Courseiva

CCNA Business Continuity, Disaster Recovery, and Incident Response Questions

8 of 83 questions · Page 2/2 · Business Continuity, Disaster Recovery, and Incident Response · Answers revealed

76
MCQmedium

A company uses a backup strategy where on Monday a full backup is taken, and on Tuesday only data changed since Monday is backed up. On Wednesday, the backup includes all data changed since Monday. What type of backup is the Wednesday backup?

A.Incremental backup
B.Synthetic full backup
C.Full backup
D.Differential backup
AnswerD

A differential backup captures all data changed since the last full backup, not since the previous incremental. Wednesday's backup therefore includes Monday's and Tuesday's changes, satisfying the stem's constraint that it contains everything modified since Monday's full backup.

Why this answer

A differential backup captures all data changed since the last full backup, regardless of how many incremental or differential backups have occurred since. Since Monday's full backup is the baseline and Wednesday's backup includes everything changed since Monday, it is a differential backup. It does not reset the baseline, so Thursday's differential would also include Tuesday's and Wednesday's changes.

Exam trap

The trap here is confusing 'changed since the last backup' (incremental) with 'changed since the last full backup' (differential) — the phrase 'since Monday' is the giveaway.

How to eliminate wrong answers

Option A is wrong because an incremental backup only captures changes since the last backup of any type (full or incremental); Wednesday's incremental would only contain Tuesday-to-Wednesday changes, not everything since Monday. Option B is wrong because a synthetic full backup is constructed by combining a previous full with subsequent incrementals on the backup server — it does not describe a client-side changed-since-full capture. Option C is wrong because a full backup copies all data, not just data changed since Monday; the scenario explicitly limits scope to changed data.

77
MCQeasy

Which type of recovery site is pre-configured with hardware and software, but does not have live data, typically requiring days to become operational?

A.Warm site
B.Cloud-based recovery
C.Cold site
D.Hot site
AnswerA

A warm site ships with installed hardware and software but lacks replicated live data, so it needs days of configuration and data restoration before production use. That places it between a cold site and a hot site.

Why this answer

A warm site is a recovery facility that is pre-configured with hardware, software, and network connectivity but lacks live, up-to-date data, so it typically takes days to become fully operational after data restoration and configuration. This matches the question's description exactly. Warm sites balance cost and recovery speed between cold and hot sites.

Exam trap

The trap is confusing warm and cold sites — candidates pick cold because 'no live data' sounds cold, but cold sites also lack hardware and software, while warm sites have them pre-installed.

How to eliminate wrong answers

Option B is wrong because cloud-based recovery is a broad category, not a specific site tier, and modern cloud DR can often be provisioned in hours, not days — it does not fit the 'pre-configured but no live data' definition. Option C is wrong because a cold site has only basic infrastructure (power, cooling, space) with no pre-installed hardware or software, requiring weeks to become operational. Option D is wrong because a hot site is fully mirrored with live data and can take over within minutes to hours, not days.

78
MCQeasy

Which recovery site strategy provides the fastest recovery time, typically within hours, and is a fully mirrored environment ready to take over operations immediately?

A.Reciprocal agreement
B.Hot site
C.Warm site
D.Cold site
AnswerB

A hot site maintains a fully mirrored, continuously synchronised replica of production infrastructure, including live data replication and pre-configured compute. This satisfies the stem's requirement for recovery within hours, since failover needs only traffic redirection rather than hardware provisioning or data restoration, unlike warm or cold alternatives.

Why this answer

A hot site is a fully mirrored recovery facility with live, synchronized data and duplicate hardware, software, and network infrastructure, enabling failover within minutes to hours. It provides the fastest recovery time among traditional site strategies and is ready to take over operations immediately. This matches the question's description of a fully mirrored, immediately available environment.

Exam trap

The trap is confusing hot and warm sites — candidates pick warm because it sounds 'ready,' but only a hot site has live data and can take over within minutes, while warm sites need days.

How to eliminate wrong answers

Option A is wrong because a reciprocal agreement is an arrangement where two organizations agree to share each other's facilities in a disaster — it is informal, untested, and typically slow, with no guarantee of availability. Option C is wrong because a warm site has hardware and software but no live data, requiring days to become operational. Option D is wrong because a cold site has only basic infrastructure and no pre-installed systems, requiring weeks to become operational.

79
Multi-Selecteasy

An organization experiences a denial-of-service (DoS) attack. Which TWO actions should the incident response team take during the containment phase? (Select two.)

Select 2 answers
A.Disconnect affected servers from the network
B.Filter malicious traffic at the firewall
C.Restore systems from backup
D.Notify law enforcement
E.Conduct a root cause analysis
AnswersA, B

Disconnecting affected servers from the network severs the attacker's path and halts ongoing traffic, preventing further damage or lateral movement. This isolation contains the DoS while preserving evidence, satisfying the containment phase before eradication and recovery begin.

Why this answer

Option A is correct because disconnecting the affected servers from the network immediately stops the flood of attack traffic from reaching those hosts, preventing further resource exhaustion and limiting the blast radius during containment. Option B is correct because filtering malicious traffic at the firewall (e.g., blocking offending source IPs, rate-limiting, or applying ACLs) mitigates the DoS at the network perimeter while keeping legitimate services reachable, which is a standard containment technique. Option C is not a containment action; restoring from backup is part of eradication and recovery, performed after the threat is removed.

Option D is not a containment step; notifying law enforcement is an external communication/coordination activity that may occur later. Option E is not containment; root cause analysis is a post-incident activity conducted after the incident is resolved.

Exam trap

CC often tests the phase boundaries — candidates pick 'restore from backup' or 'root cause analysis' because they sound like response actions, but those belong to recovery and post-incident phases, not containment.

80
MCQhard

During a disaster, an organization activates a reciprocal agreement with another company. What is a primary risk associated with this strategy?

A.Potential lack of capacity when both parties need resources simultaneously
B.Long RTO due to data transfer
C.High cost of maintaining duplicate infrastructure
D.Incompatible hardware
AnswerA

Reciprocal agreements share another organisation's standby facilities, so simultaneous disasters create contention for the same equipment, workspace and processing capacity. This resource-contention risk is the primary weakness distinguishing reciprocal agreements from dedicated alternate sites or commercial hot sites.

Why this answer

A reciprocal agreement (also called a mutual aid pact) is a disaster recovery arrangement where two organizations agree to share each other's computing facilities in an emergency. The primary risk is that a disaster may affect both parties simultaneously—such as a regional event like a hurricane, earthquake, or widespread power outage—leaving neither with spare capacity to host the other's workloads. Because neither party maintains dedicated redundant resources for the other, resource contention during a shared crisis is the defining weakness of this strategy.

Exam trap

The trap here is confusing the primary risk of a reciprocal agreement with the drawbacks of other DR strategies—candidates often pick 'high cost' (which actually describes hot sites) or 'long RTO' (which describes cold sites), missing that the unique weakness of reciprocity is simultaneous demand from both parties.

How to eliminate wrong answers

Option B is wrong because reciprocal agreements typically involve pre-staged or quickly shippable resources and do not inherently impose a long RTO due to data transfer—data transfer time depends on bandwidth and data volume, not on the agreement type itself. Option C is wrong because the entire appeal of a reciprocal agreement is that it avoids the high cost of maintaining duplicate infrastructure; that cost is a drawback of a hot site or redundant data center, not of reciprocity. Option D is wrong because incompatible hardware is a general risk of any shared or outsourced recovery arrangement and is not the primary, defining risk unique to reciprocal agreements; compatibility can be addressed contractually and technically, whereas simultaneous demand cannot.

81
MCQhard

An organization's BIA determines that the payroll system has a Maximum Tolerable Downtime (MTD) of 4 hours. The current recovery plan has an RTO of 2 hours and an RPO of 1 hour. What is the maximum Work Recovery Time (WRT) allowed to meet the MTD?

A.2 hours
B.3 hours
C.4 hours
D.1 hour
AnswerA

MTD equals RTO plus WRT. With an MTD of 4 hours and an RTO of 2 hours, the remaining allowance for work recovery is 2 hours. RPO governs data loss, not this calculation, so it does not affect the result.

Why this answer

The Maximum Tolerable Downtime (MTD) is the total time a business process can be unavailable. It is composed of the Recovery Time Objective (RTO) plus the Work Recovery Time (WRT). Given MTD = 4 hours and RTO = 2 hours, WRT = MTD - RTO = 2 hours.

Exam trap

The trap is confusing RTO and WRT, or forgetting that MTD includes both, leading to selecting RTO or MTD directly.

How to eliminate wrong answers

Option B is wrong because 3 hours would exceed the MTD when added to RTO (2+3=5 > 4). Option C is wrong because 4 hours would equal the MTD, leaving no time for recovery, and WRT must be less than MTD. Option D is wrong because 1 hour is less than the calculated WRT, but the question asks for the maximum allowed, which is 2 hours.

82
MCQmedium

A software-as-a-service (SaaS) provider is developing its business continuity plan (BCP). The company wants to ensure it can continue operating during a prolonged power outage at its primary data center. Which element of the BCP should address the alternate power source and its regular testing?

A.Incident response plan (IRP)
B.Continuity strategies
C.Disaster recovery plan (DRP)
D.Business impact analysis (BIA)
AnswerB

Continuity strategies describe the specific approaches and resources, such as alternate power sources, that will be used to maintain critical functions during a disruption. For a prolonged power outage, the strategy would include details on generators, uninterruptible power supplies, fuel contracts, and testing schedules. This element directly addresses how the SaaS provider will keep operating and ensures the power solution is documented and exercised.

Why this answer

Continuity strategies are the component of the business continuity plan that outlines how critical functions will be maintained during disruptions, including the use of alternate power sources. They specify the resources, responsibilities, and testing required to ensure the strategy works. The BIA identifies the need, but the strategy provides the solution.

Exam trap

The trap here is confusing the business impact analysis, which identifies the need for power continuity, with the continuity strategy, which actually documents the alternate power source and its testing.

83
MCQeasy

Which backup strategy requires the least amount of time to perform a daily backup but the most time to perform a full restore?

A.Differential backup
B.Full backup
C.Synthetic full backup
D.Incremental backup
AnswerD

Incremental backups copy only data changed since the last backup, so daily runs are quick. Restores require the last full backup plus every subsequent incremental in sequence, making full recovery the slowest of the strategies.

Why this answer

An incremental backup only captures data changed since the last backup of any type, so each daily run is very fast and small. However, a full restore requires the last full backup plus every incremental since then, applied in sequence—making restore the slowest of all strategies.

Exam trap

The trap is mixing up differential and incremental—candidates often remember 'incremental is fast' but forget that fast backups mean slow, chain-dependent restores.

How to eliminate wrong answers

Option A is wrong because differential backups capture everything changed since the last full, so daily backups grow larger and slower over time, though restore is faster (full + latest differential). Option B is wrong because a full backup is the slowest to perform daily but the fastest to restore—the exact opposite of the question. Option C is wrong because a synthetic full is constructed from previous backups on the backup server, which is efficient for the source but still yields a single-restore image, not the slowest restore.

← PreviousPage 2 of 2 · 83 questions total

Ready to test yourself?

Try a timed practice session using only Business Continuity, Disaster Recovery, and Incident Response questions.