CYBR 3200 EXAM 3 Questions with Complete Solutions Graded A+ Which strategy to test contingency plans involves team members acting as defenders, using their own equipment or a duplicate environment, against realistic attacks executed by external information security professionals? - Correct Answer War Gaming Incident ____ is the process of evaluating organizational events, determining which events are possible incidents, also called incident candidates, and then determining whether or not the incident candidate is an actual incident or a nonevent, also called a false positive incident candidate. - Correct Answer classification The actions an organization should take while an incident is in progress are defined in a document referred to as the ____ plan. - Correct Answer incident response (IR) _____ techniques are generally used by organizations needing immediate data recovery after an incident or disaster. - Correct Answer Shadowing ____ clustering is a more complex model in which all members of a cluster simultaneously provide application services. - Correct Answer Active/active The bulk transfer of data in batches to an off-site facility is called ____. - Correct Answer electronic vaulting The ____ review entails a detailed examination of the events that occurred from first detection to final recovery. - Correct Answer after-action Incident response focuses on immediate response to small-scale events. - Correct Answer True The business impact analysis (BIA) is the first major component of the CP process. - Correct Answer True The ____, which is also known as the Security Incident Response Team (SIRT), is the group of individuals who would be expected to respond to a detected incident. - Correct Answer Computer Security Incident Response Team (CSIRT) 1 / 2
A(n) ____ is a detailed description of the activities that occur during an attack, including the preliminary indications of the attack as well as the actions taken and the outcome. - Correct Answer attack profile According to D. L. Pipkin, the use of ___ ____ is a definite indicator of an actual incident. - Correct Answer use of dormant accounts RAID is a replacement for backup and recovery processes - Correct Answer false A(n) ____ is any clearly identified attack on the organization's information assets that would threaten the assets' confidentiality, integrity, or availability. - Correct Answer incident A _______ backup is the storage of all files that have changed or have been added since the last full backup. - Correct Answer differential ____ are the representative collection of individuals with a stake in the successful and uninterrupted operation of the organization's information infrastructure. - Correct Answer stakeholders What is the drawback of backups? - Correct Answer Time required to store and retrieve information Which cloud type acts as a collaboration between a few entities for the sole benefit of those entities. - Correct Answer Community clouds The final phase of the IR planning function is plan maintenance - Correct Answer true In some organizations, which two plans are considered to be one plan, known as the business resumption plan? - Correct Answer DR plan and BC plan The key role of a ____ is defining how to reestablish operations at the location where the organization usually operates - Correct Answer disaster recovery (DR)
- / 2