quiz
1. SP 800-88 Guide for Media Sanitization recommends anti-forensic practices for keeping and protecting data from disclosure.
True
False
0.25 points
QUESTION 2
1. A(n) _____________________________ program is intending to thoroughly indoctrinate established policies within the organization’s culture and amongst its employees.
0.25 points
QUESTION 3
1. A(n) _____________________ technology was designed to replace operating systems and its services in the event they fail.
0.25 points
QUESTION 4
1. A(n) ___________________ process is initiated by individuals who are subjected to forensic techniques with the intention of hiding or obfuscating items or objects with evidentiary value.
|
|
a. |
digital forensics |
|
|
b. |
anti-forensics |
|
|
c. |
eDiscovery |
|
|
d. |
discovery |
0.25 points
QUESTION 5
1. Formal statements, a continuity policy, direct actions for subordinate response teams to developed group specific plans and overall business operation during contingencies.
True
False
0.25 points
QUESTION 6
1. A(n) _________________________ approach shifts acknowledged threats to other assets or processes which are accomplished by reconsidering how deployment models, services, outsources, or service contracts are acquired or offered.
|
|
a. |
defense |
|
|
b. |
termination |
|
|
c. |
mitigation |
|
|
d. |
transferal |
0.25 points
QUESTION 7
1. _____________________ is a component within the disaster recovery plan that is critical for an organization’s ability to reinstate operations at its primary location after an incident has occurred.
|
|
a. |
Recovery |
|
|
b. |
Response |
|
|
c. |
Resumption |
|
|
d. |
Restoration |
0.25 points
QUESTION 8
1. A(n) ______________________ is an informal or formal group of information technology and information security personnel tasked with securing information by detecting and preventing attacks to those assets.
0.25 points
QUESTION 9
1. Identifying preventive controls is part of an organization’s ongoing security posture, as they are implemented to safeguard both online and physical information storage and facilitates its recovery.
True
False
0.25 points
QUESTION 10
1. The ___________________ component of the disaster recovery plan that is crucial for rehearsal and planning when reacting to an event or incident.
|
|
a. |
Response |
|
|
b. |
Restoration |
|
|
c. |
Resumption |
|
|
d. |
Preparation |
0.25 points
QUESTION 11
1. Business continuity planning will not fail when there is no commitment from senior leaders because its success is dependent on team members and employee's ability to understand and effectively implements all of its components.
True
False
0.25 points
QUESTION 12
1. NIST SP 801-34 guides an organization with integrating disaster recovery and business continuity elements into its contingency planning process; specifically, it focuses on business resumption planning efforts
True
False
0.25 points
QUESTION 13
1. Both management and staff members are trained to perform their roles outlined in a disaster recovery plan because information regarding training is used to test the validity and effectiveness of the described procedures and execution techniques.
True
False
0.25 points
QUESTION 14
1. A(n) __________________ is an invaluable operation and training method as it is typically conducted under adverse conditions.
0.25 points
QUESTION 15
1. Business resumption provides an overview of an organization’s philosophy on the conduct of DR operations and serves as a guide for the development of the DR plan.
True
False
0.25 points
QUESTION 16
1. A(n) ______________ is a method that enables an organization to validate that its documents are distributed in alternative languages and in intelligible form.
|
|
a. |
comprehension |
|
|
b. |
review |
|
|
c. |
compliance |
|
|
d. |
dissemination |
0.25 points
QUESTION 17
1. The disaster recovery team consists of a team leader who is also a member of the CSIRT and a representative from every major organizational department.
True
False
0.25 points
QUESTION 18
1. _____________________ is a component within the disaster recovery plan that is critical for an organization’s ability to reinstate its information systems and other resources when reacting to an incidents occurrence.
|
|
a. |
Restoration |
|
|
b. |
Response |
|
|
c. |
Recovery |
|
|
d. |
Resumption |
0.25 points
QUESTION 19
1. A critical documented function during emergency preparedness is a disaster recovery plan, as it ensures that all core operational functions can recommence at an alternative business location.
True
False
0.25 points
QUESTION 20
1. Placing uncommon central log servers in highly protected areas of the network will not prevent unauthorized access, but it could assist with pre-event analysis required to avoid the incident’s reoccurrence.
True
False
0.25 points
QUESTION 21
1. Observed network traffic that exceeds its measured baseline values is an indicator that incident candidates are presented, and during these circumstances, these occurrences are categorized with unexpected time probable indicators.
True
False
0.25 points
QUESTION 22
1. In contrast to emergency response that focuses on the immediate safety of those affected, ___________________ addresses the services needed to get the organization and its stakeholders back to original levels of productivity or satisfaction.
|
|
a. |
crisis communications |
|
|
b. |
emergency response |
|
|
c. |
cross-training |
|
|
d. |
humanitarian assistance |
0.25 points
QUESTION 23
1. IT professionals primarily do not require analytical or presentation skills because first-response skills are common amongst these professional groups and are supplemented by processing and documenting potential evidentiary information.
True
False
0.25 points
QUESTION 24
1. A Disaster Response Commander determines the specific incident type, if any, has occurred and which strategic actions are most suitable to address the situation.
True
False
0.25 points
QUESTION 25
1. A(n) ___________________ is a method that enables an organization to validate that its internal policies are accessible in a multiple of different formats.
|
|
a. |
dissemination |
|
|
b. |
compliance |
|
|
c. |
comprehension |
|
|
d. |
review |
0.25 points
QUESTION 26
1. Simulation training reconstructs actual disasters that have occurred and enables response members to perform required duties and to execute necessary procedures to address an incident without interfering or interrupting normal business operations.
True
False
0.25 points
QUESTION 27
1. PD 25666 discloses workable strategies that help an organization to implement its business continuity programs effectively.
True
False
0.25 points
QUESTION 28
1. The CSIRT should focus more on eradication, containment, and recovery efforts rather than first attempting to identify the incident’s originator.
True
False
0.25 points
QUESTION 29
1. The AppIDPS evaluate unusual application events because it reviews files created by applications to identify anomalous occurrences, invalid file executions, exceeded user authorizations, and other activities that would signal normal interactions issues between the user, applications, or data.
True
False
0.25 points
QUESTION 30
1. Organizational policies are finalized documents that are permanently implemented after dissemination to ensure that its members are aware, have read, understand, and agree on some of its contents.
True
False
0.25 points
QUESTION 31
1. Unlike the incident response and disaster recovery processes, business continuity activities do not require an after action review.
True
False
0.25 points
QUESTION 32
1. Adverse events are authentic threats to an organization’s operations because they are categorized as incidents, whereas incident candidates are processes for evaluating circumstances that are inclusive of those events.
True
False
0.25 points
QUESTION 33
1. When considering an off-site facility to house data backups and equipment, it is important to note that the IR and BC plans both must include precautions to minimize risks at the location.
True
False
0.25 points
QUESTION 34
1. A(n) ________________________ is used to illustrate process flows, system operations and its dependencies within a system analysis and design.
0.25 points
QUESTION 35
1. An Enterprise Information Security Policy (EISP) is a blueprint that aligns the development, implementation, and management of technology framework and infrastructures to support an organization’s vision, mission, and strategies.
True
False
0.25 points
QUESTION 36
1. It is highly probable for follow-on incidents to occur when infected machines or other computer systems are brought back online during an attack.
True
False
0.25 points
QUESTION 37
1. A HIDPS maintains and produces an independent audit of system logs which are used when an attacker attempts to cover his or her activities after modifying the original system logs.
True
False
0.25 points
QUESTION 38
1. The __________________________ was established because of numerous exclusions to warrant requirements and constant struggle to balance reasonable expectations for employee privacy and law enforcement’s need to conduct searches.
0.25 points
QUESTION 39
1. A(n) __________________ is a process for collecting, reviewing, and searching for electronically stored records and files that could have significance and value during a legal proceeding.
|
|
a. |
eDiscovery |
|
|
b. |
discovery |
|
|
c. |
digital forensics |
|
|
d. |
anti-forensics |
0.25 points
QUESTION 40
1. The mission and philosophy of an organization’s CSIRT incident response is to or .
0.25 points
QUESTION 41
1. Digital forensics is information, graphics, images, or other electronic components that may have evidentiary value in a criminal or civil proceeding.
True
False
0.25 points
QUESTION 42
1. Warm servers such as domain controllers, databases, web, and e-mail servers, often or frequently use reserve servers to provide a reliable backup for its redundant functions by remaining in standby or near online state.
True
False
0.25 points
QUESTION 43
1. A(n) ________________________ are incident response procedures that exclude efforts that are taken to preate actions because they are not considered a part of the required preventative controls.
0.25 points
QUESTION 44
1. A(n) ___________________________ is an initial determination for its scope of confidentiality, integrity, and availability of an information breach.
0.25 points
QUESTION 45
1. A(n) ______________________________________ is crucial because it is the last action in the recovery process and is critical for maintaining an uninterrupted business operation.
0.25 points
QUESTION 46
1. A(n) ________________________ is an internal attempted by an entity or individual to increase privileges to read information where prior permission was not granted.
0.25 points
QUESTION 47
1. The incident recovery process, while resource intensive, erases all traces of an attack and restores the organization to its original post-intent status.
True
False
0.25 points
QUESTION 48
1. A(n) _______________________ are attacks, events, or threats that abruptly occurs with minimal to no warning but has significant implications for business operations and employee welfare.
|
|
a. |
slow-onset disaster |
|
|
b. |
swift-onset disaster |
|
|
c. |
rapid-onset disaster |
|
|
d. |
steady-onset disaster |
0.25 points
QUESTION 49
1. A(n) __________________ is an enforceable recovery strategy that is implemented during an incident to reestablish an organization’s function, application, and systems.
|
|
a. |
recovery downtime objective |
|
|
b. |
recovery point objective |
|
|
c. |
recovery allowable objective |
|
|
d. |
recovery time objective |
0.25 points
QUESTION 50
1. It is impossible to monitor communication channels used by an attacker because social media IRC channels which they may use to brag about the damage they have caused are more than likely private.
True
False
0.25 points
QUESTION 51
1. A(n) ____________________________ represents the entire period an organization or its administrators are agreeable or consent to disruptions or outages to its core business functions or processes.
|
|
a. |
maximum acceptable downtime |
|
|
b. |
maximum allowable downtime |
|
|
c. |
maximum recovery downtime |
|
|
d. |
maximum tolerable downtime |
0.25 points
QUESTION 52
1. A(n) ______________ are prepacked field kits that contain portable equipment and tools needed by the digital forensic teams to conduct its investigations.
|
|
a. |
jump bag |
|
|
b. |
portal kit |
|
|
c. |
forensic bag |
|
|
d. |
evidence kit |
0.25 points
QUESTION 53
1. A(n) __________________ is a period where data and systems can recuperate information subsequent to the initial outage.
|
|
a. |
recovery point objective |
|
|
b. |
recovery time objective |
|
|
c. |
recovery allowable objective |
|
|
d. |
recovery downtime objective |
0.25 points
QUESTION 54
1. A(n) _____________________ team are responsible for recovering information and operating system resources by reestablishing the functionality of these systems during recovery efforts.
0.25 points
QUESTION 55
1. The CSIRT supports organizational people to ensure that they are aware of the policies, and procedures that are necessary to deal with an emergency, therefore, little focus is placed on the technology and data that are necessary to prevent, detect, react, and recover from any event that may potentially damage assets and information.
True
False
0.25 points
QUESTION 56
1. A(n) _____________________ preserves the confidentiality, integrity, and availablity of an organization’s information system by categorizing prospective vulnerabilities.
|
|
a. |
risk management |
|
|
b. |
risk control |
|
|
c. |
risk identification |
|
|
d. |
risk determination |
0.25 points
QUESTION 57
1. Operating systems initiates a process that creates a recording for the behavior of an object once the journaling function is enabling for the object; these recorded entries are then stored in the IDPS.
True
False
0.25 points
QUESTION 58
1. In the disaster recovery planning policy statement process, the _______________ section in the document conveys the importance of creating geographically disbursed policies and the group or entities which these policies would apply.
0.25 points
QUESTION 59
1. The most challenging part of the recovery process is to identify what information and data were disclosed during an event. Disclosed data is recoverable, but damaged data cannot be recovered.
True
False
0.25 points
QUESTION 60
1. When the business prepares to move back to its primary location, this is an indication that the beginning of the end for the disaster is approaching.
True
False
0.25 points
QUESTION 61
1. A standard that was designed to help an organization identify practical steps to improve its ability to deal with a crisis is outlined in the PAS 200.
True
False
0.25 points
QUESTION 62
1. Constructed during the preliminary phase in the business continuity process a(n) ______________________ is developed to investigate and evaluate the impact that potential attacks will have on critical business processes and functions.
0.25 points
QUESTION 63
1. _____________________ is a component within the disaster recovery plan that is critical for an organization’s ability to retrieve its information systems and other resources.
|
|
a. |
Resumption |
|
|
b. |
Response |
|
|
c. |
Recovery |
|
|
d. |
Restoration |
0.25 points
QUESTION 64
1. A(n) ___________________________ are codified procedures and standards that are used to maintain or configure systems.
0.25 points
QUESTION 65
1. A group of individuals who are tasked with planning and developing the contingency planning processes and oversight of subordinate teams and their plans are a(n) _________________________.
0.25 points
QUESTION 66
1. Distinct from inappropriate usage, authorized access occurrences are incidents that were categorized as direct violations of policies rather than intentional actions to abuse systems.
True
False
0.25 points
QUESTION 67
1. A(n) _________________________ documents, observes, and evaluates an organization’s information security posture and prospective problems it may contend with.
|
|
a. |
risk identification |
|
|
b. |
risk determination |
|
|
c. |
risk control |
|
|
d. |
risk management |
0.25 points
QUESTION 68
1. A(n) ___________________ is a method that enables an organization to validate that its workforce understands the contents and requirements that are outlined in its policies.
|
|
a. |
comprehension |
|
|
b. |
review |
|
|
c. |
dissemination |
|
|
d. |
compliance |
0.25 points
QUESTION 69
1. A(n) robust _________________________ technique or schedule ensures that the disaster recovery plan is regularly updated as it is a living document that is continuously changing.
0.25 points
QUESTION 70
1. EnCase Forensic Edition is a method that offers an inflexible digital framework that makes it tougher when developing training for investigators to perform their specialized tasks.
True
False
0.25 points
QUESTION 71
1. Inclusive of all four functional components in contingency planning, a(n) ___________________ approach decreases the impact of vulnerabilities and exploitation with more suitable preparation and planning processes.
|
|
a. |
termination |
|
|
b. |
transferal |
|
|
c. |
mitigation |
|
|
d. |
defense |
0.25 points
QUESTION 72
1. _____________________ is a component within the disaster recovery plan that is critical for an organization’s ability to suitably recognize and instantenously react to an incident.
|
|
a. |
Resumption |
|
|
b. |
Restoration |
|
|
c. |
Response |
|
|
d. |
Recovery |
0.25 points
QUESTION 73
1. Hot, warm, and cold sites are time-share options that are leased in conjunction with other business partners and allows an organization to establish disaster recovery and incident response options at a reduced cost.
True
False
0.25 points
QUESTION 74
1. It is an advantage to involve law enforcement after an incident has occurred because they will enable the organization to maintain control of its information and evidence when seeking to prosecute an attacker.
True
False
0.25 points
QUESTION 75
1. A(n) _________________ actions primarily focus on the safety of an organization’s and its members who may be directly involved or impacted by a disaster.
0.25 points
QUESTION 76
1. A(n) ________________________ is a legal record of evidence that outlines and account for all elements of the evidence’s lifecycle where an individual may have had prior access.
0.25 points
QUESTION 77
1. Business Continuity Management Standards, BS 25999, identifies requirements from a risk management viewpoint.
True
False
0.25 points
QUESTION 78
1. Weighted tables used in a business impact analysis is valuable for information technology personnel, as it enables them to compile information from various equipment that is maintained to determine categorical data frequencies for occurrences and the probability of its success.
True
False
0.25 points
QUESTION 79
1. ISO’s primary standard for crisis management, __________________ is labeled as incident response, but is intended to help organizations respond to disasters, social disruptions, or other significant events.
|
|
a. |
ISO/IEC 27031:2011 |
|
|
b. |
ISO/IEC 24762:2008 |
|
|
c. |
ISO 22301:2011 |
|
|
d. |
ISO 22320:2011 |
0.25 points
QUESTION 80
1. A(n) ___________________ assistance with all nontechnical recovery efforts and are responsible for managing these efforts to ensure its compliance to the business impact analysis.
0.25 points
QUESTION 81
1. A host-based IDPS evaluates network data traffic as it is searching for trends within preconfigured and predetermined attack patterns and other matching signatures.
True
False
0.25 points
QUESTION 82
1. A(n) _______________ is a method that enables an organization to validate that its workforce is operating in support of its established policies and guidelines.
|
|
a. |
dissemination |
|
|
b. |
review |
|
|
c. |
comprehension |
|
|
d. |
compliance |
0.25 points
QUESTION 83
1. Disaster recovery groups require a universal planning approach, which can only occur after the business disaster recovery policy is complete because this creates a context to ensure that all planning processes can interoperate.
True
False
0.25 points
QUESTION 84
1. A(n) __________________________ is a threat, attack, event, or incident that steadily occurs and weakens organization’s that are incapable of withstanding its effect.
|
|
a. |
swift-onset disaster |
|
|
b. |
slow-onset disaster |
|
|
c. |
steady-onset disaster |
|
|
d. |
rapid-onset disaster |
0.25 points
QUESTION 85
1. A(n) _______________________ are threat categories that encompass antiquated infrastructures that may lead or result in untrustworthy or unreliable systems.
0.25 points
QUESTION 86
1. A(n) ________________________ is a replaceable monitoring unit and failure indicator that protects against data loss and system failures.
|
|
a. |
failure resistant disk systems |
|
|
b. |
disaster tolerant disk systems |
|
|
c. |
disaster resistant disk systems |
|
|
d. |
failure tolerant disk systems |
0.25 points
QUESTION 87
1. A(n) _______________________________ protects data against access loss caused by cache, device change, power supply, and other controller module failures.
|
|
a. |
disaster resistant disk systems |
|
|
b. |
failure tolerant disk systems |
|
|
c. |
disaster tolerant disk systems |
|
|
d. |
failure resistant disk systems |
0.25 points
QUESTION 88
1. When composing an organization’s disaster recovery plan, it is imperative also to include a preventative phase that has similar operations, processes, and procedures as those found in the incident response plan.
True
False
0.25 points
QUESTION 89
1. The statement, "We thought we had more important issues to handle" is an example of which type of organizational response?
|
|
a. |
Deferral |
|
|
b. |
Denial |
|
|
c. |
Inattention to warn |
|
|
d. |
Ignorance |
0.25 points
QUESTION 90
1. A(n) _____________________ comprises of two or more independent zones that safeguards against loss or multiple disk failure.
|
|
a. |
disaster tolerant disk systems |
|
|
b. |
disaster resistant disk systems |
|
|
c. |
failure tolerant disk systems |
|
|
d. |
failure resistant disk systems |
0.25 points
QUESTION 91
1. A(n) ______________________ team serves as the emergency’s command-and-control group who are directed with managing the direction for all other team effects, task assignments and are constantly provided with updates.
0.25 points
QUESTION 92
1. A foundational step for developing policy is by engaging in contingency efforts that focus on instituting efforts to execute the plan.
True
False
0.25 points
QUESTION 93
1. A(n) _______________________________ team evaluates and assesses hardware, wiring, intra- and internet connectivity, and performs all tasks required to reestablish those elements operability by replacing destroyed or damaged components.
0.25 points
QUESTION 94
1. A(n) ____________________________ is an avoidance approach that counteracts vulnerabilities and exploits systems by adding safeguards that limit access to assets and eliminate weaknesses.
|
|
a. |
mitigation |
|
|
b. |
transferal |
|
|
c. |
termination |
|
|
d. |
defense |
0.25 points
QUESTION 95
1. A(n) _______________ notification is a description of an incident that has occurred, the probability of its occurrence, an outline of necessary preparation actions, and its subsequent best and worst case scenarios.
0.25 points
QUESTION 96
1. When an organization decides it needs its information assets to remain unprotected bases its decision on a(n) _______________________ when removing assets from risk environments.
|
|
a. |
defense |
|
|
b. |
transferal |
|
|
c. |
mitigation |
|
|
d. |
termination |
0.25 points
QUESTION 97
1. ISO standard _____________________ stipulates what must be accomplished when employing a business continuity management system.
|
|
a. |
ISO/IEC 24762:2008 |
|
|
b. |
ISO 22301:2011 |
|
|
c. |
ISO/IEC 27031:2011 |
|
|
d. |
ISO 22320:2011 |
0.25 points
QUESTION 98
1. A(n) ________________ occurs when infected computer systems that were previously offline during an attack are brought back online.
0.25 points
QUESTION 99
1. A(n) ________________ occurs when legitimate incidents fail to receive attention and ultimate goes unreported.
0.25 points
QUESTION 100
1. Incident response processes contain and resolve events in accordance with the incident response plan, as its overall operations are inclusive of preparation, detection, analysis, containment, eradication, and post-incident activities.
True
False