WorksheetsCISM Domain 4 Exam
Total questions: 65
Worksheet time: 1hrs 5mins
Daily backups to a local device
Weekly backups to an offsite location
Monthly backups to a cloud-based storage system
Hourly backups to a redundant, offsite location
Using intrusion detection software
Regularly reviewing logs and system events
Conducting vulnerability scans
Monitoring employee emails
Interviewing witnesses and affected parties
Examining system logs and other evidence
Conducting vulnerability scans
Restoring systems to a previous state
Installing software patches and updates
Restoring from a recent backup
Reformatting affected systems
Resetting all user passwords
Preparation
Detection and Analysis
Containment, Eradication, and Recovery
Post-Incident Activity
Preparation
Detection and Analysis
Containment, Eradication, and Recovery
Post-Incident Activity
Preparation
Detection and Analysis
Containment, Eradication, and Recovery
Post-Incident Activity
Preparation
Detection and Analysis
Containment, Eradication, and Recovery
Post-Incident Activity
Defining roles and responsibilities
Establishing communication procedures
Documenting and reporting incidents
Reacting to the incident as quickly as possible
Quickly contain the incident and then begin analysis
Notify all stakeholders and wait for their input
Begin analysis immediately and contain the incident simultaneously
Conduct analysis after the incident is fully resolved
Update the incident response plan
Escalate the incident to senior management
Continue with the current resources
Wait until the incident is fully resolved before adding resources
Documenting lessons learned
Evaluating the effectiveness of the incident response plan
Communicating the results to stakeholders
Reprimanding employees who made mistakes during the incident
It makes the process more complicated and difficult to follow
It makes the process easier to understand and follow
It is unnecessary to simplify and define the process
It increases the likelihood of a successful incident response
Testing is not important for incident response plans
It ensures that team members understand the incident response process
It is a waste of time and resources
It guarantees that there will be no incidents in the future
All team members work independently during an incident
The incident response process is managed by a single person
Team members work together and communicate during an incident
The incident response process is outsourced to a third-party provider
It adds unnecessary complexity to the incident response process
It can improve response times and effectiveness
It is too expensive for most organizations
It is not effective in preventing incidents from occurring
Security Analysts
Third Parties
Incident Response Managers
Threat Researchers
Incident Response Managers
Other Stakeholders
Security Analysts
Threat Researchers
Security Analysts
Third Parties
Incident Response Managers
Other Stakeholders
Threat Researchers
Other Stakeholders
Incident Response Managers
Security Analysts
Write a detailed plan for incident response.
Identify the critical assets and data that need protection.
Train the employees on incident response procedures.
Contact the external stakeholders and inform them about the incident response policy.
Roles and responsibilities
Communication plan
Cyber insurance policy
Escalation procedures
Review and update the policy annually.
Review and update the policy every two years.
Review and update the policy only in response to a security incident.
Review and update the policy every five years.
Low severity
Medium severity
High severity
Critical severity
Low severity
Medium severity
High severity
Critical severity
Administrative
Civil
Criminal
Regulatory
Administrative
Civil
Criminal
Regulatory
Develop recovery strategies
Identify critical business processes and systems
Assess the impact of disruptions on business operations
Prioritize business functions for recovery
Develop recovery strategies
Assess the impact of disruptions on business operations
Prioritize business functions for recovery
Document BIA findings and recommendations
The recovery strategies should be designed to address all potential disruptions equally
The recovery strategies should prioritize the recovery of critical business processes and systems
The recovery strategies should only address disruptions that are likely to occur
The recovery strategies should focus on restoring all business functions at once
Develop recovery strategies
Assess the impact of disruptions on business operations
Prioritize business functions for recovery
Present findings and recommendations to management
Ensuring the safety of employees
Identifying alternate sites for business activities
Reducing the impact of disasters on infrastructure
Hardening critical facilities against potential risks
Conducting periodic maintenance and testing
Implementing disaster recovery measures
Physically hardening systems and introducing redundancy
Hiring external consultants for BCP development
Cloud service providers are not responsible for the organization's critical business functions.
Cloud service providers have no impact on the organization's infrastructure.
A disruption at a key cloud provider can be as damaging as a failure of the organization's own infrastructure.
The organization's own continuity planning is sufficient to cover all cloud-based services.
To provide a historical record of the BCP process
To facilitate the identification of flaws in the plan
To ensure BCP personnel have a written continuity document to reference in the event of an emergency
All of the above
A document that reflects the criticality of the BCP to the organization's continued viability
A letter to the organization's employees, signed by a senior-level executive
A statement that reiterates the sentiment that "business continuity is everyone's responsibility!"
A document that outlines the implementation timetable for the BCP
To discuss all the critical business functions considered during the business impact analysis
To assess the risks to critical business functions
To outline the reasons why risks were considered acceptable or unacceptable
All of the above
A document that outlines the goals of the continuity planning process
A document that reflects the criticality of the BCP to the organization's continued viability
A document that states where critical business records will be stored and the procedures for making and storing backup copies of those records
A document that outlines the implementation timetable for the BCP
BCP focuses on recovering IT infrastructure while DRP focuses on all aspects of an organization's operations
BCP is a proactive process while DRP is a reactive process
BCP is a narrower process that focuses specifically on IT infrastructure while DRP is a broader process that encompasses all aspects of an organization's operations
BCP aims to restore critical IT systems and infrastructure as quickly as possible while DRP aims to ensure the critical business functions of an organization can continue in the face of a disruption.
To eliminate all single points of failure in critical business systems
To quickly recover from a failure after experiencing a brief disruption
To maintain an acceptable level of service during an adverse event
To minimize the risk of disruptions to business operations
Any component that can cause an entire system to fail
A component that is redundant and unnecessary
A component that can be easily replaced
A component that has a low failure rate
By adding redundant components, such as additional disks or servers
By reducing the number of components in critical business systems
By implementing high availability controls
By eliminating all single points of failure
By the number of components in a critical business system
By the percentage of time that a system is available
By the length of time it takes to recover from a failure
By the number of single points of failure in a system
RAID-0
RAID-1
RAID-5
RAID-6
RAID-0
RAID-1
RAID-5
RAID-6
Spare drives can be logically added to the array
Most hardware-based arrays support hot swapping
Hardware-based RAID arrays are generally more efficient and reliable than software-based solutions
Hardware-based RAID arrays provide an inexpensive way to enhance fault tolerance
No impact
Decreased customer satisfaction and revenue loss
Increased customer satisfaction and revenue gain
No effect on customer satisfaction, but there will be a revenue gain.
To reduce the workload on individual servers
To connect multiple servers or nodes to work as a single system
To provide backup copies of critical data
To improve network performance
A personal laptop
A printer
A database system that stores critical data
A gaming console
In an active-passive cluster, only one server is active at a time, while in an active-active cluster, all servers are active simultaneously.
In an active-passive cluster, all servers are active simultaneously, while in an active-active cluster, only one server is active at a time.
There is no difference between the two configurations.
In an active-passive cluster, the active server is responsible for processing all requests, while in an active-active cluster, servers share the processing workload.
Power strips
Extension cords
Redundant power supplies
Power adapters
Hot site
Warm site
Cold site
Mobile site
Hot site
Warm site
Cloud site
Mobile site
Hot site
Warm site
Cold site
Mobile site
Remote Mirroring
Electronic Vaulting
Remote Journaling
None of the above
Remote Journaling
Electronic Vaulting
Remote Mirroring
None of the above
Remote Journaling
Electronic Vaulting
Remote Mirroring
None of the above
Incremental backup
Differential backup
Full backup
Synthetic full backup
Incremental backup
Differential backup
Full backup
Continuous backup
Incremental backup
Differential backup
Full backup
Snapshot backup
Synthetic full backup
Differential backup
Full backup
Continuous backup
Checklist test
Structured walk-through
Simulation test
Full-interruption test
Checklist test
Structured walk-through
Parallel test
Full-interruption test
Checklist test
Structured walk-through
Simulation test
Full-interruption test
Checklist test
Structured walk-through
Parallel test
Full-interruption test
