Domain 4: Information Systems Operations and Business Resilience - PART 4B Flashcards

1
Q

The activation of an enterprise’s business continuity plan should be based on predetermined criteria that address the:

A

duration of the outage.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

After a disaster declaration, the media creation date at a warm recovery site is based on the:

A

recovery point objective. (RPO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

After completing the business impact analysis, what is the NEXT step in the business continuity planning process?

A

Develop recovery strategies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Applying a retention date on a file will ensure that:

A

data will not be deleted before that date.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

The BEST method for assessing the effectiveness of a business continuity plan is to review the:

A

results from previous tests

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A company with a limited budget has a recovery time objective of 72 hours and a recovery point objective of 24 hours. Which of the following would BEST meet the requirements of the business?

A

A warm site

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

The cost of ongoing operations when a disaster recovery plan (DRP) is in place, compared to not having a DRP, will MOST likely:

A

increase.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Depending on the complexity of an organization’s business continuity plan (BCP), it may be developed as a set of plans to address various aspects of business continuity and disaster recovery. In such an environment, it is essential that:

A

each plan is consistent with one another.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Determining the service delivery objective should be based PRIMARILY on:

A

the minimum acceptable operational capability.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

A disaster recovery plan for an organization’s financial system specifies that the recovery point objective is zero and the recovery time objective is 72 hours. Which of the following is the MOST cost-effective solution?

A

Synchronous remote copy of the data in a warm site that can be operational in 48 hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Disaster recovery planning addresses the:

A

technological aspect of business continuity planning (BCP).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Due to changes in IT, the disaster recovery plan of a large organization has been changed. What is the PRIMARY risk if the new plan is not tested?

A

Catastrophic service interruption

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

During a disaster recovery test, an IS auditor observes that the performance of the disaster recovery site’s server is slow. To find the root cause of this, the IS auditor should FIRST review the:

A

configurations and alignment of the primary and disaster recovery sites.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

During an audit of a business continuity plan (BCP), an IS auditor found that, although all departments were housed in the same building, each department had a separate BCP. The IS auditor recommended that the BCPs be reconciled. Which of the following areas should be reconciled FIRST?

A

Evacuation plan

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

During an IS audit of the disaster recovery plan of a global enterprise, the auditor observes that some remote offices have very limited local IT resources. Which of the following observations would be the MOST critical for the IS auditor?

A

A test has not been made to ensure that local resources could maintain security and service standards when recovering from a disaster or incident.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

During a review of a business continuity plan, an IS auditor noticed that the point at which a situation is declared to be a crisis has not been defined. The MAJOR risk associated with this is that:

A

execution of the disaster recovery plan could be impacted.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

During the design of a business continuity plan, the business impact analysis identifies critical processes and supporting applications. This will PRIMARILY influence the:

A

recovery strategy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

A financial institution that processes millions of transactions each day has a central communications processor (switch) for connecting to automated teller machines. Which of the following would be the BEST contingency plan for the communications processor?

A

Alternate processor at another network node

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

For effective implementation after a business continuity plan (BCP) has been developed, it is MOST important that the BCP be:

A

communicated to appropriate personnel.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

he frequent updating of which of the following is key to the continued effectiveness of a disaster recovery plan?

A

Contact information of key personnel

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

A hot site should be implemented as a recovery strategy when the:

A

disaster downtime tolerance is low.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

If the recovery time objective increases:

A

the disaster tolerance increases.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

In a contract with a hot, warm or cold site, contractual provisions should PRIMARILY cover which of the following considerations?

A

Number of subscribers permitted to use a site at one time

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

In addition to the backup considerations for all systems, which of the following is an important consideration in providing backup for online systems?

A

Ensuring periodic dumps of transaction logs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

In a disaster recovery situation, which of the following is the MOST important metric to ensure that data are synchronized between critical systems?

A

Recovery point objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

In determining the acceptable time period for the resumption of critical business processes:

A

both downtime costs and recovery costs need to be evaluated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

Integrating the business continuity plan into IT project management aids in:

A

the development of a more comprehensive set of requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
28
Q

In the event of a data center disaster, which of the following would be the MOST appropriate strategy to enable a complete recovery of a critical database?

A

Real-time replication to a remote site

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
29
Q

In which of the following situations is it MOST appropriate to implement data mirroring as the recovery strategy?

A

The recovery point objective is low.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
30
Q

An IS auditor can verify that an organization’s business continuity plan (BCP) is effective by reviewing the:

A

results of business continuity tests performed by IS and end-user personnel.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
31
Q

An IS auditor discovers that the disaster recovery plan (DRP) for a company does not include a critical application hosted in the cloud. Management’s response states that the cloud vendor is responsible for disaster recovery (DR) and DR-related testing. What is the NEXT course of action for the IS auditor to pursue?

A

Review the vendor contract to determine its DR capabilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
32
Q

An IS auditor evaluating the resilience of a high-availability network should be MOST concerned if:

A

the servers are clustered in one site.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
33
Q

An IS auditor is auditing an IT disaster recovery plan. The IS auditor should PRIMARILY ensure that the plan covers:

A

analysis and prioritization of business functions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
34
Q

An IS auditor is conducting a review of the disaster recovery procedures for a data center. Which of the following indicators BEST shows that the procedures meet the requirements?

A

A tabletop exercise using the procedures was conducted.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
35
Q

An IS auditor is performing an audit in the data center when the fire alarm begins sounding. The audit scope includes disaster recovery, so the auditor observes the data center staff response to the alarm. Which of the following is the MOST important action for the data center staff to complete in this scenario?

A

Ensure all persons in the data center are evacuated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
36
Q

An IS auditor is performing a review of the disaster recovery hot site used by a financial institution. Which of the following would be the GREATEST concern?

A

Disk space utilization data are not kept current.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
37
Q

An IS auditor is reviewing an organization’s recovery from a disaster in which not all the critical data needed to resume business operations were retained. Which of the following was incorrectly defined?

A

The recovery point objective

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
38
Q

An IS auditor is reviewing the most recent disaster recovery plan of an organization. Which approval is the MOST important when determining the availability of system resources required for the plan?

A

IT management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
39
Q

An IS auditor notes during an audit that an organization’s business continuity plan does not adequately address information confidentiality during the recovery
process. The IS auditor should recommend that the plan be modified to include:

A

the level of information security required when business recovery procedures are invoked.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
40
Q

An IS auditor observed that multiple applications are hosted on the same server. The recovery time objective (RTO) for the server will be:

A

based on the application with the shortest RTO.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
41
Q

An IS auditor reviewing an organization’s disaster recovery plan should PRIMARILY verify that it is:

A

regularly reviewed and updated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
42
Q

It is MOST appropriate to implement an incremental backup scheme when:

A

there is limited media capacity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
43
Q

IT management has decided to install a level 1 Redundant Array of Inexpensive Disks (RAID) system in all servers to compensate for the elimination of offsite backups. The IS auditor should recommend:

A

reinstating the offsite backups.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
44
Q

A large chain of shops with electronic funds transfer at point-of-sale devices has a central communications processor for connecting to the banking network. Which of the following is the BEST disaster recovery plan for the communications processor?

A

Alternative standby processor at another network node

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
45
Q

A live test of a mutual agreement for IT system recovery has been carried out, including a four-hour test of intensive usage by the business units. The test has been successful, but gives only partial assurance that the:

A

system and the IT operations team can sustain operations in the emergency environment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
46
Q

A lower recovery time objective results in:

A

higher cost.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
47
Q

The MAIN criterion for determining the severity level of a service disruption incident is:

A

downtime.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
48
Q

The MAIN purpose for periodically testing offsite disaster recovery facilities is to:

A

ensure the continued compatibility of the contingency facilities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
49
Q

Management considered two projections for its disaster recovery plan: plan A with two months to fully recover and plan B with eight months to fully recover. The recovery point objectives are the same in both plans. It is reasonable to expect that plan B projected higher:

A

downtime costs.

50
Q

A medium-sized organization, whose IT disaster recovery measures have been in place and regularly tested for years, has just developed a formal business continuity plan (BCP). A basic BCP tabletop exercise has been performed successfully. Which testing should an IS auditor recommend be performed NEXT to verify the adequacy of the new BCP?

A

Functional test of a scenario with limited IT involvement

51
Q

An offsite information processing facility with electrical wiring, air conditioning and flooring, but no computer or communications equipment, is a:

A

cold site.

52
Q

An optimized disaster recovery plan for an organization should:

A

reduce the length of the recovery time and the cost of recovery.

53
Q

An organization completed a business impact analysis as part of business continuity planning. The NEXT step in the process is to develop:

A

a business continuity strategy.

54
Q

An organization has a business process with a recovery time objective equal to zero and a recovery point objective close to one minute. This implies that the process can tolerate:

A

a data loss of up to one minute, but the processing must be continuous.

55
Q

An organization has just completed its annual risk assessment. Regarding the business continuity plan, what should an IS auditor recommend as the next step for the organization?

A

Review and evaluate the business continuity plan for adequacy

56
Q

An organization having a number of offices across a wide geographical area has developed a disaster recovery plan. Using actual resources, which of the following is the MOST cost-effective test of the disaster recovery plan?

A

Preparedness test

57
Q

An organization’s disaster recovery plan should address early recovery of:

A

processing in priority order, as defined by business management.

58
Q

The PRIMARY objective of business continuity and disaster recovery plans should be to:

A

protect human life.

59
Q

The PRIMARY objective of testing a business continuity plan is to:

A

identify limitations of the business continuity plan.

60
Q

The PRIMARY purpose of a business impact analysis is to:

A

define recovery strategies.

61
Q

The PRIMARY purpose of implementing Redundant Array of Inexpensive Disks level 1 in a file server is to:

A

ensure availability of data.

62
Q

Recovery procedures for an information processing facility are BEST based on:

A

recovery time objective.

63
Q

Segmenting a highly sensitive database results in:

A

reduced exposure.

64
Q

There are several methods of providing telecommunication continuity. The method of routing traffic through split cable or duplicate cable facilities is called:

A

diverse routing.

65
Q

To address an organization’s disaster recovery requirements, backup intervals should not exceed the:

A

recovery point objective.

66
Q

To ensure structured disaster recovery, it is MOST important that the business continuity plan and disaster recovery plan are:

A

tested regularly.

67
Q

To optimize an organization’s business continuity plan, an IS auditor should recommend a business impact analysis to determine:

A

the business processes that must be recovered following a disaster to ensure the organization’s survival.

68
Q

What is the BEST backup strategy for a large database with data supporting online sales?

A

Mirrored hard disks

69
Q

When an organization’s disaster recovery plan has a reciprocal agreement, which of the following risk treatment approaches is being applied?

A

Mitigation

70
Q

When auditing the archiving process of emails, the IS auditor should pay the MOST attention to:

A

the existence of a data retention policy.

71
Q

When developing a business continuity plan, which of the following tools should be used to gain an understanding of the organization’s business processes?

A

Risk assessment

72
Q

When developing a disaster recovery plan, the criteria for determining the acceptable downtime should be the:

A

maximum tolerable outage.

73
Q

When reviewing a disaster recovery plan, an IS auditor should be MOST concerned with the lack of:

A

process owner involvement.

74
Q

Which of the following backup techniques is the MOST appropriate when an organization requires extremely granular data restore points, as defined in the recovery point objective?

A

Continuous data backup

75
Q

Which of the following BEST helps define disaster recovery strategies?

A

Maximum tolerable downtime and data loss

76
Q

Which of the following BEST mitigates the risk arising from using reciprocal agreements as a recovery alternative?

A

Ensure that partnering organizations are separated geographically.

77
Q

Which of the following BEST mitigates the risk of backup media containing irreplaceable information being lost or stolen while in transit?

A

Maintain a duplicate copy.

78
Q

Which of the following business continuity plan tests involves participation of relevant members of the crisis management/response team to practice proper coordination?

A

Tabletop

79
Q

Which of the following choices would MOST likely ensure that a disaster recovery effort is successful?

A

Data restoration was completed.

80
Q

Which of the following disaster recovery testing techniques is the MOST efficient way to determine the effectiveness of the plan?

A

Preparedness tests

81
Q

Which of the following distinguishes a business impact analysis from a risk assessment?

A

A determination of acceptable downtime

82
Q

Which of the following ensures the availability of transactions in the event of a disaster?

A

Transmit transactions offsite in real time.

83
Q

Which of the following groups is the BEST source of information for determining the criticality of application systems as part of a business impact analysis?

A

Business processes owners

84
Q

Which of the following inputs would PRIMARILY help in designing the data backup strategy in case of potential natural disasters?

A

Recovery point objective

85
Q

Which of the following is a continuity plan test that simulates a system crash and uses actual resources to cost-effectively obtain evidence about the plan’s effectiveness?

A

Preparedness test

86
Q

Which of the following is an appropriate test method to apply to a business continuity plan?

A

Paper

87
Q

Which of the following is MOST important to determine the recovery point objective for a critical process in an enterprise?

A

Extent of data loss that is acceptable

88
Q

Which of the following issues should be the GREATEST concern to the IS auditor when reviewing an IT disaster recovery test?

A

During the test, some of the backup systems were defective or not working, causing the test of these systems to fail.

89
Q

Which of the following is the BEST indicator of the effectiveness of backup and restore procedures while restoring data after a disaster?

A

Recovery time objectives were met.

90
Q

Which of the following is the BEST method for determining the criticality of each application system in the production environment?

A

Perform a business impact analysis.

91
Q

Which of the following is the BEST method to ensure that critical IT system failures do not recur?

A

Perform root cause analysis.

92
Q

Which of the following is the BEST method to ensure that the business continuity plan remains up to date?

A

The group walks through the different scenarios of the plan from beginning to end.

93
Q

Which of the following is the BEST reason for integrating the testing of noncritical systems in disaster recovery plans (DRPs) with business continuity plans (BCPs)?

A

BCPs may assume the existence of capabilities that are not in DRPs.

94
Q

Which of the following is the GREATEST risk of an organization using reciprocal agreements for disaster recovery between two business units?

A

Both entities are vulnerable to the same incident.

95
Q

Which of the following is the GREATEST risk when storage growth in a critical file server is not managed properly?

A

Server recovery work may not meet the recovery time objective.

96
Q

Which of the following is the MOST critical element to effectively execute a disaster recovery plan?

A

Offsite storage of backup data

97
Q

Which of the following is the MOST effective method for disposing of magnetic media that contains confidential information?

A

Destroying

98
Q

Which of the following is the MOST efficient strategy for the backup of large quantities of mission-critical data when the systems need to be online to take sales orders 24 hours a day?

A

Implementing a fault-tolerant disk-to-disk backup solution

99
Q

Which of the following is the MOST important consideration when defining recovery point objectives?

A

Acceptable data loss

100
Q

Which of the following is the MOST important criterion when selecting a location for an offsite storage facility for IS backup files? The offsite facility must be:

A

physically separated from the data center and not subject to the same risk.

101
Q

Which of the following is the MOST reasonable option for recovering a non- critical system?

A

Cold site

102
Q

Which of the following is the PRIMARY objective of the business continuity plan process?

A

To manage risk while recovering from an event that adversely affected operations

103
Q

Which of the following must exist to ensure the viability of a duplicate information processing facility?

A

The workload of the primary site is monitored to ensure adequate backup is available.

104
Q

Which of the following provides the BEST evidence of an organization’s disaster recovery capability readiness?

A

Results of tests and exercises

105
Q

Which of the following recovery strategies is MOST appropriate for a business having multiple offices within a region and a limited recovery budget?

A

A reciprocal arrangement between its offices

106
Q

Which of the following represents the GREATEST risk created by a reciprocal agreement for disaster recovery made between two companies?

A

Developments may result in hardware and software incompatibility.

107
Q

Which of the following scenarios provides the BEST disaster recovery plan to implement for critical applications?

A

Daily data backups that are stored offsite and a hot site located 140 kilometers from the main data center

108
Q

Which of the following should be a MAJOR concern for an IS auditor reviewing a business continuity plan?

A

Test results are not adequately documented.

109
Q

Which of the following should be of MOST concern to an IS auditor reviewing the business continuity plan (BCP)?

A

The responsibility for declaring a disaster is not identified.

110
Q

Which of the following stakeholders is the MOST important in terms of developing a business continuity plan?

A

Process owners

111
Q

Which of the following statements is useful while drafting a disaster recovery plan

A

Downtime costs increase with time.

112
Q

Which of the following tasks should be performed FIRST when preparing a disaster recovery plan?

A

Perform a business impact analysis.

113
Q

Which of the following would be MOST important for an IS auditor to verify while conducting a business continuity audit?

A

Human safety procedures are in place.

114
Q

Which of the following would BEST ensure uninterrupted operations in an organization with IT operation centers in several countries?

A

Employee training on the business continuity plan

115
Q

Which of the following would BEST support 24/7 availability?

A

Mirroring

116
Q

Which of the following would be the MOST appropriate recovery strategy for a sensitive system with a high recovery time objective (RTO)?

A

Cold site

117
Q

Which of the following would contribute MOST to an effective business continuity plan?

A

Planning involves all user departments.

118
Q

While observing a full simulation of the business continuity plan, an IS auditor notices that the notification systems within the organizational facilities could be severely impacted by infrastructure damage. The BEST recommendation the IS auditor can provide to the organization is to ensure:

A

redundancies are built into the notification system.

119
Q

While reviewing the IT infrastructure, an IS auditor notices that storage resources are continuously being added. The IS auditor should:

A

review the capacity management process.

120
Q

With respect to business continuity strategies, an IS auditor interviews key stakeholders in an organization to determine whether they understand their roles and responsibilities. The IS auditor is attempting to evaluate the:

A

clarity and simplicity of the business continuity plans.