OF 5 CA A.RAFEQ, FCA

Institute for Business Continuity Training 1623 Military Road, # 377 Niagara Falls, NY

Q uick Guide to Disaster Recovery Planning An ITtoolkit.com White Paper

MARQUIS DISASTER RECOVERY PLAN (DRP)

Security+ Guide to Network Security Fundamentals, Fourth Edition. Chapter 13 Business Continuity

Virginia Commonwealth University School of Medicine Information Security Standard

Best Practices in Developing an IT Disaster Recovery Plan. Vijaykumar Kulkarni AGM Product Management

NIST SP , Revision 1 Contingency Planning Guide for Federal Information Systems

Certified Disaster Recovery Engineer

Planning for Disaster Disaster

2014 NABRICO Conference

Course: Information Security Management in e-governance. Day 2. Session 5: Disaster Recovery Planning

What is Business Continuity Planning (BCP) / Disaster Recovery Plan(DRP)?

Planning for Disaster. Ramesh Ramani CISM CGEIT 02 June 2010

Business Continuity Planning Principles and Best Practices Tom Hinkel and Zach Duke

Information Security Management: Business Continuity Planning. Presentation by Stanislav Nurilov March 9th, 2005 CS 996: Info. Sec. Mgmt.

Ohio Conference for Payroll Professionals Disaster Recovery

Overview of Business Continuity Planning Sally Meglathery Payoff

Fundamentals of Business Continuity Planning Have a Plan!

<Client Name> IT Disaster Recovery Plan Template. By Paul Kirvan, CISA, CISSP, FBCI, CBCP

Proposal for Business Continuity Plan and Management Review 6 August 2008

Business Continuity Planning. Presentation and. Direction

Disaster Recovery Planning. By Janet Coggins

Data Center Assistance Group, Inc. DCAG Contact: Tom Bronack Phone: (718) Fax: (718)

Clinic Business Continuity Plan Guidelines

MHA Consulting. Business Continuity Management 101

How To Prepare For A Disaster

DRAFT Disaster Recovery Policy Template

Disaster Recovery. 1.1 Introduction. 1.2 Reasons for Disaster Recovery. EKAM Solutions Ltd Disaster Recovery

Principles for BCM requirements for the Dutch financial sector and its providers.

Joint Universities Computer Centre Limited ( JUCC ) Information Security Awareness Training- Session Four

Business Continuity Template

FINRMFS9 Facilitate Business Continuity Planning and disaster recovery for a financial services organisation

KPMG Information Risk Management Business Continuity Management Peter McNally, KPMG Asia Pacific Leader for Business Continuity

The ABC s of BCP. Jeremy Sucharski Governance Risk and Compliance G31

D2-02_01 Disaster Recovery in the modern EPU

Developing a Business Continuity Plan... More Than Disaster

Version Copyright Janco Associates, Inc. - Page 1

Information System Audit. Arkansas Administrative Statewide Information System (AASIS) General Controls

Success or Failure? Your Keys to Business Continuity Planning. An Ingenuity Whitepaper

Interactive-Network Disaster Recovery

Disaster Recovery and Business Continuity Plan

Toronto Public Library Disaster Recovery recommended safeguards and controls

Company Management System. Business Continuity in SIA

Introduction UNDERSTANDING BUSINESS CONTINUITY MANAGEMENT

CENTRAL BANK OF KENYA (CBK) PRUDENTIAL GUIDELINE ON BUSINESS CONTINUITY MANAGEMENT (BCM) FOR INSTITUTIONS LICENSED UNDER THE BANKING ACT

HA / DR Jargon Buster High Availability / Disaster Recovery

Traditional Disaster Recovery versus Cloud based DR

Val-EdTM. Valiant Technologies Education & Training Services. 2-day Workshop on Business Continuity & Disaster Recovery Planning

Best Practices in Disaster Recovery Planning and Testing

Business Continuity Planning (BCP) / Disaster Recovery (DR)

Clinic Business Continuity Plan Guidelines

BUSINESS CONTINUITY: BEST PRACTICE, 2ND EDITION

BUSINESS CONTINUITY PLAN OVERVIEW

#316 The Security Elements of Business Continuity & Disaster Recovery Plans

Business Unit CONTINGENCY PLAN

Module 7. Business Continuity Management

Disaster Recovery Plan (Business Continuity) Template

How to Plan for Disaster Recovery and Business Continuity

Disaster Recovery. Hendry Taylor Tayori Limited

Transcription:

1. What is the most common planned performance duration for a continuity of operations plan (COOP)? A. 30 days B. 60 days C. 90 days D. It depends on the severity of a disaster. 2. What is the business continuity plan (BCP) that focuses on the recovery of a damaged facility or components back to normal day-to-day operations? A. Cyber Incident Response Plan B. Disaster Recovery Plan C. Crisis Communications Plan D. Occupant Emergency Plan 3. Which is not a traditional phase in preparing a business continuity plan (BCP)? A. Testing, Maintenance, Awareness, and Training B. Business Impact Analysis C. Project Management and Initiation D. Quantitative Risk Analysis 4. In business continuity planning (BCP), where did the most of operational requirements originated from? A. Analysis of recovery strategy B. Analysis of business impacts C. The system architecture D. Disaster recovery planning 5. Which of the following are steps in conducting a business impact analysis (BIA)? A. Interviewing Executives B. Vulnerability Assessments C. Gathering assessment material D. Network Scanning CISSP CBK Review Page 1

6. Which of the following is essentially an operational test? A. Simulation Test B. Parallel Test C. Checklist Test D. Full Interruption Test 7. Which of the following includes the definition of procedures for emergency response? A. Operations Planning B. Disaster Recovery Planning C. Business Continuity Planning D. Backup Planning 8. BCP must address which of the following disasters? A. Hazardous Material Spills B. Earthquakes C. Raw Material Outages D. A & B 9. Which of the following are possible preventive measures for backup procedures? A. Air Conditioning B. Suppression C. UPS D. Documentation 10. Which of the following is an advantage of a cold site over a hot site A. Air Conditioning B. Cost C. Short period to become operational D. B & C 11. A disaster recovery plan (DRP) must consider which of the following items? CISSP CBK Review Page 2

A. Cost B. People C. Software D. B & C 12. A business impact analysis (BIA) criticality survey helps to identify which of the following? A. Most critical IT functions B. Most critical Business functions C. Most critical IT Roles D. Most critical Business Roles 13. In business continuity planning (BCP), the recovery window (i.e., maximum tolerable downtime (MTD)) is determined in which phase? A. Project Initiation Phase B. Business Impact Analysis Phase C. Recovery Strategy Phase D. Testing Phase 14. A test document should include? A. List of participants B. Test Duration C. Test Results D. A & B 15. Which of the following team(s) should be part of the disaster recovery procedures? A. Test Team B. Management Team C. Salvage Team D. IT Team 16. Which of the following recovery issues must be considered in disaster recovery planning (DRP)? CISSP CBK Review Page 3

A. Continuance of Salaries B. Expense disbursement C. Public Relations D. A & B 17. A business continuity plan (BCP) should have a structure that includes: A. A detailed section on incident and risk assessment covering all the organization's key business activities. B. A detailed section on incident and risk assessment covering all the organization's business activities. C. A brief section on incident and risk assessment covering all the organization's key business activities. D. A brief section on incident and risk assessment covering all the organization's business activities. 18. Business continuity planning (BCP) projects should be approved at: A. the board level B. the front line level C. the operational level D. the team level 19. Business continuity primarily addresses what security objective? A. Availability B. Integrity C. Confidentiality D. Accountability 20. A business continuity plan (BCP) should cover all essential and critical business activities. A. True B. False C. True only when IS audit is not involved D. None of the choices. CISSP CBK Review Page 4

21. A business continuity plan (BCP) should be: A. Periodically tested in a simulated environment. B. Tested daily in a simulated environment. C. Tested bi-weekly in a simulated environment. D. Activated every day. 22. Which of the following is not a focus area in defining a disaster recovery strategy? A. Business recovery B. Technology recovery C. Data recovery D. Facility occupancy 23. What should take place in order to restore a server, its files and data after a major system failure? A. Restore from storage media backup B. Perform a parallel test C. Implement recovery procedures D. Perform a check list test 24. It is recommended that your disaster recovery plan (DRP) and business continuity plan (BCP) be tested at a minimum of what intervals? A. Six months B. When the systems and environment change C. Two years D. One year 25. In addition to preventing loss of life and further injury, what other reason is there to immediately initiate an emergency plan after a disaster? A. Secure the area to prevent any looting, fraud or vandalism. B. Reduce likelihood of further damage C. Protect the site for forensic evidence D. Investigate the extent of the damages CISSP CBK Review Page 5

26. Which is the best description of remote journaling? A. Backing up bulk data to an off-site facility B. Backing up transaction logs to an off-site facility C. Backing up transactions to a mirrored server in house D. Backing up transactions to at least two different media types 27. When shopping for an off site backup facility that will ultimately be used to store all your backup media, what is the most important factor to consider? A. The backup facility should be within 15 minutes of the original facility. B. The facility should contain an adequate number of PCs and servers and have raised flooring. C. The facility should have at least one armed guard. D. The facility should protect against unauthorized access and entry. 28. Which item will a business impact analysis not identify? A. If the company is best suited for a parallel or full-interrupt test. B. What areas would incur the greatest operational and financial loss in the event of a particular business disruption event C. What systems are considered critical and must be protected D. What amount of downtime the business can sustain before permanent damage is done 29. The final approval of the disaster recovery plan (DRP) and business continuity plan (BCP) rests with which group? A. The Change Control Review Board B. The Department representative C. Management D. The external auditing staff 30. Which answer lists the proper steps required to develop a disaster recovery and business continuity plan (DRP/BCP)? A. Project initiation, business impact analysis, strategy development, plan development, testing, maintenance B. Strategy development, project initiation, business impact analysis, plan development, testing, maintenance CISSP CBK Review Page 6

C. Business impact analysis, project initiation, strategy development, plan development, testing, maintenance D. Project initiation, plan development, business impact analysis, strategy development, testing, maintenance 31. What is the most critical factor in the development of a disaster recovery plan (DRP)? A. Business impact analysis B. Annual testing C. Participation from every department D. Management support 32. Which is least important to making the business case to management for the disaster recover plan and the business continuity plan? A. Government regulations and legal requirements B. The business vulnerabilities to disasters and disruptions C. How other companies are dealing with similar issues D. The level of impact the business can endure when a disaster hits 33. What is the best description of a structured walk through test? A. It is a test to ensure that the critical systems will run at the alternate site B. All departments receive a copy of the disaster recovery plan and walk through it C. Representatives from each department come together and go through the test collectively D. Operations are shifted to the emergency site and senior management reviews the plan on a line item by line item basis. 34. Which of the following is not a nature of reciprocity agreements? A. Agreements are enforceable B. It is a cheap solution C. It may be able to be implemented right after a disaster D. A existing data center can be overwhelmed by a disaster CISSP CBK Review Page 7

35. The business continuity planning (BCP) project management and initiation phase does not involve: A. Establishing members of the BCP team B. Determining the need for automated data collection tools C. Performing a Business Impact Analysis D. Preparing and presenting status reports 36. Which of the following backup facilities is most expensive? A. Cold B. Hot C. Warm D. Mobile 37. A business impact analysis would not likely include which of the following tasks? A. Calculating risk B. Identifying threats C. Selecting team members D. Identifying critical functions of the company 38. What is the mechanism to use when a organization is concern about the business viability of a software vendor? A. Service bureau (/ service provider) B. Standby service C. Software escrow service D. Insurance service 39. In testing the business continuity plans, what is the practice execution of a set of planned activities based on a set of pre-defined scenarios called? A. Structured walk-through B. Checklist test C. Simulation D. Full interruption test CISSP CBK Review Page 8

40. Resuming critical business functions includes: A. Determining the extent of damage B. Declaring a disaster C. Establishing the command center D. Contacting recovery team members CISSP CBK Review Page 9