Chapter 18 - Disaster Recovery Planning Flashcards

1
Q

According to the Federal Emergency Management Agency, approximately what percentage of US states is rated with at least a moderate risk of seismic activity?

A

80 percent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Which disaster type is not usually covered by standard business or homeowner’s insurance?

A

Flood

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How long does it take to activate warm sites?

A

Activation of warm site typically takes at least 12 hours from the time a disaster is declared. This does not mean that any site that can be activated in less than 12 hours qualifies as a hot site; however, switch over times for most hot sites are often measured in seconds or minutes, and complete cut overs seldom take more than an hour or two.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

During the salvage of the Local Area Network and Servers, which of the following steps would normally be performed first?

A

The first activity in every recovery plan is damage assessment, immediately followed by damage mitigation.
This first activity would typically include assessing the damage to all network and server components (including cables, boards, file servers, workstations, printers, network equipment), making a list of all items to be repaired or replaced, selecting appropriate vendors and relaying findings to Emergency Management Team.
Following damage mitigation, equipment can be recovered and LAN communications network and servers can be reinstalled.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is NOT normally one of the questions that would be asked in regards to an organization’s information security policy?

A

Actions to be performed in case of a disaster are not normally part of an information security policy but part of a Disaster Recovery Plan (DRP).
Only personnel implicated in the plan should have a copy of the Disaster Recovery Plan whereas everyone should be aware of the contents of the organization’s information security policy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The MOST common threat that impacts a business’s ability to function normally is

A

The MOST common threat that impacts a business’s ability to function normally is power. Power interruption cause more business interruption than any other type of event.
The second most common threat is Water such as flood, water damage from broken pipe, leaky roof, etc…

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who should direct short-term recovery actions immediately following a disaster?

A

The Disaster Recovery Manager should also be a member of the team that assisted in the development of the Disaster Recovery Plan. Senior-level management need to support the process but would not be involved with the initial process.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

MTD values for critical systems

A

Here are some examples of MTD values suggested by Shon Harris:
NonEssential 30 Days

Normal 7 Days

Important 72 Hours

Urgent 24 Hours
Critical Minutes to hours

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Work Recovery Time (WRT)

A

WRT is the remainder of the overall MTP values. RTO usually deals with getting the infrastructure and system backup and running, and WRT deals with restoring data, testing processes, and then marking everything “live” for production purposes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Purpose of change control committee

A

The committee is informed to ensure that all changes are properly submitted, tested, and approved. The goal is for changes to be desirable and beneficial for the company as a whole, and that change be developed and implemented in a correct manner.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

HSM

A

A hierarchical storage management (HSM) system is an automated data storage system. It provides continuous online backup functionality.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Recovery Time Objective (RTO)

A

RTO is the earliest time period and a service level within which a business process must be restored after a disaster to avoid unacceptable consequences associated with a break in business continuity.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

The backup site should be at least how many miles away from the primary site to give the company maximum protection in case of regional disasters.

A

25

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Prosper steps for developing a disaster recovery plan

A
  1. Develop the continuity planning policy statement.
  2. Conduct the business impact analysis.
  3. Identify preventive controls.
  4. Develop recovery strategies.
  5. Develop the contingency plan.
  6. Test the plan and conduct training and exercises.
  7. Maintain the plan.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Functional exercises

A

It allows personnel to validate their operational readiness for emergencies by performing their duties in a simulated operational environment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Business continuity functional analysis

A
  1. Collect data through interviews and documentary sources.
  2. Document business functions, activities, and transactions.
  3. Develops a hierarchy of business function.
  4. Applies a classification scheme to indicate each individual business unit function’s criticality level
17
Q

Characteristics of remote journaling

A
  1. Moves the journal or transaction log to a remote location, not the actual files
  2. Parallel processing of transactions to an alternative site.
  3. Backup takes place in real time (synchronous)
18
Q

Crisis Management Plan

A

CMP includes Crisis Communication plan, Emergency Operation Centre, and Call Tree.