CSX Recover and Sustain Operations 2 — Questions and Answers
Question 1: During a ransomware recovery, the team discovers backups are also encrypted. What should have been in place to prevent this?
- Air-gapped or immutable backup storage (Correct answer)
- More frequent full backups
- Encrypted backup transmission
- Offsite tape rotation
Correct answer: Air-gapped or immutable backup storage
Air-gapped or immutable backups are isolated from the network so ransomware cannot reach and encrypt them.
Question 2: Which metric measures the maximum tolerable duration of a disruption before significant business impact occurs?
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO)
- Maximum Tolerable Downtime (MTD) (Correct answer)
- Mean Time to Repair (MTTR)
Correct answer: Maximum Tolerable Downtime (MTD)
Maximum Tolerable Downtime (MTD) defines the longest an organization can survive without a critical function before impacts become unacceptable.
Question 3: What is the PRIMARY purpose of a post-incident review (PIR) in the context of sustaining operations?
- To assign blame for the incident
- To identify lessons learned and improve future response (Correct answer)
- To satisfy regulatory reporting requirements
- To calculate financial losses from the incident
Correct answer: To identify lessons learned and improve future response
Post-incident reviews focus on identifying what worked, what didn't, and how processes can be improved to strengthen future response.
Question 4: A business continuity plan (BCP) differs from a disaster recovery plan (DRP) in that the BCP primarily focuses on:
- Restoring IT systems after a failure
- Maintaining critical business functions during a disruption (Correct answer)
- Backing up data to alternate locations
- Identifying and patching vulnerabilities
Correct answer: Maintaining critical business functions during a disruption
A BCP covers maintaining essential business operations during any disruption, while a DRP specifically addresses IT system recovery.
Question 5: Which recovery strategy involves shifting operations to a fully equipped, immediately operational alternate site?
- Cold site
- Warm site
- Hot site (Correct answer)
- Mobile site
Correct answer: Hot site
A hot site is a fully equipped alternate facility with up-to-date data and systems that can take over operations immediately.
Question 6: After restoring systems from backup following an incident, what is the NEXT critical step before returning to production?
- Notify all users that systems are restored
- Verify that the vulnerability or threat that caused the incident has been remediated (Correct answer)
- Update the backup schedule to run more frequently
- Archive the incident logs
Correct answer: Verify that the vulnerability or threat that caused the incident has been remediated
Systems must be confirmed clean and the original attack vector closed before returning to production to prevent reinfection.
Question 7: In a resilience framework, 'redundancy' is BEST described as:
- Having duplicate systems or components so operations continue if one fails (Correct answer)
- Storing data in multiple geographic locations
- Conducting regular failover tests
- Implementing load balancing across servers
Correct answer: Having duplicate systems or components so operations continue if one fails
Redundancy means having duplicate components or systems so that if one fails, the other maintains continuity of operations.
During a ransomware recovery, the team discovers backups are also encrypted.
What should have been in place to prevent this?