Domain 4: Information Systems Operations and Business Resilience - PART 4B Flashcards
The activation of an enterprise’s business continuity plan should be based on predetermined criteria that address the:
duration of the outage.
After a disaster declaration, the media creation date at a warm recovery site is based on the:
recovery point objective. (RPO)
After completing the business impact analysis, what is the NEXT step in the business continuity planning process?
Develop recovery strategies.
Applying a retention date on a file will ensure that:
data will not be deleted before that date.
The BEST method for assessing the effectiveness of a business continuity plan is to review the:
results from previous tests
A company with a limited budget has a recovery time objective of 72 hours and a recovery point objective of 24 hours. Which of the following would BEST meet the requirements of the business?
A warm site
The cost of ongoing operations when a disaster recovery plan (DRP) is in place, compared to not having a DRP, will MOST likely:
increase.
Depending on the complexity of an organization’s business continuity plan (BCP), it may be developed as a set of plans to address various aspects of business continuity and disaster recovery. In such an environment, it is essential that:
each plan is consistent with one another.
Determining the service delivery objective should be based PRIMARILY on:
the minimum acceptable operational capability.
A disaster recovery plan for an organization’s financial system specifies that the recovery point objective is zero and the recovery time objective is 72 hours. Which of the following is the MOST cost-effective solution?
Synchronous remote copy of the data in a warm site that can be operational in 48 hours
Disaster recovery planning addresses the:
technological aspect of business continuity planning (BCP).
Due to changes in IT, the disaster recovery plan of a large organization has been changed. What is the PRIMARY risk if the new plan is not tested?
Catastrophic service interruption
During a disaster recovery test, an IS auditor observes that the performance of the disaster recovery site’s server is slow. To find the root cause of this, the IS auditor should FIRST review the:
configurations and alignment of the primary and disaster recovery sites.
During an audit of a business continuity plan (BCP), an IS auditor found that, although all departments were housed in the same building, each department had a separate BCP. The IS auditor recommended that the BCPs be reconciled. Which of the following areas should be reconciled FIRST?
Evacuation plan
During an IS audit of the disaster recovery plan of a global enterprise, the auditor observes that some remote offices have very limited local IT resources. Which of the following observations would be the MOST critical for the IS auditor?
A test has not been made to ensure that local resources could maintain security and service standards when recovering from a disaster or incident.
During a review of a business continuity plan, an IS auditor noticed that the point at which a situation is declared to be a crisis has not been defined. The MAJOR risk associated with this is that:
execution of the disaster recovery plan could be impacted.
During the design of a business continuity plan, the business impact analysis identifies critical processes and supporting applications. This will PRIMARILY influence the:
recovery strategy.
A financial institution that processes millions of transactions each day has a central communications processor (switch) for connecting to automated teller machines. Which of the following would be the BEST contingency plan for the communications processor?
Alternate processor at another network node
For effective implementation after a business continuity plan (BCP) has been developed, it is MOST important that the BCP be:
communicated to appropriate personnel.
he frequent updating of which of the following is key to the continued effectiveness of a disaster recovery plan?
Contact information of key personnel
A hot site should be implemented as a recovery strategy when the:
disaster downtime tolerance is low.
If the recovery time objective increases:
the disaster tolerance increases.
In a contract with a hot, warm or cold site, contractual provisions should PRIMARILY cover which of the following considerations?
Number of subscribers permitted to use a site at one time
In addition to the backup considerations for all systems, which of the following is an important consideration in providing backup for online systems?
Ensuring periodic dumps of transaction logs