Domain 2 Flashcards

1
Q

What is Business Continuity Planning (BCP)?

A

Set of controls designed to keep a business running in the face of adversity, whether natural or man-made

  • Process of creating long-term strategic business plans, policies, and procedures for continued operations after a disruptive event
  • Lists range of disaster scenarios and the steps the organization must take in any particular scenario to return operations

Also known as Continuity of Operations Planning (COOP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does defining the BCP scope involve?

A

Determining what business activities the plan will cover, what systems will be included, and what type of controls will be considered.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Business Impact Analysis?

A

Impact assessment that begins by identifying the organization’s mission-essential functions and traces those backwards to identify the critical IT systems that support those processes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How does a Cloud-Centric Environment affect BCP?

A

BCP becomes a collaboration between cloud service provider (CSP) and the customer.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the purpose of redundancy in BCP?

A

Protects against the failure of a single component.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is Single Point of Failure (SPOF) Analysis?

A

Identifies and removes SPOFs until the cost of addressing risks outweighs the benefits.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are some IT Contingency Scenarios?

A
  • Sudden bankruptcy of a key vendor
  • Insufficient storage or compute capacity
  • Failure of utility service
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is High Availability (HA)?

A

Uses multiple systems to protect against service failure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does Fault Tolerance do?

A

Makes a single system resilient against technical failures.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is Load Balancing?

A

Uses multiple systems to spread demands across systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are common points of failure in a system?

A
  • Power supply
  • Storage media
  • Networking components
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What are Power Supplies known for?

A

Contain moving parts, have high failure rates, can be redundant, and may use multiple power sources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the function of Uninterruptible Power Supplies (UPS)?

A

Supply battery power to devices during brief disruptions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What do Power Distribution Units (PDU) do?

A

Manage the power within a rack, ensuring power delivered to devices is clean and managed.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a Redundant Array of Inexpensive Disks (RAID)?

A

Technology to protect against failure of a single storage device.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the two types of RAID?

A
  • Mirroring
  • Striping
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is Disk Mirroring?

A

RAID level 1 where a server contains two disks with identical contents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is Disk Striping with parity?

A

RAID Level 5 that uses 3 or more disks to store data and parity information.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is NIC teaming?

A

Using two or more Network Interface Cards (NIC) for redundancy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is Network Redundancy?

A

Involves multiple ISPs, NIC teaming, and multipath networking.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is Disaster Recovery?

A

Subset of business continuity activities designed to restore a business to normal operations as quickly as possible following a disruption.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

What is a Disaster Recovery Plan (DRP)?

A

Immediate measures that get operations working again temporarily.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

What is the purpose of Initial Response in disaster recovery?

A

Designed to contain the damage to the organization and recover whatever capacity may be immediately restored.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

What is essential for Communication during a disaster recovery?

A

Must have a secure, reliable means to communicate with each other and the organization’s leadership.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

What is involved in Assessment during disaster recovery?

A

To triage the damage to the organization and implement functional recovery plans.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

What does Recovery Time Objective (RTO) refer to?

A

Targeted amount of time that it will take to restore a service to operation following a disruption.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

What does Recovery Point Objective (RPO) indicate?

A

Maximum time period from which data may be lost as a result of a disaster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

What does Recovery Service Level (RSL) measure?

A

Percentage of a service that must be available during a disaster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

What is the purpose of Training and Awareness in disaster recovery?

A

All personnel involved should receive periodic training about their role in the plan.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

What are the types of Backup Media?

A
  • Tape Backups
  • Disk Backups
  • Cloud Backups
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

What are Tape Backups known for?

A

Linear Tape-Open (LTO) commonly used, difficult to manage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

What are Disk Backups?

A

Write data from primary disk to special disks set aside for backup purposes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

What are Cloud Backups?

A

Writing backups directly to storage provided by cloud computing vendors.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

What are the types of Backup?

A
  • Full
  • Differential
  • Incremental
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

What does a Full Backup include?

A

Includes everything on the media being backed up.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

What is a Differential Backup?

A

Creates a copy of only the data that has changed since the last full backup.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

What is an Incremental Backup?

A

Includes only those files that have changed since the most recent full or incremental backup.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

What are Disaster Recovery Sites?

A

Alternate processing facilities designed for shifting computer functions from primary data center.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

What are Hot Sites?

A

Fully operational data centers that have all equipment and data required to handle operations ready to run.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

What are Cold Sites?

A

Used to restore operations eventually but require significant investment of time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

What are Warm Sites?

A

Have hardware and software but are not kept running in a parallel fashion.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

What is Site Resiliency?

A

Storing backups in a secure facility that’s geographically distant from the primary facility.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

What is the goal of a Disaster Recovery Test?

A

To validate that the plan functions correctly and identify necessary updates.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

What are the 5 major types of disaster recovery tests?

A
  • Read-throughs
  • Walk-throughs
  • Simulations
  • Parallel tests
  • Full interruption tests
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

What are Read-Throughs in disaster recovery testing?

A

Simplest form of test involving a checklist review.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

What are Walk-throughs in disaster recovery testing?

A

Involves getting everyone together to review the plan.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

What are Simulations in disaster recovery testing?

A

Involves the disaster recovery team discussing responses to a specific scenario.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

What are Parallel tests in disaster recovery testing?

A

Activates the DR plan in response to a simulated disaster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

What are Full interruption tests in disaster recovery?

A

Simulates disaster by shutting down the primary operating environment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
50
Q

What are the phases of Incident Response according to NIST SP 800-61?

A
  • Preparation
  • Detection and Analysis
  • Containment, Eradication and Recovery
  • Post-Incident Activity
51
Q

What does Preparation involve in Incident Response?

A

Activities used to put together an incident response plan and team.

52
Q

What is involved in Detection and Analysis in Incident Response?

A

Identifies that an incident is taking place and determines its impact.

53
Q

What is the goal of Containment, Eradication and Recovery in Incident Response?

A

Limits the damage caused by an incident and restores normal operations.

54
Q

What occurs during Post-Incident Activity?

A

Analyzes the response process and identifies lessons learned.

55
Q

What are the elements of an Incident Response Plan?

A
  • Statement of purpose
  • Clear strategies and goals
  • Approach to incident response
  • Communication within the team
  • Approval of Senior Management
56
Q

Who typically composes an Incident Response Team?

A
  • Management
  • Information Security Personnel
  • Physical Security Team members
  • Technical subject matter experts
  • Legal counsel
  • Public relations and marketing staff
  • Human resources team members
57
Q

What is the importance of Training and Testing in Incident Response?

A

Conduct regular training and testing to ensure readiness.

58
Q

What does the Incident Communication Plan cover?

A

Covers both internal and external communications.

59
Q

What is involved in Internal Communications during an incident?

A

Incident notification and escalation procedures.

60
Q

What is crucial about External Communication during an incident?

A

Be aware of what’s being communicated outside to protect investigation integrity.

61
Q

What is Secure Communication?

A

Established before an incident to share information confidentially.

62
Q

What are some information sources for identifying and analyzing security incidents?

A
  • Intrusion Detection and Prevention Systems
  • Firewalls
  • Authentication systems
  • System integrity monitors
  • Vulnerability scanners
  • System event logs
  • NetFlow connection records
  • Antimalware packages
63
Q

What is Security Information and Event Management (SIEM)?

A

Centralized log repository and analysis solutions that detect possible incidents.

64
Q

Related Plans describes what?

A

Our BCP being the overarching plan also contains our other plans

65
Q

Continuity of Operations Plan (COOP) is what?

A

How we keep operating in a disaster

66
Q

Crisis Communications Plan is what?

A

How we communicate internally and externally during a disaster
Subplan of the CMP.

67
Q

Cyber Incident Response Plan

A

How we can respond in cyber events

68
Q

Occupant Emergency Plan (OEP)

A

How do we protect our facilities, our staff and environment in a disaster event

69
Q

Business recovery Plan (BRP)

A

Lists the steps we need to take to restore normal business operations after recovering from a disruptive event

70
Q

Continuity of Support Plan

A

Focuses narrowly on support of specific IT systems and applications

71
Q

Crisis Management Plan (CMP)

A

Gives us effective coordination among the management of the organization in the event of an emergency or disruptive event

72
Q

NIST 800-34: Framework for building our BCP/DRP

A

Project initiation
Scope the project
Business Impact analysis
Identify preventative Controls

73
Q

ISO 22301

A

Business Continuity Management Systems
Supported by ISO 27031: Advise on how to work with business continuity management

74
Q

Business Continuity Institute

A

6-step process called Good Practice Guidelines -GPG, focuses on Business continuity

74
Q

Project

A

Clearly defined start and end
Moving forward

75
Q

Operations

A

Conducting the same tasks over and over again to keep things functional
Keeps status quo

76
Q

Steps as a framework for building BCP/DRP from the Older versions of NIST 800-34

A

Projection Initiation
Scope the Project
Business Impact Analysis
Identify Preventative Controls
Recovery Strategies
Plan Desin and Development
Implementation, Training, and Testing
BCP/DRP Maintenance

77
Q

3 Disaster Categories

A

Natural
Human
Environmental (Not to be confused with natural disasters)

78
Q

Natural Disaster

A

Anything caused by nature

79
Q

Human Disaster

A

Anything caused by humans

80
Q

Environmental Disaster

A

Anything in our environment

81
Q

Plans need to be continually updated. How?

A

Plans should be reviewed and updated at least every 12 months
Changed major components of our systems
We had a disaster, and we had a lot of gaps in our plans
Significant part of senior leadership has changed

82
Q

DRP should answer what 3 questions?

A

What is the objective and purpose?
Who will be the people or teams who will be responsible in case any disruptions happen?
What will these people do (our procedures) when the disaster hits?

83
Q

What is the lifecycle of the DRP?

A

Mitigation
Preparation
Response
Recovery

84
Q

Mitigation is what in the DRP lifecycle?

A

Reduces the impact, and likeliness of a disaster

85
Q

Preparation is what in the DRP lifecycle?

A

Builds programs, procedures and tools for response

86
Q

What are some simulated tests within the DRP?

A

DRP Review: Team members who are part of the DRP team review the plan quickly looking for glaring omissions, gaps, or missing sections in the plan

Read-Through (Checklist): Managers and functional areas go through the plan and check a list of components needed for in the recovery process.

Walk/Talk-through (Tabletop or structured Walkthrough): Group of managers and critical personnel sit down and talk through the recovery process

Simulation Test (Walkthrough Drill): Team simulates a disaster and teams respond with their pieces from the DRP

87
Q

Response is what in the DRP lifecycle?

A

How we react in a disaster, following the procedures

88
Q

Recovery is what in the DRP lifecycle?

A

Reestablish basic functionality and get back to full production

89
Q

MTD is what?

A

Maximum Tolerable Downtime
The time to rebuild the system and configure it for reinsertion into production must be less than or equal to our MTD

MTD >= RTO + WRT

90
Q

WRT is what?

A

Work Recovery Time (software): how much time is required to configure a recovered system.

91
Q

MTBF is what?

A

Mean Time Between Failure: How long a new or repaired system to fail

92
Q

MTTR is what?

A

How long it will take to recover a failed system

93
Q

Minimum Operating Requirements (MOR) is what?

A

Minimum environmental and connectivity requirements for our critical systems to function.

94
Q

Redundant site is what ?

A

Completed identical site to our production, receives a real time copy of our data.

95
Q

A Reciprocal Agreement Site is what?

A

Organization has a contract with another organization that they will give space in their data center in a disaster event and vice versa.

96
Q

Subscription/Cloud Site

A

Pay someone else to have a minimal or full replica of the production environment up and running within a certain number of hours (SLA)

97
Q

Mobile Site

A

Data center on wheels, often a container or trailer that can be moved wherever by a truck.

98
Q

What happens in the Lessons Learned phase?

A

Often overlooked. We removed the problem, we have implemented new controls and safeguards.

99
Q

We only use our BCP/DRP when?

A

When other countermeasures have failed

100
Q

What are some common pitfalls we want to avoid when making and maintaining the BCP/DRP?

A

Lack of senior leadership support

Too Narrow Scope

Not keeping the BCP/DRP plans up to date

101
Q

Incident Management involves what?

A

Monitoring and detection of security events on our systems, and how we react in those events

102
Q

What is an event in relation to Incident Management?

A

An observable change in state

103
Q

What is an alert in relation to Incident Management?

A

Triggers warning if certain event happens

104
Q

What is an Incident in relation to Incident Management?

A

Multiple adverse events happening on our systems or networks

105
Q

What is a problem in relation to Incident Management?

A

Incidence with an unknown cause.

106
Q

What is inconvenience in relation to Incident Management?

A

(Non-disasters): Non-disruptive failures

107
Q

What is an emergency in relation to Incident management?

A

Crisis: Urgent

108
Q

What is a disaster in relation to Incident Managemnt?

A

Entire facility is unusable for 24 hours or longer

109
Q

What is a catastrophe in relation to Incident Management?

A

Facility is destroyed

110
Q

What is NIST 800-61?

A

Incident Response Life Cycle

111
Q

What is the CIRT?

A

Computer/Cyber Incident Response Team.

Consists of:
Senior management
Incident manager
Technical leads and team
IT Security
PR, HR, and legal
Auditors IT/financial

112
Q

Provide the incident Life Cycle (ILC)

A

Preparation
Detection
Response
Mitigation
Reporting
Recovery
Remediation
Lessons Learned

113
Q

ILC - Preparation

A

All steps taken to prepare for incidences

114
Q

ILC - Detection

A

Events analyzed to determine if they might be a security incident

115
Q

ILC - Response

A

IRT begins interacting with affected systems and attempts to keep further damage from occurring as a result of the incident

116
Q

ILC - Mitigation

A

Understanding the cause of the incident so that the system can be reliably cleaned and resorted to operational status later in the recovery phase

117
Q

ILC - Reporting

A

Report throughout the process beginning with the detection.

118
Q

ILC - Recovery

A

Carefully restore the system or systems to operational status

119
Q

ILC - Remediation

A

Happens during the mitigation phase

120
Q

ILC - Lessons Learned

A

Often overlooked. Removed problem, implemented new controls and safeguards

121
Q

What is the Root-Cause Analysis in relation to Incident Management?

A

Attempt to determine the underlying weakness or vulnerability that allowed the incident to happen