CSX Recover and Sustain Operations 3 — Questions and Answers
Question 1: Which of the following BEST describes the concept of 'resilience' in cybersecurity operations?
- The ability to prevent all cyberattacks
- The ability to absorb disruptions and recover to normal operations (Correct answer)
- The use of redundant hardware to avoid downtime
- The speed at which patches are applied after a vulnerability is disclosed
Correct answer: The ability to absorb disruptions and recover to normal operations
Cyber resilience is the ability of an organization to anticipate, withstand, recover from, and adapt to adverse conditions or attacks.
Question 2: During tabletop exercises for disaster recovery, who should PRIMARILY be involved?
- Only the IT security team
- Only senior executives and board members
- Key stakeholders from across business units and IT (Correct answer)
- External auditors and regulators
Correct answer: Key stakeholders from across business units and IT
Effective tabletop exercises require participation from stakeholders across all affected business functions, not just IT, to surface cross-functional gaps.
Question 3: A Recovery Point Objective (RPO) of 4 hours means:
- Systems must be restored within 4 hours of an incident
- The organization can tolerate losing up to 4 hours of data (Correct answer)
- Backups must be tested every 4 hours
- The incident must be declared within 4 hours
Correct answer: The organization can tolerate losing up to 4 hours of data
RPO defines the maximum age of data that can be recovered — an RPO of 4 hours means up to 4 hours of data loss is acceptable.
Question 4: What distinguishes a 'workaround' from a 'permanent fix' in incident recovery?
- A workaround restores functionality temporarily while the root cause is addressed (Correct answer)
- A workaround permanently patches the vulnerability
- A workaround requires vendor involvement
- A workaround only applies to hardware failures
Correct answer: A workaround restores functionality temporarily while the root cause is addressed
A workaround is a temporary measure that restores service while the underlying cause is investigated and a permanent fix is implemented.
Question 5: Which document type defines the roles, responsibilities, and sequences of actions required when activating a disaster recovery plan?
- Risk register
- Business impact analysis (BIA)
- Incident response playbook (Correct answer)
- Standard operating procedure (SOP)
Correct answer: Incident response playbook
An incident response playbook provides step-by-step procedures and role assignments for activating and executing the DR plan.
Question 6: Which of the following is the FIRST step in a Business Impact Analysis (BIA)?
- Identify recovery time and point objectives
- Identify critical business functions and their dependencies (Correct answer)
- Develop recovery strategies for each function
- Test and validate the recovery plan
Correct answer: Identify critical business functions and their dependencies
A BIA begins by identifying which business functions are critical and mapping their dependencies before assessing financial or operational impact.
Question 7: An organization experiences a prolonged power outage affecting its primary data center. Which technology BEST supports near-zero RTO?
- Daily offsite tape backups
- Active-active geographic clustering (Correct answer)
- Weekly disk-to-disk snapshots
- Cold standby site with manual failover
Correct answer: Active-active geographic clustering
Active-active clustering runs workloads simultaneously across multiple sites so failover is seamless and recovery time is near zero.
Which of the following BEST describes the concept of 'resilience' in cybersecurity operations?