CSC Business Continuity & Disaster Recovery Planning 2 — Questions and Answers
Question 1: A security consultant identifies that a client's critical operations can tolerate no more than four hours of downtime. This value is referred to as the:
- Maximum Tolerable Downtime (MTD) (Correct answer)
- Recovery Time Objective (RTO)
- Mean Time to Recovery (MTTR)
- Recovery Point Objective (RPO)
Correct answer: Maximum Tolerable Downtime (MTD)
Maximum Tolerable Downtime (MTD) is the absolute maximum time a business process can be unavailable before the impact causes irreversible harm.
Question 2: Which type of alternate site provides basic infrastructure such as raised flooring, power, and connectivity, but requires the organization to install its own equipment?
- Hot site
- Warm site
- Cold site (Correct answer)
- Mirror site
Correct answer: Cold site
A cold site provides only the basic physical infrastructure, requiring the organization to procure and install all equipment before operations can resume.
Question 3: The concept of 'threat vulnerability asset' (TVA) mapping in business continuity planning is primarily used to:
- Schedule quarterly security audits for all departments
- Correlate identified threats and vulnerabilities to specific critical assets (Correct answer)
- Assign responsibility for continuity tasks to department heads
- Document the chain of command during a declared disaster
Correct answer: Correlate identified threats and vulnerabilities to specific critical assets
TVA mapping links specific threats and vulnerabilities to the assets they could affect, enabling targeted and prioritized risk mitigation in continuity planning.
Question 4: In a Disaster Recovery Plan (DRP), the 'crisis communications plan' ensures that:
- All external communications are suspended during a disaster
- Stakeholders, staff, and the public receive timely and accurate information (Correct answer)
- Social media accounts are deactivated to prevent misinformation
- Only the CEO is authorized to communicate with external parties
Correct answer: Stakeholders, staff, and the public receive timely and accurate information
A crisis communications plan establishes protocols for delivering timely, accurate, and consistent information to all relevant stakeholders during a disaster.
Question 5: A security consultant conducting a full-scale continuity exercise that involves actual system failovers and personnel mobilization is performing a:
- Tabletop exercise
- Functional exercise
- Full-scale simulation (Correct answer)
- Structured walkthrough
Correct answer: Full-scale simulation
A full-scale simulation activates the actual recovery plan, mobilizes resources, and tests real system failovers to validate plan effectiveness under realistic conditions.
Question 6: Which of the following is considered a critical component of a Business Continuity Plan's maintenance program?
- Locking the BCP document and restricting access to senior leadership only
- Conducting regular plan reviews and updates after organizational changes or exercises (Correct answer)
- Replacing the BCP every five years regardless of operational changes
- Delegating all plan updates to the IT department
Correct answer: Conducting regular plan reviews and updates after organizational changes or exercises
Regular reviews and updates after organizational changes, incidents, or exercises ensure the BCP remains accurate, current, and actionable.
Question 7: Under the ASIS Business Continuity Management standard (ASIS SPC.1), what is the role of senior management in a continuity program?
- To personally conduct all risk assessments and write the BCP
- To demonstrate leadership commitment, allocate resources, and establish policy (Correct answer)
- To serve as the primary incident commanders during a disaster
- To audit the IT department's backup procedures quarterly
Correct answer: To demonstrate leadership commitment, allocate resources, and establish policy
ASIS SPC.1 emphasizes that senior management must demonstrate commitment by setting policy, allocating resources, and supporting the continuity program's development.
A security consultant identifies that a client's critical operations can tolerate no more than four hours of downtime.
This value is referred to as the: