CISA BCP部分练习题

CBKBCP部分必考题和知识点
1. Which type of off-site backup facility is the most popular for companies today?
A. Hot Site
B. Cold Site
C. Reciprocal agreement

D. Warm Site

1.哪种类型的场外备份设施是当今最受公司欢迎的?
A.热站
B.冷站点
C.互惠协议

D.温站

2. The Recovery Point Objective in Disaster Recovery Planning refers to which of the following?
A. Point to which application data must be recovered to resume business transactions
B. Maximum elapsed time required to complete recovery of application data
C. Point to which application data must be recovered to resume system operations
D. Point to which information system must be operational at alternate site

2.灾难恢复计划中的恢复点目标是指以下哪项?
A.指向必须恢复哪些应用程序数据以恢复业务事务
B.完成应用程序数据恢复所需的最长时间
C.指向必须恢复哪些应用程序数据以恢复系统操作
D.指向哪个信息系统必须在备用站点运行


3. What is the window of time for recovery of information processing capabilities based on?
A. Quality of the data to be processed.
B. Nature of the disaster.
C. Criticality of the operations affected.
D. Applications that are mainframe based.

3.什么是明确恢复信息处理能力的时间窗口的基本条件?
A.要处理的数据的质量。
B.灾难的性质。

C.受影响的业务的重要性。
D.基于大型机的应用程序。


4. What is not a benefit of cold sites?
A. No resource contention with other organisation
B. Quick Recovery
C. Geographical location that is not affected by the same disaster
D. Low Cost
4.哪些不是冷站的好处?
A.与其他组织没有资源争用

B.快速恢复 (热站的)
C.不受同一灾害影响的地理位置
D.低成本


5. Which of the following best describes remote journaling?
A. Send hourly tapes containing transactions off-site.
B. Send daily tapes containing transactions off-site.
C. Real-time capture of transactions to multiple storage devices.

D. Parallel processing of transactions to an alternate site.
5.以下哪项是远程路由调度的最佳描述?
A.发送包含非现场交易的每小时磁带。
B.发送包含非现场交易的每日磁带。
C.实时捕获到多个存储设备的事务。
D.将交易并行处理到备用站点。


6. Which of the following should be most emphasized as a business impact analysis critically examines business processes?
A. composition
B. priorities

C. dependencies
D. service levels
6.在业务流程中,哪一项是BIA业务影响分析,最应该重视的?
A.组成
B.优先事项
C.依赖
D.服务水平


7. When preparing a business continuity plan, who of the following is responsible for identifying and prioritizing time-critical systems?
A. Executive management staff
B. Senior business unit management
C. BCP committee
D. Functional business units

7.在准备业务连续性计划时,以下哪些人负责识别时间要求严格的系统并确定其优先级?
A.执行管理人员

B.高管层
C. BCP委员会
D.功能业务单位


8. Which of the following steps should be performed first in a business impact analysis (BIA)?
A. Identify all business units within the organization.
B. Evaluate the impact of disruptive events.
C. Estimate the Recovery Time Objectives (RTO).
D. Evaluate the criticality of business functions.

8.在业务影响分析(BIA)中,应首先执行以下哪些步骤?
A.确定组织内的所有业务部门。
B.评估破坏性事件的影响。
C.估计恢复时间目标(RTO)。
D.评估业务功能的重要性。

9. Which of the following statements pertaining to disaster recovery is incorrect?
A. A recovery team's primary task is to get the pre-defined critical business functions at the alternate backup processing site.
B. A salvage team's task is to ensure that the primary site returns to normal processing conditions.
C. The disaster recovery plan should include how the company will return from the alternate site to the primary site.
D. When returning to the primary site, the most critical applications should be brought back first.


9.以下哪些与灾难恢复相关的陈述不正确?
A:恢复团队的主要任务是在备用备份处理站点获取预定义的关键业务功能。
B.应急团队的任务是确保主站点恢复正常的处理条件。
C.灾难恢复计划应包括公司如何从备用站点返回主站点。

D.返回主站点时,应首先恢复最关键的应用程序


10. Which disaster recovery plan test involves functional representatives meeting to review the plan in detail?
A. Simulation test
B. Checklist test
C. Parallel test
D. Structured walk-through test


10.哪些灾难恢复计划测试涉及功能代表会议以详细审查计划?
A.模拟测试
B.清单测试
C.平行测试
D.结构间的穿行测试


11. During Recovery, which of following is most critical?
A. Data
B. Hardware/Software
C. Communication Links
D. Software Applications


11.在恢复期间,以下哪项最紧要的?
A.数据
B.硬件/软件
C.通讯链接
D.软件应用程序


12. Failure of a contingency plan is usually:
A. A technical failure.

B. A management failure.
C. Because of a lack of awareness.
D. Because of a lack of training.

12.应急计划的失败通常是:
A.技术故障。
B.管理失败。
C.由于缺乏意识。
D.由于缺乏培训。


13. What is a hot-site facility?
A. A site with pre-installed computers, raised flooring, air conditioning, telecommunications and networking equipment, and UPS.
B. A site in which space is reserved with pre-installed wiring and raised floors.
C. A site with raised flooring, air conditioning, telecommunications, and networking equipment, and UPS.
D. A site with ready made work space with telecommunications equipment, LANs, PCs, and terminals for work groups.

 

13.什么是热站?

A.具有预装计算机,活动地板,空调,电信和网络设备以及UPS的站点。
B.预留空间的场地,预先安装的布线和活动地板。
C.有高架地板,空调,电信和网络设备以及UPS的场地。
D.具有现成工作空间的站点,其中包括电信设备,LAN,PC和工作组终端。


14. During the course of a Business Impact Analysis (BIA) you will less likely:
A. Estimate the financial and operational impacts of a disruption.
B. Identify regulatory exposure.

C. Determine a function's Recovery Time Objective (RTO).
D. Determine the impact upon the organization's market share and corporate image.


14.在业务影响分析(BIA)过程中,您不太可能:
A.估算中断的财务和运营影响。
B.确定监管风险。
C.确定函数的恢复时间目标(RTO)。
D.确定对组织的市场份额和企业形象的影响


15. What is the Maximum Tolerable Downtime (MTD)?
A. Maximum elapsed time required to complete recovery of application data
B. Minimum elapsed time required to complete recovery of application data
C. Maximum elapsed time required to move back to primary site after a major disruption
D. It is maximum delay businesses can tolerate and still remain viable


15.什么是最大容忍停机时间(MTD)?

A.完成应用程序数据恢复所需的最长时间
B.完成应用程序数据恢复所需的最短时间
C.在重大中断后返回主站点所需的最长时间

D.这是企业可以容忍并且仍然可行的最大延迟


16. Which of the following actions would be most appropriate after discovering that an organization's business continuity plan provides for an alternate processing site which will accommodate fifty percent of the primary processing facility's processing capability?
A. Do nothing, because generally, less than twenty five percent of all processing is critical to an organizations survival and the backup capacity is therefore adequate.
B. Identify applications that could be processed at the alternate site and develop manual procedures to back up other processing.
C. Ensure that critical applications have been identified and that the alternate site could process all such applications.
D. Recommend that the information processing facility arrange for an alternate processing site with the capacity to handle at least seventy five percent of normal processing.
16.在发现组织的业务连续性计划提供可容纳50%主要处理设施处理能力的备用处理站点后,以下哪项行动最合适?
A.什么也不做,因为通常,只有不到百分之二十五的处理对组织的生存至关重要,因此备份能力就足够了。
B.确定可在备用站点处理的应用程序,并开发手动程序以备份其他处理。

C.确保已满足关键应用程序,并确保备用站点可以处理所有此类应用程序。
D.建议信息处理设施安排备用处理站点,其处理能力至少为正常处理的百分之七十五。


17. Contracts and agreements are unenforceable in which of the following alternate backup facilities?
A. hot site
B. warm site
C. cold site
D. reciprocal agreement
17.以下哪个备用备用设施的合同和协议无法执行?【???】
A.热站
B.温站
C.冷站
D.互惠协议


18. The main advantage of using hot sites is:
A. Costs associated with this solution are relatively low.
B. Hot sites can be used for an extended amount of time.
C. Hot sites do not require that equipment and systems software be compatible with the primary installation being backed up.
D. Hot sites can be made ready for operation within a short period of time.
18.使用热门网站的主要优点是:
A.与此解决方案相关的成本相对较低。
B.热门网站可以使用更长的时间。
C.热站点不要求设备和系统软件与正在备份的主要设备兼容。

D.热点可以在短时间内准备好运行。


19. After a company is out of an emergency state, what should be moved back to the original site first?
A. Executives
B. Least critical work
C. IT support staff
D. Most critical work

19.公司退出紧急状态后,应该先将其移回原址?
A.高管
B.最不重要的工作
C. IT支持人员
D.最关键的工作


20. Which is not one of the primary goals of BIA?
A. Criticality Prioritization
B. Down time estimation
C. Determining requirements for critical business functions
D. Deciding on various test to be performed to validate Business Contuity Plan
20.哪个不是BIA的主要目标之一?
A.关键性优先排序
B.停机时间估算
C.确定关键业务功能的要求

D.决定进行各种测试以验证业务损失计划


21. Which of the following alternative business recovery strategies would be LEAST appropriate in a large database and on-line communications network environment where the critical business continuity period is 7 days ?
A. Hot site
B. Warm site
C. Duplicate information processing facilities
D. Reciprocal agreement
21.在关键业务连续性期限为7天的大型数据库和在线通信网络环境中,以下哪种替代业务恢复策略最不合适?
A.热门网站
B.温暖的网站
C.重复的信息处理设施

D.互惠协议


22. Emergency actions are taken at the incipient stage of a disaster with the objectives of preventing injuries or loss of life and of:
A. determining the extent of property damage.
B. protecting evidence.
C. preventing looting and further damage.
D. mitigating the damage to avoid the need for recovery.
22.在灾害发生初期采取紧急行动,目标是防止受伤或丧生,并且:
A.确定财产损失的程度。
B.保护证据。
C.防止抢劫和进一步破坏。

D.减轻损害以避免需要恢复。


23. Which primary element of BCP includes carrying out vulnerability analysis?
A. Scope and Plan Initiation
B. Business Impact Assessment
C. Business Continuity Plan Development
D. Plan Approval and Implementation
23. BCP的哪个主要元素包括进行漏洞分析?
A.范围和计划启动

B.业务影响评估
C.业务连续性计划制定
D.计划批准和实施


24. Which of the following is the most important consideration in locating an alternate computing facility during the development of a disaster recovery plan?
A. It is unlikely to be affected by the same contingency.
B. It is close enough to become operational quickly.
C. It is close enough to serve its users.
D. It is convenient to airports and hotels.
24.在制定灾难恢复计划期间,在确定备用计算设施时,最重要的考虑因素是以下哪一项?

A.不太可能受到同样的意外事故的影响。
B.它足够接近迅速投入运营。
C.它足够接近为用户服务。
D.方便机场和酒店。


25. Which of the following is not a direct benefit of successful Disaster Recovery Planning?
A. Maintenance of Business Continuity
B. Protection of Critical Data
C. Increase in IS performance
D. Minimized Impact of a disaster
25.以下哪项不是成功的灾难恢复计划的直接好处?
A.维持业务连续性
B.关键数据的保护

C. IS性能的提高
D.最大限度地减少灾难的影响


26. Organizations should not view disaster recovery as which of the following?
A. committed expense
B. discretionary expense
C. enforcement of legal statutes
D. compliance with regulations
26.各组织不应将灾后恢复视为以下哪项?
A.承诺费用

B.自由支配费用
C.执行法律法规
D.遵守法规


27. Which of the following server contingency solutions offers the highest availability?
A. System backups
B. Electronic vaulting/remote journaling
C. Redundant arrays of independent disks (RAID)
D. Load balancing/disk replication
27.以下哪种服务器应急解决方案提供最高可用性?
A.系统备份
B.电子跳跃/远程日记
C.独立磁盘冗余阵列(RAID)

D.负载平衡/磁盘复制


28. Which of the following recovery plan test results would be most useful to management?
A. elapsed time to perform various activities
B. list of successful and unsuccessful activities
C. amount of work completed
D. description of each activity
28.以下哪项恢复计划测试结果对管理最有用?
A.执行各种活动所用的时间

B.成功和不成功活动的清单
C.完成的工作量
D.每项活动的描述


29. Which of the following is less likely to accompany a contingency plan, either within the plan itself or in the form of an appendix?
A. Contact information for all personnel.
B. Vendor contact information, including offsite storage and alternate site.
C. Equipment and system requirements lists of the hardware, software, firmware and other resources required to support system operations.
D. The Business Impact Analysis.
29.无论是在计划本身内还是以附录的形式,以下哪一项不太可能伴随应急计划?

A.所有人员的联系信息。
B.供应商联系信息,包括异地存储和备用站点。
C.设备和系统要求支持系统操作所需的硬件,软件,固件和其他资源的列表。
D.业务影响分析。


30. Which of the following statements pertaining to business continuity planning is correct?
A. The first step when developing a business continuity plan is to perform a business impact analysis.
B. A business continuity plan mainly concerns the organization's information systems.
C. Generally, each IT platform that runs an application will need a recovery strategy.
D. Recovery of telecommunications should be part of the recovery of IT facilities.
30.以下哪些与业务连续性计划有关的陈述是正确的?
A.制定业务连续性计划的第一步是执行业务影响分析。
B.业务连续性计划主要涉及组织的信息系统。
C.通常,运行应用程序的每个IT平台都需要恢复策略。
D.恢复电信应成为信息技术设施恢复的一部分。


31. Which of the following statements pertaining to dealing with the media after a disaster occurred and disturbed the organization's activities is incorrect?
A. The CEO should always be the spokesperson for the company during a disaster.
B. The disaster recovery plan must include how the media is to be handled during the disaster.
C. The organization's spokesperson should report bad news before the press gets a hold of it through another channel.
D. An emergency press conference site should be planned ahead.
31.以下哪些与灾害发生后处理媒体有关的声明以及组织的活动受到干扰是不正确的?

A.首席执行官应该始终是灾难期间公司的发言人。
B.灾难恢复计划必须包括灾难期间如何处理媒体。
C.该组织的发言人应该在新闻媒体通过另一个频道获取此消息之前报告坏消息。
D.应提前安排紧急新闻发布会现场。


32. Which of the following statements regarding an off-site information processing facility is TRUE?
A. It should have the same amount of physical access restrictions as the primary processing site.
B. It should be located in proximity to the originating site so that it can quickly be made operational.
C. It should be easily identified from the outside so in the event of an emergency it can be easily found.
D. Need not have the same level of environmental monitoring as the originating site since this would be cost prohibitive.
32.以下哪些关于场外信息处理设施的陈述是真的?

A.它应具有与主要处理站点相同的物理访问限制。
B.它应位于原始站点附近,以便快速运行。
C.应该很容易从外部识别,因此在紧急情况下可以很容易地找到它。
D.不需要与原始地点进行相同水平的环境监测,因为这样做成本过高。


33. What assesses potential loss that could be caused by a disaster?
A. The Business Assessment (BA)
B. The Business Impact Analysis (BIA)
C. The Risk Assessment (RA)
D. The Business Continuity Plan (BCP)

33.什么评估灾难可能造成的潜在损失?
A.业务评估(BA)
B.业务影响分析(BIA)
C.风险评估(RA)
D.业务连续性计划(BCP)

 


34. The term critical support areas is defined as:
A. Business units or functions that must be present to sustain continuity of business, maintain life safety and avoid public embarrassment
B. Business units or functions that may be replaced by others in disaster situation
C. Human Resource and Information technologies
D. Business units or functions that require support against man made disasters
34.关键支撑领域一词的定义是:

A.必须存在的业务单位或职能,以维持业务的连续性,维护生命安全并避免公众阻碍
B.在灾害情况下可能被其他人替换的业务单位或职能
C.人力资源和信息技术
D.需要支持人为灾害的业务单位或职能部门


35. Which of the following is an advantage of the use of hot sites as a backup alternative?
A. The costs associated with hot sites are low.
B. Hot sites can be made ready for operation within a short period of time.
C. Hot sites can be used for an extended amount of time.
D. Hot sites do not require that equipment and systems software be compatible with the primary installation being backed up.

35.以下哪项是使用热点作为备用替代方案的优势?
A.与热点相关的成本很低。
B.热点可以在短时间内准备好运行。
C.热门网站可以使用更长的时间。
D.热站点不要求设备和系统软件与正在备份的主要设备兼容。


36. The results of a test of the disaster recovery plan conducted at a warm site notes that clients were unable to log on to the restored online systems as there were insufficient data lines connecting the client premises to the recovery site. The MOST likely conclusion that can be drawn is that:
A. The use of a warm site is inappropriate.
B. The impact of a potential disaster was not fully analyzed.

C. The clients were not sufficiently involved in plan development.
D. The external communications service providers were not involved in the test.
36.在一个热门站点进行的灾难恢复计划测试结果表明,客户无法登录已恢复的在线系统,因为没有足够的数据线将客户端场所连接到恢复站点。 最可能得出的结论是:
答:使用温暖的网站是不合适的。
B.未充分分析潜在灾害的影响。

C.客户没有充分参与计划制定。
D.外部通信服务提供商没有参与测试。


37. Several methods provide telecommunications continuity. Which of the following is a method of routing traffic through split cable or duplicate cable facilities?
A. diverse routing
B. alternative routing
C. last mile circuit protection
D. long haul network diversity
37.若干方法提供电信连续性。 以下哪项是通过分支电缆或重复电缆设施路由流量的方法?

A.多样化的路由
B.替代路由
C.最后一英里电路保护
D.长途网络多样性


38. A contingency plan should address:
A. Potential risks

B. Residual risks
C. Identified risks
D. All of the above
38.应急计划应解决:
A.潜在风险
B.剩余风险
C.确定的风险
D.以上所有


39. Qualitative loss resulting from the business interruption does not include:
A. Loss of revenue
B. Loss of competitive advantage or market share
C. Loss of public confidence and credibility
D. Public embarrassment
39.业务中断导致的质量损失不包括:

A.收入损失
B.竞争优势或市场份额的丧失
C.丧失公众信心和信誉
D.公众尴尬


40. What is not one of the drawbacks of hot sites?
A. Need Security controls, as it usually contain mirrored copies of live production data
B. Full redundancy in hardware, software, communication lines and applications is very expensive
C. The hot sites are available immediately or within maximum tolerable downtime (MTD)
D. They are administratively resource intensive, as transaction redundacy controls need to be implemented to keep data up-to-date
40.什么不是热门网站的缺点之一?
A.需要安全控制,因为它通常包含实时生产数据的镜像副本
B.硬件,软件,通信线路和应用程序的完全冗余非常昂贵

C.热点可立即使用或在最大容许停机时间内(MTD)
D.它们在行政上是资源密集型的,因为需要实施事务冗余控制以使数据保持最新


41. What is the most correct choice below when talking about the steps to resume normal operation?
A. Most critical operations are moved from alternate site to primary site before others
B. Operation may be carried by a completely different team than disaster recovery team
C. Non critical systems are moved first from alternate site to the primary business location
D. Business operations cannot be moved back, until green light is given by the salvage team that primary site is ready
41.在谈到恢复正常运作的步骤时,下面最正确的选择是什么?
A.大多数关键操作在其他操作之前从备用站点移动到主站点
B.操作可以由与灾难恢复团队完全不同的团队进行

C.非关键系统首先从备用站点移动到主要业务位置
D.业务运营不能被移回,直到打捞团队给予主要站点准备好的绿灯


42. A business impact assessment is one element in business continuity planning. What are the three primary goals of a BIA?
A. Data processing continuity planning, data recovery plan maintenance, and testing the disaster recovery plan.
B. Scope and plan initiation, business continuity plan development, and plan approval and implementation.
C. Facility requirements planning, facility security management, and administrative personnel controls.
D. Criticality prioritization, downtime estimation, and resource requirements.

42.业务影响评估是业务连续性计划的一个要素。 BIA的三个主要目标是什么?
A.数据处理连续性计划,数据恢复计划维护和测试灾难恢复计划。
B.范围和计划启动,业务连续性计划制定以及计划批准和实施。
C.设施需求规划,设施安全管理和行政人员控制。
D.关键性优先级划分,停机时间估计和资源需求。


43. Which of the following teams should not be included in an organization's contingency plan?
A. Damage assessment team
B. Hardware salvage team
C. Tiger team
D. Legal affairs team
43.以下哪些团队不应被纳入组织的应急计划?
A.损害评估小组
B.硬件打捞队

C.老虎队
D.法律事务团队


44. An offsite backup facility intended to operate an information processing facility, having no computer or communications equipment, but having flooring, electrical writing, air conditioning, etc. is better known as a:
A. Hot site
B. Duplicate processing facility
C. Cold site
D. Warm site
44.一个非现场备用设施,用于操作信息处理设施,没有计算机或通信设备,但有地板,电子书写,空调等,更为人所知:
A.热门网站
B.重复处理设施

C.冷站点
D.温暖的网站


45. Which of the following *must* be at a "hot site"?
A. Backup data, computers, climate control, cables and peripherals
B. Computers and peripherals
C. Computers, peripherals, and dedicated climate control systems
D. Dedicated climate control systems
45.以下哪个*必须*在“热门网站”?

A.备份数据,计算机,气候控制,电缆和外围设备
B.计算机和外围设备
C.计算机,外围设备和专用气候控制系统
D.专门的气候控制系统


46. What is the LEAST expensive alternative providing processing facilities in case a disaster should strike?
A. Warm site
B. Hot site
C. Reciprocal agreement
D. Cold site
46.如果发生灾害,提供加工设施的最低价格是什么?
A.温暖的网站
B.热门网站
C.互惠协议
D.冷站点


47. What is electronic vaulting?
A. Information is backed up to tape on a hourly basis and is stored in a on-site vault.
B. Information is backed up to tape on a daily basis and is stored in a on-site vault.
C. Transferring electronic journals or transaction logs to an off-site storage facility
D. A transfer of bulk information to a remote central backup facility.
47.什么是电子跳马?
答:信息每小时备份到磁带,并存储在现场保管库中。
B.信息每天备份到磁带,并存储在现场保管库中。
C.将电子期刊或交易日志转移到场外存储设施

D.将批量信息传输到远程中央备份设施。


48. Minimum level of transaction redundancy implementation is usually employed at hot sites is:
A. Daily backup

B. Electronic Vaulting
C. Electronic Journaling
D. Database Shadowing
48.热点站点通常采用最低级别的事务冗余实现:
A.每日备份
B.电子保险
C.电子日记
D.数据库阴影


49. Which of the following statements is the most important assumption behind the warm site concept?
A. The warm site is partially configured with selected network equipments and peripheral devices.
B. Heat, ventilation and air conditioning are installed at the warm site.

C. The main equipment can be obtained quickly for emergency installation at a warm site.
D. The choice of a warm site is less expensive than that of a hot site.

49.以下哪一项陈述是热门网站概念背后最重要的假设?
A.暖站点部分配置了选定的网络设备和外围设备。
B.温暖的地方安装了加热,通风和空调。
C.可以快速获得主要设备,以便在温暖的地点进行紧急安装。
D.温暖场地的选择比热场地的选择便宜。


50. Which of the following is not a common type of risk factor to an IT system?
A. Human                              B. Natural
C. Technological                        
D. Hacking
50.以下哪项不是IT系统的常见风险因素?
A.人类
B.自然
C.技术
D.黑客攻击

你可能感兴趣的:(网络安全)