8. Operations Management Flashcards
Which form of BC/DR testing has the most impact on operations?
A. Tabletop
B. Dry run
C. Full test
D. Structured walk-through
Answer: C. Full test
The full test will involve every asset in the organization, including all personnel. The others will have less impact on the organization because they do not actually involve activating the plan.
Which form of BC/DR testing has the least impact on operations?
A. Tabletop
B. Dry run
C. Full test
D. Structured test
Answer: A. Tabletop
The tabletop test involves only essential personnel and none of the production assets. The others will have greater impact.
Which characteristic of liquid propane increases its desirability as a fuel for backup generators?
A. Burn rate
B. Price
C. Does not spoil
D. Flavor
Answer: C. Does not spoil
Liquid propane does not spoil, which obviates the need to continually refresh and restock it, and might make it more cost- effective. The burn rate has nothing to do with its suitability, unless it has some direct bearing on the particular generator the data center owner has
chosen. The various relative prices of fuel fluctuate. Flavor is a distractor in this question and means nothing.
How often should the CMB meet?
A. Whenever regulations dictate
B. Often enough to address organizational needs and reduce frustration with delay
C. Every week
D. Annually
Answer: B. Often enough to address organizational needs and reduce frustration with delay.
Frustrated employees and managers can increase risk to the organization by implementing their own, unapproved modifications to the environment. The particular interval changes from organization to organization.
Adhering to ASHRAE standards for humidity can reduce the possibility of _______.
A. Breach
B. Static discharge
C. Theft
D. Inversion
**Answer: B. Static discharge **
A data center with less than optimum humidity can have a higher static electricity discharge rate. Humidity has no bearing on breaches or theft, and inversion is a nonsense term used as a distractor.
A UPS should have enough power to last how long?
A. 12 hours
B. 10 minutes
C. One day
D. Long enough for graceful shutdown
Answer: D. Long enough for graceful shutdown
The UPS is intended to last only long enough to save production data currently being processed. The exact quantity of time will depend on many variables and will differ from one data center to the next.
A generator transfer switch should bring backup power online within what time frame?
A. 10 seconds
B. Before the recovery point objective is reached
C. Before the UPS duration is exceeded
D. Three days
Answer: C. Before the UPS duration is exceeded
Generator power should be online before battery backups fail. The specific amount of time will vary between data centers.
Which characteristic of automated patching makes it attractive?
A. Cost
B. Speed
C. Noise reduction
D. Capability to recognize problems quickly
Answer: B. Speed
Automated patching is much faster and more efficient than manual patching. It is, however, not necessarily any less expensive than manual patching. Manual patching is overseen by administrators, who will recognize problems faster than automated tools. Noise reduction is not a factor in patch management at all.
Which tool can reduce confusion and misunderstanding during a BC/DR response?
A. Flashlight
B. Controls matrix
C. Checklist
D. Call tree
Answer: C. Checklist
Checklists serve as a reliable guide for BC/DR activity and should be straightforward enough to use that someone not already an expert or trained in BC/DR response could
accomplish the necessary tasks. Flashlights and call trees are certainly useful during BC/DR actions, but not to reduce confusion and misunderstanding. Control matrices are not useful during BC/DR actions.
When deciding whether to apply specific updates, it is best to follow ______ to demonstrate due care.
A. Regulations
B. Vendor guidance
C. Internal policy
D. Competitors’ actions
Answer: B. Vendor guidance
A data center that doesn’t follow vendor guidance might be seen as failing to provide due care. Regulations, internal policy, and the actions of competitors might all inform the decision to perform an update and patch, but these don’t necessarily bear directly on due care. This is a difficult, nuanced question, and all the answers are good, but option B is the best.
The CMB should include representations from all of the following offices except ___________________.
A. Regulators
B. IT department
C. Security office
D. Management
Answer: A. Regulators
Regulators are not involved in an organization’s CMB. The IT department, security office, and management all play a role in the CMB process.
For performance purposes, OS monitoring should include all of the following except ___________________.
A. Disk space
B. Disk I/O usage
C. CPU usage
D. Print spooling
Answer: D. Print spooling
Disk space, disk I/O usage, and CPU usage are all standard performance monitoring metrics. Print spooling is not normally incorporated into performance monitoring plans.
Maintenance mode requires all of these actions except___________________.
A. Remove all active production instances
B. Initiate enhanced security controls
C. Prevent new logins
D. Ensure logging continues
Answer: B. Initiate enhanced security controls
During maintenance mode, teams should remove all active production instances, prevent new logins, and ensure that logging continues. There is not normally a need to initiate
enhanced security controls.
What is one of the reasons a baseline might be changed?
A. Numerous change requests
B. Power fluctuation
C. To reduce redundancy
D. Natural disaster
Answer: A. Numerous change requests
If the CMB is receiving numerous change requests to the point where the number of requests would drop by modifying the baseline, then that is a good reason to change the baseline. The baseline should not be changed due to power fluctuations, to reduce redundancy, or due to a natural disaster.
In addition to battery backup, a UPS can offer which capability?
A. Communication redundancy
B. Line conditioning
C. Breach alert
D. Confidentiality
Answer: B. Line conditioning
A UPS can provide line conditioning, adjusting power so that it is optimized for the devices it serves, and smoothing any power fluctuations. It does not provide confidentiality,
breach alerts, or communication redundancy.
Deviations from security baselines should be investigated and ______.
A. Documented
B. Enforced
C. Revealed
D. Encouraged
Answer: A. Documented
All deviations from the baseline should be documented, including details of the investigation and outcome. We do not enforce or encourage deviations. Presumably, we would already be aware of the deviation, so “revealed” is not a reasonable answer.
The baseline should cover which of the following?
A. As many systems throughout the organization as possible
B. Data breach alerting and reporting
C. A process for version control
D. All regulatory compliance requirements
Answer: A. As many systems throughout the organization as possible
The more systems that are included in the baseline, the more cost-effective and scalable the baseline is. The baseline does not deal with breaches or version control; those are the provinces of the security office and CMB, respectively. Regulatory compliance might (and usually will) go beyond the baseline and involve systems, processes, and personnel that are not subject to the baseline.
A localized incident or disaster can be addressed in a cost-effective manner by using which of the following?
A. UPS
B. Generators
C. Joint operating agreements
D. Strict adherence to applicable regulations
Answer: C. Joint operating agreements
Joint operating agreements can provide nearby relocation sites so that a disruption limited to the organization’s own facility and campus can be addressed at a different facility and campus. UPS systems and generators are not limited to serving needs for localized causes. Regulations do not promote cost savings and are not often the immediate concern during BC/DR activities.
Generator fuel storage for a cloud data center should last for how long, at a minimum?
A. 10 minutes
B. Three days
C. Indefinitely
D. 12 hours
Answer: D. 12 hours
The Uptime Institute dictates 12 hours of generator fuel for all cloud data center tiers.
The BC/DR kit should include all of the following except ___________________.
A. Flashlight
B. Documentation equipment
C. Fuel for the backup generators
D. Annotated asset inventory
Answer: C. Fuel for the backup generators
The BC/DR kit is intended to be compact, and generator fuel is too cumbersome to include with the kit. All the other items should be included.