CHAPTER SUMMARY

This chapter has provided information on identifying assets. Asset identification is an important first step in any risk identification process. An organization’s assets include its hardware and software, data and information assets, and personnel. The seven domains of a typical IT infrastructure can be used to ensure that all the assets are identified.

Once the assets have been identified, they can be protected using various tools. A business impact analysis helps in identifying the impact to the business if a service fails, which helps in prioritizing the most important assets. A disaster recovery plan documents the steps that would need to be taken to restore a failed system. A business continuity plan is broader and is used to help ensure that mission-critical systems continue to operate even after a disaster.

KEY CONCEPTS AND TERMS

CHAPTER 7 ASSESSMENT

  1. Ensuring that a service is operational 99.999 percent of the time is possible even if a server needs to be regularly rebooted.
    1. True
    2. False
  2. What is a single point of failure?
    1. Any single part of a system that can fail
    2. Any single part of a system that can cause the entire system to fail if it fails
    3. Any single part of a system that has been protected with redundancy
    4. Any single part of a system
  3. When identifying the assets in an organization, what would be included?
    1. Hardware
    2. Software
    3. Personnel
    4. Only A and B
    5. A, B, and C
  4. When identifying hardware assets in an organization, what information should be included?
    1. Model number and manufacturer
    2. Serial number
    3. Location
    4. Only A and C
    5. A, B, and C
  5. An organization may use a ________ rotation policy to help discover dangerous shortcuts or fraudulent activity.
  6. What type of data should be included when identifying an organization’s data or information assets?
    1. Organizational data
    2. Customer data
    3. Intellectual property
    4. A and B only
    5. A, B, and C
  7. What is a data warehouse?
    1. A database used in a warehouse
    2. A database used to identify the location of products in a warehouse
    3. A database created by combining multiple databases into a central database
    4. One of several databases used to create a central database for data mining
  8. What is data mining?
    1. The process of retrieving relevant data from a data warehouse
    2. A database used in metal mining operations
    3. A database created by combining multiple databases into a central database
    4. A process used to extract, load, and transform a data warehouse
  9. What can an asset management system be compared with to ensure an entire organization is covered?
    1. Hardware and software assets
    2. Software assets
    3. Personnel and data assets
    4. The seven domains of a typical IT infrastructure
  10. When updating an organization’s business continuity plans, only ________ systems should be included.
  11. Which of the following is a privacy regulation that may impact data sourced from the European Economic Area?
    1. HIPAA
    2. GDPR
    3. PCI DSS
    4. FOIP
  12. What should an organization use if it wants to determine what the impact would be if a specific IT server fails?
    1. BIA
    2. BCP
    3. DRP
    4. BCC
  13. What should an organization use if it wants to ensure it can continue mission-critical operations in the event of a disaster?
    1. BIA
    2. BCP
    3. DRP
    4. BCC
  14. What should an organization use if it wants to ensure it can recover a system in the event of a disaster?
    1. BIA
    2. BCP
    3. DRP
    4. BCC
  15. A BCP and a DRP are two different things.
    1. True
    2. False
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
3.17.184.90