Domain 3.2 Flashcards

1
Q

What type of plan/procedure details how to make a change?

A

Change Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

true or false: change management is easy to implement

A

False:

It is easily over looked and is considered very challenging.

Essential to have clear policy surrounding add/change/remove

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the NIST SP800-61

A

Provides a handling guide for security incidents

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the steps included in an incident response lifecycle

A

-Preparation

-Detection & Analysis

-Containment, Eradication, and recovery

  • post incident activity
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are some disasters that could occur

A

Human created disasters

Natural disasters

technology or system failures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are some components of a comprehensive recovery plan

A
  • Recovery location
  • Data recovery method
  • Application restoration
  • IT team and employee availability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Describe COOP or BCP

A

Continuity of operations Planning involves the process of creating alternatives methods of operations that allow the company to continue business in the event of a total system failure.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Give some examples of a COOP

A
  • Manual transactions
  • Paper receipts
  • phone calls for approval rather than email
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what are some concerns when it comes to system lifecycles

A

Disposal of systems and their information could be unlawful.

You may need to store devices or data for particular amounts of time, or maintain data.

shred sensitive data, never throw it in the trash

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a SOP

A

Standard operating procedure

Processes and procedures of a business.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is an important component to SOPs

A

They must be documented and written down.

There should be SOPs for the notification of downtime, and facilities issues

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Name two common agreements

A

SLA -
Minimum level of service to be provided
uptime, response time

MOU -
Both sides agree on the contents of the memo.
Usually include statement of confidentiality

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are the two types of NDAs

A

Unilateral (single parties) or Bilateral (Both parties)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Describe some qualities of a good password policy

A

High password Entropy ( Very difficult to guess)

  • No single words

Mix upper and lower case with special characters

Passwords at least 8 characters

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What is an AUP

A

Acceptable use policy

Detailed document that covers many topics, internet, telephones, PCs

Used by company to limit legal liability

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is a remote access policy

A

Policy for everyone that specifies technical requirements such as:

-Encrypted connection

-Confidential credentials

-hardware/software requirements

17
Q

What is the use of a floor plan

A

Used for network documentation to overlay the wired and wireless network with the existing architectural layout.

-Wires in celling

  • AP locations
18
Q

Where does a floor plan come in handy

A

Great for matching end-user desks with a patch on the panel in the IDF/MDF

Also great for planning network projects

19
Q

What is a physical network map

A

A map that follows physical wire and devices. This can include physical rack locations as well.

20
Q

What is a distribution frame

A

Often a room or a laocation which serves a a major part of the network

Typically mounted on wall or flat surface and contains punchdown blocks and patch panels

21
Q

What is an MDF

A

Main distribution Frame -

Central point of the network
- usually in a data center

-Termination point for WAN connections which makes it a good spot to test both ends of the WAN

22
Q

What is an IDF

A

Intermediate Distribution Frame -

Extension of the MDF and a strategic distro point

uplinks from the MDF and may include workgroup switches, and other local resources

23
Q

What is a logical network map?

A

Specialized software that provides a high level view of the WAN layout, and application flows.

Useful for planning and collaboration

24
Q

What are the standards for the presentation of information that includes cable, pathway, space, and grounding identifiers in a commercial building?

A

ANSI/TIA/EIA 606

25
Q

What is the use of a site survey

A

Identify Access Points

Determine the current wireless landscape

Create heat map of wireless network

26
Q

Describe internal and external audits

A

Internal -
Self imposed checks
Validate permissions, check access logs, verify user account status

External - May be required for compliance regulations

27
Q

What is the point of fault tolerance

A

To maintain uptime in the case of a system failure

28
Q

what is a drawback to fault tolerance

A

It increases cost and complexity to managing systems

29
Q

What are some single device fault tolerance examples

A

RAID, Redundant power supplies NIC Teaming

30
Q

What are some multi-device fault tolerance examples

A

Serverfarms with load balancing

Multiple network paths

31
Q

What is clustering

A

A logical collective of servers

32
Q

What is load balancing

A

Shared service load across components

33
Q

What is implied by HA

A

High availability -

Always on, always available.

Redundancy does not mean always available

34
Q

What are the downsides to HA

A

Higher quality server components, and an ever growing list of contingencies that should be planned for.