Font size
WorksheetsChapter 10: Planning for Contingencies
Total questions: 20
Worksheet time: 9mins
Which of the following contains the contact information of individuals that need to be notified in the event of an actual incident?
incident response policy
business process
alert roster
after-action review
Detecting a modification of system logs is an indicator that an actual incident has taken place.
True
False
Which term below describes the point in time, prior to a disruption or outage, to which mission / business process data can be recovered?
Maximum Tolerable Downtime (MTD)
Recovery Time Objective (RTO)
Recovery Point Objective (RPO)
Work Recovery Time (WRT)
What is the first phase of the CP process?
Business impact analysis
Incident response planning
Disaster recovery planning
Business continuity planning
Which of the following is NOT a major component of contingency planning?
Incident response plan
Disaster relief plan
Disaster recovery plan
Business continuity plan
Slow-onset disasters occur over time and gradually degrade an organization’s ability to withstand their effects.
True
False
Which of the following terms best describe a site with a fully configured computer facility, including all services, communications links, and physical plant operations?
hot site
warm site
mobile site
cold site
Which type of offsite backup service provides backups for transactional data only, typically in real time?
Electronic vaulting
Traditional data backups
Database shadowing
Remote journaling
Which of the following is NOT considered a responsibility of the CMPT?
verifying personnel status
activating the alert roster
plan maintenance schedule
coordinating with emergency services
There are several strategies that can be used to test contingency plans. Which of the following is the simplest kind of validation and involves distributing copies of the appropriate plans to all individuals who will be assigned roles during an actual incident?
full-interruption testing
simulation
structured walk-through
desk check
One of the things that an incident response policy defines is what?
Responsibilities of different users
Staff working in the organization
Time of day to work
The incident response policy is the document that defines what?
How organisations create incidences
How organisations respond to employement
How organisations respond to incidences
How organisations employ ICT staff
An event that poses a threat to the business information, in regard to its confidentiality, integrity & availability
An information security incident
A total data recovery failure
A backup server breach
A power failure in the server room
Two things that need to be identified during an initial assessment of an incident:
Type of attack
Severity of attack
How much it will cost to resolve the incident
Whether or not to inform the police
What are the criterias needed to be an organization's ideal spokesperson? You may choose more than 1 answer
confident
knowledgeable on the crisis
only knows how to speak in native language
speaks well
slow speaker
What are the potential online platforms that organizations could use to identify and monitor crisis? You may choose more than 1 answer.
Google News, Alerts and Trends
Random online profiles
Social Network Sites such as Facebook, Instagram and Twitter
Individual web browsing patterns
Public comments
What is the suggested time frame for ' The Golden Hour'
45 minutes
30 minutes
60 minutes
120 minutes
