CJIS Disaster Recovery & Business Continuity 2 — Questions and Answers
Question 1: Under CJIS Security Policy, what is the minimum frequency for testing disaster recovery plans?
- Monthly
- Quarterly
- Annually (Correct answer)
- Every two years
Correct answer: Annually
CJIS Security Policy requires that disaster recovery plans be tested at least annually to verify effectiveness.
Question 2: Which CJIS concept describes the maximum acceptable length of time that a system can be offline following a failure?
- Recovery Point Objective (RPO)
- Recovery Time Objective (RTO) (Correct answer)
- Mean Time to Repair (MTTR)
- Maximum Tolerable Downtime (MTD)
Correct answer: Recovery Time Objective (RTO)
Recovery Time Objective (RTO) defines the maximum allowable downtime before services must be restored.
Question 3: A law enforcement agency's CJIS systems experience a ransomware attack. What is the FIRST action personnel should take?
- Pay the ransom to restore access quickly
- Isolate affected systems from the network (Correct answer)
- Notify the media about the breach
- Restore from the most recent backup immediately
Correct answer: Isolate affected systems from the network
Isolating affected systems prevents ransomware from spreading to other network segments and preserves evidence.
Question 4: What does a Business Impact Analysis (BIA) primarily identify in the context of CJIS-covered systems?
- The financial cost of upgrading hardware
- Critical functions and the effect of their disruption (Correct answer)
- The number of authorized users per system
- Compliance gaps in physical security
Correct answer: Critical functions and the effect of their disruption
A BIA identifies mission-critical functions and quantifies the impact of their disruption to prioritize recovery efforts.
Question 5: Which backup strategy requires the longest restoration time but uses the least storage space for daily backups?
- Full backup
- Differential backup
- Incremental backup (Correct answer)
- Mirror backup
Correct answer: Incremental backup
Incremental backups capture only changes since the last backup, saving storage but requiring multiple sets to restore.
Question 6: Under CJIS policy, who must be notified when a significant disaster affects criminal justice information systems?
- Only the local IT department
- The FBI CJIS Division and the State Identification Bureau (Correct answer)
- The Department of Homeland Security exclusively
- Only the agency's legal counsel
Correct answer: The FBI CJIS Division and the State Identification Bureau
CJIS policy requires notification to the FBI CJIS Division and the appropriate State Identification Bureau when systems are compromised or experience significant outages.
Question 7: What is a 'hot site' in the context of CJIS disaster recovery planning?
- A facility with power but no equipment installed
- A fully equipped alternate site that can assume operations immediately (Correct answer)
- A geographic location with favorable climate for data centers
- A site that takes 72 hours or more to become operational
Correct answer: A fully equipped alternate site that can assume operations immediately
A hot site is a fully equipped, continuously operational alternate facility that can take over CJIS functions with minimal delay.
Under CJIS Security Policy, what is the minimum frequency for testing disaster recovery plans?