Chapter 3: Planning for Contingencies
TRUE/FALSE
1. When an incident takes place, the disaster recovery (DR) plan is invoked before the incident response
(IR) plan.
2. In most organizations, the COO is responsible for creating the IR plan.
3. In a warm site, all services and communications links are fully configured and the site can be fully
functional within minutes.
4. When performing parallel testing, normal operations of the business are not impacted.
5. Training should be as specialized as possible; personnel who are responsible for one duty should not
be trained on other duties to avoid confusion during a disaster.
MULTIPLE CHOICE
1. Which of the following has the main goal of restoring normal modes of operation with minimal cost
and disruption to normal business activities after an event?
a.
risk management
c.
business response
b.
contingency planning
d.
disaster readiness
2. In the event of an incident or disaster, which team sets up and starts off-site operations?
a.
project management
c.
disaster recovery
b.
business continuity
d.
incident response
3. Which is the first step in the contingency planning process?
a.
business continuity training
c.
incident response planning
b.
disaster recovery planning
d.
business impact analysis
4. Which of the following is a tool that can be useful in resolving the issue of what business function is
the most critical?
a.
BIA questionnaire
c.
recovery time organizer
b.
weighted analysis tool
d.
MTD comparison
5. What is the last stage of the business impact analysis?
a.
identify resource requirements
c.
collect critical information about each
business unit
b.
analysis and prioritization of business
processes
d.
prioritize resources associated with the
business processes
6. At what point in the incident lifecycle is the IR plan initiated?
a.
before an incident takes place
c.
once the DRP is activated
b.
when an incident is detected
d.
once the BCP is activated
7. Which of the following is the process of examining a possible incident and determining whether it
constitutes an actual incident?
a.
Incident classification
c.
Incident registration
b.
Incident identification
d.
Incident verification
8. Which of the following is a possible indicator of an actual incident?
a.
Unusual consumption of computing resources
b.
Activities at unexpected times
c.
Presence of hacker tools
d.
Reported attacks
9. Which of the following is a definite indicator of an actual incident?
a.
Unusual system crashes
c.
Presence of new accounts
b.
Reported attack
d.
Use of dormant accounts
10. Which of the following determines the scope of the breach of confidentiality, integrity, and availability
of information and information assets?
a.
incident report
c.
information loss assessment
b.
incident damage assessment
d.
damage report
11. After an incident, but before returning to its normal duties, the CSIRT must do which of the following?
a.
create the incident damage assessment
c.
restore data from backups
b.
conduct an after-action review
d.
restore services and processes in use
12. Which of the following is a part of the incident recovery process?
a.
Identifying the vulnerabilities that allowed the incident to occur and spread
b.
Determining the event’s impact on normal business operations and, if necessary, making a
disaster declaration
c.
Supporting personnel and their loved ones during the crisis
d.
Keeping the public informed about the event and the actions being taken to ensure the
recovery of personnel and the enterprise
13. Which of the following is an example of a rapid-onset disaster?
a.
Flood
c.
Famine
b.
Pest infestation
d.
Environmental degradation
14. Which of the following is usually conducted via leased lines or secure Internet connections whereby
the receiving server archives the data as it is received?.
a.
Database shadowing
c.
Traditional backups
b.
Timesharing
d.
Electronic vaulting
15. Which of the following is the transfer of live transactions to an off-site facility?
a.
Remote journaling
c.
Database shadowing
b.
Electronic vaulting
d.
Timesharing
16. When a disaster renders the current business location unusable, which plan is put into action?
a.
crisis management
c.
incident response
b.
business continuity
d.
disaster recovery
17. Which of the following is true about a hot site?
a.
It is an empty room with standard heating, air conditioning, and electrical service.
b.
It includes computing equipment and peripherals with servers but not client workstations.
c.
It duplicates computing resources, peripherals, phone systems, applications, and
workstations.
d.
All communications services must be installed after the site is occupied.
18. In which type of site are no computer hardware or peripherals provided?
a.
cold site
c.
timeshare
b.
warm site
d.
hot site
19. Which of the following is a responsibility of the crisis management team?
a.
Restoring the data from backups
b.
Evaluating monitoring capabilities
c.
Activating the alert roster
d.
Restoring the services and processes in use
20. In which contingency plan strategy do individuals act as if an actual incident occurred, and begin
performing their required tasks and executing the necessary procedures, without interfering with the
normal operations of the business?
a.
a desk check
c.
a structured walk-through
b.
a simulation
d.
parallel testing
21. Which contingency plan strategy do individuals work on their own tasks and are responsible for
identifying the faults in their own procedures?
a.
A desk check
c.
A structured walk-through
b.
A simulation
d.
Parallel testing
COMPLETION
1. The four components of contingency planning are the ____________________, the incident response
plan, the disaster recovery plan, and the business continuity plan.
2. If operations at the primary site cannot be quickly restored, the ____________________ occurs
concurrently with the DR plan, enabling the business to continue at an alternate site.
3. The ____________________ plan is a detailed set of processes and procedures that anticipate, detect,
and mitigate the effects of an unexpected event that might compromise information resources and
assets.
4. A(n) ____________________ occurs when an attack affects information resources and/or assets,
causing actual damage or other disruptions.
5. A(n) ____________________ is a document containing contact information of the individuals to
notify in the event of an actual incident.
6. When dealing with an incident, the incident response team must conduct a(n)
____________________, which entails a detailed examination of the events that occurred from first
detection to final recovery.
7. ____________________ planning ensures that critical business functions can continue if a disaster
occurs.
8. A(n) ____________________ is an agency that provides, in the case of DR/BC planning, physical
facilities for a fee.
9. The bulk batch-transfer of data to an off-site facility is known as ____________________.
10. In ____________________ testing of contingency plans, the individuals follow each and every
procedure, including the interruption of service, restoration of data from backups, and notification of
appropriate individuals.
SHORT ANSWER
1. What are the four major components of contingency planning?
2. What teams are involved in contingency planning and contingency operations?
3. Explain the difference between a business impact analysis and the risk management process.
4. When undertaking the BIA, what are the five elements of the analysis the organization should
consider?
5. List four of the eight key components of a typical IR policy.
6. There are six key elements that the CP team must build into the DR Plan. What are three of them?
7. List the seven steps of the incident recovery process.
8. Compare and contrast a hot site, a warm site, and a cold site.
9. What are the three roles performed by the crisis management team?
10. Discuss three of the five strategies that can be used to test contingency strategies.