Courseiva

CCNA Business Continuity, Disaster Recovery, and Incident Response Questions

75 of 83 questions · Page 1/2 · Business Continuity, Disaster Recovery, and Incident Response · Answers revealed

1
MCQeasy

An organization is developing a Business Continuity Plan (BCP). Which analysis is performed first to identify critical business functions and their dependencies?

A.Risk assessment
B.Business Impact Analysis (BIA)
C.Vulnerability assessment
D.Gap analysis
AnswerB

A Business Impact Analysis identifies critical business functions, quantifies the impact of their disruption, and maps dependencies on systems, people and suppliers, producing the foundation from which recovery priorities and continuity strategies are later derived.

Why this answer

The Business Impact Analysis (BIA) is performed first in BCP development because it identifies critical business functions, their dependencies, and the impact of disruption over time. This data drives recovery time objectives (RTO) and recovery point objectives (RPO), which then inform the rest of the BCP. Risk assessment and other analyses come after the BIA because you must know what to protect before assessing threats to it.

Exam trap

The trap is assuming risk assessment comes first because it sounds foundational — but BCP best practice (and ISO 22301) places the BIA first to define what matters before assessing threats.

How to eliminate wrong answers

Option A is wrong because risk assessment identifies threats and vulnerabilities to assets, but it is performed after the BIA has determined which business functions and assets are critical. Option C is wrong because vulnerability assessment focuses on technical weaknesses in systems, not on identifying critical business functions and their dependencies. Option D is wrong because gap analysis compares current capabilities against desired state and is typically done after the BIA and risk assessment to plan improvements.

2
MCQmedium

During a disaster recovery test, the IT team successfully restored systems from backups and achieved the recovery time objective (RTO). However, users could not resume normal work because additional configuration and data validation were needed. Which metric was NOT met?

A.Recovery Point Objective (RPO)
B.Work Recovery Time (WRT)
C.Maximum Tolerable Downtime (MTD)
D.Recovery Time Objective (RTO)
AnswerB

WRT is the time needed after systems are restored to validate data and resume normal business operations. Meeting RTO restored the systems, but the outstanding configuration and validation work means WRT was not met, so users could not resume work.

Why this answer

Work Recovery Time (WRT) is the time required to restore business operations after systems are technically recovered. In this scenario, systems were restored within RTO, but users could not resume work due to additional configuration and data validation, meaning WRT was not met. Therefore, WRT is the metric not met.

Exam trap

CC often tests the distinction between RTO and WRT, and candidates may incorrectly assume that meeting RTO means full recovery, ignoring the additional time needed for business operations to resume.

How to eliminate wrong answers

Option A is wrong because RPO relates to data loss, and there is no indication that data loss exceeded the RPO. Option C is wrong because MTD is the total time a system can be down, and the scenario does not specify that MTD was exceeded. Option D is wrong because RTO was met, as systems were restored within the objective.

3
Multi-Selectmedium

During a ransomware incident, the incident response team needs to communicate with stakeholders. According to best practices, which TWO groups should be notified immediately? (Select TWO.)

Select 2 answers
A.Affected customers
B.Legal and public relations
C.All employees
D.Competitors
E.Internal management
AnswersB, E

Legal counsel and public relations must be engaged immediately because ransomware triggers regulatory breach-notification duties and reputational exposure. Legal assesses disclosure obligations, while PR controls messaging to customers, regulators and media. This satisfies the best-practise requirement to notify stakeholders whose functions cannot wait until containment completes.

Why this answer

Option B (Legal and public relations) is correct because during a ransomware incident, legal counsel must be engaged immediately to assess regulatory notification obligations (e.g., GDPR, HIPAA, SEC disclosure rules) and preserve attorney-client privilege, while public relations manages external messaging to protect the organization's reputation and prevent misinformation. Option E (Internal management) is correct because executive leadership and management must be notified right away to authorize incident response actions, allocate resources, make critical business decisions, and fulfill their governance and oversight responsibilities. Option A (Affected customers) is not an immediate notification group; customer notification typically occurs after the scope of the breach is determined and legal/regulatory guidance is obtained, often with a defined timeline.

Option C (All employees) is too broad for immediate notification, as mass communication can cause panic or leaks; only those with a need to know are informed initially. Option D (Competitors) has no legitimate role in incident response notification and would only expose the organization to further risk.

Exam trap

The trap is selecting 'affected customers' or 'all employees' as immediate notifications because they seem most impacted — but best practice prioritizes legal/PR and internal management for controlled, authorized response.

4
MCQeasy

After an incident is resolved, which phase involves reviewing what happened, documenting lessons learned, and updating procedures?

A.Eradication
B.Containment
C.Lessons learned
D.Recovery
AnswerC

The lessons learned phase follows eradication and recovery, reviewing the incident, documenting findings and updating procedures to prevent recurrence. This matches the stem's post-resolution review, documentation and procedure-update criteria, distinguishing it from containment and recovery activities.

Why this answer

The Lessons Learned phase occurs after an incident is resolved and focuses on reviewing the response, documenting what happened, and updating procedures to prevent recurrence. It is a post-incident activity, distinct from the active response phases. Containment, eradication, and recovery all happen during the incident lifecycle before lessons learned.

Exam trap

The trap is confusing the order of incident response phases — candidates may pick Recovery because it sounds like the final step, but the exam expects you to know that Lessons Learned is the post-incident review phase.

How to eliminate wrong answers

Option A is wrong because Eradication is the phase where the root cause (e.g., malware, vulnerability) is removed from the environment, not where lessons are documented. Option B is wrong because Containment aims to limit the scope and impact of the incident while it is still active. Option D is wrong because Recovery restores systems to normal operation after eradication, but it does not include the formal review and documentation of lessons learned.

5
MCQmedium

An organization is selecting a recovery site strategy that offers the fastest recovery time, measured in hours, to minimize downtime for critical applications. Which recovery site type best meets this requirement?

A.Cloud-based recovery
B.Cold site
C.Warm site
D.Hot site
AnswerD

A hot site provides pre-installed hardware, live data replication and near-immediate failover, delivering recovery within hours. It satisfies the fastest-recovery constraint, unlike cold or warm sites, which require hardware provisioning or partial restoration before critical applications resume.

Why this answer

A hot site is a fully equipped alternate facility that is ready to operate immediately, offering the fastest recovery time, often within hours. It mirrors the primary site's hardware, software, and data, allowing critical applications to resume quickly. Thus, D is correct.

Exam trap

The trap is assuming warm site is fast enough; candidates may pick warm site because it's a middle ground, but only hot site guarantees recovery in hours.

How to eliminate wrong answers

Option A is wrong because cloud-based recovery can be fast but depends on the specific implementation; it is not a standard recovery site type and may not guarantee recovery in hours without proper configuration. Option B is wrong because a cold site is an empty facility with power and network but no equipment, requiring days or weeks to set up. Option C is wrong because a warm site has some equipment but may require configuration and data restoration, typically taking longer than a hot site.

6
MCQmedium

A company experiences a data breach involving personal data of EU residents. Under GDPR, what is the maximum time within which the organization must notify the supervisory authority?

A.48 hours
B.72 hours
C.7 days
D.24 hours
AnswerB

Article 33 of the UK GDPR and EU GDPR requires controllers to notify the supervisory authority within 72 hours of becoming aware of a personal data breach, unless the breach is unlikely to result in a risk to rights and freedoms.

Why this answer

Article 33 of the GDPR requires controllers to notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to data subjects' rights and freedoms. This 72-hour window is the maximum; earlier notification is encouraged where feasible.

Exam trap

The trap is the plausible-sounding '48 hours' distractor — candidates who half-remember the GDPR rule often pick 48 or 24 hours instead of the correct 72 hours.

How to eliminate wrong answers

Option A is wrong because 48 hours is not a GDPR notification deadline — it is a common distractor that sounds plausible but has no basis in Article 33. Option C is wrong because 7 days is far longer than the GDPR allows; the regulation deliberately sets a tight window to protect data subjects. Option D is wrong because 24 hours is shorter than the actual requirement and reflects a misconception that breach notification must be near-immediate; the GDPR allows up to 72 hours.

7
MCQmedium

During a data breach incident, the incident response team discovers that personally identifiable information (PII) of European Union residents was compromised. According to GDPR, what is the maximum time frame for notifying the supervisory authority?

A.72 hours
B.48 hours
C.7 days
D.24 hours
AnswerA

GDPR Article 33 requires notification of a personal data breach to the supervisory authority within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to rights and freedoms. This fixed deadline satisfies the stem's EU-resident PII constraint.

Why this answer

GDPR Article 33 mandates that a controller notify the competent supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to natural persons' rights and freedoms. This is the maximum allowable window under the regulation.

Exam trap

The trap is the recurring '48 hours' distractor — candidates who confuse GDPR's 72-hour rule with other regimes (or with the 24/48-hour options) pick the wrong value.

How to eliminate wrong answers

Option B is wrong because 48 hours is not specified anywhere in GDPR Article 33 — it is a distractor that mimics the real deadline. Option C is wrong because 7 days is far too long; the GDPR deliberately imposes a tight 72-hour maximum to ensure timely regulatory oversight. Option D is wrong because 24 hours is stricter than the regulation requires and reflects a misunderstanding that notification must be near-instantaneous.

8
MCQmedium

Which phase of the incident response process involves restoring systems to normal operation and applying patches to prevent recurrence?

A.Containment
B.Eradication
C.Detection
D.Recovery
AnswerD

Recovery restores affected systems to normal operation from clean backups or rebuilt hosts, then applies patches and configuration changes that close the vulnerability exploited. It follows eradication and returns the organisation to routine business functioning.

Why this answer

The Recovery phase of the incident response process is specifically focused on restoring systems to normal operation after the incident has been contained and eradicated. This includes applying patches, reconfiguring systems, and validating that the environment is secure before returning to production. According to NIST SP 800-61, Recovery involves restoring systems, implementing safeguards against similar incidents, and testing to ensure functionality.

Thus, Recovery is the correct answer.

Exam trap

The trap here is confusing Eradication with Recovery; many candidates think that removing the root cause (Eradication) also includes restoring systems, but Recovery is the distinct phase that focuses on returning to normal operations and applying preventive measures.

How to eliminate wrong answers

Option A is wrong because Containment focuses on limiting the scope and impact of the incident, not on restoring normal operations or patching. Option B is wrong because Eradication involves removing the root cause (e.g., deleting malware, closing vulnerabilities) but does not include the full restoration of systems to normal operation. Option C is wrong because Detection is about identifying and confirming that an incident has occurred, not about recovery actions.

9
MCQeasy

An organization wants to ensure that its critical business functions can continue operating during a disruption. Which plan specifically addresses keeping the business running during a disruption?

A.Incident Response Plan (IRP)
B.Disaster Recovery Plan (DRP)
C.Business Continuity Plan (BCP)
D.Business Impact Analysis (BIA)
AnswerC

A Business Continuity Plan addresses sustaining critical business functions throughout a disruption, covering people, processes and alternate working arrangements. This differs from a Disaster Recovery Plan, which focuses on restoring IT infrastructure and systems after disruption rather than keeping operations running during it.

Why this answer

The Business Continuity Plan (BCP) is specifically designed to ensure that critical business functions continue operating during and after a disruption. It encompasses strategies for maintaining operations, while DRP focuses on recovering IT infrastructure. Thus, BCP is the correct answer.

Exam trap

The trap here is confusing BCP with DRP; candidates often select DRP because it sounds like it covers disruptions, but BCP is the broader plan for business continuity.

How to eliminate wrong answers

Option A is wrong because an Incident Response Plan (IRP) focuses on detecting, responding to, and mitigating security incidents, not on maintaining business operations. Option B is wrong because a Disaster Recovery Plan (DRP) addresses recovery of IT systems and data after a disaster, not the continuity of business functions during the disruption. Option D is wrong because a Business Impact Analysis (BIA) is a prerequisite for BCP/DRP that identifies critical functions and dependencies, but it does not itself provide a plan for keeping the business running.

10
MCQhard

A security analyst detects unusual outbound traffic from a server that suggests a data breach. According to GDPR, within what timeframe must the organization notify the supervisory authority?

A.72 hours
B.48 hours
C.7 days
D.24 hours
AnswerA

72 hours satisfies the GDPR Article 33 requirement to notify the supervisory authority of a personal data breach without undue delay and, where feasible, no later than 72 hours after becoming aware of it. The detected exfiltration of personal data triggers this controller obligation, so this timeframe is correct.

Why this answer

GDPR mandates notification within 72 hours of awareness of a breach.

11
Multi-Selectmedium

A company is creating a backup strategy for its critical database. The database is updated continuously, and the company can tolerate up to 2 hours of data loss. Which TWO backup methods would best help achieve a recovery point objective (RPO) of 2 hours? (Select TWO.)

Select 2 answers
A.Monthly full backups
B.Weekly full backups
C.Daily full backups
D.Hourly full backups
E.Transaction log backups every 30 minutes
AnswersD, E

Hourly full backups capture the entire database every hour, so at most one hour of committed transactions is lost, comfortably meeting the two-hour RPO. The stem's continuous-update and two-hour tolerance constraints are satisfied by this cadence.

Why this answer

The RPO of 2 hours means backups must capture data at least every 2 hours, so option D (Hourly full backups) is correct because running a full backup every hour guarantees a maximum data loss of 1 hour, which is within the 2-hour RPO. Option E (Transaction log backups every 30 minutes) is also correct because transaction log backups capture all committed transactions since the last log backup, limiting potential data loss to 30 minutes, well inside the 2-hour RPO, and they are the standard method for continuous-update databases. Options A (Monthly full backups) and B (Weekly full backups) are far too infrequent, allowing up to a month or a week of data loss respectively, which violates the 2-hour RPO.

Option C (Daily full backups) only captures data once every 24 hours, so up to 24 hours of updates could be lost, also exceeding the 2-hour RPO.

Exam trap

The trap is assuming 'daily' backups satisfy a 2-hour RPO — candidates must convert RPO into a backup frequency requirement (backup interval ≤ RPO) rather than picking the most familiar schedule.

12
MCQmedium

An organization's recovery time objective (RTO) for its customer database is 4 hours, and the recovery point objective (RPO) is 1 hour. The database is backed up every hour using full backups. A disaster occurs at 2:00 PM, and the last successful backup was at 1:00 PM. The system is restored and operational at 5:30 PM, but data from 1:00 PM to 2:00 PM is lost. Which statement is correct?

A.Both the RTO and RPO were met.
B.The RTO was met, but the RPO was exceeded.
C.The RTO was exceeded, but the RPO was met.
D.Both the RTO and RPO were exceeded.
AnswerA

Restoration finished at 5:30 PM, 3.5 hours after the 2:00 PM disaster, inside the 4-hour RTO. The last backup at 1:00 PM means only one hour of data was lost, matching the 1-hour RPO, so both targets were satisfied.

Why this answer

The RTO is 4 hours and the system was restored at 5:30 PM after a 2:00 PM disaster — a 3.5-hour recovery, which is within the 4-hour RTO. The RPO is 1 hour and the last backup was at 1:00 PM, so up to 1 hour of data (1:00–2:00 PM) was lost, which is exactly at the 1-hour RPO limit and therefore met. Both objectives were satisfied.

Exam trap

The trap is treating 'exactly at the limit' as a failure — candidates often mark the RPO as exceeded when data loss equals (rather than exceeds) the stated RPO.

How to eliminate wrong answers

Option B is wrong because the RPO was not exceeded — 1 hour of data loss equals the 1-hour RPO, which is acceptable (the limit is 'up to' 1 hour). Option C is wrong because the RTO was not exceeded — 3.5 hours is less than the 4-hour RTO. Option D is wrong because neither objective was breached; both were met within their stated limits.

13
MCQmedium

A company uses a reciprocal agreement for disaster recovery. What is a primary risk of this strategy?

A.Data confidentiality issues
B.Both organizations may be impacted by the same disaster
C.Slow recovery due to lack of equipment
D.High cost of maintaining the agreement
AnswerB

Reciprocal agreements rely on each party hosting the other's workloads, so a disaster affecting one organisation's region or infrastructure can simultaneously hit the partner's site. That shared geographic or environmental exposure defeats the purpose of offsite recovery, which is the primary risk the stem asks about.

Why this answer

A reciprocal agreement is an arrangement where two organizations agree to host each other's workloads in the event of a disaster. The primary risk is geographic and correlated failure: if both organizations are in the same disaster zone (flood, hurricane, regional power outage), the same event can disable both sites simultaneously, leaving neither able to host the other.

Exam trap

The trap is focusing on cost or confidentiality as the headline risk — the exam expects candidates to recognize that reciprocal agreements fail primarily because both parties can be hit by the same disaster.

How to eliminate wrong answers

Option A is wrong because while confidentiality is a legitimate concern when sharing facilities, it is a secondary risk managed by access controls and NDAs — not the primary structural weakness of reciprocal agreements. Option C is wrong because reciprocal agreements typically assume the partner has spare capacity, but the real issue is not slowness from lack of equipment; it is that the equipment may be unavailable because the partner is also affected. Option D is wrong because reciprocal agreements are generally low-cost (often just formalized goodwill), so high cost is not the defining risk.

14
MCQhard

An organization uses a 3-2-1 backup strategy. They have a primary full backup on a local NAS, a second copy on tape stored offsite, and a third copy in the cloud. During a ransomware attack, the local NAS and the tape library are both encrypted. Which copy should be used for recovery?

A.The tape backup
B.The local NAS backup
C.The cloud backup
D.A new full backup from production data
AnswerC

The 3-2-1 strategy keeps one copy offsite and offline from the primary environment. Since both the local NAS and the offsite tape library were encrypted, only the cloud copy remains intact and uninfected, so recovery must draw from that isolated third copy.

Why this answer

The cloud backup is the only copy that was not compromised by the ransomware attack, since both the local NAS and the offsite tape library were encrypted. In a 3-2-1 strategy, the offsite copy is specifically intended to survive local disasters, but here the attacker reached both on-premises copies. The cloud copy, being isolated and typically immutable or versioned, is the correct recovery source.

Exam trap

The trap is assuming that the offsite tape copy is automatically safe — the question explicitly states it was encrypted, testing whether you read the scenario carefully rather than applying the 3-2-1 rule blindly.

How to eliminate wrong answers

Option A is wrong because the tape library was explicitly encrypted by the ransomware, so the tape backup is compromised and cannot be trusted for recovery. Option B is wrong because the local NAS was also encrypted and is therefore unusable. Option D is wrong because generating a new full backup from production data would capture the ransomware-encrypted or corrupted state, and production data may itself be compromised — this is a classic mistake that reintroduces the threat.

15
MCQmedium

A financial institution's incident response team is handling a denial-of-service (DoS) attack that is affecting customer access. The team has identified the attack source IPs and implemented filtering rules on the perimeter firewall. Which phase of incident response is being performed?

A.Detection
B.Recovery
C.Eradication
D.Containment
AnswerD

Filtering malicious source IPs at the perimeter firewall blocks the attack's traffic, limiting its scope and impact while remediation continues. This matches containment, which stops the spread rather than eradicating the root cause or restoring normal operations.

Why this answer

Containment involves limiting the scope and impact of an incident — in this case, implementing firewall filtering rules to block attack source IPs and prevent further damage while the team investigates. This phase focuses on stopping the spread and isolating affected systems, which matches the described action. Eradication would involve removing the root cause (e.g., patching vulnerabilities), and recovery would restore normal operations.

Exam trap

CC often tests the boundaries between containment and eradication, and candidates pick eradication because blocking IPs feels like 'fixing' the problem, when in fact it is a temporary containment measure that does not remove the root cause.

How to eliminate wrong answers

Option A is wrong because detection is the phase where the incident is identified and analyzed — the team has already identified the attack and source IPs, so detection is complete. Option B is wrong because recovery involves restoring systems and services to normal operation after the threat is eliminated, which has not yet occurred. Option C is wrong because eradication is the phase where the root cause is removed, such as patching a vulnerability or deleting malware — blocking IPs is a temporary containment measure, not a permanent fix.

16
MCQhard

An organization has an RTO of 4 hours and an RPO of 1 hour for its customer database. After a disaster, the IT team restores the database from backups that are 2 hours old, and the system becomes operational in 3 hours. Which of the following is true?

A.Neither the RTO nor RPO was met.
B.The RPO was met, but the RTO was not.
C.Both the RTO and RPO were met.
D.The RTO was met, but the RPO was not.
AnswerD

Recovery completed in 3 hours, inside the 4-hour RTO, so the availability target was satisfied. However, the restored data was 2 hours old, exceeding the 1-hour RPO, meaning up to an hour of transactions was lost.

Why this answer

The RTO of 4 hours was met because the system became operational in 3 hours, which is within the 4-hour target. However, the RPO of 1 hour was not met because the restored data was 2 hours old, meaning up to 2 hours of data was lost, exceeding the 1-hour maximum tolerable data loss. Therefore, the RTO was met but the RPO was not.

Exam trap

The trap is confusing RTO and RPO — candidates often swap the definitions or assume that meeting one metric implies meeting the other, when they measure entirely different things (downtime vs. data loss).

How to eliminate wrong answers

Option A is wrong because the RTO was clearly met (3 hours < 4 hours), so claiming neither was met is incorrect. Option B is wrong because it reverses the metrics — the RPO was violated (2 hours > 1 hour) and the RTO was satisfied, not the other way around. Option C is wrong because the RPO was exceeded (2-hour-old data vs. 1-hour RPO), so both were not met.

17
MCQhard

A financial services firm has a recovery time objective (RTO) of 2 hours for its trading platform and a recovery point objective (RPO) of 15 minutes. The disaster recovery team is evaluating whether a warm site can meet these requirements. Which statement best describes the limitation of a warm site in this scenario?

A.A warm site cannot meet the RPO because it does not support data replication from the primary site.
B.A warm site can meet the RTO because it only requires switching network routes to the standby environment.
C.A warm site is identical to a hot site and can meet both the RTO and RPO without any additional configuration.
D.A warm site cannot meet the RTO because it requires manual data restoration and configuration, which typically takes longer than 2 hours.
AnswerD

A warm site has hardware and connectivity pre-installed but lacks live data and may need manual restoration and configuration. For a trading platform with a 2-hour RTO, the time to restore data, apply configurations, and validate systems often exceeds that window. This makes a warm site unsuitable unless extensive automation and replicated data are added, which would effectively turn it into a hot site.

Why this answer

A warm site provides pre-installed hardware and network connectivity but requires data restoration and system configuration before it can operate. For a trading platform with a 2-hour RTO, this manual effort typically exceeds the acceptable outage window. While the 15-minute RPO could be addressed with replication, the RTO is the binding constraint that makes a warm site a poor fit without substantial automation.

Exam trap

The trap here is focusing on the RPO and assuming replication alone makes a warm site adequate, when the 2-hour RTO is the more demanding constraint that a warm site usually cannot satisfy.

18
MCQeasy

Which recovery site strategy provides the shortest recovery time objective (RTO), typically measured in hours, by maintaining a fully mirrored environment that can be activated immediately?

A.Warm site
B.Reciprocal agreement
C.Cold site
D.Hot site
AnswerD

A hot site maintains fully mirrored hardware, software and near-live data replication, so operations resume within hours rather than days. This directly satisfies the stem's shortest-RTO constraint, unlike warm or cold sites, which require restoration or configuration before activation.

Why this answer

A hot site is fully configured with hardware, software, and real-time data replication, enabling recovery within hours.

19
MCQmedium

A software company's incident response plan defines a severity level of 'Critical' for incidents that cause a complete outage of customer-facing services. A developer accidentally deploys a faulty update that crashes the production web servers, making the service unavailable to all customers. Which incident response phase should the team be in when they apply a rollback to the previous working version?

A.Preparation
B.Containment
C.Recovery
D.Eradication
AnswerC

The recovery phase involves restoring systems to normal operation after an incident has been contained and eradicated. Applying a rollback to a previous working version is a recovery action because it brings the production web servers back to a functional state. This phase focuses on implementing the fix and verifying that the service is fully operational. It follows containment and eradication, where the faulty update would have been identified and removed.

Why this answer

The recovery phase focuses on restoring systems to normal operation after an incident has been contained and eradicated. Applying a rollback to a previous working version is a recovery action because it brings the production web servers back online and functional. This phase ensures the service is fully restored and verified.

It follows containment (limiting impact) and eradication (removing the cause).

Exam trap

The trap here is confusing the recovery phase with eradication, as both involve actions to fix the issue, but recovery specifically restores normal operations.

20
MCQeasy

Which recovery site strategy provides the fastest Recovery Time Objective (RTO), typically within hours, by maintaining a fully operational mirrored environment?

A.Cold site
B.Warm site
C.Hot site
D.Cloud-based recovery
AnswerC

A hot site maintains a fully operational, mirrored environment with current data and ready hardware, enabling failover within hours. This satisfies the stem's fastest-RTO constraint, unlike warm or cold sites, which require longer setup and data restoration.

Why this answer

A hot site is a fully operational duplicate of the primary data center with mirrored hardware, data replication, and network connectivity, enabling failover typically within minutes to hours. Because it maintains real-time or near-real-time synchronization, it delivers the fastest Recovery Time Objective (RTO) among the traditional site strategies. This makes it the correct choice when the business cannot tolerate extended downtime.

Exam trap

The trap here is conflating 'cloud-based recovery' with a hot site — candidates assume anything cloud is automatically fastest, but the exam wants the classic hot/warm/cold classification where 'fully operational mirrored environment' maps specifically to hot site.

How to eliminate wrong answers

Option A is wrong because a cold site provides only basic infrastructure (space, power, cooling) with no pre-installed hardware or data, resulting in RTO measured in days or weeks. Option B is wrong because a warm site has some pre-configured hardware and periodic backups but still requires restoration and configuration, yielding an RTO of hours to days — slower than a hot site. Option D is wrong because 'cloud-based recovery' is not one of the three classic recovery site categories (hot/warm/cold); while cloud DR can be fast, the question asks for the strategy that maintains a fully operational mirrored environment, which is the definition of a hot site.

21
MCQeasy

A retail company experiences a distributed denial-of-service (DDoS) attack that overwhelms its online store. The incident response team successfully mitigates the attack, and the store is back online. Which activity should the team perform as part of the post-incident activity phase?

A.Conduct a lessons-learned meeting to identify improvements in the DDoS response process.
B.Notify law enforcement and press charges against the attackers.
C.Immediately reconfigure the firewall to block the attacking IP addresses.
D.Restore the online store from the most recent backup.
AnswerA

The post-incident activity phase is designed to review the incident, gather feedback from responders, and update plans and controls. A lessons-learned meeting helps the retail company understand how the DDoS was detected, what worked well, and what needs improvement. This aligns with the goal of continuous improvement and is a core activity after the incident is closed.

Why this answer

After an incident is contained and systems are restored, the post-incident activity phase involves reviewing the event to improve future response. A lessons-learned meeting allows the team to document what happened, identify gaps, and update the incident response plan. This is the key activity that distinguishes post-incident work from ongoing operational tasks.

Exam trap

The trap here is choosing a technical remediation step like firewall changes or backups, when the question specifically asks for a post-incident activity, which is about review and improvement.

22
MCQeasy

An organization is creating a Business Continuity Plan (BCP). Which analysis should be performed first to identify critical business functions and their dependencies?

A.Risk Assessment
B.Business Impact Analysis
C.Vulnerability Assessment
D.Gap Analysis
AnswerB

A Business Impact Analysis identifies critical business functions and maps their dependencies, plus tolerable downtime and recovery priorities. It is performed first because its output — the RTO and RPO figures — drives every subsequent BCP and recovery strategy decision.

Why this answer

The Business Impact Analysis (BIA) is the foundational step in BCP development because it systematically identifies critical business functions, their dependencies, and the impact of their disruption over time. It quantifies the consequences of downtime, helping prioritize recovery objectives like RTO and RPO. Without a BIA, subsequent risk assessment and recovery strategies lack a business-driven focus.

Exam trap

The trap here is confusing the sequence of BCP steps: many candidates assume Risk Assessment comes first because it sounds like the starting point for security planning, but in BCP, the BIA must precede risk assessment to identify what is critical.

How to eliminate wrong answers

Option A is wrong because Risk Assessment identifies threats and vulnerabilities to assets, but it does not determine which business functions are critical or their dependencies; it typically follows the BIA. Option C is wrong because Vulnerability Assessment focuses on technical weaknesses in systems, not on business processes or their interdependencies. Option D is wrong because Gap Analysis compares current capabilities against desired recovery objectives, which can only be defined after a BIA has established those objectives.

23
Multi-Selecthard

An organization is updating its incident response plan. Which THREE elements should be included in the preparation phase? (Select THREE.)

Select 3 answers
A.Restoring data from backups
B.Notifying law enforcement
C.Conducting tabletop exercises
D.Acquiring forensic analysis tools
E.Creating an incident response team
AnswersC, D, E

Tabletop exercises rehearse the plan against simulated scenarios, exposing gaps in roles, escalation paths and communications before a real incident. This validates readiness during preparation, satisfying the requirement to test and refine response capabilities rather than improvise them live.

Why this answer

Option C (Conducting tabletop exercises) is correct because tabletop exercises are a preparation-phase activity that validates and rehearses the incident response plan, roles, and communication paths before a real incident occurs. Option D (Acquiring forensic analysis tools) is correct because procuring and maintaining forensic toolkits (e.g., disk imaging, memory capture, and analysis utilities) is part of building the resources and capabilities needed during preparation. Option E (Creating an incident response team) is correct because establishing the CSIRT/IR team, defining its roles, and assigning responsibilities is a foundational preparation-phase element.

Option A (Restoring data from backups) belongs to the recovery/eradication-and-recovery phase, since restoration happens after containment and eradication, not during preparation. Option B (Notifying law enforcement) is a coordination/communication action taken during or after detection and response, not a preparation-phase element.

24
MCQmedium

A security analyst detects unusual outbound network traffic from a server that normally does not communicate externally. After confirming a malware infection, the analyst isolates the server from the network. Which incident response phase is the analyst performing?

A.Recovery
B.Detection
C.Containment
D.Eradication
AnswerC

Isolation halts the malware's spread and external communication while the environment is still compromised, which is the containment phase's defining action. It sits between detection and eradication, satisfying the stem's need to stop ongoing impact before recovery begins.

Why this answer

Isolating the server is a containment action to prevent spread.

25
MCQmedium

A mid-sized hospital's disaster recovery team is reviewing its incident response plan after a ransomware attack encrypted the electronic health record (EHR) system. The team determines that the attack began 36 hours before it was detected. Which incident response phase was most directly compromised by this delay?

A.Preparation
B.Post-Incident Activity
C.Detection and Analysis
D.Containment, Eradication, and Recovery
AnswerC

Detection and Analysis is the phase where monitoring tools, alerts, and staff identify that an incident is occurring and determine its scope. A 36-hour gap between the start of the ransomware attack and its discovery is a direct failure of this phase. The organization did not detect the unauthorized encryption activity in a timely manner, delaying the entire response effort.

Why this answer

The 36-hour gap between the onset of the ransomware attack and its discovery points directly to a failure in the Detection and Analysis phase, where monitoring and alerting should identify malicious activity quickly. While preparation, containment, and post-incident review all matter, the scenario describes a delay in recognizing the incident, which is the defining activity of detection and analysis. Improving detection capabilities would most directly address this gap.

Exam trap

The trap here is assuming that a slow response is always a containment failure, when the scenario actually describes a delay in noticing the incident, which belongs to Detection and Analysis.

26
MCQmedium

A healthcare organization experiences a data breach involving protected health information (PHI). Under GDPR, within how many hours must the organization notify the relevant supervisory authority?

A.24 hours
B.48 hours
C.72 hours
D.7 days
AnswerC

72 hours is the maximum period under GDPR Article 33(1) for notifying a supervisory authority of a personal data breach, counted from awareness. This satisfies the stem's PHI breach scenario, since the regulation sets a single deadline regardless of sector; healthcare organisations must also document the breach internally.

Why this answer

Under GDPR Article 33, a controller must notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in a risk to data subjects' rights and freedoms. PHI constitutes personal data under GDPR, so the 72-hour clock applies. This deadline is a maximum; notification should occur as soon as possible within that window.

Exam trap

The trap here is confusing GDPR's 72-hour supervisory authority notification with other breach-notification timelines (such as 24 hours under some sectoral rules or 30/60 days under HIPAA), causing candidates to select a shorter or longer window than Article 33 actually specifies.

How to eliminate wrong answers

Option A is wrong because 24 hours is the notification window used by some other regimes (e.g., certain NIS2 sectoral rules) and is not the GDPR Article 33 deadline. Option B is wrong because 48 hours has no basis in GDPR breach notification provisions. Option D is wrong because 7 days is far too long and does not correspond to any GDPR notification timeline; GDPR requires 72 hours, and data subjects must be notified without undue delay when high risk exists.

27
MCQhard

A financial services firm has activated its disaster recovery plan after a ransomware attack encrypted its primary data center. The incident response team has contained the attack, but the recovery team must restore operations. Which action should the recovery team take FIRST to ensure a successful restoration?

A.Immediately restore the most recent full backup to the primary data center.
B.Rebuild the primary data center from scratch using the original installation media.
C.Notify all customers about the data breach and provide credit monitoring services.
D.Validate that the most recent backups are free from malware and can be restored.
AnswerD

Before restoring any data, the recovery team must ensure that the backups are not compromised. Ransomware often attempts to encrypt or delete backups, and restoring an infected backup could reintroduce the malware. Validating the integrity and cleanliness of backups is a critical first step to prevent reinfection. This aligns with incident response best practices, which emphasize verifying the trustworthiness of recovery sources before initiating restoration.

Why this answer

In a ransomware recovery scenario, the first step is to ensure that backups are clean and restorable. Ransomware often targets backups, so validating their integrity prevents restoring malicious code. Once backups are verified, the team can proceed with restoration.

This approach aligns with the incident response principle of containing and eradicating the threat before recovery. Skipping validation risks reinfection and further downtime.

Exam trap

The trap here is prioritizing speed over security by immediately restoring backups without first verifying they are malware-free.

28
MCQmedium

After a ransomware attack, the IT team restores systems from backups. The CEO asks how quickly data can be recovered. Which metric addresses the acceptable amount of data loss?

A.Work Recovery Time (WRT)
B.Recovery Time Objective (RTO)
C.Maximum Tolerable Downtime (MTD)
D.Recovery Point Objective (RPO)
AnswerD

Recovery Point Objective (RPO) defines the maximum tolerable data loss measured in time, directly answering how much data can be lost between the last backup and the incident. It satisfies the CEO's question about acceptable data loss, unlike Recovery Time Objective, which measures restoration duration.

Why this answer

RPO (Recovery Point Objective) defines the maximum acceptable amount of data loss measured in time — i.e., how far back in time you can afford to lose data. The CEO's question about 'acceptable amount of data loss' maps directly to RPO. RTO, by contrast, addresses how quickly systems must be restored, not how much data can be lost.

Exam trap

The trap is confusing RPO with RTO — both are recovery metrics, but RPO is about data loss (how much data) while RTO is about downtime (how long), and exam questions often swap the phrasing to test whether candidates can distinguish the two.

How to eliminate wrong answers

Option A is wrong because Work Recovery Time (WRT) refers to the time needed to verify and resume business operations after systems are restored, not the amount of data loss. Option B is wrong because RTO (Recovery Time Objective) measures the acceptable duration of downtime before systems must be operational, not the volume of data loss. Option C is wrong because Maximum Tolerable Downtime (MTD) is the total time a business process can be unavailable before unacceptable consequences occur, which is a downtime metric, not a data-loss metric.

29
Multi-Selecthard

A company is planning its backup strategy and wants to balance storage efficiency with restore speed. Which TWO backup strategies should the company consider? (Select TWO)

Select 2 answers
A.Full backup weekly, incremental daily
B.Full backup daily, no other backups
C.Full backup weekly, differential daily
D.Full backup monthly, incremental weekly
E.Full backup weekly, incremental daily, and differential weekly
AnswersA, C

Correct. Full backup weekly with daily incremental backups minimizes storage because incrementals only store changes. Restore requires the full plus all incrementals, which is slower but storage-efficient.

Why this answer

To minimize storage usage while ensuring fast restores, a common strategy is to use a full backup as the primary and either incremental or differential as the secondary. Option A (full weekly + incremental daily) saves storage as incremental backups only store changes since the last backup, but restore requires the full and all incrementals. Option C (full weekly + differential daily) uses more storage than incremental but restore is faster as only the full and last differential are needed.

Both strategies meet the requirements; other options either use excessive storage (B, E) or slow restore (D) or are not two-type strategies.

30
MCQmedium

During an incident, the incident response team identifies that a malware infection is spreading. They isolate affected systems to prevent further damage. Which phase of the incident response process are they performing?

A.Recovery
B.Eradication
C.Detection
D.Containment
AnswerD

Isolating infected systems halts malware propagation, which is the defining activity of the containment phase. Containment limits incident scope before eradication and recovery begin, directly satisfying the stem's goal of preventing further damage across the network.

Why this answer

Containment is the incident response phase focused on limiting the scope and impact of an incident by stopping the spread of malware and preventing further damage. Isolating affected systems directly aligns with this goal, as it prevents lateral movement and additional infections. This phase occurs after detection and before eradication and recovery.

Exam trap

The trap here is confusing containment with eradication; candidates often think that isolating systems is part of removing the malware, but containment is specifically about stopping the spread, not eliminating the threat.

How to eliminate wrong answers

Option A is wrong because Recovery involves restoring systems to normal operations after the threat has been eliminated, not isolating them during an active spread. Option B is wrong because Eradication focuses on removing the malware and its artifacts from the environment, not on preventing its spread. Option C is wrong because Detection is the phase where the incident is identified and confirmed, which has already occurred before isolation actions are taken.

31
MCQeasy

Which type of backup copies all data that has changed since the last full backup, regardless of any subsequent incremental or differential backups?

A.Full backup
B.Differential backup
C.Incremental backup
D.Synthetic full backup
AnswerB

A differential backup captures every block changed since the last full backup, so each successive run accumulates all modifications regardless of earlier differentials. This satisfies the stem's constraint of copying changes since the last full backup, unlike incremental backups, which capture only changes since the previous backup of any type.

Why this answer

A differential backup copies all data that has changed since the last full backup, regardless of any subsequent incremental or differential backups. This means each differential backup includes all changes since the last full backup, growing in size over time. Therefore, differential backup is the correct answer.

Exam trap

CC often tests the confusion between incremental and differential backups, particularly the point of reference (last backup vs. last full backup) and the resulting restore complexity.

How to eliminate wrong answers

Option A is wrong because a full backup copies all data, not just changes since the last full backup. Option C is wrong because an incremental backup copies only data changed since the last backup of any type (full or incremental). Option D is wrong because a synthetic full backup constructs a full backup from previous backups, but it does not copy changes since the last full backup in the described manner.

32
MCQeasy

A company is developing a business continuity plan. Which document identifies critical business functions and their dependencies, including the maximum acceptable downtime?

A.Disaster Recovery Plan (DRP)
B.Business Continuity Plan (BCP)
C.Incident Response Plan (IRP)
D.Business Impact Analysis (BIA)
AnswerD

A Business Impact Analysis identifies critical business functions, maps their dependencies, and quantifies the maximum acceptable downtime and data loss, producing the recovery objectives a continuity plan needs. It is the document that establishes those tolerances.

Why this answer

A Business Impact Analysis (BIA) identifies critical business functions, their dependencies, and the maximum acceptable downtime (MTD) and recovery objectives. It is the foundational analysis that feeds the BCP and DRP. The question's description of identifying critical functions and dependencies with maximum acceptable downtime is the textbook definition of a BIA.

Exam trap

The trap is confusing the BIA with the BCP or DRP — the BIA is the analysis that identifies critical functions and downtime tolerances, while the BCP and DRP are the plans that document how to maintain or restore operations based on that analysis.

How to eliminate wrong answers

Option A is wrong because a Disaster Recovery Plan (DRP) focuses on restoring IT infrastructure and systems after a disruption, not on identifying business functions and dependencies. Option B is wrong because a Business Continuity Plan (BCP) is the overarching plan for maintaining business operations during and after a disruption; it is built on the BIA but does not itself perform the analysis. Option C is wrong because an Incident Response Plan (IRP) addresses detecting, responding to, and recovering from security incidents, not business function dependency analysis.

33
MCQmedium

Which backup strategy offers the fastest restore time but requires the most storage space?

A.Incremental backup
B.Differential backup
C.Snapshot backup
D.Full backup
AnswerD

A full backup captures every selected file in a single operation, so restoration requires only one pass from one backup set — no incremental chain to replay. This satisfies the stem's fastest-restore constraint, while duplicating all data at each run explains the maximum storage consumption.

Why this answer

A full backup copies all selected data every time, so restoring requires only the latest full backup, resulting in the fastest restore time. However, because it duplicates all data with each backup, it requires the most storage space compared to incremental or differential backups.

Exam trap

CC often tests the trade-off between restore speed and storage consumption, and candidates may incorrectly assume incremental backups are fastest to restore because they are smallest.

How to eliminate wrong answers

Option A is wrong because incremental backups only copy data changed since the last backup (full or incremental), requiring the full backup plus all incrementals to restore, which is slower and uses less storage. Option B is wrong because differential backups copy data changed since the last full backup, requiring the full plus the latest differential to restore, which is faster than incremental but slower than full and uses less storage than full. Option C is wrong because snapshot backups capture the state of a system at a point in time and can be fast to restore, but they often rely on copy-on-write and may require additional storage for changes, and they are not typically the fastest or most storage-intensive compared to full backups.

34
MCQhard

During an incident, a security analyst identifies a SQL injection attack. The team contains the threat by blocking the attacker's IP. Which step should be performed next in the incident response process?

A.Detection
B.Lessons Learned
C.Recovery
D.Eradication
AnswerD

Eradication follows containment in the incident response lifecycle. After blocking the attacker's IP, the team must remove the SQL injection vulnerability, patch the application and eliminate any malware or persistence, so the threat cannot recur before recovery begins.

Why this answer

The incident response lifecycle is Preparation, Detection, Containment, Eradication, Recovery, and Lessons Learned. After containing the threat by blocking the attacker's IP, the next step is eradication, which involves removing the root cause — such as patching the SQL injection vulnerability, removing malware, or closing the attack vector. Recovery (restoring systems) follows eradication.

Exam trap

CC often tests the order of incident response phases, and candidates commonly confuse eradication (removing the root cause) with recovery (restoring operations) after containment.

How to eliminate wrong answers

Option A is wrong because detection already occurred — the analyst identified the SQL injection attack, so detection is complete. Option B is wrong because Lessons Learned is the final phase, performed after recovery, to document and improve processes. Option C is wrong because recovery restores normal operations and comes after eradication, not immediately after containment.

35
MCQmedium

A retail company's business continuity plan includes a requirement to test its disaster recovery capabilities annually. The IT team proposes conducting a tabletop exercise with key stakeholders. Which benefit does this type of test provide?

A.It verifies that the recovery site can handle the production workload within the RTO.
B.It provides a full-scale simulation of a disaster to test all technical recovery procedures.
C.It automatically updates the disaster recovery plan based on identified gaps during the exercise.
D.It evaluates the decision-making and communication processes without disrupting live operations.
AnswerD

A tabletop exercise is a discussion-based test where participants walk through a simulated emergency scenario. It allows stakeholders to practice roles, decision-making, and communication without affecting production systems. This makes it a low-risk, cost-effective way to identify gaps in plans and coordination. It does not validate technical recovery capabilities, but it is valuable for testing the human and procedural aspects of the plan.

Why this answer

A tabletop exercise is a discussion-based test that simulates an emergency scenario to evaluate plans, roles, and communication. It does not disrupt live operations and is relatively low-cost. It helps identify gaps in coordination and decision-making.

It is not a technical test of recovery systems; instead, it focuses on the human and procedural elements of business continuity and disaster recovery.

Exam trap

The trap here is assuming a tabletop exercise tests technical recovery, when it actually tests plans and communication without live failover.

36
MCQmedium

Which incident category involves an attempt to make a system or network resource unavailable to its intended users?

A.Malware
B.Data breach
C.Denial of service
D.Social engineering
AnswerC

Denial-of-service attacks exhaust a system's capacity — flooding bandwidth, connection tables or CPU — so legitimate users cannot reach the resource, directly matching the stem's unavailability criterion. Unlike data-theft or intrusion categories, the objective here is disruption rather than access, making this the precise incident classification.

Why this answer

A denial-of-service (DoS) incident is defined as any attempt to make a system or network resource unavailable to its intended users, typically by flooding it with traffic or exploiting resource exhaustion. This matches the question's description exactly. Other categories like malware or data breach involve different objectives such as data theft or code execution.

Exam trap

The trap here is conflating 'availability' attacks with 'confidentiality' or 'integrity' attacks; candidates may pick 'data breach' because they associate all cyber incidents with data theft, missing the specific wording about making resources unavailable.

How to eliminate wrong answers

Option A is wrong because malware incidents involve malicious software designed to damage, disrupt, or gain unauthorized access, not necessarily to make a resource unavailable. Option B is wrong because a data breach focuses on unauthorized access to and exfiltration of sensitive data, not on service availability. Option D is wrong because social engineering manipulates people into revealing information or performing actions, which is a human-centric attack rather than a resource exhaustion attack.

37
MCQmedium

A company performs a full backup every Sunday and incremental backups on other days. On Wednesday, a server failure occurs. Which backups are needed to restore the server to its state at Tuesday's backup?

A.Only Tuesday incremental backup
B.Sunday full backup, Monday incremental, and Tuesday incremental
C.Only the Sunday full backup
D.Sunday full backup and Monday incremental backup
AnswerB

Incremental backups capture only changes since the previous backup, so restoration requires the last full backup plus every incremental in sequence. Sunday's full plus Monday's and Tuesday's incrementals reconstruct Tuesday's state; omitting either incremental loses intervening changes.

Why this answer

With a weekly full backup on Sunday and daily incrementals, each incremental captures only changes since the last backup. To restore to Tuesday's state you must apply the Sunday full backup first, then Monday's incremental, then Tuesday's incremental in sequence. Incrementals cannot be applied standalone because they depend on the previous backup chain.

Exam trap

The trap here is confusing incremental with differential backups — candidates who think each incremental is self-contained will pick 'only Tuesday incremental', but incrementals always require the full plus all prior incrementals.

How to eliminate wrong answers

Option A is wrong because a Tuesday incremental only contains changes since Monday's backup and cannot reconstruct the full system state on its own. Option C is wrong because the Sunday full backup only restores the state as of Sunday, losing all Monday and Tuesday changes. Option D is wrong because it stops at Monday's incremental and omits Tuesday's changes, so the restore would not reflect Tuesday's state.

38
MCQmedium

Which type of incident involves an attacker attempting to make a system or network resource unavailable to legitimate users?

A.Denial of service
B.Social engineering
C.Malware
D.Data breach
AnswerA

Denial of service floods a system or network with traffic or malformed requests, exhausting bandwidth, connections or processing capacity so legitimate users cannot access the resource. Availability, rather than confidentiality or integrity, is the target of this incident type.

Why this answer

A Denial of Service (DoS) attack explicitly aims to disrupt the availability of a system or network resource, making it inaccessible to legitimate users. This aligns with the definition of a DoS incident, which focuses on overwhelming the target with traffic or exploiting vulnerabilities to exhaust resources. The other options describe different attack categories: social engineering targets human trust, malware is malicious software, and data breach involves unauthorized data access.

Exam trap

The trap here is confusing the goal of an attack with the method; candidates might select malware or social engineering because they are common attack types, but the question specifically asks for the incident type defined by the objective of making resources unavailable.

How to eliminate wrong answers

Option B is wrong because social engineering manipulates people into divulging confidential information or performing actions, not directly causing unavailability. Option C is wrong because malware is a broad category of malicious software that can have various goals, including data theft or disruption, but it is not specifically defined by the goal of denying service. Option D is wrong because a data breach involves unauthorized access to and exfiltration of sensitive data, not the disruption of service availability.

39
Multi-Selectmedium

During a security incident, a company must notify stakeholders without revealing sensitive details that could worsen the situation. Which TWO groups should typically be notified immediately according to incident response best practices? (Select TWO)

Select 2 answers
A.All affected customers immediately
B.General public via press release
C.Legal department
D.Executive management
E.Local law enforcement automatically
AnswersC, D

Legal counsel must be engaged immediately because they assess breach-notification duties, preserve attorney-client privilege over incident findings, and approve any external wording before disclosure. This satisfies the stem's constraint of notifying stakeholders without revealing sensitive details that could worsen the situation, since legal review gates what may lawfully and safely be communicated.

Why this answer

Option C (Legal department) is correct because incident response best practices require immediate legal counsel involvement to assess regulatory notification obligations (e.g., GDPR 72-hour breach reporting, HIPAA, SEC disclosure rules), preserve attorney-client privilege over incident findings, and guide controlled communications that avoid premature or legally risky disclosures. Option D (Executive management) is correct because senior leadership must be notified immediately to authorize containment actions, allocate resources, make strategic decisions about service shutdowns or customer impact, and serve as the approved channel for any external statements. Option A is not correct because notifying all affected customers immediately is premature before the scope, root cause, and legal notification requirements are established, and it risks amplifying the incident.

Option B is not correct because issuing a general public press release at the outset can worsen the situation by revealing sensitive details and tipping off attackers. Option E is not correct because law enforcement should be engaged selectively based on jurisdiction, legal guidance, and incident severity, not automatically in every case.

40
MCQeasy

Which incident category involves an attacker tricking an employee into revealing their login credentials through a fraudulent email?

A.Social engineering
B.Malware
C.Unauthorised access
D.Denial of service
AnswerA

Social engineering manipulates people into divulging confidential information; phishing emails impersonating trusted entities are its classic vector. The fraudulent email tricking an employee into revealing credentials is precisely this category, distinguishing it from technical exploits such as malware or network attacks.

Why this answer

Social engineering is the category of incident where an attacker manipulates a person into divulging confidential information such as login credentials, typically via phishing or pretexting. A fraudulent email tricking an employee into revealing credentials is the textbook definition of social engineering, which exploits human trust rather than technical vulnerabilities.

Exam trap

The trap is conflating the attack method (social engineering) with its consequence (unauthorised access) — candidates pick the outcome category instead of the technique category.

How to eliminate wrong answers

Option B is wrong because malware involves malicious software executing on a system (viruses, ransomware, trojans) — no code execution is described here, only deception of a human. Option C is wrong because unauthorised access is the outcome or effect of an attack, not the attack category itself; the credential theft may lead to unauthorised access, but the incident described is the deception. Option D is wrong because denial of service aims to disrupt availability of systems or services, which is unrelated to tricking a user into revealing credentials.

41
MCQmedium

An organization is adopting the 3-2-1 backup rule. They currently have data on a primary server and a daily backup to an external hard drive. To comply with the rule, what is the minimum additional requirement?

A.A second external hard drive stored on-site
B.An incremental backup to a network share
C.A full backup on tape stored in the same room
D.A cloud backup stored offsite
AnswerD

A cloud backup stored offsite satisfies the 3-2-1 rule's offsite leg, since the existing external drive already provides the second copy on a different medium. The primary server plus daily external backup give two copies; only an offsite location remains outstanding, which cloud storage delivers without physical transport.

Why this answer

The 3-2-1 backup rule requires at least three copies of data, on two different media types, with one copy stored offsite. The organization currently has two copies (primary and external hard drive), both likely on-site and possibly the same media type. Adding a cloud backup provides the required third copy and satisfies the offsite requirement, making it the minimum additional requirement.

Exam trap

The trap here is confusing the components of 3-2-1: candidates might think adding any third copy suffices, but the offsite requirement is critical and often overlooked.

How to eliminate wrong answers

Option A is wrong because a second external hard drive stored on-site would provide a third copy but still lacks an offsite copy, violating the '1' in 3-2-1. Option B is wrong because an incremental backup to a network share may be on-site and does not guarantee a different media type or offsite storage. Option C is wrong because a full backup on tape stored in the same room is not offsite and may not meet the '2' media types if the primary and external drive are both disk-based.

42
MCQmedium

An organization adopts the 3-2-1 backup rule. Which combination of backups satisfies this rule?

A.Primary storage and one tape backup stored offsite
B.Primary storage and two tape backups in the same room
C.Primary storage, backup server (disk), and a second backup server (disk) in the same building
D.Primary storage, backup server (disk), and cloud storage
AnswerD

Three copies exist (primary, disk backup, cloud), on two media types (disk and cloud), with one copy offsite in the cloud. This satisfies the 3-2-1 rule's requirement for an offsite copy, protecting against site-level loss.

Why this answer

The 3-2-1 rule requires three copies of data, on two different media types, with one copy stored offsite. Option D satisfies all three: the primary storage is copy one, the on-premises disk backup server is copy two on a different medium, and cloud storage is copy three stored offsite. This combination is the canonical textbook example of a compliant 3-2-1 implementation.

Exam trap

The trap here is confusing 'three backups' with 'three copies' — candidates count only the backup targets and forget that primary storage counts as one of the three copies.

How to eliminate wrong answers

Option A is wrong because it only provides two copies of the data (primary plus one tape), violating the '3' in 3-2-1. Option B is wrong because although it has three copies on two media types, both tape backups are in the same room, so there is no offsite copy — violating the '1'. Option C is wrong because all three copies (primary, disk backup, second disk backup) reside in the same building, again failing the offsite requirement and arguably using only one media type.

43
MCQmedium

A security analyst detects unusual outbound network traffic from a server that typically only handles internal file sharing. The traffic appears to be exfiltrating sensitive data. Which phase of the incident response process should the analyst initiate next?

A.Containment
B.Analysis
C.Lessons learned
D.Eradication
AnswerB

Analysis follows detection: the analyst must validate the alert, scope the exfiltration, and determine impact before escalating. This phase satisfies the stem's need to confirm and understand the suspicious outbound traffic prior to containment or eradication.

Why this answer

The analyst has detected unusual outbound traffic indicating potential data exfiltration. According to the incident response process, after detection and initial validation, the next phase is analysis, where the analyst investigates the scope, impact, and nature of the incident. Containment (A) would come after analysis to prevent further damage.

Eradication (D) and lessons learned (C) are later phases. Therefore, the analyst should initiate analysis next.

Exam trap

The trap here is confusing the order of incident response phases; candidates might jump to containment because it seems urgent, but the exam expects adherence to the standard sequence where analysis precedes containment.

How to eliminate wrong answers

Option A is wrong because containment is a response action taken after the incident has been analyzed to prevent spread; initiating containment without analysis could be premature. Option C is wrong because lessons learned is a post-incident activity conducted after eradication and recovery. Option D is wrong because eradication involves removing the root cause and is performed after containment, which follows analysis.

44
Multi-Selectmedium

A security analyst is prioritizing incidents based on severity. Which TWO factors are most important for determining incident severity?

Select 2 answers
A.Sensitivity of the data potentially compromised
B.Type of operating system involved
C.Number of users affected
D.Time of day the incident occurred
E.Color of the server room
AnswersA, C

Sensitivity of the data potentially compromised directly determines severity because exposure of regulated, confidential or personal information raises legal, financial and reputational impact. It satisfies the prioritisation criterion by weighting potential harm, alongside factors such as affected system criticality.

Why this answer

Option A is correct because the sensitivity of the data potentially compromised directly drives severity: exposure of regulated or high-classification data (e.g., PII, PHI, cardholder data under PCI DSS, or trade secrets) raises the potential impact and therefore the incident's severity rating. Option C is correct because the number of users affected measures the scope and blast radius of the incident, and broader impact across more accounts or systems generally elevates severity. The type of operating system involved (B) is not a primary severity factor, since impact depends on the affected assets and data rather than the OS platform itself.

The time of day the incident occurred (D) is contextual and may influence response logistics but not the intrinsic severity. The color of the server room (E) is irrelevant to incident severity.

Exam trap

CC often tests whether candidates confuse contextual response factors (time of day, OS type) with true impact drivers (data sensitivity, user count) — only the latter determine severity.

45
MCQmedium

An organization experiences a ransomware attack that encrypts critical files. The incident response team follows the standard IR phases. After containing the infection and eradicating the malware, what is the next phase?

A.Detection
B.Preparation
C.Recovery
D.Lessons learned
AnswerC

Recovery restores encrypted systems and data to normal operation, satisfying the phase that follows eradication in the standard incident response lifecycle. It involves validating backups, rebuilding affected hosts, and confirming services function before returning them to production, directly addressing the stem's sequence after containment and eradication.

Why this answer

The standard incident response phases are Preparation, Detection and Analysis, Containment, Eradication, Recovery, and Lessons Learned. After containing the infection and eradicating the malware, the next phase is Recovery, where systems are restored to normal operation and validated before returning to production.

Exam trap

The trap here is confusing the order of phases, particularly placing Lessons Learned immediately after Eradication, when Recovery must occur first to restore operations before reviewing the incident.

How to eliminate wrong answers

Option A is wrong because Detection occurs before containment and eradication; it is the phase where the incident is identified. Option B is wrong because Preparation is the first phase, done before an incident occurs. Option D is wrong because Lessons Learned is the final phase, after recovery is complete; it involves reviewing the incident to improve future response.

46
Multi-Selecthard

During a security incident, the crisis communication team must notify stakeholders. According to best practices, which THREE groups should always be included in initial notifications? (Select THREE.)

Select 3 answers
A.Legal department
B.Internal management
C.Affected customers
D.Law enforcement
E.Public relations
AnswersA, B, E

Legal must be notified immediately because initial breach communications can create legal obligations and privilege considerations. Involving counsel early preserves attorney-client privilege over incident findings and ensures notifications meet regulatory and contractual duties, satisfying the stem's requirement that crisis communications follow established best practise during a live security incident.

Why this answer

Legal department (A) must be included in initial notifications because they assess regulatory and contractual breach-notification obligations, preserve legal privilege, and guide the organization on disclosure requirements that may carry statutory deadlines. Internal management (B) is essential because executives and incident-response leadership need immediate situational awareness to authorize containment actions, allocate resources, and make business-impact decisions. Public relations (E) belongs in the initial notification group because they control the organization's external messaging, prepare holding statements, and prevent inconsistent or damaging communications while facts are still being verified.

Affected customers (C) are typically notified only after the scope and impact are confirmed and legal/PR messaging is prepared, so they are not part of the initial internal notification wave. Law enforcement (D) is engaged selectively depending on the incident type, jurisdiction, and whether criminal activity or regulatory reporting mandates apply, so it is not always an initial notification recipient.

Exam trap

CC often tests the ordering of incident notifications — candidates incorrectly include affected customers or law enforcement in the 'initial' tier, when best practice places them in later, post-assessment tiers.

47
MCQmedium

A company’s backup strategy: Full backup every Sunday, differential backups Monday through Saturday. On Thursday, the system fails. How many backups are needed to restore the data?

A.Two: Sunday full and Thursday differential
B.One: Thursday differential only
C.Four: Monday through Thursday differentials
D.Five: Monday through Thursday differentials plus full
AnswerA

Restoring requires the Sunday full backup plus Thursday's differential, because differentials capture every change since that full. Wednesday's and earlier differentials are superseded, so only two sets are needed. This satisfies the stem's Thursday failure point, where the latest differential alone completes the chain.

Why this answer

With a full backup on Sunday and differential backups Monday through Saturday, a restore on Thursday requires the Sunday full backup and the most recent differential (Thursday). Differential backups capture all changes since the last full backup, so only the latest differential is needed along with the full.

Exam trap

The trap here is confusing differential and incremental backup restore requirements; candidates often think all daily backups are needed, but differential only requires the latest one plus the full.

How to eliminate wrong answers

Option B is wrong because a differential backup alone does not include the full backup data; you cannot restore from just a differential without the base full backup. Option C is wrong because differential backups are cumulative since the last full, so you do not need each day's differential; only the latest one is required. Option D is wrong because it describes the restore process for incremental backups (which require all incrementals since the last full), not differential backups.

48
MCQeasy

Which phase of the incident response process involves actions to stop the incident from causing further damage, such as isolating affected systems?

A.Eradication
B.Analysis
C.Containment
D.Detection
AnswerC

Containment limits an incident's spread by isolating affected systems, such as disconnecting compromised hosts from the network. This directly satisfies the stem's requirement to stop further damage, distinguishing it from eradication, which removes the threat's root cause after containment.

Why this answer

Containment is the incident response phase focused on limiting the scope and impact of an incident — isolating affected systems, disabling compromised accounts, and blocking malicious traffic to prevent further damage. It occurs after detection and analysis but before eradication and recovery. The goal is to stop the spread while preserving evidence for investigation.

Exam trap

The trap here is confusing containment with eradication — candidates often pick eradication because both 'stop the incident,' but containment limits spread while eradication removes the threat entirely.

How to eliminate wrong answers

Option A is wrong because eradication is the phase where the root cause (malware, backdoor, vulnerability) is removed from systems — it happens after containment, not as the initial damage-limiting step. Option B is wrong because analysis is the investigative phase where the scope and nature of the incident are determined, not the phase where systems are isolated. Option D is wrong because detection is the phase where the incident is first identified, preceding any response action.

49
MCQhard

During a data breach investigation, the incident response team discovers that personally identifiable information (PII) of EU residents was exfiltrated. Under GDPR, what is the maximum time frame for notifying the supervisory authority?

A.72 hours
B.7 days
C.48 hours
D.24 hours
AnswerA

72 hours is the maximum period under GDPR Article 33, running from awareness of the breach. This satisfies the stem's constraint: PII of EU residents was exfiltrated, triggering the controller's obligation to notify the supervisory authority without undue delay. Notification must occur within that window unless the breach is unlikely to result in risk.

Why this answer

GDPR requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.

50
MCQmedium

A hospital's electronic health record (EHR) system must be available 24/7. The disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour. Which combination of backup and site strategy best meets these objectives?

A.Cloud-based recovery with daily snapshots
B.Warm site with weekly full backups
C.Hot site with continuous data replication
D.Cold site with daily full backups
AnswerC

Continuous replication keeps the standby site within minutes of the primary, comfortably satisfying the one-hour RPO, while a hot site runs pre-provisioned infrastructure ready to take over well inside the four-hour RTO. For a 24/7 EHR, this pairing is the only one meeting both recovery objectives simultaneously.

Why this answer

A hot site with continuous data replication best meets an RTO of 4 hours and RPO of 1 hour because a hot site is a fully operational duplicate facility that can take over almost immediately, and continuous replication keeps data loss well under 1 hour. This combination provides the lowest recovery time and data loss, aligning with the hospital's 24/7 availability requirement.

Exam trap

CC often tests RTO/RPO by pairing them with site types — the trap is that candidates pick a cheaper site (warm/cold) that fails the strict RTO, or a backup frequency that fails the RPO.

How to eliminate wrong answers

Option A is wrong because daily snapshots yield an RPO of up to 24 hours, far exceeding the 1-hour RPO requirement, even if cloud recovery could meet the RTO. Option B is wrong because weekly full backups produce an RPO of up to 7 days, massively violating the 1-hour RPO, and a warm site may not meet the 4-hour RTO reliably. Option D is wrong because a cold site lacks pre-installed infrastructure and can take days to become operational, failing the 4-hour RTO, and daily full backups fail the 1-hour RPO.

51
MCQeasy

Which of the following best describes a Disaster Recovery Plan (DRP)?

A.A plan to restore IT systems after a disruption
B.A plan to evacuate personnel during an emergency
C.A plan to identify critical business functions
D.A plan to keep the business running during a disruption
AnswerA

A DRP documents the procedures, roles and resources for recovering IT systems and data after an outage, disaster or cyber incident. Restoring IT systems after a disruption captures its core purpose, distinguishing it from business continuity planning, which covers broader operations during the event.

Why this answer

A Disaster Recovery Plan (DRP) is specifically focused on restoring IT systems, applications, and data after a disruption — it defines recovery time objectives (RTO), recovery point objectives (RPO), backup restoration procedures, and failover steps. It is a subset of the broader Business Continuity Plan (BCP).

Exam trap

CC often tests the distinction between DRP (IT system recovery) and BCP (business operations continuity) — candidates frequently swap the two definitions.

How to eliminate wrong answers

Option B is wrong because personnel evacuation is covered by an Emergency Response Plan or Occupant Emergency Plan, not a DRP. Option C is wrong because identifying critical business functions is part of Business Impact Analysis (BIA), which feeds into both BCP and DRP but is not the DRP itself. Option D is wrong because keeping the business running during a disruption is the definition of a Business Continuity Plan (BCP), which is broader than and distinct from a DRP.

52
MCQeasy

Which of the following is a key component of the 3-2-1 backup rule?

A.Two copies on different media, one off-site
B.One copy on two different media, two off-site
C.Three copies on different media, two off-site
D.Three copies, two different media types, one off-site
AnswerD

Three copies of data, stored on two different media types, with one copy held off-site, directly satisfies the 3-2-1 rule's redundancy and geographic-separation constraints. The two-media requirement protects against media-specific failures, while the off-site copy survives local disasters affecting the primary and secondary copies.

Why this answer

The 3-2-1 backup rule specifies three copies of data (one primary plus two backups), stored on two different media types, with one copy kept off-site. Option D captures all three elements precisely, which is why it is the canonical definition used in CompTIA and vendor backup guidance.

Exam trap

The trap here is that candidates memorize '3-2-1' as a slogan without mapping each digit to its meaning, so they swap the '2 media' and '1 off-site' counts under time pressure.

How to eliminate wrong answers

Option A is wrong because it only accounts for two copies total and omits the requirement for three copies of data. Option B is wrong because it reverses the media and off-site counts — the rule requires two media types and one off-site copy, not one media type and two off-site copies. Option C is wrong because it states three copies on different media and two off-site, but the rule only requires one off-site copy, not two.

53
MCQhard

A company has a reciprocal agreement with another organization for disaster recovery. During a major outage, the company attempts to activate the agreement but finds that the partner's facility is also impacted by the same disaster. This scenario highlights a primary disadvantage of which recovery strategy?

A.Cold site
B.Warm site
C.Reciprocal agreement
D.Hot site
AnswerC

Reciprocal agreements depend on a partner's facility remaining available, so a single regional disaster can incapacitate both sites simultaneously. This shared-fate exposure is the strategy's core weakness, directly satisfying the stem's constraint that the partner's facility was impacted by the same outage, leaving no viable recovery location.

Why this answer

A reciprocal agreement is a DR arrangement where two organizations agree to host each other's workloads during a disaster, typically at no or low cost. The scenario shows the classic failure mode: a regional disaster affects both parties simultaneously, so the partner site is unavailable exactly when it is needed.

Exam trap

The trap is that candidates see 'agreement with another organization' and assume it is a hot site or a formal DR contract, missing that the question is testing the specific weakness of reciprocal agreements — correlated disaster exposure.

How to eliminate wrong answers

Option A is wrong because a cold site is a company-owned or leased facility with power and connectivity but no pre-installed hardware; it would not be 'the partner's facility' and its disadvantage is slow activation, not shared-disaster impact. Option B is wrong because a warm site is a partially equipped company facility, again not a partner's site, and its disadvantage is longer RTO than a hot site. Option D is wrong because a hot site is a fully equipped, often commercially leased facility with near-zero RTO; its disadvantage is cost, not mutual disaster exposure.

54
MCQeasy

A company is creating a business continuity plan. Which analysis should be performed first to identify critical business functions and their dependencies?

A.Vulnerability assessment
B.Business Impact Analysis (BIA)
C.Risk assessment
D.Gap analysis
AnswerB

The Business Impact Analysis is performed first, identifying critical business functions, their dependencies and tolerable downtime, which then inform recovery strategies and RTO/RPO targets. It satisfies the stem's requirement to identify functions and dependencies before plan creation.

Why this answer

A Business Impact Analysis (BIA) is the first step in BCP to identify critical functions, dependencies, and recovery requirements.

55
MCQmedium

An organization stores backup data on a tape drive (onsite) and also replicates critical data to a cloud storage service. This practice best exemplifies which backup rule?

A.Incremental backup strategy
B.Differential backup strategy
C.Full backup strategy
D.3-2-1 backup rule
AnswerD

The 3-2-1 rule requires three copies of data, on two different media types, with one copy held offsite. Tape and cloud storage satisfy the two-media requirement, while cloud replication provides the offsite copy, directly matching the stem's onsite tape plus cloud arrangement.

Why this answer

The 3-2-1 backup rule states that you should keep at least three copies of data, on two different media types, with one copy stored offsite. Storing backups on tape (onsite) plus replicating critical data to cloud storage satisfies the multiple-media and offsite requirements, making it the textbook example of the rule.

Exam trap

The trap here is confusing backup methods (full, incremental, differential) with the 3-2-1 rule, which is about copy count, media diversity, and offsite placement rather than how changes are captured.

How to eliminate wrong answers

Option A is wrong because incremental backup is a backup method that only captures changes since the last backup, not a rule about copy count, media, or location. Option B is wrong because differential backup captures changes since the last full backup — again a method, not the 3-2-1 principle. Option C is wrong because full backup copies all data every time; it describes a backup type, not the multi-copy/offsite strategy illustrated.

56
MCQeasy

An organization is preparing its Business Continuity Plan (BCP). Which process identifies critical business functions and the impact of disruptions?

A.Incident Response Plan (IRP)
B.Disaster Recovery Plan (DRP)
C.Risk Assessment
D.Business Impact Analysis (BIA)
AnswerD

A Business Impact Analysis identifies critical business functions and quantifies the operational and financial impact of their disruption, plus dependencies and recovery priorities. It is the BCP process that satisfies the stem's requirement to identify functions and disruption impact.

Why this answer

A Business Impact Analysis (BIA) identifies critical business functions, dependencies, and the impact of disruptions, providing metrics like MTD, RTO, and RPO.

57
MCQhard

A company follows the 3-2-1 backup rule. It has two full backups: one on an external hard drive in the server room and one on tape in a safe on-site. Which step should be taken to fully comply with the rule?

A.No action needed; the rule is satisfied
B.Store the tape copy in a secure offsite location
C.Use cloud storage as an additional copy
D.Add a third copy to the external hard drive
AnswerB

Storing the tape copy offsite satisfies the 3-2-1 rule's requirement for one copy at a separate geographic location, protecting against site-wide disasters such as fire or flood. The external hard drive and on-site tape already provide three copies across two media types, so only geographic separation remains outstanding.

Why this answer

The 3-2-1 rule requires three copies of data (including the original), stored on at least two different media types, with at least one copy stored offsite. Currently, the company has the original data plus two backups (external HDD and tape) — three copies total — but both backups are on-site. To fully comply, one of the backup copies must be moved to an offsite location.

Option B, storing the tape copy offsite, satisfies the '1 offsite' requirement.

58
MCQhard

A financial institution requires near-instantaneous recovery of its trading platform after a disaster. The recovery time objective (RTO) is 2 hours, and the recovery point objective (RPO) is 15 minutes. Which recovery site strategy best meets these requirements?

A.Reciprocal agreement
B.Warm site
C.Cold site
D.Hot site
AnswerD

A hot site provides a fully mirrored, continuously replicated environment, enabling activation well within the two-hour RTO while keeping data loss inside the fifteen-minute RPO. Warm and cold sites cannot meet such aggressive recovery targets.

Why this answer

A hot site is a fully operational duplicate of the primary data center with real-time or near-real-time data replication, allowing recovery within minutes. It is the only strategy that can meet an RTO of 2 hours and an RPO of 15 minutes for a trading platform. Hot sites are expensive but necessary for near-instantaneous recovery.

Exam trap

The trap is assuming a warm site is 'good enough' because it has some equipment; candidates must map the stated RTO/RPO to the site type that can actually meet those numbers.

How to eliminate wrong answers

Option A is wrong because a reciprocal agreement relies on another organization's facilities and is not guaranteed available, typically yielding recovery in days, far exceeding a 2-hour RTO. Option B is wrong because a warm site has hardware and some data but requires configuration and restoration, usually taking hours to days, which cannot meet a 15-minute RPO. Option C is wrong because a cold site is an empty facility with power and cooling but no equipment, requiring days or weeks to restore, the slowest option.

59
MCQhard

A company’s disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour for its critical database. The database is backed up every hour using incremental backups. After a catastrophic failure, restoration takes 3 hours, but the database must be rolled forward using transaction logs. The total time to make the database fully operational is 5 hours. Which statement is correct?

A.Both RTO and RPO are exceeded
B.RPO is exceeded but RTO is met
C.Both RTO and RPO are met
D.RTO is exceeded but RPO is likely met
AnswerD

Total recovery of five hours exceeds the four-hour RTO, so that target is breached. Hourly incremental backups with transaction-log rollforward cap data loss near one hour, so the one-hour RPO is likely satisfied despite the overrun.

Why this answer

The RTO is 4 hours, but the total time to make the database fully operational is 5 hours, so RTO is exceeded. The RPO is 1 hour, and backups are taken every hour; the data loss is at most 1 hour of transactions, so RPO is likely met. Therefore, RTO is exceeded but RPO is likely met.

Exam trap

CC often tests the distinction between RTO and RPO, and candidates may incorrectly assume that restoration time alone defines RTO, ignoring additional steps like transaction log roll-forward.

How to eliminate wrong answers

Option A is wrong because RPO is not exceeded; the hourly backups meet the 1-hour RPO. Option B is wrong because RTO is exceeded, not met. Option C is wrong because RTO is exceeded, so both cannot be met.

60
MCQeasy

Which incident category involves an attacker tricking an employee into revealing credentials?

A.Data breach
B.Social engineering
C.Malware
D.Denial of service
AnswerB

Social engineering manipulates human trust rather than exploiting software flaws, using phishing, pretexting or impersonation to persuade an employee to hand over credentials. The attacker targets the person, not the system, which is the defining characteristic of this incident category.

Why this answer

Social engineering is the incident category that involves manipulating people into divulging confidential information, such as credentials. Attackers use psychological tactics like phishing, pretexting, or baiting to trick employees into revealing passwords or other sensitive data.

Exam trap

The trap here is conflating the attack method (social engineering) with its potential outcome (data breach); candidates may choose data breach because credentials were revealed, but the question asks for the incident category of the trickery itself.

How to eliminate wrong answers

Option A is wrong because a data breach is the outcome of unauthorized data access, not the method of tricking an employee; social engineering can lead to a data breach, but the category here is the attack technique. Option C is wrong because malware is malicious software, not a human manipulation tactic. Option D is wrong because denial of service disrupts availability, not credential theft through deception.

61
MCQhard

During a disaster recovery test, an organization uses a warm site. The site has partially configured servers and network infrastructure but lacks recent data. The recovery team expects to have the system operational within 2 days. Which recovery metric is most directly addressed by the warm site's capabilities?

A.Recovery Point Objective (RPO)
B.Recovery Time Objective (RTO)
C.Maximum Tolerable Downtime (MTD)
D.Work Recovery Time (WRT)
AnswerB

A warm site provides partially configured infrastructure, enabling systems to be operational within roughly two days. That timeframe directly defines the Recovery Time Objective, the maximum acceptable downtime, rather than data loss measured by RPO.

Why this answer

A warm site with partially configured servers and network infrastructure but lacking recent data is designed to bring systems online within a defined timeframe — in this case, 2 days. That timeframe is the Recovery Time Objective (RTO), which specifies the maximum acceptable time to restore operations after a disruption. The warm site's capabilities directly address how quickly recovery can occur, making RTO the metric most directly addressed.

Exam trap

The trap here is confusing RTO with RPO — candidates see 'lacks recent data' and jump to RPO, but the question emphasizes the 2-day operational timeframe, which is squarely an RTO concern.

How to eliminate wrong answers

Option A is wrong because RPO (Recovery Point Objective) defines the maximum acceptable amount of data loss measured in time — it relates to backup frequency and data currency, not how quickly systems can be brought back online. The warm site's lack of recent data actually highlights an RPO gap, but the question asks about the recovery timeframe. Option C is wrong because MTD (Maximum Tolerable Downtime) is the total time a business can survive a disruption before unacceptable consequences occur — it is a business-level constraint that encompasses both RTO and WRT, not a metric directly satisfied by the warm site's 2-day capability.

Option D is wrong because WRT (Work Recovery Time) is the time needed after systems are restored to verify data integrity and resume business processes — it is a component of MTD, not the primary metric addressed by the site's infrastructure readiness.

62
Multi-Selecthard

An organization experiences a data breach involving personally identifiable information (PII) of European Union residents. According to GDPR, which THREE of the following are required actions?

Select 3 answers
A.Document the breach, its effects, and the remedial actions taken.
B.Restore all affected systems from the latest full backup.
C.Communicate the breach to affected data subjects without undue delay if it poses a risk to their rights and freedoms.
D.Conduct a Business Impact Analysis (BIA) to determine the financial impact.
E.Notify the relevant supervisory authority within 72 hours of becoming aware of the breach.
AnswersA, C, E

GDPR Article 33(5) requires controllers to document all breaches, including the facts, effects and remedial action taken. This record-keeping duty applies regardless of whether the breach is notifiable, satisfying the stem's requirement for a mandatory action following the PII incident.

Why this answer

Option A is correct because GDPR Article 33(5) requires the controller to document all personal data breaches, including the facts, effects, and remedial actions taken, so the supervisory authority can verify compliance. Option C is correct because GDPR Articles 33(1) and 34(1) require communication to affected data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms. Option E is correct because GDPR Article 33(1) mandates notifying the relevant supervisory authority within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk.

Option B is not a GDPR requirement; restoring from backup is a general recovery practice, not a breach-notification obligation. Option D is not required by GDPR; a BIA is a business continuity tool, whereas GDPR requires a Data Protection Impact Assessment (DPIA) in certain cases, not a BIA for breach response.

Exam trap

The trap here is mixing general IT/BCP practices (backup restore, BIA) with GDPR-specific legal obligations — candidates who are strong in IT operations may pick B or D, but the exam expects the three explicit GDPR articles: 33(5) documentation, 34 communication, and 33(1) 72-hour notification.

63
Multi-Selectmedium

An organization is developing an incident response plan. Which TWO phases are part of the incident response lifecycle according to the NIST framework? (Select two.)

Select 2 answers
A.Preparation
B.Business impact analysis
C.Recovery
D.Risk assessment
E.Vulnerability scanning
AnswersA, C

Preparation establishes the capabilities required before an incident occurs, including incident response policy, tooling, communications plans and trained personnel. NIST SP 800-61 places Preparation as the first lifecycle phase, directly satisfying the stem's requirement for a framework-defined phase that precedes detection and analysis, containment, eradication, recovery and post-incident activity.

Why this answer

Option A (Preparation) is correct because the NIST SP 800-61 incident response lifecycle begins with the Preparation phase, which covers establishing an IR capability, acquiring tools and resources, and developing policies and procedures before an incident occurs. Option C (Recovery) is correct because NIST defines Recovery as the phase in which systems are restored to normal operation, data is validated, and lessons learned are captured after containment and eradication. The other options do not belong: Business impact analysis (B) is part of business continuity planning, Risk assessment (D) is a risk management activity, and Vulnerability scanning (E) is a technical security control, none of which are named phases of the NIST incident response lifecycle.

Exam trap

The trap is that BIA and Risk Assessment sound like security lifecycle activities, so candidates pick them — but the exam is asking specifically for NIST SP 800-61 IR phases, not general security management activities.

64
Multi-Selecthard

A security team is developing an incident response plan. Which THREE of the following are essential components of crisis communications during a data breach? (Choose three.)

Select 3 answers
A.Notifying affected customers
B.Revealing technical details of the attack to the public
C.Complying with regulatory notification requirements
D.Informing the organization's executive management
E.Deleting all logs to prevent evidence leakage
AnswersA, C, D

Notifying affected customers is a core crisis communication duty, ensuring individuals can take protective action against identity theft or fraud. It satisfies the stem's requirement for essential breach communication components, complementing regulatory notification and executive briefing.

Why this answer

Option A (Notifying affected customers) is correct because crisis communications during a data breach must include timely, clear notification to the individuals whose personal data was compromised, enabling them to take protective steps such as changing passwords or monitoring accounts. Option C (Complying with regulatory notification requirements) is correct because laws and regulations such as GDPR, HIPAA, and state breach-notification statutes mandate specific disclosures to regulators and affected parties within defined timeframes, making compliance a core communications obligation. Option D (Informing the organization's executive management) is correct because executives need accurate, prompt situational awareness to authorize response actions, allocate resources, and serve as the organization's authoritative voice internally and externally.

Option B is not correct because publicly revealing technical attack details can expose unpatched vulnerabilities, aid attackers, and jeopardize ongoing forensic investigations. Option E is not correct because deleting logs destroys evidence, violates legal hold and retention obligations, and would obstruct incident response and regulatory compliance.

65
Multi-Selecthard

A multinational corporation is reviewing its incident response plan after a recent data breach. The security team wants to ensure that during future incidents, evidence is properly preserved for potential legal action. Which TWO actions should be included in the incident response plan to support forensic readiness? (Choose two.)

Select 2 answers
A.Establish a chain of custody for all collected evidence.
B.Allow only senior management to access the incident response plan.
C.Immediately shut down all affected systems to prevent further data loss.
D.Delete all logs after 30 days to reduce storage costs.
E.Conduct regular training for incident responders on evidence handling procedures.
AnswersA, E

A chain of custody documents who handled evidence, when, and why, ensuring its integrity and admissibility in legal proceedings. For a multinational corporation, this is essential to prove that digital evidence from the breach was not tampered with. It should be part of the incident response plan so that responders know how to label, store, and transfer evidence properly from the moment it is collected.

Why this answer

Forensic readiness requires that evidence be preserved in a way that is admissible in legal proceedings. Establishing a chain of custody ensures evidence integrity, and training responders on evidence handling ensures that procedures are followed correctly. Together, these actions help a multinational corporation maintain credible evidence for potential litigation or regulatory investigations.

Exam trap

The trap here is assuming that immediate shutdown is a good containment step, when it actually destroys volatile evidence and undermines forensic readiness.

66
Multi-Selectmedium

An organization is evaluating recovery site options. Which TWO factors are most critical when selecting between a hot site and a warm site? (Select TWO.)

Select 2 answers
A.Cost
B.Geographic diversity
C.Number of employees
D.Recovery time objective (RTO)
E.Regulatory compliance
AnswersA, D

Hot sites duplicate production with live data and near-instant failover, while warm sites hold hardware without current data; that capability gap drives the substantial cost difference. Cost is therefore a decisive factor when choosing between the two.

Why this answer

Option A (Cost) is correct because a hot site is fully equipped with duplicate hardware, live data replication, and staff ready to take over almost instantly, making it far more expensive to build and maintain than a warm site, which has hardware but requires data restoration and configuration—so budget is a primary decision factor between the two. Option D (Recovery time objective, RTO) is correct because the RTO defines the maximum tolerable downtime, and a hot site typically delivers near-zero to minutes of recovery while a warm site may take hours or days; the required RTO therefore directly dictates which site type is appropriate. Geographic diversity (B) matters for any alternate site to avoid a shared disaster, but it does not distinguish a hot site from a warm site.

The number of employees (C) affects capacity sizing and seat counts but is not the deciding factor between hot and warm configurations. Regulatory compliance (E) imposes requirements on the overall DR strategy but does not by itself determine whether a hot or warm site is chosen.

Exam trap

CC often tests the cost-versus-RTO trade-off for recovery sites — candidates are drawn to plausible distractors like 'geographic diversity' or 'regulatory compliance', which apply to all tiers and do not distinguish hot from warm.

67
MCQeasy

Which phase of the incident response process involves restoring systems to normal operations and confirming they are functioning correctly?

A.Recovery
B.Detection
C.Containment
D.Eradication
AnswerA

Recovery restores affected systems to normal operations and verifies they function correctly, directly satisfying the stem's requirement. Unlike eradication, which removes the threat, or lessons learned, which reviews the incident afterwards, recovery focuses on validated restoration. It confirms services are operational before returning to normal business activity.

Why this answer

Recovery is the phase after eradication where systems are restored and tested.

68
MCQhard

During an incident, a security analyst detects unusual network traffic from a workstation that is exfiltrating data to an external IP address. The analyst isolates the workstation. Which incident response phase does the isolation action belong to?

A.Detection
B.Analysis
C.Containment
D.Eradication
AnswerC

Containment limits the scope and spread of an incident once detected. Isolating the workstation stops further data exfiltration to the external IP address and prevents lateral movement, while preserving evidence for the later eradication and recovery phases.

Why this answer

Isolation of an affected workstation is a containment action because it stops the spread of the incident and prevents further data exfiltration while the investigation continues. Containment is the phase in the NIST/SANS incident response lifecycle (Preparation, Detection & Analysis, Containment, Eradication, Recovery, Post-Incident) where the goal is to limit damage and prevent the incident from expanding. Detection and analysis involve identifying and validating the event; eradication removes the root cause.

Exam trap

The trap here is confusing Containment with Eradication — candidates see 'isolate the workstation' and think of removing the threat, but isolation only limits spread; removal of the root cause is Eradication.

How to eliminate wrong answers

Option A is wrong because Detection is the phase where the analyst first identifies the unusual traffic — it precedes any response action. Option B is wrong because Analysis is where the analyst investigates and scopes the incident (e.g., determining what data was exfiltrated), not where the workstation is isolated. Option D is wrong because Eradication involves removing malware, closing the attack vector, and remediating the root cause — it happens after containment, not at the moment of isolation.

69
Multi-Selecthard

A company is selecting a recovery site strategy. They need to balance cost and recovery time. Which THREE factors should they consider when choosing between hot, warm, and cold sites? (Select three.)

Select 3 answers
A.Geographic diversity
B.Vendor lock-in risks
C.Cost of the facility and equipment
D.Recovery time objective (RTO)
E.Data synchronization capabilities
AnswersC, D, E

Hot sites duplicate all infrastructure with real-time replication, warm sites keep scaled-down hardware ready, and cold sites provide only space and power. Facility and equipment cost rises sharply across that spectrum, directly satisfying the stem's requirement to balance cost against recovery time when selecting a strategy.

Why this answer

Option C is correct because the cost of the facility and equipment is the primary differentiator among hot, warm, and cold sites: a hot site duplicates all hardware and is fully operational (highest cost), a warm site has partial infrastructure and some pre-installed equipment (moderate cost), and a cold site provides only basic space and power (lowest cost), so this factor directly addresses the stated need to balance cost. Option D is correct because the recovery time objective (RTO) determines how quickly operations must be restored, and the site type must match that target: hot sites deliver near-zero RTO, warm sites typically hours to days, and cold sites days to weeks, making RTO the key recovery-time factor in the decision. Option E is correct because data synchronization capabilities differ by site type and affect both recovery point objective (RPO) and readiness: hot sites require real-time replication or mirroring, warm sites may use periodic backups or asynchronous replication, and cold sites rely on restoring from offsite backups, so synchronization directly influences the cost-versus-recovery-time tradeoff.

Option A is not among the marked answers because geographic diversity is a general resilience and site-separation consideration that applies regardless of whether the site is hot, warm, or cold, and it is not the factor that distinguishes these three strategies. Option B is not among the marked answers because vendor lock-in risk concerns procurement and portability of technology choices, not the cost-versus-recovery-time characteristics that define hot, warm, and cold site selection.

Exam trap

The trap here is confusing site-selection criteria (geographic diversity, vendor risk) with tier-selection criteria (cost, RTO, data sync), causing candidates to pick plausible-sounding but category-mismatched options.

70
MCQeasy

Which backup method copies all data that has changed since the last full backup, regardless of subsequent incremental or differential backups?

A.Full backup
B.Synthetic full backup
C.Differential backup
D.Incremental backup
AnswerC

A differential backup captures every change made since the last full backup, accumulating data across days regardless of intervening backups. Incremental backups instead capture only changes since the previous backup of any type, so they fail the stem's "since the last full backup" constraint.

Why this answer

A differential backup captures all data changed since the last full backup, so each successive differential grows larger until the next full backup resets the baseline. This differs from an incremental backup, which only captures changes since the last backup of any type. The key characteristic in the question — 'regardless of subsequent incremental or differential backups' — matches the differential model, where the reference point remains the last full backup.

Exam trap

The trap is the wording 'since the last full backup' — candidates often pick Incremental, but incrementals reset their baseline after every backup, while differentials always reference the last full.

How to eliminate wrong answers

Option A is wrong because a Full backup copies all data every time, not just changes since the last full backup. Option B is wrong because a Synthetic full backup is constructed by combining a full backup with subsequent incremental backups on the backup server, not a method that copies changes since the last full backup. Option D is wrong because an Incremental backup copies only data changed since the most recent backup (full or incremental), so its baseline shifts with each run rather than staying anchored to the last full.

71
Multi-Selectmedium

A financial services company is conducting a Business Impact Analysis (BIA) for its online banking platform. Which THREE of the following are correctly defined metrics used in BIA?

Select 3 answers
A.Service Level Agreement (SLA) – the contractual uptime percentage guaranteed to customers.
B.Recovery Time Objective (RTO) – the maximum amount of time to restore a business function after a disruption.
C.Maximum Tolerable Downtime (MTD) – the total time a business function can be unavailable before causing irreparable harm.
D.Annualized Loss Expectancy (ALE) – the expected monetary loss per year from a risk.
E.Recovery Point Objective (RPO) – the maximum acceptable amount of data loss measured in time.
AnswersB, C, E

RTO defines the maximum tolerable downtime before a business function's disruption causes unacceptable impact, so it correctly bounds restoration time for the online banking platform. This matches the BIA metric definition, distinct from RPO, which measures tolerable data loss rather than recovery duration.

Why this answer

Option B is correct because the Recovery Time Objective (RTO) is a core BIA metric defining the maximum acceptable time to restore a business function or process after a disruption before unacceptable consequences occur. Option C is correct because the Maximum Tolerable Downtime (MTD), also called Maximum Acceptable Outage (MAO), defines the total time a business function can be unavailable before causing irreparable harm to the organization, and it typically bounds the RTO. Option E is correct because the Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time, determining the required backup or replication frequency.

Option A is not a BIA metric but a contractual service commitment, and Option D is a risk-analysis quantitative value (SLE × ARO) rather than a BIA recovery metric.

Exam trap

The trap is mixing risk-analysis metrics (ALE, SLE, ARO) with BIA recovery metrics (RTO, RPO, MTD) — candidates see 'metric' and pick ALE because it sounds quantitative and important.

72
Multi-Selecthard

After a major power outage, an organization needs to declare a disaster and activate its DRP. Which THREE elements should be included in the initial crisis communication?

Select 3 answers
A.A statement that a disaster has been declared
B.Details of the vulnerability exploited
C.Contact information for the incident response team
D.Instructions for employees to work remotely
E.Names of affected customers
AnswersA, C, D

The initial crisis communication must formally announce that a disaster has been declared, triggering DRP activation and mobilising response teams. Without this declaration, staff and stakeholders lack the authoritative signal that normal operations are suspended and recovery procedures now govern.

Why this answer

Option A is correct because the initial crisis communication must explicitly state that a disaster has been declared, which formally triggers the DRP and informs stakeholders that recovery procedures are now in effect. Option C is correct because providing contact information for the incident response team ensures that responders and key personnel can be reached immediately to coordinate recovery activities. Option D is correct because instructing employees to work remotely helps maintain business continuity and safety by directing staff away from potentially affected facilities.

Option B is not included because details of the exploited vulnerability are typically investigated and disclosed later by security or forensic teams, not in the initial crisis notification. Option E is also not included because naming affected customers raises privacy and legal concerns and is not part of the immediate internal crisis communication.

Exam trap

CC often tests the boundaries of what should be included in initial crisis communication, and candidates may incorrectly include technical details or customer information, confusing the need for transparency with the need for confidentiality and security.

73
MCQeasy

During which phase of the incident response process would the team identify the root cause of a security incident?

A.Eradication
B.Preparation
C.Analysis
D.Detection
AnswerC

Analysis is the phase where investigators examine evidence to determine how the incident occurred, establishing root cause and scope. This directly satisfies the stem's requirement to identify root cause, distinguishing it from containment or eradication, which address the incident itself rather than understanding its origin.

Why this answer

The Analysis phase (also called Investigation) is where the incident response team examines all available data—logs, memory dumps, network captures—to determine how the incident occurred, what systems were affected, and the root cause. This phase follows Detection and precedes Eradication. Identifying the root cause is essential to ensure the same vulnerability isn't exploited again after containment and recovery.

Exam trap

The trap here is confusing the Analysis phase with Eradication, because many candidates think root cause is identified while removing the threat; however, eradication is purely about elimination, and analysis must precede it.

How to eliminate wrong answers

Option A is wrong because Eradication focuses on removing the threat (e.g., deleting malware, patching vulnerabilities) after the root cause has already been identified during Analysis. Option B is wrong because Preparation involves establishing policies, tools, and training before an incident occurs; no root cause analysis happens here. Option D is wrong because Detection is the phase where the incident is first discovered and confirmed, not where in-depth root cause investigation takes place.

74
MCQmedium

A company's Business Impact Analysis (BIA) determines that its online payment system can tolerate a maximum of 2 hours of downtime. The IT team estimates that restoring the system from backups will take 1 hour, and the team needs another 30 minutes to verify data integrity and resume normal operations. Which metric does the 30-minute verification period represent?

A.Recovery Point Objective (RPO)
B.Work Recovery Time (WRT)
C.Maximum Tolerable Downtime (MTD)
D.Recovery Time Objective (RTO)
AnswerB

WRT is the time needed after systems are restored to verify data integrity and resume normal operations. The 30-minute verification period fits this definition, sitting separately from the 1-hour recovery time within the 2-hour tolerance.

Why this answer

The 30-minute verification period represents Work Recovery Time (WRT), which is the time needed after systems are technically restored to validate data integrity and confirm normal operations can resume. WRT is distinct from RTO because RTO covers only the time to bring systems back online, while WRT accounts for the post-recovery validation phase. Together, RTO + WRT must fit within the Maximum Tolerable Downtime (MTD) of 2 hours, which in this case is satisfied (1 hour RTO + 30 min WRT = 1.5 hours).

Exam trap

The trap here is confusing WRT with RTO — candidates see 'time to restore' and 'time to verify' and lump them together, but the exam specifically tests whether you know WRT is the post-restoration validation phase that sits between RTO completion and full business resumption.

How to eliminate wrong answers

Option A is wrong because RPO defines the maximum acceptable data loss measured in time (how far back the last good backup can be), not the verification period after restoration. Option C is wrong because MTD is the total maximum time the business can tolerate the system being unavailable (2 hours here), which encompasses both RTO and WRT rather than representing just the verification window. Option D is wrong because RTO is the target time to restore the system from backups (1 hour here), not the additional time needed to verify data integrity and resume normal operations.

75
MCQmedium

A regional hospital's emergency department relies on a patient tracking system. The BIA shows the system's maximum tolerable downtime (MTD) is 2 hours. The recovery time objective (RTO) is currently 6 hours, and the recovery point objective (RPO) is 24 hours. Which action best aligns the recovery capability with the business requirement?

A.Increase the MTD to 6 hours so it matches the existing RTO.
B.Implement a hot site that can recover the system within 24 hours, matching the RPO.
C.Reduce the RTO to 2 hours or less and reduce the RPO to a level that meets clinical data loss tolerance.
D.Maintain the current RTO and RPO because the MTD is only a guideline and not a strict requirement.
AnswerC

The MTD of 2 hours is the absolute limit the hospital can tolerate without unacceptable patient safety risk. The RTO must be less than or equal to the MTD to ensure recovery occurs within that window. Additionally, the RPO must be reviewed to ensure the acceptable data loss aligns with clinical needs, because a 24-hour RPO could mean losing a full day of patient records. This option directly addresses both the time to recover and the data loss tolerance.

Why this answer

The MTD is the maximum time a business process can be unavailable. For the patient tracking system, the MTD is 2 hours. The RTO, which is the target time to restore the system, must be less than or equal to the MTD.

The current RTO of 6 hours exceeds the MTD, so it must be reduced. The RPO must also be evaluated to ensure data loss is acceptable. Reducing the RTO and reassessing the RPO ensures recovery aligns with the business requirement.

Exam trap

The trap here is confusing the MTD with the RTO, or assuming the MTD can be changed to match an existing RTO, when the MTD is a fixed business requirement.

Page 1 of 2 · 83 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Business Continuity, Disaster Recovery, and Incident Response questions.