ISC2 CISSP Recovery Disaster Recovery Business Continuity Physical And Personnel Safety Practice Test
7 Security Operations • 24 original questions
This CISSP practice test focuses on recovery disaster recovery business continuity physical and personnel safety through original scenario-based questions aligned to the current ISC2 CISSP Certification Exam Outline. Use the full ExamSnap CISSP collection for practice across all eight domains. For broader exam preparation, review the ISC2 CISSP Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
After a business change, VanArsdel Energy discovers that DR personnel is not handled consistently for the branch-office network. The security operations manager needs to address the control objective while preserving availability of the critical business service. Which recommendation BEST addresses the issue? The operating team supports 66 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. It directly addresses DR personnel while preserving availability of the critical business service.
Option review:
A: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address DR personnel in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address DR personnel in this scenario.
C: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. That action can be useful in a different security decision, but it does not most directly address DR personnel in this scenario.
D: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. It directly addresses DR personnel while preserving availability of the critical business service.
Learning point: Execute DR through defined roles, communications, assessment, restoration priorities, training, and lessons learned. A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit.
Northwind Health is preparing a security decision for the industrial control network. The decision involves DR communications. The business continuity lead must address the control objective without replacing governance with a technology-only shortcut. Which option BEST reflects CISSP-level security practice? The operating team supports 83 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. It directly addresses DR communications without replacing governance with a technology-only shortcut.
Option review:
A: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address DR communications in this scenario.
B: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. It directly addresses DR communications without replacing governance with a technology-only shortcut.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address DR communications in this scenario.
D: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address DR communications in this scenario.
Learning point: Execute DR through defined roles, communications, assessment, restoration priorities, training, and lessons learned. A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit.
During a risk workshop for the research data repository, the team identifies DR assessment as the deciding issue. The privacy and compliance lead is expected to address the control objective while keeping the process defensible to auditors and business owners. What is the MOST appropriate course of action? The operating team supports 9 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. It directly addresses DR assessment while keeping the process defensible to auditors and business owners.
Option review:
A: Resource protection must follow data and media across storage, movement, reuse, and disposal. That action can be useful in a different security decision, but it does not most directly address DR assessment in this scenario.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address DR assessment in this scenario.
C: Risk-based vulnerability management is more effective than patching purely by severity score or release date. That action can be useful in a different security decision, but it does not most directly address DR assessment in this scenario.
D: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. It directly addresses DR assessment while keeping the process defensible to auditors and business owners.
Learning point: Execute DR through defined roles, communications, assessment, restoration priorities, training, and lessons learned. A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit.
A control owner at A. Datum Analytics proposes a quick technical fix for DR restoration in the payment processing service. The security architect must address the control objective while minimizing irreversible action until facts and authority are established. What should happen FIRST? The operating team supports 26 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. It directly addresses DR restoration while minimizing irreversible action until facts and authority are established.
Option review:
A: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address DR restoration in this scenario.
B: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address DR restoration in this scenario.
C: Foundational operations controls reduce concentration of privilege and make accountability visible. That action can be useful in a different security decision, but it does not most directly address DR restoration in this scenario.
D: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. It directly addresses DR restoration while minimizing irreversible action until facts and authority are established.
Learning point: Execute DR through defined roles, communications, assessment, restoration priorities, training, and lessons learned. A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit.
Blue Yonder Airlines is standardizing security across several business units. The software delivery pipeline raises a question about DR training and awareness. The security operations manager needs to address the control objective while preserving evidence needed for later review. Which action provides the BEST governance and security outcome? The operating team supports 43 critical systems under documented recovery and escalation procedures.
Correct answer: C
Why: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. It directly addresses DR training and awareness while preserving evidence needed for later review.
Option review:
A: Personnel safety takes precedence over property and system restoration during emergencies. That action can be useful in a different security decision, but it does not most directly address DR training and awareness in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address DR training and awareness in this scenario.
C: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. It directly addresses DR training and awareness while preserving evidence needed for later review.
D: Incident management minimizes business impact while supporting investigation and continuous improvement. That action can be useful in a different security decision, but it does not most directly address DR training and awareness in this scenario.
Learning point: Execute DR through defined roles, communications, assessment, restoration priorities, training, and lessons learned. A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit.
During a secure software initiative, City Power asks the business continuity lead to address DR lessons learned for its AI-assisted customer service platform. The requirement is to address the control objective without granting broader privilege than the business need requires. What should the organization do FIRST? The operating team supports 60 critical systems under documented recovery and escalation procedures.
Correct answer: A
Why: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. It directly addresses DR lessons learned without granting broader privilege than the business need requires.
Option review:
A: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. It directly addresses DR lessons learned without granting broader privilege than the business need requires.
B: Foundational operations controls reduce concentration of privilege and make accountability visible. That action can be useful in a different security decision, but it does not most directly address DR lessons learned in this scenario.
C: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. That action can be useful in a different security decision, but it does not most directly address DR lessons learned in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address DR lessons learned in this scenario.
Learning point: Execute DR through defined roles, communications, assessment, restoration priorities, training, and lessons learned. A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit.
Tailspin Logistics is revising controls for its global collaboration platform. A review highlights Read-through/tabletop testing. The privacy and compliance lead must address the control objective without creating a new single point of failure. Which action is the BEST next step? The operating team supports 77 critical systems under documented recovery and escalation procedures.
Correct answer: A
Why: Tabletop testing provides low-risk validation of plan logic and stakeholder understanding. It directly addresses Read-through/tabletop testing without creating a new single point of failure.
Option review:
A: Tabletop testing provides low-risk validation of plan logic and stakeholder understanding. It directly addresses Read-through/tabletop testing without creating a new single point of failure.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Read-through/tabletop testing in this scenario.
C: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. That action can be useful in a different security decision, but it does not most directly address Read-through/tabletop testing in this scenario.
D: Resource protection must follow data and media across storage, movement, reuse, and disposal. That action can be useful in a different security decision, but it does not most directly address Read-through/tabletop testing in this scenario.
Learning point: Use a tabletop/read-through when the objective is to validate roles, decisions, and communications with minimal operational disruption. Tabletop testing provides low-risk validation of plan logic and stakeholder understanding.
An auditor asks Alpine Sports to demonstrate how it handles Walkthrough testing in the e-commerce application. The security architect must address the control objective while ensuring that emergency access cannot become permanent access. Which response is MOST appropriate? The operating team supports 3 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: DR test methods trade realism against operational disruption; the test should match the assurance objective. It directly addresses Walkthrough testing while ensuring that emergency access cannot become permanent access.
Option review:
A: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Walkthrough testing in this scenario.
B: DR test methods trade realism against operational disruption; the test should match the assurance objective. It directly addresses Walkthrough testing while ensuring that emergency access cannot become permanent access.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Walkthrough testing in this scenario.
D: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. That action can be useful in a different security decision, but it does not most directly address Walkthrough testing in this scenario.
Learning point: Choose a DR test method that provides the needed assurance while matching the organization’s tolerance for disruption, and communicate status to stakeholders. DR test methods trade realism against operational disruption; the test should match the assurance objective.
After a business change, Fabrikam Manufacturing discovers that Simulation testing is not handled consistently for the clinical records environment. The security operations manager needs to address the control objective while allowing independent verification of the control outcome. Which recommendation BEST addresses the issue? The operating team supports 20 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: Simulation increases realism while keeping destructive production changes out of scope. It directly addresses Simulation testing while allowing independent verification of the control outcome.
Option review:
A: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Simulation testing in this scenario.
B: Simulation increases realism while keeping destructive production changes out of scope. It directly addresses Simulation testing while allowing independent verification of the control outcome.
C: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Simulation testing in this scenario.
D: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Simulation testing in this scenario.
Learning point: Use a simulation when teams need realistic response practice without actually failing production systems. Simulation increases realism while keeping destructive production changes out of scope.
Trey Research is preparing a security decision for the remote access service. The decision involves Parallel testing. The business continuity lead must address the control objective while accounting for third-party and lifecycle dependencies. Which option BEST reflects CISSP-level security practice? The operating team supports 37 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: Parallel tests provide stronger technical assurance while limiting production interruption. It directly addresses Parallel testing while accounting for third-party and lifecycle dependencies.
Option review:
A: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. That action can be useful in a different security decision, but it does not most directly address Parallel testing in this scenario.
B: Parallel tests provide stronger technical assurance while limiting production interruption. It directly addresses Parallel testing while accounting for third-party and lifecycle dependencies.
C: Personnel safety takes precedence over property and system restoration during emergencies. That action can be useful in a different security decision, but it does not most directly address Parallel testing in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Parallel testing in this scenario.
Learning point: Use a parallel test when alternate recovery capabilities should be exercised without shutting down the primary production environment. Parallel tests provide stronger technical assurance while limiting production interruption.
During a risk workshop for the customer identity platform, the team identifies Full-interruption testing as the deciding issue. The privacy and compliance lead is expected to address the control objective while maintaining the organization’s stated risk appetite. What is the MOST appropriate course of action? The operating team supports 54 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Full interruption gives strong evidence but carries the greatest business risk. It directly addresses Full-interruption testing while maintaining the organization’s stated risk appetite.
Option review:
A: Incident management minimizes business impact while supporting investigation and continuous improvement. That action can be useful in a different security decision, but it does not most directly address Full-interruption testing in this scenario.
B: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Full-interruption testing in this scenario.
C: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Full-interruption testing in this scenario.
D: Full interruption gives strong evidence but carries the greatest business risk. It directly addresses Full-interruption testing while maintaining the organization’s stated risk appetite.
Learning point: Use a full-interruption test only when leadership accepts the operational risk and the objective requires the highest realism. Full interruption gives strong evidence but carries the greatest business risk.
A control owner at Wide World Importers proposes a quick technical fix for DR test communications to stakeholders and regulators in the data analytics lake. The security architect must address the control objective while meeting the business objective with the least unnecessary operational complexity. What should happen FIRST? The operating team supports 71 critical systems under documented recovery and escalation procedures.
Correct answer: A
Why: DR test methods trade realism against operational disruption; the test should match the assurance objective. It directly addresses DR test communications to stakeholders and regulators while meeting the business objective with the least unnecessary operational complexity.
Option review:
A: DR test methods trade realism against operational disruption; the test should match the assurance objective. It directly addresses DR test communications to stakeholders and regulators while meeting the business objective with the least unnecessary operational complexity.
B: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address DR test communications to stakeholders and regulators in this scenario.
C: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. That action can be useful in a different security decision, but it does not most directly address DR test communications to stakeholders and regulators in this scenario.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address DR test communications to stakeholders and regulators in this scenario.
Learning point: Choose a DR test method that provides the needed assurance while matching the organization’s tolerance for disruption, and communicate status to stakeholders. DR test methods trade realism against operational disruption; the test should match the assurance objective.
Bellows University is standardizing security across several business units. The branch-office network raises a question about Business Continuity planning and exercises. The security operations manager needs to address the control objective while keeping the control sustainable for normal operations. Which action provides the BEST governance and security outcome? The operating team supports 88 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. It directly addresses Business Continuity planning and exercises while keeping the control sustainable for normal operations.
Option review:
A: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Business Continuity planning and exercises in this scenario.
B: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. It directly addresses Business Continuity planning and exercises while keeping the control sustainable for normal operations.
C: Foundational operations controls reduce concentration of privilege and make accountability visible. That action can be useful in a different security decision, but it does not most directly address Business Continuity planning and exercises in this scenario.
D: Firewalls, IDS/IPS, allowlisting, sandboxing, honeypots, anti-malware, and AI tools each address different threats and require tuning. That action can be useful in a different security decision, but it does not most directly address Business Continuity planning and exercises in this scenario.
Learning point: Exercise business continuity processes and dependencies with business owners, capture gaps, and update the plan from results. Business continuity validates the organization’s ability to continue critical functions, not just restore technology.
During a third-party onboarding review, Litware Services asks the business continuity lead to address Perimeter physical security controls for its industrial control network. The requirement is to address the control objective while ensuring the decision can be repeated consistently across business units. What should the organization do FIRST? The operating team supports 14 critical systems under documented recovery and escalation procedures.
Correct answer: A
Why: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. It directly addresses Perimeter physical security controls while ensuring the decision can be repeated consistently across business units.
Option review:
A: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. It directly addresses Perimeter physical security controls while ensuring the decision can be repeated consistently across business units.
B: Monitoring is effective when logs are trustworthy, correlated, tuned, and tied to response rather than merely retained. That action can be useful in a different security decision, but it does not most directly address Perimeter physical security controls in this scenario.
C: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. That action can be useful in a different security decision, but it does not most directly address Perimeter physical security controls in this scenario.
D: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Perimeter physical security controls in this scenario.
Learning point: Use layered perimeter and internal physical security with monitored access and controls appropriate to the protected area. Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier.
Humongous Insurance is revising controls for its research data repository. A review highlights Internal physical security controls. The privacy and compliance lead must address the control objective while preserving clear accountability and audit evidence. Which action is the BEST next step? The operating team supports 31 critical systems under documented recovery and escalation procedures.
Correct answer: A
Why: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. It directly addresses Internal physical security controls while preserving clear accountability and audit evidence.
Option review:
A: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. It directly addresses Internal physical security controls while preserving clear accountability and audit evidence.
B: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address Internal physical security controls in this scenario.
C: Risk-based vulnerability management is more effective than patching purely by severity score or release date. That action can be useful in a different security decision, but it does not most directly address Internal physical security controls in this scenario.
D: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Internal physical security controls in this scenario.
Learning point: Use layered perimeter and internal physical security with monitored access and controls appropriate to the protected area. Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier.
An auditor asks Woodgrove Bank to demonstrate how it handles Travel security in the payment processing service. The security architect must address the control objective while protecting sensitive data throughout the change. Which response is MOST appropriate? The operating team supports 48 critical systems under documented recovery and escalation procedures.
Correct answer: C
Why: Personnel safety takes precedence over property and system restoration during emergencies. It directly addresses Travel security while protecting sensitive data throughout the change.
Option review:
A: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. That action can be useful in a different security decision, but it does not most directly address Travel security in this scenario.
B: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Travel security in this scenario.
C: Personnel safety takes precedence over property and system restoration during emergencies. It directly addresses Travel security while protecting sensitive data throughout the change.
D: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Travel security in this scenario.
Learning point: Protect human life and safety first through travel, emergency, duress, insider-threat, and security-awareness measures before prioritizing asset recovery. Personnel safety takes precedence over property and system restoration during emergencies.
After a business change, Relecloud Systems discovers that Security training and awareness including insider threat, social media, and MFA fatigue is not handled consistently for the software delivery pipeline. The security operations manager needs to address the control objective while preserving availability of the critical business service. Which recommendation BEST addresses the issue? The operating team supports 65 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Personnel safety takes precedence over property and system restoration during emergencies. It directly addresses Security training and awareness including insider threat, social media, and MFA fatigue while preserving availability of the critical business service.
Option review:
A: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Security training and awareness including insider threat, social media, and MFA fatigue in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Security training and awareness including insider threat, social media, and MFA fatigue in this scenario.
C: Baselines and drift control make systems predictable, auditable, and recoverable. That action can be useful in a different security decision, but it does not most directly address Security training and awareness including insider threat, social media, and MFA fatigue in this scenario.
D: Personnel safety takes precedence over property and system restoration during emergencies. It directly addresses Security training and awareness including insider threat, social media, and MFA fatigue while preserving availability of the critical business service.
Learning point: Protect human life and safety first through travel, emergency, duress, insider-threat, and security-awareness measures before prioritizing asset recovery. Personnel safety takes precedence over property and system restoration during emergencies.
Contoso Financial is preparing a security decision for the AI-assisted customer service platform. The decision involves Emergency management. The business continuity lead must address the control objective without replacing governance with a technology-only shortcut. Which option BEST reflects CISSP-level security practice? The operating team supports 82 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: Personnel safety takes precedence over property and system restoration during emergencies. It directly addresses Emergency management without replacing governance with a technology-only shortcut.
Option review:
A: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Emergency management in this scenario.
B: Personnel safety takes precedence over property and system restoration during emergencies. It directly addresses Emergency management without replacing governance with a technology-only shortcut.
C: Resource protection must follow data and media across storage, movement, reuse, and disposal. That action can be useful in a different security decision, but it does not most directly address Emergency management in this scenario.
D: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. That action can be useful in a different security decision, but it does not most directly address Emergency management in this scenario.
Learning point: Protect human life and safety first through travel, emergency, duress, insider-threat, and security-awareness measures before prioritizing asset recovery. Personnel safety takes precedence over property and system restoration during emergencies.
During a risk workshop for the global collaboration platform, the team identifies Duress as the deciding issue. The privacy and compliance lead is expected to address the control objective while keeping the process defensible to auditors and business owners. What is the MOST appropriate course of action? The operating team supports 8 critical systems under documented recovery and escalation procedures.
Correct answer: A
Why: Personnel safety takes precedence over property and system restoration during emergencies. It directly addresses Duress while keeping the process defensible to auditors and business owners.
Option review:
A: Personnel safety takes precedence over property and system restoration during emergencies. It directly addresses Duress while keeping the process defensible to auditors and business owners.
B: Physical access controls should deter, detect, delay, and support response rather than rely on a single barrier. That action can be useful in a different security decision, but it does not most directly address Duress in this scenario.
C: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address Duress in this scenario.
D: Resource protection must follow data and media across storage, movement, reuse, and disposal. That action can be useful in a different security decision, but it does not most directly address Duress in this scenario.
Learning point: Protect human life and safety first through travel, emergency, duress, insider-threat, and security-awareness measures before prioritizing asset recovery. Personnel safety takes precedence over property and system restoration during emergencies.
A control owner at Lamna Healthcare proposes a quick technical fix for Backup storage strategies including cloud, onsite, and offsite in the e-commerce application. The security architect must address the control objective while minimizing irreversible action until facts and authority are established. What should happen FIRST? The operating team supports 25 critical systems under documented recovery and escalation procedures.
Correct answer: D
Why: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. It directly addresses Backup storage strategies including cloud, onsite, and offsite while minimizing irreversible action until facts and authority are established.
Option review:
A: Risk-based vulnerability management is more effective than patching purely by severity score or release date. That action can be useful in a different security decision, but it does not most directly address Backup storage strategies including cloud, onsite, and offsite in this scenario.
B: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address Backup storage strategies including cloud, onsite, and offsite in this scenario.
C: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Backup storage strategies including cloud, onsite, and offsite in this scenario.
D: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. It directly addresses Backup storage strategies including cloud, onsite, and offsite while minimizing irreversible action until facts and authority are established.
Learning point: Design recovery around business RTO/RPO using protected backups, appropriate recovery sites, resilient processing, and tested failover capacity. Recovery architecture should meet business objectives rather than simply maximizing technical redundancy.
Fourth Coffee is standardizing security across several business units. The clinical records environment raises a question about Cold and hot recovery-site strategies and capacity agreements. The security operations manager needs to address the control objective while preserving evidence needed for later review. Which action provides the BEST governance and security outcome? The operating team supports 42 critical systems under documented recovery and escalation procedures.
Correct answer: C
Why: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. It directly addresses Cold and hot recovery-site strategies and capacity agreements while preserving evidence needed for later review.
Option review:
A: Controlled change reduces outages and security regressions while preserving accountability. That action can be useful in a different security decision, but it does not most directly address Cold and hot recovery-site strategies and capacity agreements in this scenario.
B: Risk acceptance is a business decision that requires informed ownership and cannot substitute for analysis. That action can be useful in a different security decision, but it does not most directly address Cold and hot recovery-site strategies and capacity agreements in this scenario.
C: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. It directly addresses Cold and hot recovery-site strategies and capacity agreements while preserving evidence needed for later review.
D: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address Cold and hot recovery-site strategies and capacity agreements in this scenario.
Learning point: Design recovery around business RTO/RPO using protected backups, appropriate recovery sites, resilient processing, and tested failover capacity. Recovery architecture should meet business objectives rather than simply maximizing technical redundancy.
During a acquisition integration, Consolidated Messenger asks the business continuity lead to address Multiple processing sites for its remote access service. The requirement is to address the control objective without granting broader privilege than the business need requires. What should the organization do FIRST? The operating team supports 59 critical systems under documented recovery and escalation procedures.
Correct answer: A
Why: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. It directly addresses Multiple processing sites without granting broader privilege than the business need requires.
Option review:
A: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. It directly addresses Multiple processing sites without granting broader privilege than the business need requires.
B: Incident management minimizes business impact while supporting investigation and continuous improvement. That action can be useful in a different security decision, but it does not most directly address Multiple processing sites in this scenario.
C: Manual emergency workarounds are fragile and do not provide the consistent assurance required by the scenario. That action can be useful in a different security decision, but it does not most directly address Multiple processing sites in this scenario.
D: Business continuity validates the organization’s ability to continue critical functions, not just restore technology. That action can be useful in a different security decision, but it does not most directly address Multiple processing sites in this scenario.
Learning point: Design recovery around business RTO/RPO using protected backups, appropriate recovery sites, resilient processing, and tested failover capacity. Recovery architecture should meet business objectives rather than simply maximizing technical redundancy.
Proseware Labs is revising controls for its customer identity platform. A review highlights System resilience, high availability, QoS, and fault tolerance. The privacy and compliance lead must address the control objective without creating a new single point of failure. Which action is the BEST next step? The operating team supports 76 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. It directly addresses System resilience, high availability, QoS, and fault tolerance without creating a new single point of failure.
Option review:
A: A product-first response can add complexity without proving that the actual governance, risk, or control requirement is satisfied. That action can be useful in a different security decision, but it does not most directly address System resilience, high availability, QoS, and fault tolerance in this scenario.
B: Recovery architecture should meet business objectives rather than simply maximizing technical redundancy. It directly addresses System resilience, high availability, QoS, and fault tolerance without creating a new single point of failure.
C: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. That action can be useful in a different security decision, but it does not most directly address System resilience, high availability, QoS, and fault tolerance in this scenario.
D: Resource protection must follow data and media across storage, movement, reuse, and disposal. That action can be useful in a different security decision, but it does not most directly address System resilience, high availability, QoS, and fault tolerance in this scenario.
Learning point: Design recovery around business RTO/RPO using protected backups, appropriate recovery sites, resilient processing, and tested failover capacity. Recovery architecture should meet business objectives rather than simply maximizing technical redundancy.
An auditor asks Southridge Media to demonstrate how it handles DR response in the data analytics lake. The security architect must address the control objective while ensuring that emergency access cannot become permanent access. Which response is MOST appropriate? The operating team supports 93 critical systems under documented recovery and escalation procedures.
Correct answer: B
Why: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. It directly addresses DR response while ensuring that emergency access cannot become permanent access.
Option review:
A: DR test methods trade realism against operational disruption; the test should match the assurance objective. That action can be useful in a different security decision, but it does not most directly address DR response in this scenario.
B: A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit. It directly addresses DR response while ensuring that emergency access cannot become permanent access.
C: Broad standing privilege conflicts with least privilege and treats symptoms rather than fixing the underlying control design. That action can be useful in a different security decision, but it does not most directly address DR response in this scenario.
D: Forensic usefulness depends on evidence integrity, repeatability, documentation, and legal or organizational authority. That action can be useful in a different security decision, but it does not most directly address DR response in this scenario.
Learning point: Execute DR through defined roles, communications, assessment, restoration priorities, training, and lessons learned. A recovery plan only works when responsibilities, communications, restoration sequencing, and practice are explicit.
Popular posts
Recent Posts
