Disaster Recovery and Incident Response (Ch. 12) Flashcards
A physical site that can be used if the main site is inaccessible (destroyed) but that lacks all of the resources necessary to enable an organization to use it immediately.
cold site
A type of backup that includes only new files or files that have changed since the last full backup, but does not clear the archive bit
differential backup
The act of recovering data following a disaster in which it has been destroyed.
disaster recovery
A plan outlining the procedure by which data is recovered after a disaster.
disaster-recovery plan
The process of reconstructing a system or switching over to other systems when a failure is detected.
failover
A flagged event that isn’t really a notable incident and has been falsely triggered.
false positive
In terms of security, the act of looking at all the data at your disposal to try to figure out who gained unauthorized access and the extent of that access.
forensics
A backup that copies all data to the archive medium.
full backup
A location that can provide operations within hours of a failure of the main site.
hot site
A type of backup that includes only new files or files that have changed since the last full backup and then clears the archive bit upon completion.
incremental backup
The act of entering a system without authorization to do so.
intrusion
Any set of tools that can identify an attack using defined rules or logic.
intrusion detection system (IDS)
Any set of tools that identify and then actively respond to attacks based on defined rules, and can be network or host based.
intrusion prevention system (IPS)
Penetration and other testing that involves trying to break into the network.
intrusive tests
Penetration/vulnerability testing that takes a passive approach rather than actually trying to break into the network.
nonintrusive tests