Domain 2 - BC / DR and Incident Response Flashcards

1
Q

What is the Continuity of Operations Plan (COOP)?

A

Details how we keep operating in a disaster

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the crisis communications plan?

A

How we communicate internally and externally

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is a cyber incident response plan?

A

How we respond in cyber events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the Occupant Emergency Plan (OEP)?

A

How we protect our facilities, our staff, and the environment in a disaster event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the Business Recovery Plan?

A

It lists the steps we need to take in order to restore normal business operations after a disruptive event.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the continuity of Support Plan?

A

It narrowly focuses on support of specific IT systems and applications.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the Crisis Management Plan (CMP)?

A

It provides effective coordination of management of the organization in an emergency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the three disaster categories?

A

Natural

Human

Environmental (Not nature)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Is the Disaster Recovery Plan a sub-plan of the Business Continuity Plan?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the disaster recovery plan lifecycle?

A

Mitigation

Preparation

Response

Recovery

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the definition of RPO?

A

The acceptable amount of data that cannot be recovered.

Think restore point intervals.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the definition for Maximum Tolerable Downtime (MTD) in Disaster Recovery?

A

The maximum amount of downtime for any given system.

You want to be certain you can rebuild the system before the MTD limit is reached.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is Work Recovery Time (WRT) in Disaster Recovery?

A

It is the time required to configure the software for a recovered system.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the Minimum Operating Requirements in Disaster Recovery?

A

It is the bare minimum specifications that a system can run on.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is a redundant site in Disaster Recovery?

A

It is an identical site to production and receives a real-time copy of the data.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a hot site in Disaster Recovery?

A

Similar to a redundant site, but it only houses critical applications and systems. Manual failover

17
Q

What is a warm site in Disaster Recovery?

A

Similar to a hot site, but the data is not real-time or even near real-time. Takes between 4 - 24 hours to restore. Manual failover

18
Q

What is a cold site in Disaster Recovery?

A

A smaller, but full data center with redundancies. Restoration can take weeks.

19
Q

Incident management is what kind of function?

A

An Administrative function

20
Q

What is an event in incident management?

A

It is an observable change in state

21
Q

Wha is a problem in incident management?

A

An incidence with an unknown cause.

22
Q

What is an inconvenience in incident management?

A

A non-disruptive failure

23
Q

What is a disaster in incident management?

A

Our entire facility is unusable for 24 hours

24
Q

What is a catastrophe in incident management?

A

Our entire facility is destroyed.

25
Q

Should senior management be on the cyber incident response team?

A

Yes

26
Q

What are the eight steps of incident management?

A

Preparation

Detection

Response

Mitigation

Reporting

Recovery

Remediation

Lessons Learned

27
Q

In what phase of the incident management plan do users begin interacting with affected systems?

A

The Response phase

28
Q

What is the mitigation phase of the incident management plan?

A

It’s when the cause of the incident is identified and now steps can be taken to bring the system back to operational status

29
Q
A