Font size
WorksheetsRisk Management and Backup Strategies
Total questions: 95
Worksheet time: 48mins
What stages does the risk management process include? Choose the correct chain:
Risk identification - Risk assessment - Defining risk tolerance and appetite - Risk mitigation measures
Risk identification - Risk assessment - Risk prioritization - Defining risk tolerance and appetite - Risk mitigation measures
Risk identification - Risk prioritization - Risk assessment - Defining risk tolerance and appetite - Risk mitigation measures
A company performs a backup strategy where the first backup copies all data, and subsequent backups copy only the changes made since the last full backup, without relying on other intermediate backups. Which type of backup is this?
Full Backup
Incremental Backup
Differential Backup
Which of the following situations is an example of insourced offshore IT service delivery?
An international company opens its own development center in another country for performing IT services.
The company signs a contract with a local IT firm to provide technical support.
An IT company engages a foreign contractor to perform software developments.
The company sets up a joint venture with a local firm to manage IT services in another country.
Choose the correct chain for developing performance metrics:
Identify expected outputs - process to compare actual output with target - identify critical processes
Identify expected outputs - identify critical processes - process to compare actual output with target
Identify critical processes - process to compare actual output with target - Identify expected outputs
Identify critical processes - Identify expected outputs - process to compare actual output with target
Which of the following processes can be described as: "This is a method for performing tests or reviews to verify that the product is free of defects and meets the user's requirements?"
Quality assurance
Quality control
IT balance scorecard
User acceptance testing
Which of the following is relevant to the results of a Business Impact Analysis (BIA)?
Estimating the cost of downtime and developing alternative data collection methods.
Identify key business processes and their recovery times.
Analyzing risks and developing strategies to minimize them.
Developing the company's information security policy.
Which type of systems can be described as: "Functions of this system cannot be performed unless they are replaced by identical capabilities. Critical applications cannot be replaced by manual methods. Tolerance to interruption is very low; therefore, cost of interruption is very high."
Vital
Sensitive
Critical
Non-sensitive
What is system resiliency?
The ability of a system to prevent unauthorized access and ensure data security.
The capability of a system to adapt, recover, and maintain functionality after disruptions.
The speed at which a system can process large amounts of data under high load conditions.
The process of continuously upgrading system hardware and software to avoid failures.
A company has implemented a clustered database system. In this system, all nodes process requests simultaneously, distributing the load and ensuring high availability. Which cluster configuration is being used?
Active-Passive
Active-Active
Primary-Secondary
Fault-Tolerant
Which type of document is described in following statement: "A third-party expert opinion on the organization's compliance with the essential requirements and the provision of appropriate controls"
SOC
SLA
MDA
SOW
Which of the following statements correctly distinguishes between a full backup and an incremental backup?
A full backup copies only the files that have changed since the last backup, while an incremental backup copies all files.
A full backup copies all files and data, while an incremental backup copies only the changes made since the last backup.
A full backup requires less storage space than an incremental backup, as it includes only critical files.
A full backup is faster to create than an incremental backup because it skips unchanged files.
Which of the following BCP testing methods is the riskiest?
Desk-based evaluation
Preparedness test
Full operational test
What is the difference between BCP and DRP?
BCP is broader and covers all aspects of organizational continuity, while DRP is focused on IT systems recovery.
DRP includes the management of non-IT assets, while BCP excludes them.
BCP ensures minimal disruption to business operations, while DRP focuses on recovery speed.
DRP includes contingency planning for data breaches, while BCP excludes security issues.
All of these apply to the description of the DRP except
Focuses on restoring IT systems and data after a disruption.
Ensures the continuation of critical business processes during any interruption.
Includes detailed recovery plans for hardware, software, and network infrastructure.
Is activated after a disaster has already occurred.
A company determines that its email system must be restored within 4 hours to avoid significant business impact. This 4-hour timeframe is an example of:
Recovery Time Objective (RTO)
Recovery Point Objective (RPO)
Maximum Tolerable Downtime (MTD)
Service Level Agreement (SLA)
Which of the following best describes the Recovery Point Objective (RPO)?
The maximum acceptable time a system can be offline during a disaster.
The maximum amount of data that can be lost during a disaster.
The time required to switch to a backup system.
The frequency at which backups are created.
If a company has an RTO of 2 hours and an RPO of 30 minutes, which of the following scenarios meets both objectives?
The system is restored 3 hours after failure with 15 minutes of data lost.
The system is restored 2 hours after failure with 1 hour of data lost.
The system is restored 1 hour after failure with 25 minutes of data lost.
The system is restored 1.5 hours after failure with 40 minutes of data lost.
Which strategy should be taken?
Mirroring\ Real-time replication + active-active clustering
Mirroring\ Real-time replication + active-passive clustering
Snapshots +active-active clustering
Snapshots + active-passive clustering
What other approach can you consider?
Going back to desktops instead of servers
Using only desktops to reduce costs
Using a Reciprocal Agreement
Outsourcing the entire IT department
Choose the correct end of sentence: Short-term interruptions…
Last from a few millionths to a few thousandths of a second and can be controlled by uninterruptible power supply (UPS) devices.
Last from a few seconds to 30 minutes and can be prevented by using properly placed surge protectors.
Last from a few millionths to a few thousandths of a second and can be prevented by using properly placed surge protectors.
Last from a few seconds to 30 minutes Can be controlled by uninterruptible power supply (UPS) devices.
The number of times an individual not granted authority to use a system is falsely accepted by the system is:
FAR
FER
FRR
EER
A network device that sends messages only to designated devices and can store MAC addresses in a lookup table is called:
Hub
Switch
Router
Gateway
Which firewall implementation scheme consists of 2 NIC-s, bastion host and 1 packet filtering router?
Dual-Homed firewall
Screened-host firewall
Screened-subnet firewall
Demilitarized zone
Performing the audit is an example of which types of control?
Managerial + preventive
Detective + physical
Managerial+ detective
Corrective + managerial
What is an example of certification authority in Kazakhstan?
National Certification Center of the Republic of Kazakhstan (NCC RK) - НУЦ РК
E-gov
State Information Center "Infocom" under the Agency of the Republic of Kazakhstan for Civil Service and Counteraction to Corruption
Which type of cloud solution might be the most suitable for your company?
Public Cloud
Private Cloud
Hybrid Cloud
Community Cloud
Which type of cloud service model is most suitable for your company?
Infrastructure as a Service (IaaS)
Platform as a Service (PaaS)
Software as a Service (SaaS)
Choose the correct chain to create a "hosted virtualization":
Host hardware - host OS - hypervisor - guest OS - app
Host hardware - hypervisor - host OS - guest OS - app
Host hardware - hypervisor - guest OS - app
Host hardware - guest OS - hypervisor - app
To meet the legal requirements and ensure the privacy and protection of customer data, which of the following regulations should your company comply with?
GDPR (General Data Protection Regulation)
HIPAA (Health Insurance Portability and Accountability Act)
PCI DSS (Payment Card Industry Data Security Standard)
OWASP (Open Web Application Security Project)
What is ITIL?
A programming language that is primarily used for system-level programming in embedded systems.
A software application used for project management.
A set of detailed practices for IT service management (ITSM) that focuses on aligning IT services with the needs of business.
A cloud computing platform offering various services including compute power, database storage, and content delivery.
What stages does the risk management process include? Choose the correct chain:
Risk identification - Risk assessment - Defining risk tolerance and appetite - Risk mitigation measures
Risk identification - Risk assessment - Risk prioritization - Defining risk tolerance and appetite - Risk mitigation measures
Risk identification - Risk prioritization - Risk assessment - Defining risk tolerance and appetite - Risk mitigation measures
A company performs a backup strategy where the first backup copies all data, and subsequent backups copy only the changes made since the last full backup, without relying on other intermediate backups. Which type of backup is this?
Full Backup
Incremental Backup
Differential Backup
Which of the following situations is an example of outsource onsite IT service delivery?
A company hires an external IT provider to work directly at the company's headquarters.
A company establishes its own IT team at a foreign location to handle local IT operations.
An organization contracts a foreign IT vendor to deliver services from their home country.
A business opens an offshore development center to manage internal IT services.
Choose the correct chain for developing performance metrics:
Identify expected outputs - process to compare actual output with target - identify critical processes
Identify expected outputs - identify critical processes - process to compare actual output with target
Which of the following processes can be described as: "This is a process that aims to provide adequate confidence that an item or product conforms to the requirements developed. QA staff verify that changes to the system are approved, checked, and implemented in a controlled manner."
Quality assurance
Quality control
IT balance scorecard
User acceptance testing
Which of the following is relevant to the results of a Business Impact Analysis (BIA)?
Estimating the cost of downtime and developing alternative data collection methods.
Identify key business processes and their recovery times.
Analyzing risks and developing strategies to minimize them.
Developing the company's information security policy.
Which type of systems can be described as: "These functions can be performed manually, at a tolerable cost and for an extended period of time. While they can be performed manually, it usually is a difficult process and requires additional staff to perform."
Vital
Sensitive
Critical
Non-sensitive
What is system resiliency?
The ability of a system to prevent unauthorized access and ensure data security.
The capability of a system to adapt, recover, and maintain functionality after disruptions.
The speed at which a system can process large amounts of data under high load conditions.
The process of continuously upgrading system hardware and software to avoid failures.
A company has set up a clustered web server. In this setup, one server actively handles all requests, while the other server remains on standby, ready to take over in case of failure. Which cluster configuration is being used?
Active-Active
Active-Passive
Load-Balanced
High-Performance
Which type of document is described in following statement: "A third-party expert opinion on the organization's compliance with the essential requirements and the provision of appropriate controls"
SOC
SLA
MDA
SOW
Which of the following statements correctly distinguishes between a full backup and an incremental backup?
A full backup copies only the files that have changed since the last backup, while an incremental backup copies all files.
A full backup copies all files and data, while an incremental backup copies only the changes made since the last backup.
A full backup requires less storage space than an incremental backup, as it includes only critical files.
A full backup is faster to create than an incremental backup because it skips unchanged files.
Which of the following BCP testing methods provides an opportunity to simulate a system crash?
Desk-based evaluation
Preparedness test
Full operational test
All of these apply to the description of the DRP except
Is a subset of the overall business continuity strategy.
Focuses on IT systems rather than broader organizational processes.
Involves routine operational planning for business disruptions.
Provides a framework for recovering servers, databases, and applications.
What is the difference between BCP and DRP?
BCP focuses on maintaining critical business functions, while DRP focuses on restoring IT systems after a disaster.
DRP includes all aspects of organizational continuity, while BCP focuses only on IT systems.
BCP ensures rapid disaster recovery, while DRP is concerned with long-term business strategies.
There is no difference; both terms mean the same.
The finance department requires that no more than 15 minutes of transaction data is lost in case of a system failure. This 15-minute limit represents:
Recovery Time Objective (RTO)
Recovery Point Objective (RPO)
Data Retention Policy
Backup Cycle
Which of the following best describes the Recovery Point Objective (RPO)?
The maximum acceptable time a system can be offline during a disaster.
The maximum amount of data that can be lost during a disaster.
The time required to switch to a backup system.
The frequency at which backups are created.
If a company has an RTO of 2 hours and an RPO of 30 minutes, which of the following scenarios meets both objectives?
The system is restored 3 hours after failure with 15 minutes of data lost.
The system is restored 2 hours after failure with 1 hour of data lost.
The system is restored 1 hour after failure with 25 minutes of data lost.
The system is restored 1.5 hours after failure with 40 minutes of data lost.
RTO = 1-4 hrs, RPO = 0-1 hrs. Which strategy should be taken?
Mirroring\ Real-time replication + active-active clustering
Mirroring\ Real-time replication + active-passive clustering
Snapshots +active-active clustering
Snapshots + active-passive clustering
Your company is looking for a way to ensure business continuity in the event of a catastrophic situation unrelated to natural disasters. You have considered various options, including renting a hot site, utilizing cloud services, and installing your own equipment at an alternate location. However, all of these options have proven to be very costly. What other approach can you consider?
Going back to desktops instead of servers
Using only desktops to reduce costs
Using a Reciprocal Agreement
Outsourcing the entire IT department
Choose the correct end of sentence: "Intermediate-term interruptions…"
Last from a few millionths to a few thousandths of a second and can be controlled by uninterruptible power supply (UPS) devices.
Last from a few seconds to 30 minutes and can be prevented by using properly placed surge protectors.
Last from a few millionths to a few thousandths of a second and can be prevented by using properly placed surge protectors.
Last from a few seconds to 30 minutes Can be controlled by uninterruptible power supply (UPS) devices.
The number of times an individual not granted authority to use a system is falsely accepted by the system is:
FAR
FER
FRR
EER
A network device that sends messages only to designated devices and can store MAC addresses in a lookup table is called:
Hub
Switch
Router
Gateway
Which firewall implementation scheme consists of 2 NIC-s, bastion host and 1 packet filtering router?
Dual-Homed firewall
Screened-host firewall
Screened-subnet firewall
Demilitarized zone
Performing the audit is an example of which types of control?
Managerial + preventive
Detective + physical
Managerial+ detective
Corrective + managerial
What is an example of certification authority in Kazakhstan?
National Certification Center of the Republic of Kazakhstan (NCC RK) - НУЦ РК
E-gov
State Information Center "Infocom" under the Agency of the Republic of Kazakhstan for Civil Service and Counteraction to Corruption (Государственный Центр Информации "Инфоком" при Агентстве Республики Казахстан по делам государственной службы и противодействию коррупции)
You're a healthcare organization that handles highly sensitive patient data. For some of your less sensitive and flexible workloads, you're open to using scalable cloud solutions. However, there are regulation requirements that dictate that certain patient information must be kept on-premise. What cloud deployment model would be the best fit for your requirements?
Public Cloud
Private Cloud
Hybrid Cloud
Community Cloud
Your company wants to implement a new email system. You require a solution that doesn't require hardware provisioning, software management, patching or updates, but at the same time offering broad accessibility and reliability. What kind of cloud service model would best serve your company?
Infrastructure as a Service (IaaS)
Platform as a Service (PaaS)
Software as a Service (SaaS)
Choose the correct chain to create a "bare metal virtualization":
Host hardware - host OS - hypervisor - guest OS - app
Host hardware - hypervisor - host OS - guest OS - app
Host hardware - hypervisor - guest OS - app
Host hardware - guest OS - hypervisor - app
Your company is a healthcare provider that manages protected health information (PHI) of patients in the United States. In order to comply with the standards to protect the privacy and security of such confidential information, which regulation should your company follow?
GDPR (General Data Protection Regulation)
HIPAA (Health Insurance Portability and Accountability Act)
PCI DSS (Payment Card Industry Data Security Standard)
OWASP (Open Web Application Security Project)
What is ITIL?
A programming language that is primarily used for system-level programming in embedded systems.
A software application used for project management.
A set of detailed practices for IT service management (ITSM) that focuses on aligning IT services with the needs of business.
A cloud computing platform offering various services including compute power, database storage, and content delivery.
Which backup strategy requires the most storage capacity?
Incremental Backup
Differential Backup
Full Backup
Cloud Backup
Which of the following systems has the lowest tolerance for interruption?
Vital systems
Critical systems
Sensitive systems
Nonsensitive systems
Which plan has the broader scope, Business Continuity Planning (BCP) or Disaster Recovery Planning (DRP)?
BCP, as it focuses on maintaining all business operations after a disaster.
DRP, as it focuses on maintaining all business operations after a disaster.
Both BCP and DRP have the same scope.
Neither BCP nor DRP cover the scope of keeping the business running.
Which of the following is an example of a preventive technical control?
Login screen
Network isolation
Manual fire alarms
Intrusion detection system
Which cloud computing model provides complete software solutions?
IaaS
PaaS
SaaS
DaaS
What is a characteristic of the public cloud?
Exclusive to a single organization
Open to all on a pay-per-use basis
Managed by a specific community
A mix of private and community clouds
Which virtualization type involves a hypervisor running directly on hardware?
Bare-metal virtualization
Hosted virtualization
Containerization
Hybrid virtualization
What is the purpose of an uninterruptible power supply (UPS)?
To increase voltage during surges
To provide backup power during outages
To reduce energy consumption
To regulate server temperatures
What is the function of the hypervisor?
Distributes private keys
Manages virtual resources
Protects from external attacks
Monitors environmental controls
Which document describes the practices of a CA?
PKI Process Document
Certification Practice Statement (CPS)
Certificate Revocation
If a primary site goes down at 2 PM and resumes at 5 PM in accordance with defined metrics, what is the RTO?
2 hours
3 hours
4 hours
1 hour.
SSO reduces the risk of a single point of failure.
True
False
Which of the following statements accurately describes the difference between SOC 1, SOC 2, and SOC 3 reports?
SOC 1 details a company's internal control over financial reporting, SOC 2 evaluates controls relevant to one or more of the five Trust Service Criteria (security, availability, processing integrity, confidentiality, and privacy), and SOC 3 is a simplified version of SOC 2 meant for public disclosure.
SOC 1 reports are targeted at the company's management, SOC 2 at the auditors, and SOC 3 is for the public.
SOC 1, SOC 2, and SOC 3 are all focused on financial reporting only with varying levels of detail.
SOC 1 and SOC 2 reports contain the same information, while SOC 3 reports focus on privacy controls.
Which of the following examples is an example of onsite insource model of service delivery?
Developers from an external company work in the customer's office.
An internal team of company employees works in the
the following examples is an example of onsite insource model of service delivery?
Developers from an external company work in the customer's office.
An internal team of company employees works in the company's office.
Developers from another country work remotely.
An external contractor works on the project from their own office.
Which of the following examples corresponds to the offshore outsource model of service delivery?
The company hires local employees to perform tasks on the customer's territory.
The work is done by a third-party contractor from another country.
Internal staff works remotely from another country.
An external contractor performs tasks from the customer's office.
Which scenario illustrates the hybrid model of service delivery?
Part of the tasks is performed by the internal team and the rest is done by a third-party contractor.
All work is done by a third-party contractor abroad.
Internal staff does all the work on their own.
An external contractor works exclusively in the client's office.
RTO= 0-1 hour, RPO = 4-24. Choose the strategy depending on identified RTO and RPO:
Tape backups, active-passive clustering
Mirroring, cold standby
Tape backups, active-active clustering
Mirroring, active-active clustering
What is the advantage of active-active clustering mode over active-passive?
Reduced hardware costs.
More even load distribution and improved performance.
Faster recovery from an active-server failure.
Eliminating the need for system monitoring.
Which of the following metrics can be identified as: "This is a metric used in biometric security systems to measure the effectiveness of the system in identifying individuals correctly. This metric is the point at which the false acceptance rate and false rejection rate are equal":
FAR
FER
FRR
EER
Which firewall implementation scheme consists of 1 NIC, bastion host and 1 packet filtering router?
Dual-Homed firewall
Screened-host firewall
Screened-subnet firewall
Demilitarized zone
What is an Application-Level firewall and at which layer of the OSI model does it operate?
Filters traffic based on user identity, operates at the presentation layer.
Provides a separate proxy for each application, operates at the application layer.
Allows traffic based on the type of connection, operates at the session layer.
Operates at the transport layer, filtering traffic based on TCP or UDP sessions.
What does SSID stands for?
Secure System Identifier
Service Set Identifier
Standard Signal Integration Device
Server Subnet Identification
What is an example of PKI in Kazakhstan?
National Certification Center of the Republic of Kazakhstan (NCC RK) - НУЦ РК
E-gov
State Information Center "Infocom" under the Agency of the Republic of Kazakhstan for Civil Service and Counteraction to Corruption (Государственный Центр Информации "Инфоком" при Агентстве Республики Казахстан по делам государственной службы и противодействию коррупции)
The company wants to organize secure collaborative editing of documents between departments without worrying about infrastructure setup and software updates.
The company wants to organize secure collaborative editing of documents between departments without worrying about infrastructure setup and software updates. Employees should have access to the documents via a web browser. Which type of cloud service is best suited for this situation?
SaaS
PaaS
IaaS
Private Cloud
The company developers need a platform to create, test and deploy web applications. They don't want to deal with server configuration or operating system management, but they need to have full control over application development. Which type of cloud service is best suited for this situation?
SaaS
PaaS
IaaS
Public Cloud
The organization conducts open educational courses and uses the cloud to store learning materials. These materials should be accessible to all users via the internet. Which type of cloud solution is most suitable for this situation?
Public Cloud
Private Cloud
Hybrid Cloud
PaaS
A bank is developing an internal system for processing transactions. The transaction data must be highly confidential, so only company employees should have access to the system. Which type of cloud solution is most suitable for this situation?
Public Cloud
Private Cloud
Hybrid Cloud
IaaS
Steve, a regular employee, tried to modify the access control filters for a particular database. However, he was unable to do so. What type of access control system is likely in place?
Discretionary Access Control (DAC), as these cannot be modified by normal users.
Both MAC and DAC, as both cannot be modified by normal users.
Mandatory Access Control (MAC), as these cannot be modified by normal users.
Neither MAC nor DAC, as both can be easily modified by normal users
Which of the following is NOT a risk when using virtualization?
Software compatibility issues
Risk associated with multi-tenant access
Reduction in operational costs
Vulnerability to "neighbor" attacks
What kind of encryption is used in PKI?
Symmetric encryption
Asymmetric encryption
Basic encryption
Non-reversible encryption
Which backup strategy requires the most storage capacity?
Incremental Backup
Differential Backup
Full Backup
Cloud Backup
Which of the following systems has the lowest tolerance for interruption?
Vital systems
Critical systems
Sensitive systems
Nonsensitive systems
Which plan has the broader scope, Business Continuity Planning (BCP) or Disaster Recovery Planning (DRP)?
BCP, as it focuses on maintaining all business operations after a disaster.
DRP, as it focuses on maintaining all business operations after a disaster.
Both BCP and DRP have the same scope.
Neither BCP nor DRP cover the scope of keeping the business running.
Which statement best describes a Disaster Recovery Plan (DRP)?
It details the steps required to restore full business operations after a disruption.
It is a plan detailing how to handle minor disruptions.
