IS3350 CHAPTER 14 Flashcards

1
Q

The number of times a threat might affect an organization during a one-year time frame is called ___?

A

ANNUAL RATE OF OCCURRENCE (ARO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q
The amount of loss that an organization can expect to have each year due to a particular risk is called \_\_\_?
ALE is often expressed as the equation:
ALE = SLE x ARO.
SLE is single loss expectancy
ARO is annual rate or occurrence
A

ANNUALIZED LOSS EXPECTANCY (ALE)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

These ___ address the recovery of an organization’s business processes and functions in the event of a disaster.
These tend to be comprehensive plans for returning an organization to normal operating conditions.

A

BUSINESS CONTINUITY (BC) PLANS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A process that identifies key business operations and the resources used to support those processes is called ___?
This also identifies maximum tolerable down-time for critical business functions.

A

BUSINESS IMPACT ANALYSIS (BIA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A basic type of disaster recovery and business continuity test that checks to make sure that supplies and inventory items needed to an organization’s business recovery are on hand is called ___?

A

CHECKLIST TEST

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A backup site for disaster recovery and business continuity planning purposes that is little more than reserved space is called ___?
It doesn’t have any hardware or equipment ready for business operations.
It will have electrical service, but most likely won’t have network connectivity.
It can take weeks to months for an organization to ready this site for business operations.

A

COLD SITE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Any situation where a person’s private interests and professional obligations collide is called ___?
Independent observers might question whether a person’s private interests improperly influence his or her professional decisions.

A

CONFLICT OF INTEREST

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A sudden, unplanned event that negatively affects the organizations’ critical business functions for an unknown period is called ___?

A

DISASTER

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Plans that address the recovery of an organization’s information technology systems in the event of a disaster is called ___?

A

DISASTER RECOVERY (DR) PLANS

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

The percentage of asset loss that is likely to be caused by an identified threat or vulnerability is called ___?

A

EXPOSURE FACTOR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

A disaster recovery and business continuity test where an organization stopes all of its normal business operations and transfers those operations to its backup site is called ___?
This is the most comprehensive form of disaster recovery and business continuity plan testing; also the most expensive.

A

FULL INTERRUPTION TEST

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

An operation backup site for disaster recovery and business continuity planning purposes is called ___?
It has equipment and infrastructure that is fully compatible with an organization’s main facility.
It is not staffed with people.
It can become operational within minutes to hours after a disaster.

A

HOT SITE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

An event that adversely affects the confidentiality, integrity, and/or availability of an organization’s data and information technology systems is called ____?

A

INCIDENT

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

A contingency plan that helps an organization respond to attacks against an organizations’ information technology infrastructure is called ___?

A

INCIDENT RESPONSE (IR)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

The amount of time that critical business processes and resurrect can be offline before an organization begins to experience irreparable business harm is called ___?

A

MAXIMUM TOLERABLE DOWNTIME (MTD)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

A fully operational backup site for disaster recovery and business continuity planning purposes is called ___?
This site actively runs an organization’s information technology functions in parallel with the organization’s mail processing facility.
It is fully staffed.
It has all necessary data and equipment to continue business operations.

A

MIRRORED SITE

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

A disaster recovery and business continuity test where an organization tests its ability to recover its information technology systems and its business data is called ___?
In this test, the organization brings its backup recovery sites online.
It will then use historical business data to test the operations of those systems.

A

PARALLEL TEST

18
Q

A marketing field that manages an organization’s public image is called ___?

A

PUBLIC RELATIONS (PR)

19
Q

A risk analysis method that uses scenarios and ratings systems to calculate risk and potential harm is called ___?
This does not attempt to assign money value to assets and risks.

A

QUALITATIVE RISK ANALYSIS

20
Q

A risk analysis method that uses real money costs and values to determine the potential monetary impact of threats and vulnerabilities is called ___?

A

QUANTITATIVE RISK ANALYSIS

21
Q

The loss that an organization has when a potential threat actually occurs is called ___?

A

REALIZED RISK

22
Q

A process for identifying threats and vulnerabilities that an organization faces is called ___?
This can be qualitative or quantitative or both.

A

RISK ASSESSMENT (RA)

23
Q

The process that an organization uses to identify risks, asses them, and reduce them to an acceptable level is called ___?

A

RISK MANAGEMENT (RM)

24
Q

A disaster recovery and business continuity test where an organization role plays a specific disaster scenario is called ___?
This type of test doesn’t interrupt normal business operations and activities.

A

SIMULATION TEST

25
Q

The amount of money that an organization stands to lose every time a specified risk is realized is called ___?

A

SINGLE LOSS EXPECTANCY (SLE)

26
Q

A basic type of disaster recovery and business continuity test that reviews a disaster recovery/business continuity plan to make sure that all of the assumptions and tasks stated in the plan are correct is called ___?

A

WALK-THROUGH TEST

27
Q

A partially equipped backup site for disaster recovery and business continuity planning purposes is called ___?
This is space that contains some, but not all, of the equipment and infrastructure that an organization needs to continue operations in the event of a disaster.
It is partially prepared for operations and has electricity and network connectivity.

A

WARM SITE

28
Q
  1. A parallel test uses current processing data to test IT system operation.
    TRUE OR FALSE
A

FALSE

29
Q
  1. Which item is NOT part of the risk management process?
  2. Risk analysis
  3. Risk response
  4. Continuous monitoring
  5. Training employees
  6. All the above are parts of the risk management process
A

All are parts of the risk management process

Risk analysis
Risk response
Continuous monitoring
Training employees

30
Q
  1. What does a risk assessment do?
A

A risk assessment identifies the threats and vulnerabilities to IT resources.

31
Q
  1. Which type of contingency plan test is the least expensive?
  2. Full interruption test
  3. Parallel test
  4. Simulation test
  5. Checklist test
  6. None of the above
A

Checklist test

32
Q
  1. Which type of risk analysis uses real numbers to calculate risk?
  2. Quantitative
  3. Qualitative
  4. Quasi-quantitative
  5. Quasi-qualitative
  6. None of the above
A

Quantitative

33
Q
  1. The ___ is the percentage of assets loss that is likely to be caused by an identified threat.
A

Exposure factor

34
Q
  1. How is annualized loss expectancy calculated?
A

The annualized loss expectancy (ALE) is the amount of loss that an organization can expect to have each year due to a particular risk.

ALE = SLE x ARO
SLE is single loss expectancy
ARO is annual rate of occurrence

35
Q
  1. What is the main benefit of a qualitative risk assessment?
  2. Measures the money cost of a risk
  3. Scope of the assessment can be easily changed
  4. Easy to administer
  5. All the above
  6. None of the above
A

Easy to administer

36
Q
  1. Which of the following is a qualitative risk assessment methodology?
  2. CRAMM
  3. ISO
  4. MTD
  5. BIA
  6. None of the above
A

CRAMM

37
Q
  1. Which risk response eliminates all risk of harm posted by a threat or vulnerability?
  2. Risk transfer
  3. Risk mitigation
  4. Risk acceptance
  5. Risk avoidance
  6. None of the above
A

Risk avoidance

38
Q
  1. Which type of contingency plan reacts to attacks against an organization’s IT infrastructure?
  2. BC plan
  3. DR plan
  4. IR plan
  5. 1 & 2 only
  6. None of the above
A

IR plan

39
Q
  1. A(n) ___ is an event that adversely affects the confidentiality, integrity, and/or availability of an organization’s data and IT systems.
A

Incident

40
Q
  1. A(n) ___ is a sudden, unplanned event that negatively affects the organization’s critical business functions for an unknown period.
A

Disaster

41
Q
  1. Which backup site is a fully operational backup site?
  2. Mirrored site
  3. Hot site
  4. Warm site
  5. Cold site
  6. None of the above
A

Mirrored site

42
Q
  1. A business impact analysis identifies key business operations and resources.
    TRUE OR FALSE
A

TRUE