ISC CISSP Practice Test Questions and Exam Dumps Part19 Q361-380

View Full ISC CISSP Exam Dumps and Practice Test Dumps.

 

Question 361

Which recovery metric defines the maximum acceptable amount of time that a system or business process can remain unavailable after a disruption?

  1. RPO
  2. RTO
  3. ALE
  4. ARO

Correct Answer: 2

Explanation

Recovery Time Objective, or RTO, defines the maximum acceptable period within which a system, service, or business process should be restored after a disruption. It is established according to business requirements and the consequences of prolonged unavailability. RTO influences recovery strategies, alternate facilities, staffing, technology requirements, and restoration procedures. RTO should be determined through business impact analysis rather than selected arbitrarily. It differs from RPO, which focuses on the acceptable amount of data loss measured in time rather than the time required to restore operations.

Question 362

Which recovery facility is typically equipped with the infrastructure necessary to support operations immediately or with minimal preparation after a major disruption?

  1. Cold site
  2. Warm site
  3. Hot site
  4. Storage archive

Correct Answer: 3

Explanation

A hot site is a recovery facility that is already equipped with substantial infrastructure and resources required to support business operations following a disruption. Depending on the design, systems and data may be maintained in a ready or near-ready state, allowing faster recovery than a cold site. Hot sites are generally more expensive because maintaining operational infrastructure and synchronization requires significant resources. Organizations should select recovery facilities according to business impact, RTO requirements, budget, geographic considerations, and the criticality of the services being protected.

Question 363

Which recovery facility provides infrastructure and equipment but generally requires additional preparation before operations can resume?

  1. Hot site
  2. Cold site
  3. Warm site
  4. Mobile storage

Correct Answer: 3

Explanation

A warm site provides more preparation and infrastructure than a cold site but is generally not maintained in a fully operational state like a hot site. It may contain servers, networking equipment, power, and environmental controls, but additional configuration, restoration, or data loading may be required before production operations can resume. Warm sites can provide a balance between recovery speed and cost. Organizations should determine whether the expected recovery capability meets the RTO established for the affected business functions.

Question 364

Which recovery facility provides basic infrastructure but generally requires significant equipment installation and configuration before it can support normal operations?

  1. Cold site
  2. Hot site
  3. Warm site
  4. Mirrored site

Correct Answer: 1

Explanation

A cold site provides basic facilities such as physical space, power, environmental controls, and connectivity but generally lacks fully configured production systems. Significant preparation, equipment installation, configuration, and data restoration may therefore be required before operations can resume. Cold sites are typically less expensive to maintain than hot sites but usually have longer recovery times. They may be appropriate when business functions can tolerate extended downtime or when budget constraints make fully equipped recovery facilities impractical. Recovery plans should account for equipment availability and transportation requirements.

Question 365

Which backup strategy copies all selected data each time the backup is performed?

  1. Incremental backup
  2. Differential backup
  3. Full backup
  4. Snapshot backup

Correct Answer: 3

Explanation

A full backup copies all selected data during each backup operation. Because every backup contains a complete copy of the selected information, restoration can generally be simpler and faster compared with strategies that require multiple dependent backup sets. However, full backups typically require more storage capacity and may take longer to complete. Organizations may combine periodic full backups with incremental or differential backups to balance storage, backup windows, and recovery requirements. Backup schedules should also account for retention, encryption, offsite storage, and restoration testing.

Question 366

Which backup method contains changes made since the most recent full backup?

  1. Differential backup
  2. Incremental backup
  3. Full backup
  4. Mirror backup

Correct Answer: 1

Explanation

A differential backup contains data that has changed since the most recent full backup. Each new differential backup continues to include all changes made after that full backup, so its size generally increases until another full backup is created. During restoration, the organization normally needs the latest full backup and the latest differential backup. This can make restoration simpler than using a long chain of incremental backups. The appropriate strategy depends on recovery requirements, available storage, backup windows, and the organization’s operational priorities.

Question 367

Which disaster recovery activity verifies that personnel and procedures can successfully execute the documented recovery plan without necessarily performing a full technical recovery?

  1. Tabletop exercise
  2. Vulnerability scan
  3. Penetration test
  4. Code review

Correct Answer: 1

Explanation

A tabletop exercise is a discussion-based disaster recovery or incident response exercise in which participants work through a simulated scenario using documented plans and procedures. It can reveal unclear responsibilities, communication problems, missing dependencies, and weaknesses in decision-making without requiring a complete technical recovery. Participants discuss what actions they would take and how they would coordinate with other teams. Tabletop exercises are generally less disruptive and less expensive than full-scale technical exercises, making them useful for regularly validating plans and identifying improvement opportunities.

Question 368

Which disaster recovery exercise involves actually restoring systems or performing operational recovery activities to validate technical capabilities?

  1. Document review
  2. Full interruption test
  3. Technical recovery test
  4. Policy acknowledgment

Correct Answer: 3

Explanation

A technical recovery test validates whether systems, infrastructure, procedures, and personnel can perform required recovery activities. Depending on the scope, the test may involve restoring backups, rebuilding servers, activating alternate infrastructure, testing network connectivity, or validating application dependencies. Technical testing provides stronger evidence of actual recovery capability than simply reviewing documentation. Organizations should carefully define scope and safeguards to prevent unnecessary disruption. Results should be documented, weaknesses assigned to responsible personnel, and recovery procedures updated based on lessons learned.

Question 369

Which business continuity concept identifies the resources and dependencies required for a critical business process to operate?

  1. Resource dependency analysis
  2. Password management
  3. Security awareness
  4. Log rotation

Correct Answer: 1

Explanation

Resource dependency analysis identifies the resources and relationships necessary for a business process to function. Dependencies may include personnel, facilities, applications, databases, network services, suppliers, utilities, telecommunications, and other supporting resources. Understanding these relationships helps organizations identify potential single points of failure and determine appropriate continuity and recovery strategies. The analysis can also reveal dependencies that may not be immediately obvious, such as a critical application relying on a specific database or external service. Results should be incorporated into continuity and disaster recovery planning.

Question 370

Which activity establishes how quickly critical services must be restored and how much data loss can be tolerated?

  1. Data classification
  2. Business impact analysis
  3. Vulnerability assessment
  4. Security awareness training

Correct Answer: 2

Explanation

Business impact analysis helps organizations determine the consequences of disruptions and establish recovery requirements for critical business functions. Among other outcomes, it supports the development of recovery time and recovery point objectives. The analysis considers factors such as financial loss, regulatory obligations, operational disruption, customer impact, and dependencies. BIA results help management prioritize recovery activities and determine which resources require stronger resilience. It differs from vulnerability assessment, which focuses on weaknesses that could be exploited or otherwise cause security problems.

Question 371

Which security governance document establishes management’s overall direction and expectations for protecting organizational information?

  1. Security policy
  2. Incident ticket
  3. Network diagram
  4. System log

Correct Answer: 1

Explanation

A security policy establishes management’s high-level direction, expectations, and requirements concerning information security. It provides a foundation for standards, procedures, guidelines, and technical controls. Policies may address topics such as access control, acceptable use, data protection, incident response, risk management, and personnel responsibilities. Senior management approval is important because policies represent organizational authority and expectations. Policies should be communicated to relevant personnel and periodically reviewed to ensure they remain aligned with business objectives, legal requirements, technological changes, and current security risks.

Question 372

Which document provides mandatory, detailed requirements that support the implementation of an organizational security policy?

  1. Guideline
  2. Standard
  3. Memo
  4. Risk register

Correct Answer: 2

Explanation

A security standard establishes mandatory and specific requirements for implementing a broader organizational policy. Standards can define approved technologies, configurations, security settings, password requirements, encryption methods, or other measurable requirements. Unlike guidelines, which are generally recommendations, standards are normally expected to be followed unless an approved exception exists. Standards translate management expectations into consistent technical or operational requirements. Organizations should maintain standards as environments change and should establish exception processes for situations where a mandatory requirement cannot reasonably be implemented.

Question 373

Which document provides recommended practices that personnel may follow but does not normally impose mandatory requirements?

  1. Standard
  2. Policy
  3. Guideline
  4. Regulation

Correct Answer: 3

Explanation

A guideline provides recommended practices or advice intended to help personnel achieve security objectives. Unlike a standard, a guideline generally does not impose a mandatory requirement, although organizations may choose to make specific guidelines mandatory through policy or standards. Guidelines can be useful when different situations require flexibility or when personnel need practical recommendations for implementing security requirements. Examples include recommended configuration practices, secure handling advice, and suggested administrative procedures. Guidelines should remain aligned with organizational policies and should be reviewed as technologies and risks evolve.

Question 374

Which document describes the specific sequence of actions personnel should follow when performing a recurring security task?

  1. Procedure
  2. Policy
  3. Guideline
  4. Mission statement

Correct Answer: 1

Explanation

A procedure provides detailed, step-by-step instructions for performing a specific task or process. Procedures translate broader policies and standards into repeatable operational actions. Examples include account provisioning procedures, incident escalation procedures, backup restoration procedures, and employee termination procedures. Well-written procedures help promote consistency, reduce errors, and clarify responsibilities. They should identify prerequisites, required approvals, actions, validation steps, and documentation requirements where appropriate. Procedures should be reviewed periodically and updated when systems, responsibilities, technologies, or organizational requirements change.

Question 375

Which governance activity ensures that an organization continually monitors whether security objectives and controls remain aligned with business requirements?

  1. Security governance
  2. Data compression
  3. Network translation
  4. Media destruction

Correct Answer: 1

Explanation

Security governance provides the structures, responsibilities, policies, and oversight mechanisms used to direct and control an organization’s security program. Effective governance helps ensure that security objectives remain aligned with business strategy, risk tolerance, legal obligations, and operational requirements. Governance may involve senior management oversight, security policies, risk reporting, performance measurements, compliance monitoring, and accountability structures. It is broader than implementing individual technical controls. Strong governance ensures that security decisions are made consistently and that management receives appropriate information about significant risks and control effectiveness.

Question 376

Which concept requires an organization to identify and manage the security responsibilities of external suppliers and service providers throughout their relationship?

  1. Third-party risk management
  2. Password synchronization
  3. Data deduplication
  4. Network tunneling

Correct Answer: 1

Explanation

Third-party risk management addresses security risks introduced by vendors, contractors, suppliers, cloud providers, and other external parties. It should cover the full relationship lifecycle, including selection, assessment, contracting, onboarding, monitoring, changes, and termination. Organizations may establish security requirements, conduct assessments, review independent evidence, define incident notification obligations, and maintain audit rights. Risk should be evaluated according to the sensitivity of information and services involved. Ongoing monitoring is important because a vendor’s security posture can change after the initial assessment.

Question 377

Which personnel security practice helps determine whether an individual is suitable for a position before granting access to sensitive organizational resources?

  1. Background screening
  2. Data aggregation
  3. Network segmentation
  4. Key rotation

Correct Answer: 1

Explanation

Background screening is a personnel security practice used to evaluate an individual’s suitability for a position based on applicable organizational, legal, and regulatory requirements. Depending on the role and jurisdiction, screening may consider employment history, education, references, identity, or other permitted information. Screening requirements should be risk-based and consistently applied according to organizational policy and applicable law. Screening is only one part of personnel security. Organizations should also address onboarding, security awareness, access management, role changes, disciplinary processes, and termination procedures.

Question 378

Which personnel security process ensures that an employee’s physical and logical access is removed when employment ends?

  1. Offboarding
  2. Onboarding
  3. Job rotation
  4. Security awareness

Correct Answer: 1

Explanation

Offboarding is the controlled process used when an employee or contractor leaves an organization. It can include disabling accounts, collecting access badges and equipment, revoking credentials, removing application permissions, retrieving organizational information, and communicating relevant obligations. Prompt offboarding reduces the opportunity for former personnel to retain unauthorized access. The process should coordinate human resources, management, physical security, identity management, and information technology functions. Organizations should define different procedures for routine and involuntary termination because the timing and security requirements may differ.

Question 379

Which personnel security practice periodically moves employees between different job responsibilities to reduce the opportunity for fraud and improve organizational resilience?

  1. Mandatory vacation
  2. Job rotation
  3. Separation of duties
  4. Background screening

Correct Answer: 2

Explanation

Job rotation periodically moves personnel between different responsibilities or positions. It can reduce the likelihood that one individual maintains exclusive control over a process for an extended period and may expose irregularities that another employee notices. Job rotation can also improve cross-training and organizational resilience by ensuring multiple employees understand important processes. It should be carefully planned because moving employees between roles can introduce temporary access and training requirements. Job rotation works well alongside separation of duties, mandatory vacations, monitoring, and access reviews.

Question 380

Which personnel security practice requires employees in sensitive positions to take a continuous period of leave so that another individual can perform their duties and potential irregularities may be identified?

  1. Job rotation
  2. Mandatory vacation
  3. Background screening
  4. Privilege escalation

Correct Answer: 2

Explanation

Mandatory vacation requires personnel, particularly those in sensitive or privileged positions, to take a defined period of continuous leave. Another employee performs the individual’s responsibilities during the absence, which can expose fraudulent activity, policy violations, or unusual processes that might otherwise remain hidden. The practice can also support personnel wellbeing and operational continuity. Mandatory vacation is not a substitute for monitoring, access controls, or separation of duties. Organizations should establish appropriate requirements based on risk, role sensitivity, applicable employment rules, and operational needs.