Domain 2 Flashcards

1
Q

What is Business Continuity (BC)?

A

The ability of an organization to maintain essential functions during and after a disaster.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is Disaster Recovery (DR)?

A

The process of restoring IT systems and operations after a disruption.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is Incident Response?

A

A structured approach to handling and managing a cybersecurity incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a Business Continuity Plan (BCP)?

A

A documented plan that outlines how an organization will continue operating during an unplanned disruption.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is a Disaster Recovery Plan (DRP)?

A

A documented, structured approach with instructions for responding to unplanned incidents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is a Critical Business Function?

A

A business activity that is essential to the survival and operations of an organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is a Recovery Time Objective (RTO)?

A

The maximum acceptable amount of time to restore a function after a disruption.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is a Recovery Point Objective (RPO)?

A

The maximum acceptable amount of data loss measured in time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is a Tabletop Exercise?

A

A discussion-based exercise where participants talk through their roles during an incident without actual execution.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is an After Action Report (AAR)?

A

A document that reviews actions taken during an incident to identify strengths and areas for improvement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a Hot Site?

A

A fully equipped alternate location where operations can be moved immediately after a disruption.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a Warm Site?

A

An alternate location that is partially equipped and requires additional setup before operations can resume.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is a Cold Site?

A

An alternate location that has infrastructure but no active equipment or data, requiring setup before use.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is an Incident Response Plan (IRP)?

A

A formal document detailing how an organization detects, responds to, and recovers from incidents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is an Incident Response Team (IRT)?

A

A group of individuals assigned to prepare for and respond to incidents.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is Business Impact Analysis (BIA)?

A

A process that identifies critical functions and evaluates the impact of a disruption.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is Contingency Planning?

A

Preparations made in advance to deal with potential future incidents or disasters.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What is Crisis Communication?

A

The process of informing stakeholders during and after a disruptive incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is a Service-Level Agreement (SLA)?

A

A contract that defines the level of service expected from a service provider.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

What is Chain of Custody?

A

The documentation and handling process that maintains the integrity of evidence.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

What is the main goal of Business Continuity Planning?

A

To ensure critical operations continue during and after a disruption.

22
Q

What is the first step in creating a Business Continuity Plan?

A

Conduct a Business Impact Analysis (BIA).

23
Q

Who typically leads the Incident Response Team (IRT)?

A

The Incident Response Manager or Coordinator.

24
Q

What is the goal of an Incident Response Plan?

A

To minimize the impact of security incidents and restore normal operations quickly.

25
Q

What does an After Action Report (AAR) help improve?

A

Future incident response effectiveness.

26
Q

What type of alternate site requires the most setup time?

A

Cold site.

27
Q

What is the main difference between a hot site and a cold site?

A

A hot site is fully operational, while a cold site requires setup.

28
Q

What is a communication plan in business continuity?

A

A strategy for notifying stakeholders during an incident.

29
Q

What are the typical phases of the Incident Response process?

A

Preparation, Detection and Analysis, Containment, Eradication, Recovery, and Lessons Learned.

30
Q

What is the purpose of containment during an incident?

A

To limit the damage caused by an incident and prevent its spread.

31
Q

Why is Business Impact Analysis (BIA) critical to BCP and DRP?

A

It identifies critical functions and prioritizes recovery efforts.

32
Q

What is the primary goal of Disaster Recovery?

A

To restore IT services and operations as quickly as possible after a disruption.

33
Q

How does an SLA relate to disaster recovery?

A

It defines the service levels that must be maintained or recovered after an incident.

34
Q

What is an example of a tabletop exercise in incident response?

A

A scenario where participants walk through a simulated cyberattack without actual system disruption.

35
Q

What should be included in an Incident Response Plan?

A

Roles and responsibilities, communication procedures, escalation paths, and technical steps.

36
Q

What are the benefits of a warm site over a cold site?

A

Faster recovery times because systems and data are partially pre-configured.

37
Q

Why is maintaining chain of custody important during an incident investigation?

A

To ensure evidence is legally admissible and credible.

38
Q

What is a crisis communication team responsible for?

A

Managing information released to internal and external stakeholders during an incident.

39
Q

How is a BCP different from an IRP?

A

BCP focuses on maintaining operations; IRP focuses on responding to security incidents.

40
Q

Why are tabletop exercises important?

A

They help test and refine plans without disrupting actual operations.

41
Q

Describe the steps to create a Business Continuity Plan.

A

Conduct BIA, identify recovery strategies, develop plans, train employees, test and maintain plans.

42
Q

Explain how RTO and RPO affect disaster recovery planning.

A

They define recovery goals for downtime and data loss, influencing backup strategies and resources.

43
Q

Give an example of containment during a cyber incident.

A

Disconnecting an infected server from the network to stop malware spread.

44
Q

How can poor crisis communication worsen a disaster?

A

It can lead to misinformation, panic, legal issues, and reputational damage.

45
Q

Why should disaster recovery sites be geographically separated?

A

To reduce the risk that the same event (e.g., earthquake) affects both primary and backup locations.

46
Q

What could be a drawback of using a cold site for disaster recovery?

A

Longer recovery times due to the need to install and configure systems and data.

47
Q

How does a Business Impact Analysis support risk management decisions?

A

By identifying the most critical operations and systems to prioritize protection and recovery efforts.

48
Q

What are two important outputs of a BIA?

A

Critical business processes and the associated RTO and RPO for each.

49
Q

How do legal and regulatory requirements impact Incident Response?

A

They may dictate how incidents are handled, reported, and documented.

50
Q

Why must the Incident Response Plan be tested regularly?

A

To ensure the team is prepared and the plan is effective in real incidents.