8. Operations Management Flashcards

1
Q

Which form of BC/DR testing has the most impact on operations?

A. Tabletop
B. Dry run
C. Full test
D. Structured walk-through

A

Answer: C. Full test

The full test will involve every asset in the organization, including all personnel. The others will have less impact on the organization because they do not actually involve activating the plan.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which form of BC/DR testing has the least impact on operations?

A. Tabletop
B. Dry run
C. Full test
D. Structured test

A

Answer: A. Tabletop

The tabletop test involves only essential personnel and none of the production assets. The others will have greater impact.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Which characteristic of liquid propane increases its desirability as a fuel for backup generators?

A. Burn rate
B. Price
C. Does not spoil
D. Flavor

A

Answer: C. Does not spoil

Liquid propane does not spoil, which obviates the need to continually refresh and restock it, and might make it more cost-­ effective. The burn rate has nothing to do with its suitability, unless it has some direct bearing on the particular generator the data center owner has
chosen. The various relative prices of fuel fluctuate. Flavor is a distractor in this question and means nothing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How often should the CMB meet?

A. Whenever regulations dictate
B. Often enough to address organizational needs and reduce frustration with delay
C. Every week
D. Annually

A

Answer: B. Often enough to address organizational needs and reduce frustration with delay.

Frustrated employees and managers can increase risk to the organization by implementing their own, unapproved modifications to the environment. The particular interval changes from organization to organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Adhering to ASHRAE standards for humidity can reduce the possibility of _______.

A. Breach
B. Static discharge
C. Theft
D. Inversion

A

**Answer: B. Static discharge **

A data center with less than optimum humidity can have a higher static electricity discharge rate. Humidity has no bearing on breaches or theft, and inversion is a nonsense term used as a distractor.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A UPS should have enough power to last how long?

A. 12 hours
B. 10 minutes
C. One day
D. Long enough for graceful shutdown

A

Answer: D. Long enough for graceful shutdown

The UPS is intended to last only long enough to save production data currently being processed. The exact quantity of time will depend on many variables and will differ from one data center to the next.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A generator transfer switch should bring backup power online within what time frame?

A. 10 seconds
B. Before the recovery point objective is reached
C. Before the UPS duration is exceeded
D. Three days

A

Answer: C. Before the UPS duration is exceeded

Generator power should be online before battery backups fail. The specific amount of time will vary between data centers.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which characteristic of automated patching makes it attractive?

A. Cost
B. Speed
C. Noise reduction
D. Capability to recognize problems quickly

A

Answer: B. Speed

Automated patching is much faster and more efficient than manual patching. It is, however, not necessarily any less expensive than manual patching. Manual patching is overseen by administrators, who will recognize problems faster than automated tools. Noise reduction is not a factor in patch management at all.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Which tool can reduce confusion and misunderstanding during a BC/DR response?

A. Flashlight
B. Controls matrix
C. Checklist
D. Call tree

A

Answer: C. Checklist

Checklists serve as a reliable guide for BC/DR activity and should be straightforward enough to use that someone not already an expert or trained in BC/DR response could
accomplish the necessary tasks.
Flashlights and call trees are certainly useful during BC/DR actions, but not to reduce confusion and misunderstanding. Control matrices are not useful during BC/DR actions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

When deciding whether to apply specific updates, it is best to follow ______ to demonstrate due care.

A. Regulations
B. Vendor guidance
C. Internal policy
D. Competitors’ actions

A

Answer: B. Vendor guidance

A data center that doesn’t follow vendor guidance might be seen as failing to provide due care. Regulations, internal policy, and the actions of competitors might all inform the decision to perform an update and patch, but these don’t necessarily bear directly on due care. This is a difficult, nuanced question, and all the answers are good, but option B is the best.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

The CMB should include representations from all of the following offices except ___________________.

A. Regulators
B. IT department
C. Security office
D. Management

A

Answer: A. Regulators

Regulators are not involved in an organization’s CMB. The IT department, security office, and management all play a role in the CMB process.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

For performance purposes, OS monitoring should include all of the following except ___________________.

A. Disk space
B. Disk I/O usage
C. CPU usage
D. Print spooling

A

Answer: D. Print spooling

Disk space, disk I/O usage, and CPU usage are all standard performance monitoring metrics. Print spooling is not normally incorporated into performance monitoring plans.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Maintenance mode requires all of these actions except___________________.

A. Remove all active production instances
B. Initiate enhanced security controls
C. Prevent new logins
D. Ensure logging continues

A

Answer: B. Initiate enhanced security controls

During maintenance mode, teams should remove all active production instances, prevent new logins, and ensure that logging continues. There is not normally a need to initiate
enhanced security controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is one of the reasons a baseline might be changed?

A. Numerous change requests
B. Power fluctuation
C. To reduce redundancy
D. Natural disaster

A

Answer: A. Numerous change requests

If the CMB is receiving numerous change requests to the point where the number of requests would drop by modifying the baseline, then that is a good reason to change the baseline. The baseline should not be changed due to power fluctuations, to reduce redundancy, or due to a natural disaster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

In addition to battery backup, a UPS can offer which capability?

A. Communication redundancy
B. Line conditioning
C. Breach alert
D. Confidentiality

A

Answer: B. Line conditioning

A UPS can provide line conditioning, adjusting power so that it is optimized for the devices it serves, and smoothing any power fluctuations. It does not provide confidentiality,
breach alerts, or communication redundancy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Deviations from security baselines should be investigated and ______.

A. Documented
B. Enforced
C. Revealed
D. Encouraged

A

Answer: A. Documented

All deviations from the baseline should be documented, including details of the investigation and outcome. We do not enforce or encourage deviations. Presumably, we would already be aware of the deviation, so “revealed” is not a reasonable answer.

17
Q

The baseline should cover which of the following?

A. As many systems throughout the organization as possible
B. Data breach alerting and reporting
C. A process for version control
D. All regulatory compliance requirements

A

Answer: A. As many systems throughout the organization as possible

The more systems that are included in the baseline, the more cost-­effective and scalable the baseline is. The baseline does not deal with breaches or version control; those are the provinces of the security office and CMB, respectively. Regulatory compliance might (and usually will) go beyond the baseline and involve systems, processes, and personnel that are not subject to the baseline.

18
Q

A localized incident or disaster can be addressed in a cost-effective manner by using which of the following?

A. UPS
B. Generators
C. Joint operating agreements
D. Strict adherence to applicable regulations

A

Answer: C. Joint operating agreements

Joint operating agreements can provide nearby relocation sites so that a disruption limited to the organization’s own facility and campus can be addressed at a different facility and campus. UPS systems and generators are not limited to serving needs for localized causes. Regulations do not promote cost savings and are not often the immediate concern during BC/DR activities.

19
Q

Generator fuel storage for a cloud data center should last for how long, at a minimum?

A. 10 minutes
B. Three days
C. Indefinitely
D. 12 hours

A

Answer: D. 12 hours

The Uptime Institute dictates 12 hours of generator fuel for all cloud data center tiers.

20
Q

The BC/DR kit should include all of the following except ___________________.

A. Flashlight
B. Documentation equipment
C. Fuel for the backup generators
D. Annotated asset inventory

A

Answer: C. Fuel for the backup generators

The BC/DR kit is intended to be compact, and generator fuel is too cumbersome to include with the kit. All the other items should be included.