Font size
Worksheetsdig infra 4a
Total questions: 105
Worksheet time: 54mins
What is the purpose of the disaster recovery policy?
Preventing cybersecurity incidents from occurring.
Ensuring damage is quickly recovered from after an incident.
Performing regular backups of all data.
Analysing the cause of attacks and identifying improvements to procedures.
What kind of threats can disaster recovery policies help to protect us from being impacted by?
Natural disasters
Malware
Hardware failure
All of the above.
A “hot site” is a location that a business can instantly switch business operation over to after a disaster.
True
False
Which of the following would be included in a disaster recovery policy?
Choose two options.
Establishing the severity of the attack
Definition of the backup process
Analysis of the cause of the disaster
Timeline for data recovery
What action to take after an attack is described below?
Establish the cause of the attack and mistakes made and update policies and procedures.
Respond
Manage
Recover
Investigate
Analyse
What action to take after an attack is described below?
Identify when and why the attack happened and establish the severity of the attack.
Respond
Manage
Recover
Investigate
Analyse
What action to take after an attack is described below?
Implement the disaster recovery policy.
Respond
Manage
Recover
Investigate
Analyse
What action to take after an attack is described below?
Isolate & contain the attack and use appropriate measures to resume services.
Respond
Manage
Recover
Investigate
Analyse
What action to take after an attack is described below?
Inform the relevant stakeholders and authorities.
Respond
Manage
Recover
Investigate
Analyse
Which of the following may be common uses of location-based data?
Choose two options.
Showing country-specific deals.
Providing analytics on how you use a website.
Planning a route on a map app.
Analysing buying habits in a store.
Which of the following are uses of cookies?
Choose two options.
Storing data between website sessions.
Showing you where to find restaurants local to you.
Identifying trends in product sales.
Collecting analytics, like how long you spend on a web page.
Which of the following are benefits of using shared data?
Choose two options.
Always accurate and safe.
Is automatically protected by the data protection act.
Helps businesses to better target advertising.
Helps businesses make better decisions.
Which of the following are drawbacks of using shared data?
Choose two options.
Causes bad decisions to be made
Could be fined under the DPA.
Could be stolen & misused by malicious users.
Is more costly than gathering the data manually.
What legislation protects the use of personal data shared with businesses?
Data Protection Act (1998)
Data Protection Act (2018)
Computer Misuse Act (1990)
Computer Misuse Act (1998)
Businesses have an ethical responsibility to protect shared data as otherwise they may be fined under the Data Protection Act.
True
False
Which is a strong password?
Soofmu1.
123456
Passwords should include? (Choose all that apply)
Colour
Letters
Numbers
Symbols
After using a public computer (like in a library), you should stay logged in to everything.
True
False
What is the role of security policies. (Choose all that apply)
To allow staff to work remotely
Outline how staff are expected to behave
List staff responsibilities
Plan for what should happen in a disaster
Which of the following are features of a disaster recovery plan?
Who has responsibility for tasks
A list of passwords for the system
Identifying potential risks
What staff should and should not do.
Identify the features of an AUP (Acceptable Use Policy) . (Choose all that apply)
It's purpose is to reduce potential internal threats to the organisations information.
It applies to all the employees in an organisation and any others who may use technology belonging to the organisations.
It outlines steps to take to in the event of a disaster.
It covers acceptable use of all assets eg Data, Hardware and Software
Identify the behaviours that would be considered acceptable in a AUP.
Download non-work related materials, software, music and video files.
Use email in a professional and courteous manner
Make negative comments about the organisation on social media.
Report any technical issues to the technical support department
Identify the behaviours that would be considered not acceptable in a AUP.
Keep passwords confidential
Visit inappropriate websites
Make negative comments about the organisation on social media.
Use equipment with care and respect.
Identify examples of security policies. (Choose all that apply)
Responsible use policies
Disaster Recovery Policy
Life Insurance policy
System Security policy
The steps an organisation should take after an attack include: Investigate, Respond, Manage, Recover. However one step is missing which is it?
Report
Disconnect
Disinfect
Analyse
What is contingency planning?
Deletion of data in information security assets
Preparation to detect and react to threats to information security threats
Destruction of information security assets
Which of the following the components of contingency planning?
Business Impact Analysis
Incident Response Plan
Identification Planning
Disaster Recovery Plan
Who are responsible in conducting Business Impact Analysis (BIA)?
Business Continuity (BC) Team
Incident Response (IR) Team
CP Management Team
Disaster Recovery (DR) Team
"Set and start operations after disaster"
Which team is responsible in performing the above task?
Business Continuity Team
Incident Response Team
Disaster Recovery Team
CP Management Team
How many components are there in contingency planning?
3
4
5
6
How many stages are there in contingency planning?
5
6
7
8
What is the duty of Incident Response Team?
Detects, evaluates, and responds to incidents
Responsible for re-establishing operations at the primary business site
Responsible for setting up and starting off-site operations after an incident or a disaster
What is the duty of Business Continuity Team?
Detects, evaluates, and responds to incidents
Responsible for re-establishing operations at the primary business site
Responsible for setting up and starting off-site operations after an incident or a disaster
What is the duty of Disaster Recovery Team?
Detects, evaluates, and responds to incidents
Responsible for re-establishing operations at the primary business site
Responsible for setting up and starting off-site operations after an incident or a disaster
What is crisis management?
Steps to create problems and disaster
Step to deal with people during and after a disaster
Steps to create haywire
What is the main objective of Business Continuity Planning (BCP) in an organization?
To ensure the highest profitability in all market conditions
To assess risks to organizational processes and develop policies to minimize the impact of these risks
To provide training to new employees about the organizational structure
To focus solely on the recovery of IT infrastructure after a disaster
What is one of the primary responsibilities of individuals in charge of business continuity planning (BCP)?
To immediately invest in new technology that supports remote work.
To perform an analysis of the business organization to identify all departments and individuals who have a stake in the BCP process.
To prioritize marketing strategies to communicate the BCP to external stakeholders.
To focus exclusively on the IT department as they are typically the most affected in crisis situations.
In the initial stages of business continuity planning, why is it crucial for planners to identify all departments and individuals with a stake in the BCP process?
To reduce the overall budget allocated for the BCP by focusing only on key departments.
To ensure comprehensive coverage and collaboration across the organization, recognizing that different departments may have unique requirements and contributions.
To single out departments that are less important to the continuity plan and reduce their operational capacity.
To focus primarily on external stakeholders and their expectations from the BCP.
Why is the identification process of departments and individuals critical in the initial stages of Business Continuity Planning (BCP)?
Because it is a regulatory requirement for all businesses to list their departments annually.
Because it ensures that the most technologically advanced departments are prioritized in the plan.
Because it provides the groundwork for identifying potential BCP team members and builds the foundation for the remainder of the BCP process.
Because it is primarily a formality to demonstrate the organization's commitment to external stakeholders.
What is a critical flaw in the approach to Business Continuity Planning (BCP) where only the IT and/or security departments are involved, with no input from other operational or support departments?
It creates a plan that may be unknown to other departments until a disaster is imminent or occurs, potentially leading to inadequate preparation and response.
It leads to an overemphasis on financial investment in IT infrastructure.
It results in a BCP that is too comprehensive and difficult to implement.
It causes unnecessary training and drills that could disrupt the daily operations of the business.
Once the organizational review is validated in the Business Continuity Planning (BCP) process, what is the next critical step for the BCP team?
To immediately implement the most cost-effective solutions regardless of their alignment with the organizational review.
To conduct a comprehensive assessment of the resources required by the BCP effort, including personnel, technology, and financial assets.
To focus solely on external partnerships and outsourcing strategies for crisis management.
To disband the organizational review team and hand over responsibilities to the IT department.
Which of the following best describes a significant risk in the approach to Business Continuity Planning (BCP) where the responsibility is confined exclusively to the IT and/or security departments, without the involvement of other key operational or support departments?
It may lead to a lack of technical expertise in the BCP, as IT departments are often not equipped with the necessary knowledge for comprehensive planning.
The involvement of only IT and/or security departments might lead to a faster and more efficient planning process, thereby increasing the overall effectiveness of the BCP.
The BCP might become too IT-centric, leading to excessive financial expenditure on technological solutions while neglecting other affordable options.
The plan might focus solely on IT recovery and overlook critical aspects like supply chain management, human resources, and customer relations, potentially leading to a fragmented and ineffective response in a crisis.
Why is the use of a proven methodology crucial in the development of a resilient business continuity plan (BCP)?
To ensure the plan is focused exclusively on technology recovery rather than the overall business processes.
To guarantee a higher financial profit during the first quarter after implementing the plan.
To follow a structured, systematic approach that ensures all critical aspects of business continuity are addressed effectively.
To comply with international laws regarding business operations, regardless of the specific needs of the organization.
What is the overall goal of Business Continuity Planning (BCP) in an organization?
To ensure the organization always remains technologically advanced compared to competitors.
To delegate emergency response tasks to external agencies without internal coordination.
To solely focus on the prevention of potential risks without planning for response and recovery.
To provide a quick, calm, and efficient response in the event of an emergency, and to enhance the organization's ability to promptly recover from a disruptive event while maintaining mission-critical tasks.
What is the primary goal of Business Continuity Planning (BCP) in an organization?
To ensure that the organization remains the market leader in its industry
To reduce the organization's operational costs in day-to-day activities
To maintain continuous operation of the business with minimal impact in the event of an emergency through a combination of policies, procedures, and processes
To focus on employee performance improvement and skill development
What is the purpose of a backup and recovery plan in IT disaster recovery?
To slow down the recovery process
To ensure that critical data and systems can be restored in the event of a disaster or data loss.
To increase the risk of data loss
To create unnecessary work for IT staff
List and explain three common data backup methods used in IT disaster recovery.
Cloud backup, local backup, and external backup
Physical backup, virtual backup, and remote backup
Full backup, incremental backup, and differential backup
Manual backup, automatic backup, and scheduled backup
Why is disaster recovery testing important in IT?
To test the speed of the internet connection
To practice using new software
To see if the office building is up to code
To ensure that systems and processes are capable of being restored in the event of a disaster or outage.
What are the advantages of using cloud-based disaster recovery for IT systems?
Limited storage capacity, high cost, and restricted access
Inflexible, unreliable, and difficult to integrate with existing systems
Advantages of using cloud-based disaster recovery include easy scalability, cost-effectiveness, and accessibility from anywhere.
Difficult to implement, slow performance, and lack of security
Explain the difference between hot, warm, and cold IT disaster recovery strategies.
The hot IT disaster recovery strategy involves having backup systems that need to be fully configured before use, the warm strategy involves maintaining fully operational duplicate systems, and the cold strategy involves having partially operational duplicate systems.
The hot IT disaster recovery strategy involves using spicy technology, the warm strategy involves using lukewarm technology, and the cold strategy involves using frozen technology.
The hot IT disaster recovery strategy involves using outdated technology, the warm strategy involves using cutting-edge technology, and the cold strategy involves using average technology.
The hot IT disaster recovery strategy involves maintaining fully operational duplicate systems, the warm strategy involves having partially operational duplicate systems, and the cold strategy involves having backup systems that need to be fully configured before use.
What are the key components of a comprehensive backup and recovery plan?
Regular data backups, offsite storage, testing of backups, documentation of recovery procedures, and a clear communication plan
Storing all backups on the same server
Using outdated software and hardware
Not having a clear communication plan
Discuss the concept of incremental backup in data backup methods.
Backing up only the data that has changed since the last backup
Not backing up any data at all
Only backing up the most important files
Backing up the entire system every time
What are the challenges of implementing disaster recovery testing in IT?
Lack of interest from IT staff
Complexity of IT systems, specialized skills and resources, potential disruption to normal operations
Minimal impact on business operations
Easily accessible resources
How does cloud-based disaster recovery provide scalability for IT systems?
It provides scalability by limiting the capacity of IT systems
It provides scalability by allowing IT systems to easily scale up or down based on the organization's needs.
It provides scalability by increasing the complexity of IT systems
It provides scalability by reducing the flexibility of IT systems
Compare and contrast the pros and cons of on-site vs off-site data backup methods in IT disaster recovery.
The number of employees in the IT department
The color of the backup server
The brand of the backup software
The correct answer for the question is to analyze the cost, accessibility, security, and reliability of on-site vs off-site data backup methods in IT disaster recovery.
What is the purpose of a backup and recovery plan in IT disaster recovery?
To slow down the recovery process
To ensure that critical data and systems can be restored in the event of a disaster or data loss.
To increase the risk of data loss
To create unnecessary work for IT staff
List and explain three common data backup methods used in IT disaster recovery.
Cloud backup, local backup, and external backup
Physical backup, virtual backup, and remote backup
Full backup, incremental backup, and differential backup
Manual backup, automatic backup, and scheduled backup
Why is disaster recovery testing important in IT?
To test the speed of the internet connection
To practice using new software
To see if the office building is up to code
To ensure that systems and processes are capable of being restored in the event of a disaster or outage.
What are the advantages of using cloud-based disaster recovery for IT systems?
Limited storage capacity, high cost, and restricted access
Inflexible, unreliable, and difficult to integrate with existing systems
Advantages of using cloud-based disaster recovery include easy scalability, cost-effectiveness, and accessibility from anywhere.
Difficult to implement, slow performance, and lack of security
Explain the difference between hot, warm, and cold IT disaster recovery strategies.
The hot IT disaster recovery strategy involves having backup systems that need to be fully configured before use, the warm strategy involves maintaining fully operational duplicate systems, and the cold strategy involves having partially operational duplicate systems.
The hot IT disaster recovery strategy involves using spicy technology, the warm strategy involves using lukewarm technology, and the cold strategy involves using frozen technology.
The hot IT disaster recovery strategy involves using outdated technology, the warm strategy involves using cutting-edge technology, and the cold strategy involves using average technology.
The hot IT disaster recovery strategy involves maintaining fully operational duplicate systems, the warm strategy involves having partially operational duplicate systems, and the cold strategy involves having backup systems that need to be fully configured before use.
What are the key components of a comprehensive backup and recovery plan?
Regular data backups, offsite storage, testing of backups, documentation of recovery procedures, and a clear communication plan
Storing all backups on the same server
Using outdated software and hardware
Not having a clear communication plan
Discuss the concept of incremental backup in data backup methods.
Backing up only the data that has changed since the last backup
Not backing up any data at all
Only backing up the most important files
Backing up the entire system every time
What are the challenges of implementing disaster recovery testing in IT?
Lack of interest from IT staff
Complexity of IT systems, specialized skills and resources, potential disruption to normal operations
Minimal impact on business operations
Easily accessible resources
How does cloud-based disaster recovery provide scalability for IT systems?
It provides scalability by limiting the capacity of IT systems
It provides scalability by allowing IT systems to easily scale up or down based on the organization's needs.
It provides scalability by increasing the complexity of IT systems
It provides scalability by reducing the flexibility of IT systems
Compare and contrast the pros and cons of on-site vs off-site data backup methods in IT disaster recovery.
The number of employees in the IT department
The color of the backup server
The brand of the backup software
The correct answer for the question is to analyze the cost, accessibility, security, and reliability of on-site vs off-site data backup methods in IT disaster recovery.
One characteristic of employee fraud is that the fraud ...............
is perpetrated at a level to which internal controls do not apply
involves misstating financial statements
involves the direct conversion of cash or other assets tp the employee's personal benefit
involves misappropriating assets in a series of complex transactions involving third parties
Which of the following is not a feature of employee fraud?
Concealing the crime to avoid detection
Stealing something of value
Misstating financial statements
Converting the asset to a usable form
A mailroom clerk opens envelopes containing checks and remittance advice. The clerk steals a check, cashes it, and destroys the remittance advice. What type of fraud is this?
Skimming
Pay-and-return-fraud
Cash larceny
Lapping
The purchasing agent for a company XYZ places an order with a false vendor, which is himself. He then purchases the needed items from a legitimate vendor and sells them to the Company XYZ at higher that market price. What type of fraud is this?
Lapping
Pass through fraud
Shell company
Kiting
For an action to be called fraudulent, all of the following conditions are required EXCEPT .........
material fact
false representation
intent to deceive
injury loss
all of them are conditions
What is computer forensics?
It is an attempt to expose, alter, destabilize, destroy, remove to gain unauthorized access or use an asset.
It is the discipline that combines the elements of law and computer science to collect and analyze data from computer Systems, network, Wireless communications and storage devices in a way that is admisible as evidence in a court of law.
What are the examples of latent data? choose 3.
Belkasoft Live RAM capturer
Information that is in the computer's storage but is not easily mentioned in the file allocation tables.
Data that has been deliberately removed.
Information that the operating System or commonly used software Application cannot easily see.
1. A _______ has occurred, collecting all relevant evidence is of the utmost importance in answering the questions described above.
file headers.
forensic investigator.
cyber attack.
What are the main types of computer forensics?
Of operating Systems
Of security
Of network.
On the cloud.
On Mobile devices
It is the process of retrieving useful Information from the computer or mobile device in questions.
Of network
On the cloud
Of operating Systems
It aims to retrieve digital evidence or relevant data from a mobile device in a way that preserves the evidence in a sound forensic condition.
On the cloud
Of operating Systems
On mobile devices
It refers to the collection, monitoring, and analysis of network activities to discover the source of attacks, viruses, intrusions, or security breaches that occur On a network or in network traffic.
On the cloud
On mobile devices
Of operating Systems
Of network
Refers to any technique, device or software designed to hinder a computer investigation.
Anti-forensic computing.
Encryption.
File headers.
Focuses primarily On gathering digital forensic Information from a cloud infrastructure.
On mobile devices.
On the cloud.
FTK Imager
You use a complex set of rules called an algorithm to make data unreadable.
Encryption
Metadata
Computer forensic analysis
Is a data and image preview tool that allows you to browse files and folders on local hard drives, network drives, CD / DVD and review the content of forensic images or memory dumps.
FTK Imager
Volatility
HashCalc
Es un programa de calculadora desarrollado por SlavaSoft
HashCalc
Belkasoft Live RAM capturer
Volatility
For volatile memory analysis there are several tools such as:
Volatility
Belkasoft Live RAM capturer
HashCalc
It must be accurate, comprehensive, unbiased, recorded, repeatable, and completed within the available time frames and allocated resources.
Computer forensic analysis
The computer expert
Volatility
It is used behind the scenes in Autopsy and in many other commercial and open source forensic tools.
Encase Forensics
Sleuth kit
SIFT Workstation 3
Quickly search, identify and prioritize potential evidence, on computers and mobile devices, to determine if further investigation is warranted.
Encase Forensics
Digital forensics
safety
Forensics v6
It is a group of open source free incident response and forensic tools designed to perform detailed digital forensic examinations in a variety of environments.
Access Data Registry Viewer.
SIFT Workstation 3
Sleuthkit
Provides one of the fastest and most powerful ways to locate files On a Windows computer. You can search by file Name, size, creation and modification dates, and other criteria
OsForensics v6
SIFT Workstation 3
Forense digital
Reveal when a document first appeared On a computer, when it was last edited, when it was last saved or printed, and which user performed these actions.
Defense in depth
Safety
Computer forensic examination
The implementation of this type of security model in which the principles of computer forensics are also adopted is also known as:
Defense in depth
Safety
Criminology
Vulnerability and testing
