CSX Recover and Sustain Operations 1 — Questions and Answers
Question 1: What is the primary goal of a business continuity plan (BCP)?
- To eliminate future cyberattacks
- To avoid regulatory audits
- To maintain operations during disruptions (Correct answer)
- To increase customer reviews
Correct answer: To maintain operations during disruptions
The primary goal of a Business Continuity Plan (BCP) is to ensure that an organization can continue to deliver critical business functions during and after a disruptive event. It outlines procedures and resources to maintain essential operations, minimize downtime, and recover quickly from incidents like natural disasters or cyberattacks. A BCP focuses on keeping the business running despite adversity.
Question 2: Which backup method captures only changes made since the last full backup?
- Full backup
- Differential backup
- Incremental backup (Correct answer)
- Snapshot
Correct answer: Incremental backup
An incremental backup only saves data that has changed since the *last* backup of any type (full or incremental). This method is highly efficient in terms of storage space and backup time, as it only copies new or modified files. However, restoration can be more complex, requiring the last full backup plus all subsequent incremental backups in the correct order.
Question 3: Which metric indicates how quickly systems must be restored after a disruption?
- Mean Time to Respond
- Recovery Point Objective
- Recovery Time Objective (Correct answer)
- System Uptime Goal
Correct answer: Recovery Time Objective
Recovery Time Objective (RTO) is a critical metric in disaster recovery planning that specifies the maximum acceptable duration of downtime after a disruption. It defines how quickly systems, applications, and data must be restored to an operational state to meet business requirements and minimize impact. RTO dictates the speed at which recovery must occur.
Question 4: What is the purpose of conducting a post-incident review?
- To punish responsible staff
- To eliminate root causes permanently
- To improve future incident handling (Correct answer)
- To submit to auditors only
Correct answer: To improve future incident handling
A post-incident review, also known as a lessons learned session, is conducted after an incident is fully resolved. Its purpose is to analyze what happened, how the incident was handled, identify strengths and weaknesses in the response process, and implement improvements. This continuous improvement cycle enhances future incident handling capabilities and overall security posture.
Question 5: What should be regularly tested to ensure operational resilience after an incident?
- Marketing strategy
- Disaster recovery plan (Correct answer)
- Annual financial reports
- Employee satisfaction survey
Correct answer: Disaster recovery plan
A Disaster Recovery Plan (DRP) outlines the procedures for an organization to recover from a disaster and restore critical IT infrastructure and operations. Regular testing of the DRP is essential to ensure its effectiveness, identify any gaps or outdated information, and confirm that the organization can indeed achieve operational resilience in the face of a real incident. Testing validates the plan's viability.
Question 6: What is a major benefit of system redundancy in recovery planning?
- Increases attack surface
- Improves backup compression
- Ensures high availability (Correct answer)
- Reduces patching efforts
Correct answer: Ensures high availability
System redundancy involves duplicating critical components or systems to provide a backup in case of failure. A major benefit in recovery planning is that it ensures high availability, meaning that if one component fails, another can immediately take over. This minimizes downtime and maintains continuous operation, significantly improving an organization's resilience against disruptions.
What is the primary goal of a business continuity plan (BCP)?