Emergency Preparedness & Safety Flashcards
7 cards from real CSA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Emergency Preparedness & Safety flashcards as text
An organization's data center is located in a flood zone. Which physical control MOST directly mitigates flood risk to server equipment?
Answer: Raising server equipment on elevated platforms and installing water-detection sensors
Elevating equipment above potential flood levels and placing water-detection sensors beneath raised floors directly addresses flood risk to hardware.
Which standard provides a framework specifically for Information Security Management System (ISMS) continuity management?
Answer: ISO/IEC 27031
ISO/IEC 27031 provides guidelines on ICT readiness for business continuity as part of the broader ISMS, bridging ISO 22301 and information security.
A sysadmin performing a post-incident review discovers that alerts were generated 4 hours before the incident but were not acted on. Which remediation action BEST addresses this gap?
Answer: Implement an escalation policy ensuring unacknowledged alerts auto-escalate to on-call management
An auto-escalation policy ensures that unacknowledged alerts reach higher levels of the on-call chain, preventing critical warnings from being silently missed.
Under the National Incident Management System (NIMS), which organizational structure is used to manage emergency response with a clear chain of command?
Answer: Incident Command System (ICS)
The Incident Command System (ICS) is the NIMS-standardized hierarchical management structure used across all emergency response disciplines in the US.
Which of the following BEST describes a 'cold site' disaster recovery option?
Answer: A facility with basic utilities and space but no installed equipment, requiring days or weeks to become operational
A cold site provides only basic infrastructure (power, cooling, connectivity) with no pre-installed equipment, resulting in the highest RTO of the three site types.
During an active ransomware incident, the incident commander orders the sysadmin to immediately disconnect all affected servers from the network. This action BEST exemplifies which IR phase activity?
Answer: Containment
Network isolation of infected systems to prevent ransomware from spreading is a containment action within the Containment, Eradication, and Recovery phase.
An organization must comply with HIPAA and experiences a breach of ePHI due to a ransomware attack. What is the required breach notification timeline to HHS under the HIPAA Breach Notification Rule?
Answer: Within 60 days of discovery of the breach
The HIPAA Breach Notification Rule requires covered entities to notify HHS (and affected individuals) within 60 days of discovering a breach of unsecured ePHI.