Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

CISM Domain 4 Exam

Total questions: 65

Worksheet time: 1hrs 5mins

Name
Class
Date
1.
During the preparation phase of incident response, which of the following is the best approach for managing critical data backups?
a)

Daily backups to a local device

b)

Weekly backups to an offsite location

c)

Monthly backups to a cloud-based storage system

d)

Hourly backups to a redundant, offsite location

2.
During the identification phase of incident response, which of the following is the best approach for detecting a potential incident?
a)

Using intrusion detection software

b)

Regularly reviewing logs and system events

c)

Conducting vulnerability scans

d)

Monitoring employee emails

3.
During the investigation phase of incident response, which of the following is the best approach for determining the scope and impact of the incident?
a)

Interviewing witnesses and affected parties

b)

Examining system logs and other evidence

c)

Conducting vulnerability scans

d)

Restoring systems to a previous state

4.
During the recovery phase of incident response, which of the following is the best approach for restoring systems to normal operation?
a)

Installing software patches and updates

b)

Restoring from a recent backup

c)

Reformatting affected systems

d)

Resetting all user passwords

5.
John, a security analyst, has identified a potential security incident. Which stage of the NIST Incident Response Framework should he proceed to?
a)

Preparation

b)

Detection and Analysis

c)

Containment, Eradication, and Recovery

d)

Post-Incident Activity

6.
After detecting and analyzing an incident, what is the next step in the NIST Incident Response Framework?
a)

Preparation

b)

Detection and Analysis

c)

Containment, Eradication, and Recovery

d)

Post-Incident Activity

7.
After an incident has been contained, what is the next step in the NIST Incident Response Framework?
a)

Preparation

b)

Detection and Analysis

c)

Containment, Eradication, and Recovery

d)

Post-Incident Activity

8.
What is the final step in the NIST Incident Response Framework?
a)

Preparation

b)

Detection and Analysis

c)

Containment, Eradication, and Recovery

d)

Post-Incident Activity

9.
Jane, the security analyst, is responsible for preparing the organization's incident response plan. Which of the following is NOT an essential element of incident response planning?
a)

Defining roles and responsibilities

b)

Establishing communication procedures

c)

Documenting and reporting incidents

d)

Reacting to the incident as quickly as possible

10.
After detecting a security incident, Tom, the Incident Response Manager, analyzes the incident to determine the scope and severity of the incident. Which of the following is the BEST approach for incident analysis?
a)

Quickly contain the incident and then begin analysis

b)

Notify all stakeholders and wait for their input

c)

Begin analysis immediately and contain the incident simultaneously

d)

Conduct analysis after the incident is fully resolved

11.
During an incident response, the Incident Response Team determines that the incident is more extensive than initially thought and requires additional resources. What is the next step?
a)

Update the incident response plan

b)

Escalate the incident to senior management

c)

Continue with the current resources

d)

Wait until the incident is fully resolved before adding resources

12.
After an incident has been resolved, the Incident Response Team performs a post-incident review to identify areas for improvement. Which of the following is NOT a component of the post-incident review process?
a)

Documenting lessons learned

b)

Evaluating the effectiveness of the incident response plan

c)

Communicating the results to stakeholders

d)

Reprimanding employees who made mistakes during the incident

13.
What is the benefit of simplifying and defining the incident response process?
a)

It makes the process more complicated and difficult to follow

b)

It makes the process easier to understand and follow

c)

It is unnecessary to simplify and define the process

d)

It increases the likelihood of a successful incident response

14.
Why is it important to test your incident response plan?
a)

Testing is not important for incident response plans

b)

It ensures that team members understand the incident response process

c)

It is a waste of time and resources

d)

It guarantees that there will be no incidents in the future

15.
What is a centralized approach to incident response?
a)

All team members work independently during an incident

b)

The incident response process is managed by a single person

c)

Team members work together and communicate during an incident

d)

The incident response process is outsourced to a third-party provider

16.
What is the benefit of implementing incident response technology?
a)

It adds unnecessary complexity to the incident response process

b)

It can improve response times and effectiveness

c)

It is too expensive for most organizations

d)

It is not effective in preventing incidents from occurring

17.
During an incident response, who is responsible for coordinating the team and ensuring that the response plan is followed?
a)

Security Analysts

b)

Third Parties

c)

Incident Response Managers

d)

Threat Researchers

18.
Who is responsible for analyzing security alerts and identifying potential incidents?
a)

Incident Response Managers

b)

Other Stakeholders

c)

Security Analysts

d)

Threat Researchers

19.
Which role in an incident response team may be responsible for providing technical expertise and assisting with containment efforts?
a)

Security Analysts

b)

Third Parties

c)

Incident Response Managers

d)

Other Stakeholders

20.
Who may be responsible for conducting a post-incident review and identifying areas for improvement in the incident response process?
a)

Threat Researchers

b)

Other Stakeholders

c)

Incident Response Managers

d)

Security Analysts

21.
Sarah works as an IT manager in a large organization. She has been tasked with developing an incident response policy for her organization. What should be the first step she takes in this process?
a)

Write a detailed plan for incident response.

b)

Identify the critical assets and data that need protection.

c)

Train the employees on incident response procedures.

d)

Contact the external stakeholders and inform them about the incident response policy.

22.
Which of the following is NOT a key component of an incident response policy?
a)

Roles and responsibilities

b)

Communication plan

c)

Cyber insurance policy

d)

Escalation procedures

23.
Which of the following is a best practice for reviewing and updating incident response policies?
a)

Review and update the policy annually.

b)

Review and update the policy every two years.

c)

Review and update the policy only in response to a security incident.

d)

Review and update the policy every five years.

24.
A phishing email was sent to a few employees, but no one clicked on the link or provided any sensitive information. How would you classify this incident?
a)

Low severity

b)

Medium severity

c)

High severity

d)

Critical severity

25.
An employee accidentally deleted critical data from a company's database. How would you classify this incident?
a)

Low severity

b)

Medium severity

c)

High severity

d)

Critical severity

26.
An organization has discovered that an employee has been downloading and sharing sensitive company information with unauthorized third parties. What type of incidence investigation should be conducted?
a)

Administrative

b)

Civil

c)

Criminal

d)

Regulatory

27.
An organization has experienced a security incident that resulted in the loss of customer data. The incident has been reported to relevant regulatory authorities. What type of incidence investigation is likely to be conducted?
a)

Administrative

b)

Civil

c)

Criminal

d)

Regulatory

28.
John is leading the BIA process for his organization. What is the first step he should take?
a)

Develop recovery strategies

b)

Identify critical business processes and systems

c)

Assess the impact of disruptions on business operations

d)

Prioritize business functions for recovery

29.
Mary is conducting a BIA for her company and has identified several critical processes. What should she do next?
a)

Develop recovery strategies

b)

Assess the impact of disruptions on business operations

c)

Prioritize business functions for recovery

d)

Document BIA findings and recommendations

30.
Tom is developing recovery strategies as part of the BIA process. What should he keep in mind when doing so?
a)

The recovery strategies should be designed to address all potential disruptions equally

b)

The recovery strategies should prioritize the recovery of critical business processes and systems

c)

The recovery strategies should only address disruptions that are likely to occur

d)

The recovery strategies should focus on restoring all business functions at once

31.
Lisa has completed the BIA process and has documented her findings and recommendations. What should she do next?
a)

Develop recovery strategies

b)

Assess the impact of disruptions on business operations

c)

Prioritize business functions for recovery

d)

Present findings and recommendations to management

32.
What is the first priority of the Provisions and Processes phase in BCP?
a)

Ensuring the safety of employees

b)

Identifying alternate sites for business activities

c)

Reducing the impact of disasters on infrastructure

d)

Hardening critical facilities against potential risks

33.
What are the two main methods of protecting critical infrastructure in BCP?
a)

Conducting periodic maintenance and testing

b)

Implementing disaster recovery measures

c)

Physically hardening systems and introducing redundancy

d)

Hiring external consultants for BCP development

34.
Why is it important to ensure cloud service providers conduct sufficient continuity planning?
a)

Cloud service providers are not responsible for the organization's critical business functions.

b)

Cloud service providers have no impact on the organization's infrastructure.

c)

A disruption at a key cloud provider can be as damaging as a failure of the organization's own infrastructure.

d)

The organization's own continuity planning is sufficient to cover all cloud-based services.

35.
What is the purpose of BCP documentation?
a)

To provide a historical record of the BCP process

b)

To facilitate the identification of flaws in the plan

c)

To ensure BCP personnel have a written continuity document to reference in the event of an emergency

d)

All of the above

36.
What is the statement of organizational responsibility?
a)

A document that reflects the criticality of the BCP to the organization's continued viability

b)

A letter to the organization's employees, signed by a senior-level executive

c)

A statement that reiterates the sentiment that "business continuity is everyone's responsibility!"

d)

A document that outlines the implementation timetable for the BCP

37.
What is the purpose of the risk assessment section of BCP documentation?
a)

To discuss all the critical business functions considered during the business impact analysis

b)

To assess the risks to critical business functions

c)

To outline the reasons why risks were considered acceptable or unacceptable

d)

All of the above

38.
What is the vital records program?
a)

A document that outlines the goals of the continuity planning process

b)

A document that reflects the criticality of the BCP to the organization's continued viability

c)

A document that states where critical business records will be stored and the procedures for making and storing backup copies of those records

d)

A document that outlines the implementation timetable for the BCP

39.
In what ways do BCP and DRP differ?
a)

BCP focuses on recovering IT infrastructure while DRP focuses on all aspects of an organization's operations

b)

BCP is a proactive process while DRP is a reactive process

c)

BCP is a narrower process that focuses specifically on IT infrastructure while DRP is a broader process that encompasses all aspects of an organization's operations

d)

BCP aims to restore critical IT systems and infrastructure as quickly as possible while DRP aims to ensure the critical business functions of an organization can continue in the face of a disruption.

40.
What is the primary objective of resilience and fault tolerance controls?
a)

To eliminate all single points of failure in critical business systems

b)

To quickly recover from a failure after experiencing a brief disruption

c)

To maintain an acceptable level of service during an adverse event

d)

To minimize the risk of disruptions to business operations

41.
What is a single point of failure?
a)

Any component that can cause an entire system to fail

b)

A component that is redundant and unnecessary

c)

A component that can be easily replaced

d)

A component that has a low failure rate

42.
How can organizations increase fault tolerance and minimize downtime?
a)

By adding redundant components, such as additional disks or servers

b)

By reducing the number of components in critical business systems

c)

By implementing high availability controls

d)

By eliminating all single points of failure

43.
How is the effectiveness of resilience and fault tolerance controls measured?
a)

By the number of components in a critical business system

b)

By the percentage of time that a system is available

c)

By the length of time it takes to recover from a failure

d)

By the number of single points of failure in a system

44.
John is a system administrator at a large company that uses RAID technology to enhance fault tolerance and system resilience. Which RAID configuration would you recommend to John if he wants to implement fault tolerance with minimum disk requirements?
a)

RAID-0

b)

RAID-1

c)

RAID-5

d)

RAID-6

45.
Sarah is a technical professional who wants to enhance the resilience of her company's computer systems. Which RAID configuration would you recommend to Sarah if she wants to use mathematical calculations to reconstruct data if a single disk fails?
a)

RAID-0

b)

RAID-1

c)

RAID-5

d)

RAID-6

46.
David is a system administrator at a small company that wants to implement hardware-based RAID technology. Which of the following advantages of hardware-based RAID arrays is most significant for David?
a)

Spare drives can be logically added to the array

b)

Most hardware-based arrays support hot swapping

c)

Hardware-based RAID arrays are generally more efficient and reliable than software-based solutions

d)

Hardware-based RAID arrays provide an inexpensive way to enhance fault tolerance

47.
John works for a company that provides an online service to its customers. What would be the impact on the company's business if the server hosting the service fails?
a)

No impact

b)

Decreased customer satisfaction and revenue loss

c)

Increased customer satisfaction and revenue gain

d)

No effect on customer satisfaction, but there will be a revenue gain.

48.
What is the purpose of a failover cluster?
a)

To reduce the workload on individual servers

b)

To connect multiple servers or nodes to work as a single system

c)

To provide backup copies of critical data

d)

To improve network performance

49.
Which of the following is an example of a system that can benefit from a failover cluster?
a)

A personal laptop

b)

A printer

c)

A database system that stores critical data

d)

A gaming console

50.
What is the difference between an active-passive and an active-active failover cluster?
a)

In an active-passive cluster, only one server is active at a time, while in an active-active cluster, all servers are active simultaneously.

b)

In an active-passive cluster, all servers are active simultaneously, while in an active-active cluster, only one server is active at a time.

c)

There is no difference between the two configurations.

d)

In an active-passive cluster, the active server is responsible for processing all requests, while in an active-active cluster, servers share the processing workload.

51.
John manages a data center and wants to add fault tolerance to the power sources. What is an example of a fault-tolerant power source he can use?
a)

Power strips

b)

Extension cords

c)

Redundant power supplies

d)

Power adapters

52.
After a hurricane caused extensive damage to their headquarters, a company needs to quickly resume operations to avoid losing business. Which recovery site would be the most appropriate option for them to minimize downtime?
a)

Hot site

b)

Warm site

c)

Cold site

d)

Mobile site

53.
A company wants to implement a disaster recovery site that can be easily scaled up or down based on their needs. Which recovery site option would be the most appropriate for them?
a)

Hot site

b)

Warm site

c)

Cloud site

d)

Mobile site

54.
A company wants to implement a cost-effective disaster recovery site that provides basic infrastructure such as power and connectivity. Which recovery site option would be the most appropriate for them?
a)

Hot site

b)

Warm site

c)

Cold site

d)

Mobile site

55.
John works for a large corporation and is responsible for ensuring that the company's critical data is backed up and recoverable in the event of a disaster. Which database recovery technique involves maintaining an exact copy of the primary database at a secondary site using a dedicated network connection?
a)

Remote Mirroring

b)

Electronic Vaulting

c)

Remote Journaling

d)

None of the above

56.
Sarah works for a healthcare organization and needs to ensure that patient data is backed up and recoverable in the event of a disaster. Which database recovery technique involves maintaining a log of all changes made to the database in a remote location?
a)

Remote Journaling

b)

Electronic Vaulting

c)

Remote Mirroring

d)

None of the above

57.
Alex is responsible for implementing database recovery techniques for his company's critical data. Which database recovery technique involves copying database changes to a remote location using electronic means, such as tape, disk, or a network connection?
a)

Remote Journaling

b)

Electronic Vaulting

c)

Remote Mirroring

d)

None of the above

58.
Sarah is an IT manager at a manufacturing company. She wants to back up all of the company's data once a week to ensure that everything is backed up. Which type of backup should she use?
a)

Incremental backup

b)

Differential backup

c)

Full backup

d)

Synthetic full backup

59.
John is an IT technician at a software development company. He wants to back up only the data that has changed since the last backup. Which type of backup should he use?
a)

Incremental backup

b)

Differential backup

c)

Full backup

d)

Continuous backup

60.
Mark is an IT administrator at a law firm. He wants to back up all data that has changed since the last full backup. Which type of backup should he use?
a)

Incremental backup

b)

Differential backup

c)

Full backup

d)

Snapshot backup

61.
Amy is an IT manager at a financial services company. She wants to create a new full backup without having to perform another full backup. Which type of backup should she use?
a)

Synthetic full backup

b)

Differential backup

c)

Full backup

d)

Continuous backup

62.
Your organization is testing its disaster recovery plan, and the team is working through a simulated disaster scenario step by step. What type of test is this?
a)

Checklist test

b)

Structured walk-through

c)

Simulation test

d)

Full-interruption test

63.
Your organization is conducting a test to identify any discrepancies between the primary and backup systems and ensure that the backup system is ready to take over in the event of a disaster. What type of test is this?
a)

Checklist test

b)

Structured walk-through

c)

Parallel test

d)

Full-interruption test

64.
Your organization is simulating a natural disaster to test the effectiveness of its disaster recovery plan. What type of test is this?
a)

Checklist test

b)

Structured walk-through

c)

Simulation test

d)

Full-interruption test

65.
Your organization is conducting a complete shutdown of the primary system and switching over to the backup system to identify any issues that may arise during a disaster. What type of test is this?
a)

Checklist test

b)

Structured walk-through

c)

Parallel test

d)

Full-interruption test