wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Risk Management and Backup Strategies

Total questions: 95

Worksheet time: 48mins

Name
Class
Date
1.

What stages does the risk management process include? Choose the correct chain:

a)

Risk identification - Risk assessment - Defining risk tolerance and appetite - Risk mitigation measures

b)

Risk identification - Risk assessment - Risk prioritization - Defining risk tolerance and appetite - Risk mitigation measures

c)

Risk identification - Risk prioritization - Risk assessment - Defining risk tolerance and appetite - Risk mitigation measures

2.

A company performs a backup strategy where the first backup copies all data, and subsequent backups copy only the changes made since the last full backup, without relying on other intermediate backups. Which type of backup is this?

a)

Full Backup

b)

Incremental Backup

c)

Differential Backup

3.

Which of the following situations is an example of insourced offshore IT service delivery?

a)

An international company opens its own development center in another country for performing IT services.

b)

The company signs a contract with a local IT firm to provide technical support.

c)

An IT company engages a foreign contractor to perform software developments.

d)

The company sets up a joint venture with a local firm to manage IT services in another country.

4.

Choose the correct chain for developing performance metrics:

a)

Identify expected outputs - process to compare actual output with target - identify critical processes

b)

Identify expected outputs - identify critical processes - process to compare actual output with target

c)

Identify critical processes - process to compare actual output with target - Identify expected outputs

d)

Identify critical processes - Identify expected outputs - process to compare actual output with target

5.

Which of the following processes can be described as: "This is a method for performing tests or reviews to verify that the product is free of defects and meets the user's requirements?"

a)

Quality assurance

b)

Quality control

c)

IT balance scorecard

d)

User acceptance testing

6.

Which of the following is relevant to the results of a Business Impact Analysis (BIA)?

a)

Estimating the cost of downtime and developing alternative data collection methods.

b)

Identify key business processes and their recovery times.

c)

Analyzing risks and developing strategies to minimize them.

d)

Developing the company's information security policy.

7.

Which type of systems can be described as: "Functions of this system cannot be performed unless they are replaced by identical capabilities. Critical applications cannot be replaced by manual methods. Tolerance to interruption is very low; therefore, cost of interruption is very high."

a)

Vital

b)

Sensitive

c)

Critical

d)

Non-sensitive

8.

What is system resiliency?

a)

The ability of a system to prevent unauthorized access and ensure data security.

b)

The capability of a system to adapt, recover, and maintain functionality after disruptions.

c)

The speed at which a system can process large amounts of data under high load conditions.

d)

The process of continuously upgrading system hardware and software to avoid failures.

9.

A company has implemented a clustered database system. In this system, all nodes process requests simultaneously, distributing the load and ensuring high availability. Which cluster configuration is being used?

a)

Active-Passive

b)

Active-Active

c)

Primary-Secondary

d)

Fault-Tolerant

10.

Which type of document is described in following statement: "A third-party expert opinion on the organization's compliance with the essential requirements and the provision of appropriate controls"

a)

SOC

b)

SLA

c)

MDA

d)

SOW

11.

Which of the following statements correctly distinguishes between a full backup and an incremental backup?

a)

A full backup copies only the files that have changed since the last backup, while an incremental backup copies all files.

b)

A full backup copies all files and data, while an incremental backup copies only the changes made since the last backup.

c)

A full backup requires less storage space than an incremental backup, as it includes only critical files.

d)

A full backup is faster to create than an incremental backup because it skips unchanged files.

12.

Which of the following BCP testing methods is the riskiest?

a)

Desk-based evaluation

b)

Preparedness test

c)

Full operational test

13.

What is the difference between BCP and DRP?

a)

BCP is broader and covers all aspects of organizational continuity, while DRP is focused on IT systems recovery.

b)

DRP includes the management of non-IT assets, while BCP excludes them.

c)

BCP ensures minimal disruption to business operations, while DRP focuses on recovery speed.

d)

DRP includes contingency planning for data breaches, while BCP excludes security issues.

14.

All of these apply to the description of the DRP except

a)

Focuses on restoring IT systems and data after a disruption.

b)

Ensures the continuation of critical business processes during any interruption.

c)

Includes detailed recovery plans for hardware, software, and network infrastructure.

d)

Is activated after a disaster has already occurred.

15.

A company determines that its email system must be restored within 4 hours to avoid significant business impact. This 4-hour timeframe is an example of:

a)

Recovery Time Objective (RTO)

b)

Recovery Point Objective (RPO)

c)

Maximum Tolerable Downtime (MTD)

d)

Service Level Agreement (SLA)

16.

Which of the following best describes the Recovery Point Objective (RPO)?

a)

The maximum acceptable time a system can be offline during a disaster.

b)

The maximum amount of data that can be lost during a disaster.

c)

The time required to switch to a backup system.

d)

The frequency at which backups are created.

17.

If a company has an RTO of 2 hours and an RPO of 30 minutes, which of the following scenarios meets both objectives?

a)

The system is restored 3 hours after failure with 15 minutes of data lost.

b)

The system is restored 2 hours after failure with 1 hour of data lost.

c)

The system is restored 1 hour after failure with 25 minutes of data lost.

d)

The system is restored 1.5 hours after failure with 40 minutes of data lost.

18.

Which strategy should be taken?

a)

Mirroring\ Real-time replication + active-active clustering

b)

Mirroring\ Real-time replication + active-passive clustering

c)

Snapshots +active-active clustering

d)

Snapshots + active-passive clustering

19.

What other approach can you consider?

a)

Going back to desktops instead of servers

b)

Using only desktops to reduce costs

c)

Using a Reciprocal Agreement

d)

Outsourcing the entire IT department

20.

Choose the correct end of sentence: Short-term interruptions…

a)

Last from a few millionths to a few thousandths of a second and can be controlled by uninterruptible power supply (UPS) devices.

b)

Last from a few seconds to 30 minutes and can be prevented by using properly placed surge protectors.

c)

Last from a few millionths to a few thousandths of a second and can be prevented by using properly placed surge protectors.

d)

Last from a few seconds to 30 minutes Can be controlled by uninterruptible power supply (UPS) devices.

21.

The number of times an individual not granted authority to use a system is falsely accepted by the system is:

a)

FAR

b)

FER

c)

FRR

d)

EER

22.

A network device that sends messages only to designated devices and can store MAC addresses in a lookup table is called:

a)

Hub

b)

Switch

c)

Router

d)

Gateway

23.

Which firewall implementation scheme consists of 2 NIC-s, bastion host and 1 packet filtering router?

a)

Dual-Homed firewall

b)

Screened-host firewall

c)

Screened-subnet firewall

d)

Demilitarized zone

24.

Performing the audit is an example of which types of control?

a)

Managerial + preventive

b)

Detective + physical

c)

Managerial+ detective

d)

Corrective + managerial

25.

What is an example of certification authority in Kazakhstan?

a)

National Certification Center of the Republic of Kazakhstan (NCC RK) - НУЦ РК

b)

E-gov

c)

State Information Center "Infocom" under the Agency of the Republic of Kazakhstan for Civil Service and Counteraction to Corruption

26.

Which type of cloud solution might be the most suitable for your company?

a)

Public Cloud

b)

Private Cloud

c)

Hybrid Cloud

d)

Community Cloud

27.

Which type of cloud service model is most suitable for your company?

a)

Infrastructure as a Service (IaaS)

b)

Platform as a Service (PaaS)

c)

Software as a Service (SaaS)

28.

Choose the correct chain to create a "hosted virtualization":

a)

Host hardware - host OS - hypervisor - guest OS - app

b)

Host hardware - hypervisor - host OS - guest OS - app

c)

Host hardware - hypervisor - guest OS - app

d)

Host hardware - guest OS - hypervisor - app

29.

To meet the legal requirements and ensure the privacy and protection of customer data, which of the following regulations should your company comply with?

a)

GDPR (General Data Protection Regulation)

b)

HIPAA (Health Insurance Portability and Accountability Act)

c)

PCI DSS (Payment Card Industry Data Security Standard)

d)

OWASP (Open Web Application Security Project)

30.

What is ITIL?

a)

A programming language that is primarily used for system-level programming in embedded systems.

b)

A software application used for project management.

c)

A set of detailed practices for IT service management (ITSM) that focuses on aligning IT services with the needs of business.

d)

A cloud computing platform offering various services including compute power, database storage, and content delivery.

31.

What stages does the risk management process include? Choose the correct chain:

a)

Risk identification - Risk assessment - Defining risk tolerance and appetite - Risk mitigation measures

b)

Risk identification - Risk assessment - Risk prioritization - Defining risk tolerance and appetite - Risk mitigation measures

c)

Risk identification - Risk prioritization - Risk assessment - Defining risk tolerance and appetite - Risk mitigation measures

32.

A company performs a backup strategy where the first backup copies all data, and subsequent backups copy only the changes made since the last full backup, without relying on other intermediate backups. Which type of backup is this?

a)

Full Backup

b)

Incremental Backup

c)

Differential Backup

33.

Which of the following situations is an example of outsource onsite IT service delivery?

a)

A company hires an external IT provider to work directly at the company's headquarters.

b)

A company establishes its own IT team at a foreign location to handle local IT operations.

c)

An organization contracts a foreign IT vendor to deliver services from their home country.

d)

A business opens an offshore development center to manage internal IT services.

34.

Choose the correct chain for developing performance metrics:

a)

Identify expected outputs - process to compare actual output with target - identify critical processes

b)

Identify expected outputs - identify critical processes - process to compare actual output with target

35.

Which of the following processes can be described as: "This is a process that aims to provide adequate confidence that an item or product conforms to the requirements developed. QA staff verify that changes to the system are approved, checked, and implemented in a controlled manner."

a)

Quality assurance

b)

Quality control

c)

IT balance scorecard

d)

User acceptance testing

36.

Which of the following is relevant to the results of a Business Impact Analysis (BIA)?

a)

Estimating the cost of downtime and developing alternative data collection methods.

b)

Identify key business processes and their recovery times.

c)

Analyzing risks and developing strategies to minimize them.

d)

Developing the company's information security policy.

37.

Which type of systems can be described as: "These functions can be performed manually, at a tolerable cost and for an extended period of time. While they can be performed manually, it usually is a difficult process and requires additional staff to perform."

a)

Vital

b)

Sensitive

c)

Critical

d)

Non-sensitive

38.

What is system resiliency?

a)

The ability of a system to prevent unauthorized access and ensure data security.

b)

The capability of a system to adapt, recover, and maintain functionality after disruptions.

c)

The speed at which a system can process large amounts of data under high load conditions.

d)

The process of continuously upgrading system hardware and software to avoid failures.

39.

A company has set up a clustered web server. In this setup, one server actively handles all requests, while the other server remains on standby, ready to take over in case of failure. Which cluster configuration is being used?

a)

Active-Active

b)

Active-Passive

c)

Load-Balanced

d)

High-Performance

40.

Which type of document is described in following statement: "A third-party expert opinion on the organization's compliance with the essential requirements and the provision of appropriate controls"

a)

SOC

b)

SLA

c)

MDA

d)

SOW

41.

Which of the following statements correctly distinguishes between a full backup and an incremental backup?

a)

A full backup copies only the files that have changed since the last backup, while an incremental backup copies all files.

b)

A full backup copies all files and data, while an incremental backup copies only the changes made since the last backup.

c)

A full backup requires less storage space than an incremental backup, as it includes only critical files.

d)

A full backup is faster to create than an incremental backup because it skips unchanged files.

42.

Which of the following BCP testing methods provides an opportunity to simulate a system crash?

a)

Desk-based evaluation

b)

Preparedness test

c)

Full operational test

43.

All of these apply to the description of the DRP except

a)

Is a subset of the overall business continuity strategy.

b)

Focuses on IT systems rather than broader organizational processes.

c)

Involves routine operational planning for business disruptions.

d)

Provides a framework for recovering servers, databases, and applications.

44.

What is the difference between BCP and DRP?

a)

BCP focuses on maintaining critical business functions, while DRP focuses on restoring IT systems after a disaster.

b)

DRP includes all aspects of organizational continuity, while BCP focuses only on IT systems.

c)

BCP ensures rapid disaster recovery, while DRP is concerned with long-term business strategies.

d)

There is no difference; both terms mean the same.

45.

The finance department requires that no more than 15 minutes of transaction data is lost in case of a system failure. This 15-minute limit represents:

a)

Recovery Time Objective (RTO)

b)

Recovery Point Objective (RPO)

c)

Data Retention Policy

d)

Backup Cycle

46.

Which of the following best describes the Recovery Point Objective (RPO)?

a)

The maximum acceptable time a system can be offline during a disaster.

b)

The maximum amount of data that can be lost during a disaster.

c)

The time required to switch to a backup system.

d)

The frequency at which backups are created.

47.

If a company has an RTO of 2 hours and an RPO of 30 minutes, which of the following scenarios meets both objectives?

a)

The system is restored 3 hours after failure with 15 minutes of data lost.

b)

The system is restored 2 hours after failure with 1 hour of data lost.

c)

The system is restored 1 hour after failure with 25 minutes of data lost.

d)

The system is restored 1.5 hours after failure with 40 minutes of data lost.

48.

RTO = 1-4 hrs, RPO = 0-1 hrs. Which strategy should be taken?

a)

Mirroring\ Real-time replication + active-active clustering

b)

Mirroring\ Real-time replication + active-passive clustering

c)

Snapshots +active-active clustering

d)

Snapshots + active-passive clustering

49.

Your company is looking for a way to ensure business continuity in the event of a catastrophic situation unrelated to natural disasters. You have considered various options, including renting a hot site, utilizing cloud services, and installing your own equipment at an alternate location. However, all of these options have proven to be very costly. What other approach can you consider?

a)

Going back to desktops instead of servers

b)

Using only desktops to reduce costs

c)

Using a Reciprocal Agreement

d)

Outsourcing the entire IT department

50.

Choose the correct end of sentence: "Intermediate-term interruptions…"

a)

Last from a few millionths to a few thousandths of a second and can be controlled by uninterruptible power supply (UPS) devices.

b)

Last from a few seconds to 30 minutes and can be prevented by using properly placed surge protectors.

c)

Last from a few millionths to a few thousandths of a second and can be prevented by using properly placed surge protectors.

d)

Last from a few seconds to 30 minutes Can be controlled by uninterruptible power supply (UPS) devices.

51.

The number of times an individual not granted authority to use a system is falsely accepted by the system is:

a)

FAR

b)

FER

c)

FRR

d)

EER

52.

A network device that sends messages only to designated devices and can store MAC addresses in a lookup table is called:

a)

Hub

b)

Switch

c)

Router

d)

Gateway

53.

Which firewall implementation scheme consists of 2 NIC-s, bastion host and 1 packet filtering router?

a)

Dual-Homed firewall

b)

Screened-host firewall

c)

Screened-subnet firewall

d)

Demilitarized zone

54.

Performing the audit is an example of which types of control?

a)

Managerial + preventive

b)

Detective + physical

c)

Managerial+ detective

d)

Corrective + managerial

55.

What is an example of certification authority in Kazakhstan?

a)

National Certification Center of the Republic of Kazakhstan (NCC RK) - НУЦ РК

b)

E-gov

c)

State Information Center "Infocom" under the Agency of the Republic of Kazakhstan for Civil Service and Counteraction to Corruption (Государственный Центр Информации "Инфоком" при Агентстве Республики Казахстан по делам государственной службы и противодействию коррупции)

56.

You're a healthcare organization that handles highly sensitive patient data. For some of your less sensitive and flexible workloads, you're open to using scalable cloud solutions. However, there are regulation requirements that dictate that certain patient information must be kept on-premise. What cloud deployment model would be the best fit for your requirements?

a)

Public Cloud

b)

Private Cloud

c)

Hybrid Cloud

d)

Community Cloud

57.

Your company wants to implement a new email system. You require a solution that doesn't require hardware provisioning, software management, patching or updates, but at the same time offering broad accessibility and reliability. What kind of cloud service model would best serve your company?

a)

Infrastructure as a Service (IaaS)

b)

Platform as a Service (PaaS)

c)

Software as a Service (SaaS)

58.

Choose the correct chain to create a "bare metal virtualization":

a)

Host hardware - host OS - hypervisor - guest OS - app

b)

Host hardware - hypervisor - host OS - guest OS - app

c)

Host hardware - hypervisor - guest OS - app

d)

Host hardware - guest OS - hypervisor - app

59.

Your company is a healthcare provider that manages protected health information (PHI) of patients in the United States. In order to comply with the standards to protect the privacy and security of such confidential information, which regulation should your company follow?

a)

GDPR (General Data Protection Regulation)

b)

HIPAA (Health Insurance Portability and Accountability Act)

c)

PCI DSS (Payment Card Industry Data Security Standard)

d)

OWASP (Open Web Application Security Project)

60.

What is ITIL?

a)

A programming language that is primarily used for system-level programming in embedded systems.

b)

A software application used for project management.

c)

A set of detailed practices for IT service management (ITSM) that focuses on aligning IT services with the needs of business.

d)

A cloud computing platform offering various services including compute power, database storage, and content delivery.

61.

Which backup strategy requires the most storage capacity?

a)

Incremental Backup

b)

Differential Backup

c)

Full Backup

d)

Cloud Backup

62.

Which of the following systems has the lowest tolerance for interruption?

a)

Vital systems

b)

Critical systems

c)

Sensitive systems

d)

Nonsensitive systems

63.

Which plan has the broader scope, Business Continuity Planning (BCP) or Disaster Recovery Planning (DRP)?

a)

BCP, as it focuses on maintaining all business operations after a disaster.

b)

DRP, as it focuses on maintaining all business operations after a disaster.

c)

Both BCP and DRP have the same scope.

d)

Neither BCP nor DRP cover the scope of keeping the business running.

64.

Which of the following is an example of a preventive technical control?

a)

Login screen

b)

Network isolation

c)

Manual fire alarms

d)

Intrusion detection system

65.

Which cloud computing model provides complete software solutions?

a)

IaaS

b)

PaaS

c)

SaaS

d)

DaaS

66.

What is a characteristic of the public cloud?

a)

Exclusive to a single organization

b)

Open to all on a pay-per-use basis

c)

Managed by a specific community

d)

A mix of private and community clouds

67.

Which virtualization type involves a hypervisor running directly on hardware?

a)

Bare-metal virtualization

b)

Hosted virtualization

c)

Containerization

d)

Hybrid virtualization

68.

What is the purpose of an uninterruptible power supply (UPS)?

a)

To increase voltage during surges

b)

To provide backup power during outages

c)

To reduce energy consumption

d)

To regulate server temperatures

69.

What is the function of the hypervisor?

a)

Distributes private keys

b)

Manages virtual resources

c)

Protects from external attacks

d)

Monitors environmental controls

70.

Which document describes the practices of a CA?

a)

PKI Process Document

b)

Certification Practice Statement (CPS)

c)

Certificate Revocation

71.

If a primary site goes down at 2 PM and resumes at 5 PM in accordance with defined metrics, what is the RTO?

a)

2 hours

b)

3 hours

c)

4 hours

d)

1 hour.

72.

SSO reduces the risk of a single point of failure.

a)

True

b)

False

73.

Which of the following statements accurately describes the difference between SOC 1, SOC 2, and SOC 3 reports?

a)

SOC 1 details a company's internal control over financial reporting, SOC 2 evaluates controls relevant to one or more of the five Trust Service Criteria (security, availability, processing integrity, confidentiality, and privacy), and SOC 3 is a simplified version of SOC 2 meant for public disclosure.

b)

SOC 1 reports are targeted at the company's management, SOC 2 at the auditors, and SOC 3 is for the public.

c)

SOC 1, SOC 2, and SOC 3 are all focused on financial reporting only with varying levels of detail.

d)

SOC 1 and SOC 2 reports contain the same information, while SOC 3 reports focus on privacy controls.

74.

Which of the following examples is an example of onsite insource model of service delivery?

a)

Developers from an external company work in the customer's office.

b)

An internal team of company employees works in the

75.

the following examples is an example of onsite insource model of service delivery?

a)

Developers from an external company work in the customer's office.

b)

An internal team of company employees works in the company's office.

c)

Developers from another country work remotely.

d)

An external contractor works on the project from their own office.

76.

Which of the following examples corresponds to the offshore outsource model of service delivery?

a)

The company hires local employees to perform tasks on the customer's territory.

b)

The work is done by a third-party contractor from another country.

c)

Internal staff works remotely from another country.

d)

An external contractor performs tasks from the customer's office.

77.

Which scenario illustrates the hybrid model of service delivery?

a)

Part of the tasks is performed by the internal team and the rest is done by a third-party contractor.

b)

All work is done by a third-party contractor abroad.

c)

Internal staff does all the work on their own.

d)

An external contractor works exclusively in the client's office.

78.

RTO= 0-1 hour, RPO = 4-24. Choose the strategy depending on identified RTO and RPO:

a)

Tape backups, active-passive clustering

b)

Mirroring, cold standby

c)

Tape backups, active-active clustering

d)

Mirroring, active-active clustering

79.

What is the advantage of active-active clustering mode over active-passive?

a)

Reduced hardware costs.

b)

More even load distribution and improved performance.

c)

Faster recovery from an active-server failure.

d)

Eliminating the need for system monitoring.

80.

Which of the following metrics can be identified as: "This is a metric used in biometric security systems to measure the effectiveness of the system in identifying individuals correctly. This metric is the point at which the false acceptance rate and false rejection rate are equal":

a)

FAR

b)

FER

c)

FRR

d)

EER

81.

Which firewall implementation scheme consists of 1 NIC, bastion host and 1 packet filtering router?

a)

Dual-Homed firewall

b)

Screened-host firewall

c)

Screened-subnet firewall

d)

Demilitarized zone

82.

What is an Application-Level firewall and at which layer of the OSI model does it operate?

a)

Filters traffic based on user identity, operates at the presentation layer.

b)

Provides a separate proxy for each application, operates at the application layer.

c)

Allows traffic based on the type of connection, operates at the session layer.

d)

Operates at the transport layer, filtering traffic based on TCP or UDP sessions.

83.

What does SSID stands for?

a)

Secure System Identifier

b)

Service Set Identifier

c)

Standard Signal Integration Device

d)

Server Subnet Identification

84.

What is an example of PKI in Kazakhstan?

a)

National Certification Center of the Republic of Kazakhstan (NCC RK) - НУЦ РК

b)

E-gov

c)

State Information Center "Infocom" under the Agency of the Republic of Kazakhstan for Civil Service and Counteraction to Corruption (Государственный Центр Информации "Инфоком" при Агентстве Республики Казахстан по делам государственной службы и противодействию коррупции)

d)

The company wants to organize secure collaborative editing of documents between departments without worrying about infrastructure setup and software updates.

85.

The company wants to organize secure collaborative editing of documents between departments without worrying about infrastructure setup and software updates. Employees should have access to the documents via a web browser. Which type of cloud service is best suited for this situation?

a)

SaaS

b)

PaaS

c)

IaaS

d)

Private Cloud

86.

The company developers need a platform to create, test and deploy web applications. They don't want to deal with server configuration or operating system management, but they need to have full control over application development. Which type of cloud service is best suited for this situation?

a)

SaaS

b)

PaaS

c)

IaaS

d)

Public Cloud

87.

The organization conducts open educational courses and uses the cloud to store learning materials. These materials should be accessible to all users via the internet. Which type of cloud solution is most suitable for this situation?

a)

Public Cloud

b)

Private Cloud

c)

Hybrid Cloud

d)

PaaS

88.

A bank is developing an internal system for processing transactions. The transaction data must be highly confidential, so only company employees should have access to the system. Which type of cloud solution is most suitable for this situation?

a)

Public Cloud

b)

Private Cloud

c)

Hybrid Cloud

d)

IaaS

89.

Steve, a regular employee, tried to modify the access control filters for a particular database. However, he was unable to do so. What type of access control system is likely in place?

a)

Discretionary Access Control (DAC), as these cannot be modified by normal users.

b)

Both MAC and DAC, as both cannot be modified by normal users.

c)

Mandatory Access Control (MAC), as these cannot be modified by normal users.

d)

Neither MAC nor DAC, as both can be easily modified by normal users

90.

Which of the following is NOT a risk when using virtualization?

a)

Software compatibility issues

b)

Risk associated with multi-tenant access

c)

Reduction in operational costs

d)

Vulnerability to "neighbor" attacks

91.

What kind of encryption is used in PKI?

a)

Symmetric encryption

b)

Asymmetric encryption

c)

Basic encryption

d)

Non-reversible encryption

92.

Which backup strategy requires the most storage capacity?

a)

Incremental Backup

b)

Differential Backup

c)

Full Backup

d)

Cloud Backup

93.

Which of the following systems has the lowest tolerance for interruption?

a)

Vital systems

b)

Critical systems

c)

Sensitive systems

d)

Nonsensitive systems

94.

Which plan has the broader scope, Business Continuity Planning (BCP) or Disaster Recovery Planning (DRP)?

a)

BCP, as it focuses on maintaining all business operations after a disaster.

b)

DRP, as it focuses on maintaining all business operations after a disaster.

c)

Both BCP and DRP have the same scope.

d)

Neither BCP nor DRP cover the scope of keeping the business running.

95.

Which statement best describes a Disaster Recovery Plan (DRP)?

a)

It details the steps required to restore full business operations after a disruption.

b)

It is a plan detailing how to handle minor disruptions.