Filters
Question type

Study Flashcards

When dealing with an incident,the incident response team must conduct a(n)____________________,which entails a detailed examination of the events that occurred from first detection to final recovery.

Correct Answer

verifed

verified

after acti...

View Answer

Which of the following is usually conducted via leased lines or secure Internet connections whereby the receiving server archives the data as it is received?.


A) Database shadowing
B) Timesharing
C) Traditional backups
D) Electronic vaulting

Correct Answer

verifed

verified

If operations at the primary site cannot be quickly restored,the ____________________ occurs concurrently with the DR plan,enabling the business to continue at an alternate site.

Correct Answer

verifed

verified

BCP busine...

View Answer

Which document must be changed when evidence changes hands or is stored?


A) Chain of custody
B) Search warrant
C) Affidavit
D) Evidentiary material

Correct Answer

verifed

verified

Compare and contrast a hot site,a warm site,and a cold site.

Correct Answer

verifed

verified

Hot site-A hot site is a fully configure...

View Answer

What is the final stage of the business impact analysis when using the NIST SP 800-34 approach?


A) Identify resource requirements
B) Identify business processes
C) Determine mission/business processes and recovery criticality
D) Identify recovery priorities for system resources

Correct Answer

verifed

verified

Disaster classification is the process of examining an adverse event or incident and determiningwhether it constitutes an actual disaster.____________

Correct Answer

verifed

verified

A(n)____________________ is an agency that provides,in the case of DR/BC planning,physical facilities for a fee.

Correct Answer

verifed

verified

What are the major components of contingency planning?

Correct Answer

verifed

verified

Business impact analysis (BIA)...

View Answer

Explain the difference between a business impact analysis and the risk management process.

Correct Answer

verifed

verified

One of the fundamental differences betwe...

View Answer

A(n)____________________ occurs when an attack affects information resources and/or assets,causing actual damage or other disruptions.

Correct Answer

verifed

verified

An item does not become evidence until it is formally admitted to evidence by a judge or other ruling official.

Correct Answer

verifed

verified

Which of the following is the best example of a rapid-onset disaster?


A) Flood
B) Pest infestation
C) Famine
D) Environmental degradation

Correct Answer

verifed

verified

What teams are involved in contingency planning and contingency operations?

Correct Answer

verifed

verified

contingency planning managemen...

View Answer

List four of the eight key components of a typical IR policy.

Correct Answer

verifed

verified

The key components of a typical IR polic...

View Answer

After an incident,but before returning to its normal duties,the CSIRT must do which of the following?


A) Create the incident damage assessment
B) Conduct an after-action review
C) Restore data from backups
D) Restore services and processes in use

Correct Answer

verifed

verified

At what point in the incident lifecycle is the IR plan initiated?


A) Before an incident takes place
B) Once the DRP is activated
C) When an incident is detectedthataffects it
D) Once the BCP is activated

Correct Answer

verifed

verified

List the seven steps of the incident recovery process according to Donald Pipkin.

Correct Answer

verifed

verified

The incident recovery process involves t...

View Answer

A(n)____________________ is a document containing contact information of the individuals to notify in the event of an actual incident.

Correct Answer

verifed

verified

The first component of the analysis phase of a digital forensic investigation is ___________,which allows the investigator to quickly and easily search for a specific type of file.

Correct Answer

verifed

verified

Showing 21 - 40 of 60

Related Exams

Show Answer