CAP CAP Business Continuity & Disaster Recovery Planning 5 — Questions and Answers
Question 1: Which NIST publication provides the primary guidance for developing federal information system contingency plans?
- NIST SP 800-53
- NIST SP 800-34 (Correct answer)
- NIST SP 800-137
- NIST SP 800-61
Correct answer: NIST SP 800-34
NIST SP 800-34, Contingency Planning Guide for Federal Information Systems, is the authoritative guidance for developing and implementing IT contingency plans.
Question 2: A warm site alternative recovery facility has systems pre-configured but requires several hours to become fully operational. How does this differ from a hot site?
- A hot site requires more configuration time than a warm site
- A hot site is fully operational with current data and can take over immediately (Correct answer)
- A warm site has no hardware present; a hot site has hardware only
- Hot sites are only used for non-critical systems
Correct answer: A hot site is fully operational with current data and can take over immediately
A hot site mirrors the production environment with up-to-date data and can assume operations with minimal delay, whereas a warm site requires additional setup time before becoming operational.
Question 3: During contingency plan testing, a tabletop exercise PRIMARILY achieves which objective?
- Validates actual technical recovery of systems
- Tests network failover under real load conditions
- Familiarizes personnel with their roles and identifies plan gaps through discussion (Correct answer)
- Measures actual RTO against documented targets
Correct answer: Familiarizes personnel with their roles and identifies plan gaps through discussion
Tabletop exercises are discussion-based simulations that familiarize participants with recovery procedures and identify gaps in the plan without activating actual systems.
Question 4: An organization's contingency plan has not been tested in 18 months and key personnel have changed. Which risk does this MOST directly create?
- Increased likelihood of a natural disaster
- Plan may not reflect current environment or personnel roles, causing recovery failures (Correct answer)
- Regulatory fines for not testing quarterly
- Automatic revocation of the system's ATO
Correct answer: Plan may not reflect current environment or personnel roles, causing recovery failures
Untested and outdated contingency plans risk failure during actual recovery because documented procedures and assigned roles may no longer match current system configurations or staff.
Question 5: Which supply chain risk is MOST relevant to disaster recovery planning for hardware-dependent systems?
- Vendor price increases for software licenses
- Long lead times for replacement hardware during a disaster (Correct answer)
- Open-source software licensing compliance
- Cloud vendor SLA negotiation delays
Correct answer: Long lead times for replacement hardware during a disaster
Hardware replacement lead times can extend recovery far beyond the RTO during a disaster, making supply chain availability a critical DR planning consideration.
Question 6: A Continuity of Operations Plan (COOP) differs from an IT Disaster Recovery Plan (DRP) primarily in that a COOP:
- Focuses exclusively on restoring IT systems and data
- Addresses continuation of essential government functions regardless of the disruption cause (Correct answer)
- Is only required for classified information systems
- Replaces the need for individual system contingency plans
Correct answer: Addresses continuation of essential government functions regardless of the disruption cause
A COOP addresses the continuation of an organization's essential mission functions and operations, while a DRP focuses specifically on recovering IT systems and infrastructure.
Question 7: Which metric defines the point in time to which data must be recovered after a disruption, representing the maximum acceptable data loss?
- Recovery Time Objective (RTO)
- Maximum Tolerable Downtime (MTD)
- Recovery Point Objective (RPO) (Correct answer)
- Mean Time to Recover (MTTR)
Correct answer: Recovery Point Objective (RPO)
The Recovery Point Objective (RPO) defines the maximum age of data that must be recovered, essentially setting the threshold for acceptable data loss in time.
Which NIST publication provides the primary guidance for developing federal information system contingency plans?