Business Continuity and Disaster Recovery Planning Flashcards

1
Q

What does the acronym BCP stand for?

A

BCP (Business Continuity Planning)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does the acronym DRP stand for?

A

DCP (Disaster Recovery Planning)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

In terms of Business Continuity and Disaster Recovery Planning, what is the the last line of defense when all other controls have failed?

A

BCP/DRP is the last line of defense when all other controls have failed; the final control that may prevent drastic events like injury or loss of life or failure of an organizations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

In terms of Business Continuity and Disaster Recovery Planning,

characterize the difference between BCP and DRP.

A

BCP is an umbrella plan which includes multiple specific plans; most importantly the Disaster recovery Plan (DRP)

DRP is IT centric.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

In terms of Business Continuity and Disaster Recovery Planning,

What is the definition of BCP?

A

BCP: Business Continuity Planning: ensuring the business will continue to operate before, throughout and after a disaster; a long term strategic business oriented plan; long term plan to ensure the continuity of the business.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

In terms of Business Continuity and Disaster Recovery Planning,

What is the definition of DRP?

A

Disaster Recovery Plan (DRP): A short term plan to recover from a disruptive event.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

In terms of Business Continuity and Disaster Recovery Planning,

What is the definition of COOP?

A

Continuity of Operations Plan (COOP): A plan to maintain operations during a disaster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

In terms of Business Continuity and Disaster Recovery Planning,

What is the definition of Disaster?

A

Disaster: Any disruptive event that interrupts normal systems operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

In terms of Business Continuity and Disaster Recovery Planning,

What is the definition of the Mean Time Between Failures?

A

Mean Time Between Failures (MTBF): Quantifies how long a new or repaired system will run on average before failing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

In terms of Business Continuity and Disaster Recovery Planning,

What dos the acronym MTBF stand for?

A

Mean Time Between Failures (MTBF): Quantifies how long a new or repaired system will run on average before failing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

In terms of Business Continuity and Disaster Recovery Planning,

What dos the acronym MTTR stand for?

A

Mean Time To Repair (MTTR): Describes how long it will take to recover a failed system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In terms of Business Continuity and Disaster Recovery Planning,

What is the definition of Mean Time To Repair?

A

Mean Time To Repair (MTTR): Describes how long it will take to recover a failed system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

In terms of Disaster Types

What is the likelihood of a Natural Diasaster?

A

Low likelihood but depends on where you are.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

In terms of Disaster Types

Technical disastgers (Cyber warfare, espionage, crime, hactivism) are a subset of whct kind of Disaster?

A

Human Disaster

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

In terms of Disaster Types

What is the most common kind of Disaster?

A

Human Unintentional is the most common disaster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

In terms of Disaster Types

What is the most easily avoided kind of Disaster?

A

Human Unintentional is the most common disaster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

In terms of Disaster Types

What type of disaster are Personnel Shortages?

A

Human Disaster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

In terms of Disaster Types

What are the trhee kinds of Personnel Shortages?

A

1: Pandemic & Disease
2: Strikes
3: Availability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

In terms of Disaster Types

Is weather a natural disaster or an environmental disaster?

A

natural disaster

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

In terms of Disaster Types

What is an environmental disaster?

A

Environmental pertains to information systems: Power outages or hardware and/or software failures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

In terms of Disaster Types

What is the most common disaster in a datacenter?

A

Power is the most common that will affect a datacenter.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

In terms of the Disaster Recovery Process

What is the most most important issue?

A

Personnel safety is the most important issue

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is are the five steps to the Disaster Recovery Process

A

1: Response
2: Recovery Team Activation
3: Tactical Communication
4: Damage Assessment
5: Critical Asset recovery (Reconstitution)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

In terms of the Disaster Recovery Process

What is is th epurpose of the Response Phase?

A

Initial Damage Assessment; Speed is key

Are people safe?

Is it a disaster?

Do we need to engage the alternate processing center?

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

In terms of the Disaster Recovery Process

What are three considerations to Tactical Communication?

A

1: Quick and frequent updates about the situation
2: May have to be done out of band
3: May have to communicate to the public

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What are the six steps when Developing the BCP/ DRP

A

1: Project Initiation
2: Project Scope
3: Business Impact Analysis
4: Preventive Controls Identification
5: Recovery Strategy
6: Plan Design and Development

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

In terms of Developing the BCP/ DRP

What are the seven steps to Project Initiation?

A

1: Develop the contingency planning policy statement: provides authority to develop plan
2: Conduct Business Impact Analysis (BIA): ID critical IT systems
3: ID Preventative controls:
4: Develop recovery strategies
5: Develop IT Contingency plan
6: Plan testing, exercises and training
7: Plan maintenance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

In terms of Developing the BCP/ DRP

What are the five steps to Project Scope?

A

1: Define exactly which assets to protect
2: Define which emergency events the plan will address
3: Get C-Level approval
4: Determine objectives and deliverables in if-then format (If hurricane – enact Plan H)
5: Assess Critical State by creating a Critical State IT Asset list

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

In terms of Developing the BCP/ DRP

During Project Scope, What are three considerations when getting C-Level approval?

A

1: Support for initiating the plan
2: Final Approval
3: Demonstrate due care and due diligence or be held liable under law

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

In terms of Developing the BCP/ DRP

During Project Scope, when assessing the Critical State, does the PM us a qualitative approach or a a quantitative approach ?

A

The PM uses a qualitative approach when documenting assets; during the BIA later, he will use a the quantitative method.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

In terms of Developing the BCP/ DRP

What is a Business Impact Analysis?

A

A formal method for determining how a disruption to the IT systems will impact the organization with respect to the mission.

It is an analysis to identify and prioritize critical IT systems and components.

It aims to quantify the consequence of a disruption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

In terms of Developing the BCP/ DRP

What is the primary goal of a Business Impact Analysis?

A

Determine the Maximum Tolerable Downtime (MTD) for a specific asset

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

In terms of Developing the BCP/ DRP

What does the Maximum Tolerable Downtime (MTD) mean

A

MTD is the total time a system can be inoperable before an organization is severely impacted.

It is the max time it takes the reconstitution phase.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

In terms of Developing the BCP/ DRP

What does the acronym (MTD) stand for

A

Maximum Tolerable Downtime (MTD)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

In terms of Developing the BCP/ DRP

What are the two metrics that comprise the Maximum Tolerable Downtime (MTD) ?

A

1: Recovery Time Objective (RTO)
2: Work recovery Time (WRT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

In terms of Developing the BCP/ DRP

What are the three alternative names to Maximum Tolerable Downtime (MTD) ?

A

1: Maximum Allowable Downtime (MAD)
2: Maximum Tolerable Outage (MTO)
3: Maximum Acceptable Outage (MAO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

In terms of Developing the BCP/ DRP and determining the Maximum Tolerable Downtime (MTD)

What does the Recovery Time Objective (RTO) mean?

A

Recovery Time objective (RTO) is the maximum desired length of time allowed between a disaster and the resumption of normal operations.

The RTO defines the point in time after a disaster at which the consequences of the interruption become unacceptable.

MTD = RTO + WRT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

In terms of Developing the BCP/ DRP and determining the Maximum Tolerable Downtime (MTD)

What does the acronym (RTO) stand for?

A

Recovery Time objective (RTO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

In terms of Developing the BCP/ DRP and determining the Maximum Tolerable Downtime (MTD)

What does the acronym (WRT) stand for?

A

Work Recovery Time (WRT)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

In terms of Developing the BCP/ DRP and determining the Maximum Tolerable Downtime (MTD)

What does Work Recovery Time (WRT) mean?

A

The time it takes to get business processes up and running after the systems have been restored.

MTD = RTO + WRT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

In terms of Developing the BCP/ DRP and determining the Maximum Tolerable Downtime (MTD)

What is the general rule MTD time and revoery cost?

A

As a general rule, the shorter the MTD, the more expensive the recovery solution.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

In terms of conducting the Business Impact Analysis

What is the Reconstitution Phase?

A

Reconstitution Phase is the process of moving an organization from disaster recovery to business operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

In terms of conducting the Business Impact Analysis

What is a significant side benefit?

A

Side benefit: If there are inefficiencies in the business process, the BIA will identify them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

In terms of Developing the BCP/ DRP

What does the acronym BIA stand for?

A

Business Impact Analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

In terms of Business Impact Analysis

What are the six common metrics used

A

1: Recovery Point Objective (RPO)
2: Recovery Time Objective (RTO):
3: Work Recovery Time (WRT):
4: Mean Time Between Failures (MTBF)
5: Mean Time To Repair (MTTR):
6: Minimum Operating requirements (MOR):

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

In terms of Business Impact Analysis

What is the Recovery Point Objective (RPO)?

A

The amount of data loss or system inaccessibility (measured in time) that an organization can withstand.

Defined by specific actions like the point in time when users are allowed to deliver payroll checks again.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

In terms of Business Impact Analysis

What does the acronym (RPO) stand for?

A

Recovery Point Objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

In terms of Business Impact Analysis

What is the Mean Time Between Failures (MTBF)?

A

Mean Time Between Failures (MTBF): Quantifies how long a new or repaired system will run before failing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

In terms of Business Impact Analysis

What is Mean Time To Repair (MTTR)?

A

Mean Time To Repair (MTTR): Quantifies how long it will take to recover a failed system. It is a best estimate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

In terms of Business Impact Analysis

What are the Minimum Operating Requirements (MOR)?

A

Minimum Operating requirements (MOR): Describes the minimum environmental and connectivity requirements in order to operate computer equipment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
51
Q

In terms of Business Impact Analysis

What does the acronym (MOR) stand for?

A

Minimum Operating requirements (MOR): Describes the minimum environmental and connectivity requirements in order to operate computer equipment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
52
Q

In terms of Business Impact Analysis

Name the two processes that make up the BIA?

A

The BIA is comprised of two processes:

1: Identify Critical assets
2: Conduct a comprehensive risk assessment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
53
Q

In terms of Business Impact Analysis during the Recovery Strategy

Name the five kinds of alternate sites listed in order for cost to implement and degree of availability

A

1: No Plan
2: Cold Site: A datacenter with raised floor, and utilities. No equipment or data.
3: Warm Site: A datacenter with raised floor, utilities, fully configured computers but no data.
4: Hot Site: A datacenter with raised floor, utilities, fully configured computers and data. The idea is to switch over in a small amount of time.
5: Redundant Site: An exact production duplicate.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
54
Q

In terms of Business Impact Analysis during the Recovery Strategy

Are you restricted to use any specific kind of control?

A

No - Always use the three kinds of controls: technical, physical and administrative. Just because you are in t a tent after a hurricane does not obviate the need for physical security.

55
Q

In terms of Business Impact Analysis during the Recovery Strategy

What is Supply Chain Management?

A

Supply Chain Management: Manage supplies by considering local disasters that only affect your organization or regional disasters that affect all businesses in the area that will compete for resources.

56
Q

In terms of Business Impact Analysis during the Recovery Strategy

What is Telecommunication Management?

A

Telecommunication Management: Ensures the availability of electronics communications during a disaster.

57
Q

In terms of Business Impact Analysis during the Recovery Strategy

What is Utility Management?

A

Utility Management: addresses the availability of power, water, gas, erc during the disaster.

58
Q

In terms of Business Impact Analysis during the Recovery Strategy

What is a Reciprocal Agreement or Mutual Aid Agreement?

A

Reciprocal Agreement (Also called Mutual Aid Agreements): a bi-directional agreement between two organizations that agree to allow the other to move into their spaces during a disaster.

59
Q

In terms of Business Impact Analysis during the Recovery Strategy

What is a Mobile Site?

A

Mobile Site: Datacenters on wheels.

60
Q

In terms of Business Impact Analysis during the Recovery Strategy

What are Subscription Services?

A

Subscription Services: Outsource your BCP/ DRP to another company.

61
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase

What are the 7 Related Plans?

A

1: Continuity of Operations Plan (COOP):
2: Business Recovery Plan (BRP): .
3: Continuity of Support Plan
4: Cyber Incident Response Plan:
5: Occupant Emergency Plan (OEP):
6: Crisis Management Plan (CMP):
7: Crisis Communications Plan:

62
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase

What is Continuity of Operations Plan (COOP)?

A

Continuity of Operations Plan (COOP): Describes procedures required to maintain operations during a disaster to include transfer of personnel to alternate site and the operation of that site.

63
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase

What is the Business Recovery Plan (BRP):?

A

Business Recovery Plan (BRP): Also known as the Business Resumption Plan details the steps required to restore the business operation after the disaster. Picks up when the COOP is complete.

64
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase

What is the Continuity of Support Plan?

A

Continuity of Support Plan focuses narrowly on specific IT systems. Also called the IT Contingency Plan.

65
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase

What is the Cyber Incident Response Plan?

A

Cyber Incident Response Plan: Designed to respond to disruptive cyber events including network attacks, worms, viruses, etc.

66
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase

What is the Occupant Emergency Plan (OEP):?

A

Occupant Emergency Plan (OEP): response procedures for facility occupants in the even to f a situation posing a potential threat to health and safety of personnel. It is facilities focused and not business focused. Should include safety drills.

67
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase

What is the Crisis Management Plan (CMP)?

A

Crisis Management Plan (CMP): provide effective coordination between managers in the event of an emergency.

68
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase

What does the acronym COOP stand for?

A

Continuity of Operations Plan (COOP): Describes procedures required to maintain operations during a disaster to include transfer of personnel to alternate site and the operation of that site.

69
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase

What does the acronym BRP stand for?

A

Business Recovery Plan (BRP): Also known as the Business Resumption Plan details the steps required to restore the business operation after the disaster. Picks up when the COOP is complete.

70
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase

What idoes the acronym OEP stand for?

A

Occupant Emergency Plan (OEP): response procedures for facility occupants in the even to f a situation posing a potential threat to health and safety of personnel. It is facilities focused and not business focused. Should include safety drills.

71
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase

What does the acronym CMP stand for?

A

Crisis Management Plan (CMP): provide effective coordination between managers in the event of an emergency.

72
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase and part of the Crisis Management Plan (CMP)

What is the Crisis Communications Plan?

A

Crisis Communications Plan: The plan to communicate to the staff and public during a disaster.

73
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase and part of the Crisis Management Plan (CMP) and the Crisis Communications Plan

What is a Call Tree

A

Call Trees: used to quickly communicate news throughout an organization.

74
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase and part of the Crisis Management Plan (CMP) and the Crisis Communications Plan

What are two charateristice to an effective Call Tree

A

1: Most effective when there is two-way reporting (message down and verification up that all has received the info.
2: Must be drilled.

75
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase and part of the Crisis Management Plan (CMP) and the Crisis Communications Plan

What are is a Automated Call Trees

A

Call Trees Hosted by offsite third parties.

76
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase and part of the Crisis Management Plan (CMP)

What are is the Emergency Operations Center (EOC)

A

Emergency Operations Center (EOC): The command post

77
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase and part of the Crisis Management Plan (CMP)

What does the acronym EOC stand for?

A

Emergency Operations Center (EOC): The command post

78
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase and part of the Crisis Management Plan (CMP)

Where should Vital records be stored?

A

Vital records: Should be stored offsite.

Best practice is to have hard copies and electronic copies.

79
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase and part of the Crisis Management Plan (CMP)

What is the best practice dor storing Vital records?

A

Vital records: Should be stored offsite.

Best practice is to have hard copies and electronic copies.

80
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase and part of the Crisis Management Plan (CMP)

What is Executive Succession Planning?

A

Executive Succession Planning: Ensure that there is always an executive available to make a decision.

81
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase and part of the Crisis Management Plan (CMP)

What is a common mistake with Executive Succession Planning?

A

A common mistake is to have the entire executive team travel together.

82
Q

In terms of Business Impact Analysis during the Plan Design and Development Phase and part of the Crisis Management Plan (CMP)

What are two of the simplest executive powers that are vital during a crisis?

A

1: Sign checks
2: Procure money.

83
Q

In terms of Backups and Availability

Where do you store Critical backup media ?

A

Critical backup media must be stored offsite.

84
Q

In terms of Backups and Availability

What is an important design decision to consider whem storing Critical backup media ?

A

Situate the backup location so that an organization can efficiently access the media with the purpose of taking it to the primary or secondary recovery operation.

85
Q

In terms of Backups and Availability

What is an important design decision to consider when using backup software to store Critical backup media ?

A

Be sure to address software licensing issues

86
Q

In terms of Backups and Availability for COOP

What is one element that you should consider in regards to hardcopy data?

A

Hardcopy data: Consider operating only on hard copies

87
Q

In terms of Backups and Availability for COOP

What are the three types of Electronic Backup?

A

1: Full: Every piece of data is copied.
2: Incremental: Only changes since the last full or incremental backup.
3: Differential: Only changes since the last full;

88
Q

In terms of Backups and Availability

What is Electronic vaulting?

A

Electronic vaulting: Electronically transmitting data to a location for backup.

89
Q

In terms of Backups and Availability

What is Remote journaling?

A

A log of all database transactions to backup and restore a database.

Takes a snapshot of the data (checkpoint) at regular intervals.

Recover data to a checkpoint and then use the journal to restore the rest.

Saves the database checkpoints and journaling to an offsite location.

90
Q

In terms of Backups and Availability

What is Database Shadowing?

A

Uses two or more databases that are update simultaneously. The shadow can exist locally but it is best practice to host one shadow offsite.

Allows faster recover time compared to remote journaling.

91
Q

In terms of Backups and Availability

What is High Availability?

A

Requirements of zero downtime and MTD (Max Tolerable Downtime) of zero.

92
Q

In terms of Backups and Availability

What is the difference between an Active – Active Cluster and a Active – Passive Cluster?

A

Active – Active Cluster:

1: Multiple Systems all of which are online and actively processing traffic or data.
2: Commonly referred to as Load Balancing
3: Especially common with public facing systems like web front ends.

Active – Passive Cluster:

1: Devices that are already in place, configured, powered-on and ready to start processing if a failure occurs.
2: Any configuration change on the active system is automatically done on the passive system

Also referred to as a hot spare, standby, and failover cluster configuration.

93
Q

In terms of Backups and Availability

What is another name for an Active - Active Cluster?

A

Load Balancing

94
Q

In terms of Backups and Availability

What is Software Escrow?

A

Software Escrow: Neutral third party holds the source code in case the development company goes out of business.

95
Q

In terms of DRP Testing, Training and Awareness

What are the five types of Testing?

A

1: Checklist (Consistency) Testing:
2: Structured Walk-thru Tabletop:
3: Simulation Test / Walkthrough Drill (Not to be confused with walkthrough tabletop) :
4: Parallel Processing:
5: Partial and Complete Business Interruption:

96
Q

In terms of DRP Testing, Training and Awareness

What is the Checklist Test?

A

Lists all necessary components for a successful recovery.

Often performed concurrently with a structured walkthrough or tabletop exercise.

Focused on ensuring that the organization has, or can acquire in a timely fashion, sufficient resources to recover.

97
Q

In terms of DRP Testing, Training and Awareness

What is the Structured Walk-thru Tabletop Test?

A

Allow all personnel knowledgeable about the systems to thoroughly review the approach.

98
Q

In terms of DRP Testing, Training and Awareness

What is the Simulation Test / Walkthrough Drill Test?

A

Goes beyond just talking and has teams execute recovery processes by responding to a simulated disaster.

Tactical goal: determine if the team can recover the systems impacted by the simulated disaster.

Strategic goal: Prepare the team to recover from any disaster.

99
Q

In terms of DRP Testing, Training and Awareness

What is the difference between the Simulation Test / Walkthrough Drill Test and the Structured Walk-thru Tabletop Test

A

Structured Walk-thru Tabletop: Allow all personnel knowledgeable about the systems to thoroughly review the approach.

Simulation Test / Walkthrough Drill: Goes beyond just talking and has teams execute recovery processes by responding to a simulated disaster.

100
Q

In terms of DRP Testing, Training and Awareness

What is the Parallel Processing: Test?

A

Recover critical assets at a alternate site.

Organizations that are highly dependent on mainframes and midrange systems will employ these tests.

101
Q

In terms of DRP Testing, Training and Awareness

What is the Partial and Complete Business Interruption Test?

A

Partial and Complete Business Interruption

102
Q

In terms of DRP Testing, Training and Awareness

What six compnents must the Training Plan address

A

1: There is an element of training when conducting tests
2: First Aid / CPR
3: Starting Emergency Power:
4: Calling Tree Test
5: Awareness
6: Must address events that pose a threat to human safety.

103
Q

In terms of Continued BRP /DCP Maintenance

What is Change Management?

A

Process designed to ensure that security is not affected as systems are introduced, changed, and updated.

Includes tracking and documenting all planned changes.

104
Q

In terms of Continued BRP /DCP Maintenance

What is the key design characteristic of Change Management?

A

All changes must be auditable.

105
Q

In terms of Continued BRP /DCP Maintenance

What group focuses on Change Management for an organization?

A

The Change Control Board Manages this process. The BCP Team should be a member of the Board.

106
Q

In terms of Organization BCP / DRP Planning Process

Who develops the POlicy Statement?

A

1: C-Level Managers Develop the Policy Statement

107
Q

In terms of Organization BCP / DRP Planning Process

Who Conducts the BIA (Business Impact Assessment)?

A

BCP/DRP Stakeholders and Project PM Conduct the BIA

108
Q

In terms of Organization BCP / DRP Planning Process

Who identifies preventative controls?

A

Stakeholders and PM identify the preventative controls

109
Q

In terms of Organization BCP / DRP Planning Process

Who develops recovery strategies?

A

C-Level managers develop recovery strategies.

110
Q

In terms of Organization BCP / DRP Planning Process

What are 10 common Mistakes?

A

1: lack of Management Support
2: Lack of BU involvement
3: Lack of prioritization of critical staff
4: Improper (often too narrow) scope.
5: Inadequate telecommunications management
6: Inadequate supply chain mgt
7: Inadequate crisis management plan
8: Lack of Testing
9: Lack of training and awareness
10: Failure to maintain

111
Q

In terms of Specific BRP / DCP Frameworks

Name four common frameworks

A

1: NIST SP 800-34
2: ISO/IEC-27031
3: BS-2599
4: BCI (Business Continuity Institute) six steps for Business Continuity Management

112
Q

In terms of Specific BRP / DCP Frameworks

What are the two key characteristic of the NIST SP 800-34 framework?

A

1: High Quality
2: In the public domain.

113
Q

In terms of Specific BRP / DCP Frameworks

In the ISO/IEC-27031 framework, what does the acronym ICT mean?

A

ICT: Information and Communication Technology

114
Q

In terms of Specific BRP / DCP Frameworks

In the ISO/IEC-27031 framework, what does the acronym ISMS mean?

A

ISMS: Information Security Management Systems

115
Q

In terms of Specific BRP / DCP Frameworks

Who wrote the BS-2599 Framework?

A

British Standards Institute (BSI)

116
Q

In terms of Specific BRP / DCP Frameworks

What are the two parts to the BS-2599 Framework?

A

Part 1: Guidance on best practices for continuity management

Part 2: A Specification for a Business Continuity Management System (BCMS)

117
Q

In terms of Specific BRP / DCP Frameworks

In the BS-2599 Framework, what does the acronym BCMS mean?

A

Business Continuity Management System (BCMS)

118
Q

In terms of Specific BRP / DCP Frameworks

In the BCI (Business Continuity Institute) six steps for Business Continuity Management, what are the six steps?

A

1: Policy and Program Mgt
2: Understanding the Organization
3: Determining BCM strategy
4: Developing and Implementing BCM response
5: Exercising, Maintaining and reviewing BCM response
6: Embedding BCm in Culture

119
Q

In terms of Specific BRP / DCP Frameworks

In the BCI Six Steps for Business Continuity Management, what does the acronym BCO stand for?

A

BCI (Business Continuity Institute)

120
Q

1: Maximum Tolerable Downtime (MTD) is also known as what?

A: Maximum Allowable Downtime (MAD)
B: Mean Time Between Failure (MTBF)
C: Mean Time To Repair (MTTR)
D: Minimum Operating Requirements (MOR)

A

A: Maximum Allowable Downtime (MAD)

121
Q

2: What is the Primary goal of DRP?

A: Integrity of Data
B: Preservation of Business Capital
C: Restoration of Business processes.
D: Safety of Personnel

A

D: Safety of Personnel

122
Q

3: What business process can be used to determine the outer band of Max Tolerable Downtime?

A: Accounts receivable
B: Invoicing
C: Payroll
D: Shipment of Goods

A

C: Payroll

123
Q

4: Your Max Tolerable Downtime is 48 Hours. What is the most cost effective alternate site choice.

A: Cold
B: Hot
C: redundant
D: Warm

A

D: Warm

124
Q

5: A Structured Walkthrough test is also known as what kind of test

A: Checklist
B: Simulation
C: Tabletop Exercise
D: walkthrough Drill

A

C: Tabletop Exercise

125
Q

6: Which plan provides the response procedures for occupants of a facility in the event a situation poses a threat to the health and safety of personnel?

A: BRP (Business recovery Plan)
B: COOP (Continuity of Operation Plan)
C: CMP (Crisis Management Plan)
D: OEP (Occupant Emergency Plan)

A

D: OEP (Occupant Emergency Plan)

126
Q

7: Which type of backup requires a maximum of two tapes to perform restoration.

A: Differential Backup
B: Electronic Vaulting
C: Full backup
D: Incremental Backup

A

A: Differential Backup

127
Q

8: What statement regarding the Business Continuity Plan is true?

A: BCP and DRP are separate, equal plans
B: BCP is an overarching umbrella that includes other focused plans such as DRP
C: DRP is an overarching umbrella that includes other focused plans such as BCP
D: COOP is an overarching umbrella that includes other focused plans such as BCP

A

B: BCP is an overarching umbrella that includes other focused plans such as DRP

128
Q

9: Which High Availabilty solution involves multiple systems which are online and actively processing traffic and data

A: Active – Active cluster
B: Active-Passive Cluster
C: database Shadowing
D: remote Journaling

A

A: Active – Active cluster

129
Q

10: What plan is designed to promote effective coordination among the managers of the organization in the event of an emergency or disruptive event?

A: Call tree
B: Continuity of Support Plan
C: Crisis management Plan
D: Crisis Communications Plan

A

C: Crisis management Plan

130
Q

11: Which plan details the steps required to restore normal business operations after recovering from a disruptive event?

A: Business Continuity Plan (BCP)
B: Business Resumption Planning (BRP)
C: Continuity of Operations Plan (COOP)
D: occupant Emergency Plan (OEP)

A

B: Business Resumption Planning (BRP)

131
Q

12: What metric describes how long it will take to recover a failed system?

A: Minimum Operating Requirements (MOR)
B: mean Time Between Failures (MTBF)
C: the Mean Time to repair (MTTR)
D: recovery Point Objective (RPO)

A

C: the Mean Time to repair (MTTR)

132
Q

13: What metric describes the moment in time in which data must be recovered and made available to users in order to resume business operations

A: Mean Time Between Failures (MTBF)
B: the Mean Time to repair (MTTR)
C: Recovery Point Objective (RPO)
D: Recovery Time Objective (RTO)

A

C: Recovery Point Objective (RPO)

133
Q

15: Which draft business continuity guideline ensures business continuity of the Information Communications Technology (ICT) as part of the organization’s Information Security Management Systems (ISMS)?

A: BCI
B: BS-7799
C: ISO/IEC-27031
D: NIST 800-34

A

C: ISO/IEC-27031