Quizn.docx

1. SP 800-88 Guide for Media Sanitization recommends anti-forensic practices for keeping and protecting data from disclosure.

 True

 False

0.25 points   

QUESTION 2

1. A(n) _____________________________ program is intending to thoroughly indoctrinate established policies within the organization’s culture and amongst its employees.

0.25 points   

QUESTION 3

1. A(n) _____________________ technology was designed to replace operating systems and its services in the event they fail.

0.25 points   

QUESTION 4

1. A(n) ___________________ process is initiated by individuals who are subjected to forensic techniques with the intention of hiding or obfuscating items or objects with evidentiary value.

a.

digital forensics

b.

anti-forensics

c.

eDiscovery

d.

discovery

0.25 points   

QUESTION 5

1. Formal statements, a continuity policy, direct actions for subordinate response teams to developed group specific plans and overall business operation during contingencies.

 True

 False

0.25 points   

QUESTION 6

1. A(n) _________________________ approach shifts acknowledged threats to other assets or processes which are accomplished by reconsidering how deployment models, services, outsources, or service contracts are acquired or offered.

a.

defense

b.

termination

c.

mitigation

d.

transferal

0.25 points   

QUESTION 7

1. _____________________ is a component within the disaster recovery plan that is critical for an organization’s ability to reinstate operations at its primary location after an incident has occurred.

a.

Recovery

b.

Response

c.

Resumption

d.

Restoration

0.25 points   

QUESTION 8

1. A(n) ______________________ is an informal or formal group of information technology and information security personnel tasked with securing information by detecting and preventing attacks to those assets.

0.25 points   

QUESTION 9

1. Identifying preventive controls is part of an organization’s ongoing security posture, as they are implemented to safeguard both online and physical information storage and facilitates its recovery.

 True

 False

0.25 points   

QUESTION 10

1. The ___________________ component of the disaster recovery plan that is crucial for rehearsal and planning when reacting to an event or incident.

a.

Response

b.

Restoration

c.

Resumption

d.

Preparation

0.25 points   

QUESTION 11

1. Business continuity planning will not fail when there is no commitment from senior leaders because its success is dependent on team members and employee's ability to understand and effectively implements all of its components.

 True

 False

0.25 points   

QUESTION 12

1. NIST SP 801-34 guides an organization with integrating disaster recovery and business continuity elements into its contingency planning process; specifically, it focuses on business resumption planning efforts

 True

 False

0.25 points   

QUESTION 13

1. Both management and staff members are trained to perform their roles outlined in a disaster recovery plan because information regarding training is used to test the validity and effectiveness of the described procedures and execution techniques.

 True

 False

0.25 points   

QUESTION 14

1. A(n) __________________ is an invaluable operation and training method as it is typically conducted under adverse conditions.

0.25 points   

QUESTION 15

1. Business resumption provides an overview of an organization’s philosophy on the conduct of DR operations and serves as a guide for the development of the DR plan.

 True

 False

0.25 points   

QUESTION 16

1. A(n) ______________ is a method that enables an organization to validate that its documents are distributed in alternative languages and in intelligible form.

a.

comprehension

b.

review

c.

compliance

d.

dissemination

0.25 points   

QUESTION 17

1. The disaster recovery team consists of a team leader who is also a member of the CSIRT and a representative from every major organizational department.

 True

 False

0.25 points   

QUESTION 18

1. _____________________ is a component within the disaster recovery plan that is critical for an organization’s ability to reinstate its information systems and other resources when reacting to an incidents occurrence.

a.

Restoration

b.

Response

c.

Recovery

d.

Resumption

0.25 points   

QUESTION 19

1. A critical documented function during emergency preparedness is a disaster recovery plan, as it ensures that all core operational functions can recommence at an alternative business location.

 True

 False

0.25 points   

QUESTION 20

1. Placing uncommon central log servers in highly protected areas of the network will not prevent unauthorized access, but it could assist with pre-event analysis required to avoid the incident’s reoccurrence.

 True

 False

0.25 points   

QUESTION 21

1. Observed network traffic that exceeds its measured baseline values is an indicator that incident candidates are presented, and during these circumstances, these occurrences are categorized with unexpected time probable indicators.

 True

 False

0.25 points   

QUESTION 22

1. In contrast to emergency response that focuses on the immediate safety of those affected, ___________________ addresses the services needed to get the organization and its stakeholders back to original levels of productivity or satisfaction.

a.

crisis communications

b.

emergency response

c.

cross-training

d.

humanitarian assistance

0.25 points   

QUESTION 23

1. IT professionals primarily do not require analytical or presentation skills because first-response skills are common amongst these professional groups and are supplemented by processing and documenting potential evidentiary information.

 True

 False

0.25 points   

QUESTION 24

1. A Disaster Response Commander determines the specific incident type, if any, has occurred and which strategic actions are most suitable to address the situation.

 True

 False

0.25 points   

QUESTION 25

1. A(n) ___________________ is a method that enables an organization to validate that its internal policies are accessible in a multiple of different formats.

a.

dissemination

b.

compliance

c.

comprehension

d.

review

0.25 points   

QUESTION 26

1. Simulation training reconstructs actual disasters that have occurred and enables response members to perform required duties and to execute necessary procedures to address an incident without interfering or interrupting normal business operations.

 True

 False

0.25 points   

QUESTION 27

1. PD 25666 discloses workable strategies that help an organization to implement its business continuity programs effectively.

 True

 False

0.25 points   

QUESTION 28

1. The CSIRT should focus more on eradication, containment, and recovery efforts rather than first attempting to identify the incident’s originator.

 True

 False

0.25 points   

QUESTION 29

1. The AppIDPS evaluate unusual application events because it reviews files created by applications to identify anomalous occurrences, invalid file executions, exceeded user authorizations, and other activities that would signal normal interactions issues between the user, applications, or data.

 True

 False

0.25 points   

QUESTION 30

1. Organizational policies are finalized documents that are permanently implemented after dissemination to ensure that its members are aware, have read, understand, and agree on some of its contents.

 True

 False

0.25 points   

QUESTION 31

1. Unlike the incident response and disaster recovery processes, business continuity activities do not require an after action review.

 True

 False

0.25 points   

QUESTION 32

1. Adverse events are authentic threats to an organization’s operations because they are categorized as incidents, whereas incident candidates are processes for evaluating circumstances that are inclusive of those events.

 True

 False

0.25 points   

QUESTION 33

1. When considering an off-site facility to house data backups and equipment, it is important to note that the IR and BC plans both must include precautions to minimize risks at the location.

 True

 False

0.25 points   

QUESTION 34

1. A(n) ________________________ is used to illustrate process flows, system operations and its dependencies within a system analysis and design.

0.25 points   

QUESTION 35

1. An Enterprise Information Security Policy (EISP) is a blueprint that aligns the development, implementation, and management of technology framework and infrastructures to support an organization’s vision, mission, and strategies.

 True

 False

0.25 points   

QUESTION 36

1. It is highly probable for follow-on incidents to occur when infected machines or other computer systems are brought back online during an attack.

 True

 False

0.25 points   

QUESTION 37

1. A HIDPS maintains and produces an independent audit of system logs which are used when an attacker attempts to cover his or her activities after modifying the original system logs.

 True

 False

0.25 points   

QUESTION 38

1. The __________________________ was established because of numerous exclusions to warrant requirements and constant struggle to balance reasonable expectations for employee privacy and law enforcement’s need to conduct searches.

0.25 points   

QUESTION 39

1. A(n) __________________ is a process for collecting, reviewing, and searching for electronically stored records and files that could have significance and value during a legal proceeding.

a.

eDiscovery

b.

discovery

c.

digital forensics

d.

anti-forensics

0.25 points   

QUESTION 40

1. The mission and philosophy of an organization’s CSIRT incident response is to  or . 

0.25 points   

QUESTION 41

1. Digital forensics is information, graphics, images, or other electronic components that may have evidentiary value in a criminal or civil proceeding.

 True

 False

0.25 points   

QUESTION 42

1. Warm servers such as domain controllers, databases, web, and e-mail servers, often or frequently use reserve servers to provide a reliable backup for its redundant functions by remaining in standby or near online state.

 True

 False

0.25 points   

QUESTION 43

1. A(n) ________________________ are incident response procedures that exclude efforts that are taken to preate actions because they are not considered a part of the required preventative controls.

0.25 points   

QUESTION 44

1. A(n) ___________________________ is an initial determination for its scope of confidentiality, integrity, and availability of an information breach.

0.25 points   

QUESTION 45

1. A(n) ______________________________________ is crucial because it is the last action in the recovery process and is critical for maintaining an uninterrupted business operation.

0.25 points   

QUESTION 46

1. A(n) ________________________ is an internal attempted by an entity or individual to increase privileges to read information where prior permission was not granted.

0.25 points   

QUESTION 47

1. The incident recovery process, while resource intensive, erases all traces of an attack and restores the organization to its original post-intent status.

 True

 False

0.25 points   

QUESTION 48

1. A(n) _______________________ are attacks, events, or threats that abruptly occurs with minimal to no warning but has significant implications for business operations and employee welfare.           

a.

slow-onset disaster

b.

swift-onset disaster

c.

rapid-onset disaster

d.

steady-onset disaster

0.25 points   

QUESTION 49

1. A(n) __________________ is an enforceable recovery strategy that is implemented during an incident to reestablish an organization’s function, application, and systems.

a.

recovery downtime objective

b.

recovery point objective

c.

recovery allowable objective

d.

recovery time objective

0.25 points   

QUESTION 50

1. It is impossible to monitor communication channels used by an attacker because social media IRC channels which they may use to brag about the damage they have caused are more than likely private.

 True

 False

0.25 points   

QUESTION 51

1. A(n) ____________________________ represents the entire period an organization or its administrators are agreeable or consent to disruptions or outages to its core business functions or processes.

a.

maximum acceptable downtime 

b.

maximum allowable downtime

c.

maximum recovery downtime

d.

maximum tolerable downtime

0.25 points   

QUESTION 52

1. A(n) ______________ are prepacked field kits that contain portable equipment and tools needed by the digital forensic teams to conduct its investigations.

a.

jump bag

b.

portal kit

c.

forensic bag

d.

evidence kit

0.25 points   

QUESTION 53

1. A(n) __________________ is a period where data and systems can recuperate information subsequent to the initial outage.

a.

recovery point objective

b.

recovery time objective

c.

recovery allowable objective

d.

recovery downtime objective

0.25 points   

QUESTION 54

1. A(n) _____________________ team are responsible for recovering information and operating system resources by reestablishing the functionality of these systems during recovery efforts.

0.25 points   

QUESTION 55

1. The CSIRT supports organizational people to ensure that they are aware of the policies, and procedures that are necessary to deal with an emergency, therefore, little focus is placed on the technology and data that are necessary to prevent, detect, react, and recover from any event that may potentially damage assets and information.

 True

 False

0.25 points   

QUESTION 56

1. A(n) _____________________ preserves the confidentiality, integrity, and availablity of an organization’s information system by categorizing prospective vulnerabilities.

a.

risk management

b.

risk control

c.

risk identification

d.

risk determination   

0.25 points   

QUESTION 57

1. Operating systems initiates a process that creates a recording for the behavior of an object once the journaling function is enabling for the object; these recorded entries are then stored in the IDPS.

 True

 False

0.25 points   

QUESTION 58

1. In the disaster recovery planning policy statement process, the _______________ section in the document conveys the importance of creating geographically disbursed policies and the group or entities which these policies would apply.

0.25 points   

QUESTION 59

1. The most challenging part of the recovery process is to identify what information and data were disclosed during an event. Disclosed data is recoverable, but damaged data cannot be recovered.

 True

 False

0.25 points   

QUESTION 60

1. When the business prepares to move back to its primary location, this is an indication that the beginning of the end for the disaster is approaching.

 True

 False

0.25 points   

QUESTION 61

1. A standard that was designed to help an organization identify practical steps to improve its ability to deal with a crisis is outlined in the PAS 200.

 True

 False

0.25 points   

QUESTION 62

1. Constructed during the preliminary phase in the business continuity process a(n) ______________________ is developed to investigate and evaluate the impact that potential attacks will have on critical business processes and functions.

0.25 points   

QUESTION 63

1. _____________________ is a component within the disaster recovery plan that is critical for an organization’s ability to retrieve its information systems and other resources.

a.

Resumption

b.

Response

c.

Recovery

d.

Restoration

0.25 points   

QUESTION 64

1. A(n) ___________________________ are codified procedures and standards that are used to maintain or configure systems.

0.25 points   

QUESTION 65

1. A group of individuals who are tasked with planning and developing the contingency planning processes and oversight of subordinate teams and their plans are a(n) _________________________.

0.25 points   

QUESTION 66

1. Distinct from inappropriate usage, authorized access occurrences are incidents that were categorized as direct violations of policies rather than intentional actions to abuse systems.

 True

 False

0.25 points   

QUESTION 67

1. A(n) _________________________ documents, observes, and evaluates an organization’s information security posture and prospective problems it may contend with.

a.

risk identification

b.

risk determination

c.

risk control 

d.

risk management

0.25 points   

QUESTION 68

1. A(n) ___________________ is a method that enables an organization to validate that its workforce understands the contents and requirements that are outlined in its policies.  

a.

comprehension

b.

review

c.

dissemination

d.

compliance

0.25 points   

QUESTION 69

1. A(n) robust _________________________ technique or schedule ensures that the disaster recovery plan is regularly updated as it is a living document that is continuously changing.

0.25 points   

QUESTION 70

1. EnCase Forensic Edition is a method that offers an inflexible digital framework that makes it tougher when developing training for investigators to perform their specialized tasks.

 True

 False

0.25 points   

QUESTION 71

1. Inclusive of all four functional components in contingency planning, a(n) ___________________ approach decreases the impact of vulnerabilities and exploitation with more suitable preparation and planning processes.   

a.

termination

b.

transferal

c.

mitigation

d.

defense

0.25 points   

QUESTION 72

1. _____________________ is a component within the disaster recovery plan that is critical for an organization’s ability to suitably recognize and instantenously react to an incident.

a.

Resumption

b.

Restoration

c.

Response

d.

Recovery

0.25 points   

QUESTION 73

1. Hot, warm, and cold sites are time-share options that are leased in conjunction with other business partners and allows an organization to establish disaster recovery and incident response options at a reduced cost.

 True

 False

0.25 points   

QUESTION 74

1. It is an advantage to involve law enforcement after an incident has occurred because they will enable the organization to maintain control of its information and evidence when seeking to prosecute an attacker. 

 True

 False

0.25 points   

QUESTION 75

1. A(n) _________________ actions primarily focus on the safety of an organization’s and its members who may be directly involved or impacted by a disaster.

0.25 points   

QUESTION 76

1. A(n) ________________________ is a legal record of evidence that outlines and account for all elements of the evidence’s lifecycle where an individual may have had prior access.

0.25 points   

QUESTION 77

1. Business Continuity Management Standards, BS 25999, identifies requirements from a risk management viewpoint.

 True

 False

0.25 points   

QUESTION 78

1. Weighted tables used in a business impact analysis is valuable for information technology personnel, as it enables them to compile information from various equipment that is maintained to determine categorical data frequencies for occurrences and the probability of its success.

 True

 False

0.25 points   

QUESTION 79

1. ISO’s primary standard for crisis management, __________________ is labeled as incident response, but is intended to help organizations respond to disasters, social disruptions, or other significant events.

a.

ISO/IEC 27031:2011

b.

ISO/IEC 24762:2008

c.

ISO 22301:2011

d.

ISO 22320:2011

0.25 points   

QUESTION 80

1. A(n) ___________________ assistance with all nontechnical recovery efforts and are responsible for managing these efforts to ensure its compliance to the business impact analysis.

0.25 points   

QUESTION 81

1. A host-based IDPS evaluates network data traffic as it is searching for trends within preconfigured and predetermined attack patterns and other matching signatures.

 True

 False

0.25 points   

QUESTION 82

1. A(n) _______________ is a method that enables an organization to validate that its workforce is operating in support of its established policies and guidelines. 

a.

dissemination

b.

review

c.

comprehension

d.

compliance

0.25 points   

QUESTION 83

1. Disaster recovery groups require a universal planning approach, which can only occur after the business disaster recovery policy is complete because this creates a context to ensure that all planning processes can interoperate.

 True

 False

0.25 points   

QUESTION 84

1. A(n) __________________________ is a threat, attack, event, or incident that steadily occurs and weakens organization’s that are incapable of withstanding its effect.

a.

swift-onset disaster

b.

slow-onset disaster

c.

steady-onset disaster

d.

rapid-onset disaster

0.25 points   

QUESTION 85

1. A(n) _______________________ are threat categories that encompass antiquated infrastructures that may lead or result in untrustworthy or unreliable systems.

0.25 points   

QUESTION 86

1. A(n) ________________________ is a replaceable monitoring unit and failure indicator that protects against data loss and system failures.

a.

failure resistant disk systems

b.

disaster tolerant disk systems

c.

disaster resistant disk systems

d.

failure tolerant disk systems

0.25 points   

QUESTION 87

1. A(n) _______________________________ protects data against access loss caused by cache, device change, power supply, and other controller module failures.

a.

disaster resistant disk systems

b.

failure tolerant disk systems

c.

disaster tolerant disk systems

d.

failure resistant disk systems

0.25 points   

QUESTION 88

1. When composing an organization’s disaster recovery plan, it is imperative also to include a preventative phase that has similar operations, processes, and procedures as those found in the incident response plan.

 True

 False

0.25 points   

QUESTION 89

1. The statement, "We thought we had more important issues to handle" is an example of which type of organizational response?

a.

Deferral

b.

Denial

c.

Inattention to warn

d.

Ignorance

0.25 points   

QUESTION 90

1. A(n) _____________________ comprises of two or more independent zones that safeguards against loss or multiple disk failure.

a.

disaster tolerant disk systems

b.

disaster resistant disk systems

c.

failure tolerant disk systems

d.

failure resistant disk systems

0.25 points   

QUESTION 91

1. A(n) ______________________ team serves as the emergency’s command-and-control group who are directed with managing the direction for all other team effects, task assignments and are constantly provided with updates.

0.25 points   

QUESTION 92

1. A foundational step for developing policy is by engaging in contingency efforts that focus on instituting efforts to execute the plan.

 True

 False

0.25 points   

QUESTION 93

1. A(n) _______________________________ team evaluates and assesses hardware, wiring, intra- and internet connectivity, and performs all tasks required to reestablish those elements operability by replacing destroyed or damaged components.

0.25 points   

QUESTION 94

1. A(n) ____________________________ is an avoidance approach that counteracts vulnerabilities and exploits systems by adding safeguards that limit access to assets and eliminate weaknesses.

a.

mitigation

b.

transferal

c.

termination

d.

defense 

0.25 points   

QUESTION 95

1. A(n) _______________ notification is a description of an incident that has occurred, the probability of its occurrence, an outline of necessary preparation actions, and its subsequent best and worst case scenarios.

0.25 points   

QUESTION 96

1. When an organization decides it needs its information assets to remain unprotected bases its decision on a(n) _______________________ when removing assets from risk environments.

a.

defense

b.

transferal

c.

mitigation

d.

termination

0.25 points   

QUESTION 97

1. ISO standard _____________________ stipulates what must be accomplished when employing a business continuity management system.

a.

ISO/IEC 24762:2008

b.

ISO 22301:2011

c.

ISO/IEC 27031:2011

d.

ISO 22320:2011

0.25 points   

QUESTION 98

1. A(n) ________________ occurs when infected computer systems that were previously offline during an attack are brought back online.

0.25 points   

QUESTION 99

1. A(n) ________________ occurs when legitimate incidents fail to receive attention and ultimate goes unreported.

0.25 points   

QUESTION 100

1. Incident response processes contain and resolve events in accordance with the incident response plan, as its overall operations are inclusive of preparation, detection, analysis, containment, eradication, and post-incident activities.

 True

 False