Incident management, disaster recovery, and business continuity planning concepts tested on the CISSP exam.
40 cards · basic cards · AI-written, checked twice. Edit anything.
- What is the Recovery Time Objective (RTO)?
- The maximum tolerable downtime before a business function must be restored to maintain operations.
- What is the Recovery Point Objective (RPO)?
- The maximum acceptable amount of data loss measured in time before the last backup.
- Name the four phases of incident response in NIST SP 800-61.
- Preparation, Detection and Analysis, Containment/Eradication/Recovery, Post-Incident Activities.
- What is the Mean Time To Repair (MTTR)?
- The average time needed to diagnose a problem and restore a system to full operation.
- Distinguish between Business Continuity Planning (BCP) and Disaster Recovery Planning (DRP).
- BCP keeps the entire business running with alternate processes; DRP restores normal IT operations after a disaster.
- What is a cold site in disaster recovery?
- An empty facility with power, HVAC, and communications ready but no systems, data, or equipment in place.
- What is a hot site in disaster recovery?
- A fully equipped facility that mirrors the production environment, ready to assume operations immediately.
- What is a warm site in disaster recovery?
- A partially configured facility with equipment and systems but not fully current data, requiring some setup time.
- Define the Business Impact Analysis (BIA).
- A process that identifies critical business functions, their dependencies, and the impact of their loss on the organization.
- What is Maximum Tolerable Downtime (MTD)?
- The longest time a business function can be unavailable before recovery is no longer viable.
- What is chain of custody in forensic investigations?
- A documented record of who handled, accessed, and possessed evidence and when, ensuring integrity and admissibility.
- Name the first step in forensic digital evidence handling.
- Acquire and preserve the evidence without alteration, using write-blockers and cryptographic hashing.
- What is the purpose of a forensic image or forensic copy?
- To create an exact bit-for-bit duplicate of storage media that can be analyzed without risking the original evidence.
- Define root cause analysis in incident management.
- The process of identifying the underlying reason an incident occurred, not just the immediate symptoms.
- What is a post-incident review or after-action review?
- A structured meeting after an incident to identify lessons learned, improve procedures, and prevent recurrence.