2 BC/IR/DR Flashcards

1
Q

Business Continuity Planning (BCP) =

A

a set of activities and controls designed to keep a business running in the face of adversity (Availability!)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Business Impact Assessment (BIA) =

A

a tool that identifies and prioritizes risk (risk assessment)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The BIA output =

A

a prioritized listing of risks with associated cost - compare control cost with annualized loss expectancy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Single Point of Failure Analysis (SPOFs) (Business continuity tool)

A

identifies and removes SPOFs (single server - replace with server cluster)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

2 key concepts to improve availability

A

1 High Availability (HA) - redundant systems 2 Fault Tolerance (FT) - helps protect a single system from failing in the first place

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Load Balancing =

A

(related but different concept)
- uses multiple systems in an attempt to spread the burden of providing services across those systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

3 Common Points of Failure that FT addresses:

A

1 Power Supplies 2 Storage Media
3 Networking

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

RAID is a

A

Fault Tolerance technique to protect against a single disk failure, it is not a backup strategy!

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

RAID types (2)

A

1 Disk Mirroring (RAID level 1)
2 Disk Striping with Parity (RAID level 5)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Disk Mirroring (RAID level 1) server has

A
  • 2 disks
  • data is written to both identically (synchronized)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Disk Striping with Parity (RAID level 5)

A
  • 3 or more disks
  • data is written across those disks with parity blocks (additional data) spread across the disks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Incident Response Process (4) (lifecycle)

A

1 Preparation
2 Detection/Analysis
3 Containment/Eradication/Recovery
4 Post-incident Activity
NIST SP 800-61 (standard process)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Incident Response Plan elements:

A

1 statement of purpose/scope
2 clear strategies and goals for the incident response effort
3 the organization’s approach to incident response (who is responsible for what?)
4 communication with other groups
5 senior leadership approval

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

IR Plan should (4)

A

1 covers both internal and external communications
2 contain notification and escalation procedures
3 limit external communications (PR, alert attackers, etc)
4 alerting law enforcement is usually not required (complex - threat to safety, obligation)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

SIEM =

A

Security Incident and Event Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

SOAR =

A

Security Orchestration, Automation and Response

17
Q

DR steps in when

A

Business continuity fails! (a subset of Business Continuity)

18
Q

DR Initial response goals (2)

A

1 contain the damage
2 recover normal operations

19
Q

3 Metrics to used to develop the DR plan

A

1 RTO (Recovery Time Objective)
2 RPO (Recovery Point Objective)
3 RSL (Recovery Service Level)

20
Q

RTO =

A

targeted amount of time to restore service to meet the organization’s objectives

21
Q

RPO =

A
  • the organization’s data loss tolerance (the maximum amount of data loss that is acceptable)
  • example: an RPO of 1 hr requires a backup every hour
22
Q

RSL =

A
  • the percentage of service that must be available during a disaster
23
Q

3 types of backup media

A

1 Tape Backups
2 Disk-to-disk (NAS, offsite)
3 Cloud backups

24
Q

3 primary backup types

A

1 Full Backups
2 Differential Backups
3 Incremental Backups

25
Q

Full backup

A

complete copy, clears the archive bit

26
Q

Differential Backup

A
  • a copy of only the data that has changed since the last full backup
  • does not clear the archive bit
27
Q

Incremental Backup

A
  • a copy of files that have changed since either the most recent incremental or full backup. clears the archive bit
28
Q

Disaster Recovery Sites (3 types)

A

1 Hot Sites
2 Cold Sites (empty data center)
3 Warm Sites (has hardware, but software not running in parallel)

29
Q

DR testing goals (2)

A

1 validate that the plan functions correctly
2 identify necessary plan updates

30
Q

5 types of disaster recovery testing

A

1 read-through (check list reviews)
2 walk-through (tabletop discussion of everyone’s roles)
3 simulation (talk-through of actions for an actual scenario)
4 parallel test (activates DR environment but does not switch operations there)
5 full interruption test (rare - switches primary operations to the DR environment)