【计算机类职业资格】CISSP认证考试(业务连续性和灾难恢复)-试卷1及答案解析.doc
《【计算机类职业资格】CISSP认证考试(业务连续性和灾难恢复)-试卷1及答案解析.doc》由会员分享,可在线阅读,更多相关《【计算机类职业资格】CISSP认证考试(业务连续性和灾难恢复)-试卷1及答案解析.doc(20页珍藏版)》请在麦多课文档分享上搜索。
1、CISSP 认证考试(业务连续性和灾难恢复)-试卷 1 及答案解析(总分:64.00,做题时间:90 分钟)1.The NIST organization has defined best practices for creating continuity plans. Which of the following phases deals with identifying and prioritizing critical functions and systems?(分数:2.00)A.Identify preventive controls.B.Develop the continuit
2、y planning policy statement.C.Develop recovery strategies.D.Conduct the business impact analysis.2.As his companys business continuity coordinator, Matthew is responsible for helping recruit members to the business continuity planning (BCP) committee. Which of the following does not correctly descri
3、be this effort?(分数:2.00)A.Committee members should be involved with the planning stages, as well as the testing and implementation stages.B.The smaller the team the better, to keep meetings under control.C.The business continuity coordinator should work with management to appoint committee members.D
4、.The team should consist of people from different departments across the company.3.A business impact analysis is considered a functional analysis. Which of the following is not carried out during a business impact analysis?(分数:2.00)A.A parallel or full-interruption testB.The application of a classif
5、ication scheme based on criticality levelsC.The gathering of information via interviewsD.Documentation of business functions4.Which of the following is the best way to ensure that the companys backup tapes can be restored and used at a warm site?(分数:2.00)A.Ask the offsite vendor to test them and lab
6、el the ones that were properly read.B.Test them on the vendors machine, which wont be used during an emergency.C.Retrieve the tapes from the offsite facility and verify that the equipment from the original site can read them.D.Inventory each tape kept at the vendors site twice a month.5.An approach
7、to alternate offsite facilities is to establish a reciprocal agreement. Which of the following describes the pros and cons of a reciprocal agreement?(分数:2.00)A.It is fully configured and ready to operate within a few hours, but is the most expensive of the offsite choices.B.It is an inexpensive opti
8、on, but it takes the most time and effort to get up and running after a disaster.C.It is a good alternative for companies that depend upon proprietary software, but annual testing is not usually available.D.It is the cheapest of the offsite choices, but mixing operations could introduce many securit
9、y issues.6.Which of the following steps comes first in a business impact analysis?(分数:2.00)A.Calculate the risk for each different business function.B.Identify critical business functions.C.Create data-gathering techniques.D.Identify vulnerabilities and threats to business functions.7.The operations
10、 team is responsible for defining which data gets backed up and how often. Which type of backup process backs up files that have been modified since the last time all data was backed up?(分数:2.00)A.Incremental processB.Full backupC.Partial backupD.Differential process8.After a disaster occurs, a dama
11、ge assessment needs to take place. Which of the following steps occurs last in a damage assessment?(分数:2.00)A.Determine the cause of the disaster.B.Identify the resources that must be replaced immediately.C.Declare a disaster.D.Determine how long it will take to bring critical functions back online.
12、9.Of the following plans, which establishes senior management and a headquarters after a disaster?(分数:2.00)A.Continuity of operations planB.Cyber-incident response planC.Occupant emergency planD.IT contingency plan10.It is not unusual for business continuity plans to become out of date. Which of the
13、 following is not a reason why plans become outdated?(分数:2.00)A.Changes in hardware, software, and applicationsB.Infrastructure and environment changesC.Personnel turnoverD.That the business continuity process is integrated into the change management process11.Preplanned business continuity procedur
14、es provide organizations a number of benefits. Which of the following is not a capability enabled by business continuity planning?(分数:2.00)A.Resuming critical business functionsB.Letting business partners know your company is unpreparedC.Protecting lives and ensuring safetyD.Ensuring survivability o
15、f the business12.Management support is critical to the success of a business continuity plan. Which of the following is the most important to be provided to management to obtain their support?(分数:2.00)A.Business caseB.Business impact analysisC.Risk analysisD.Threat report13.Gizmos and Gadgets has re
16、stored its original facility after a disaster. What should be moved in first?(分数:2.00)A.ManagementB.Most critical systemsC.Most critical functionsD.Least critical functions14.Which of the following is a critical first step in disaster recovery and contingency planning?(分数:2.00)A.Plan testing and dri
17、lls.B.Complete a business impact analysis.C.Determine offsite backup facility alternatives.D.Organize and create relevant documentation.15.Which of the following is not a reason to develop and implement a disaster recovery plan?(分数:2.00)A.Provide steps for a post-disaster recovery.B.Extend backup op
18、erations to include more than just backing up data.C.Outline business functions and systems.D.Provide procedures for emergency responses.16.Business continuity plans can be assessed via a number of tests. Which type of test continues up to the point of actual relocation to an offsite facility and ac
19、tual shipment of replacement equipment?(分数:2.00)A.Parallel testB.Checklist testC.Structured walk-through testD.Simulation test17.With what phase of a business continuity plan does a company proceed when it is ready to move back into its original site or a new site?(分数:2.00)A.Reconstitution phaseB.Re
20、covery phaseC.Project initiation phaseD.Damage assessment phase18.Several teams should be involved in carrying out the business continuity plan. Which team is responsible for starting the recovery of the original site?(分数:2.00)A.Damage assessment teamB.BCP teamC.Salvage teamD.Restoration team19.ACME
21、 Inc. paid a software vendor to develop specialized software, and that vendor has gone out of business. ACME Inc. does not have access to the code and therefore cannot keep it updated. What mechanism should the company have implemented to prevent this from happening?(分数:2.00)A.Reciprocal agreementB.
22、Software escrowC.Electronic vaultingD.Business interruption insurance20.Which of the following incorrectly describes the concept of executive succession planning?(分数:2.00)A.Predetermined steps protect the company if a senior executive leaves.B.Two or more senior staff cannot be exposed to a particul
23、ar risk at the same time.C.It documents the assignment of deputy roles.D.It covers assigning a skeleton crew to resume operations after a disaster.21.What is the missing second step in the graphic that follows? (分数:2.00)A.Identify continuity coordinatorB.Business impact analysisC.Identify BCP commit
24、teeD.Dependency identification22.Different threats need to be evaluated and ranked based upon their severity of business risk when developing a BCP. Which ranking approach is illustrated in the graphic that follows? (分数:2.00)A.Mean time to repairB.Mean time between failuresC.Maximum critical downtim
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
5000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 计算机 职业资格 CISSP 认证 考试 业务 连续性 灾难 恢复 试卷 答案 解析 DOC
