Information assets have ____ when authorized users - persons or...
The purpose of the ____ is to define the scope of the CP operations...
The focus during a(n) ____ is on learning what worked, what...
A ____ attack is much more substantial than a DoS attack because of...
The ____ team is responsible for reestablishing connectivity between...
____ is the process of moving an organization toward its vision.
The Southeast Collegiate Cyber Defense Competition is unique in that...
In an attack known as ____, valid protocol packets exploit poorly...
The task of monitoring file systems for unauthorized change is best...
The ____ team is primarily responsible for data restoration and...
A(n) ____ is an investigation and assessment of the impact that...
A(n) ____ is used to anticipate, react to, and recover from events...
____ assigns a risk rating or score to each information asset....
____ is a risk control approach that attempts to shift the risk to...
A(n) ____ is a CSIRT team member, other than the team leader, who is...
The U.S. National Institute of Standards and Technology defines the...
One of the primary responsibilities of the IRP team is to ensure that...
Using a process known as ____, network-based IDPSs look for attack...
The first group to communicate the CSIRT's vision and operational...
According to NIST, which of the following is an example of a UA...
____ is used both for intrusion analysis and as part of evidence...
____ are highly probable when infected machines are brought back...
____ is a valuable resource for additional information on building and...
The ____ handles computer crimes that are categorized as felonies.
A ____ is used for an office or small campus, with segment distances...
A(n) ____ is an object, person, or other entity that is a potential...
The ____ is an investigation and assessment of the impact that various...
Some recovery strategies seek to improve the ____ of a server or...
A resumption location known as a ____ or a _______ is a fully...
The process of evaluating the circumstances around organizational...
A(n) ____ is a sign that an activity now occurring may signal an...
The Business Continuity Institute offers an uncertified category of...
When an organization completely outsources its IR work, typically to...
A key step in the ____ approach to incident response is to discover...
The determination of what systems fall under the CSIRT 's...
When an alert warns of new malicious code that targets software used...
When an incident includes a breach of physical security, all aspects...
Clifford Stoll's book, ____, provides an excellent story about a...
The ____ phase of forensic analysis involves the use of forensic tools...
____ are likely in the event of a hacker attack, when the attacker...
In the context of disaster notification, the ____ is a scripted...
The ____ system is an information system with a telephony interface...
____ ensures that only those with the rights and privileges to access...
____ is the risk control approach that attempts to reduce the impact...
Information assets have ____ when they are not exposed (while being...
The ____ illustrates the most critical characteristics of information...
____ hack systems to conduct terrorist activities through network or...
The ____ job functions and organizational roles focus on protecting...
The ____ is used to collect information directly from the end users...
The first major business impact analysis task is to analyze and...
The elements required to begin the ____ process are a planning...
Within an organization, a(n) ____ is a group of individuals who are...
In a CPMT, a(n) ____ should be a high-level manager with influence and...
A CPMT should include _____ who can oversee the security planning of...
Considered to be the traditional "lock and copy" approach to...
____ uses a number of hard drives to store information across multiple...
An organization aggregates all local backups to a central repository...
A(n) ____ is often included in legal documents to ensure that a vendor...
Advances in cloud computing have opened a new field in application...
Both data backups and archives should be based on a(n) ____ schedule...
A backup plan using WAN/VLAN replication and a recovery strategy using...
The training delivery method with the lowest cost to the organization...
____ is the process of systematically examining information assets for...
General users require training on the technical details of how to do...
If an intruder can ____ a device, then no electronic protection can...
When implementing a BC plan, an organization reaches a predetermined...
Once BC activities have come to a close and the organization has...
A certification offered by the Business Continuity Institute is called...
The ____ section of the business continuity policy identifies the...
A CSIRT model in which a single CSIRT handles incidents throughout the...
Those services undertaken to prepare the organization or the CSIRT...
Those services performed in response to a request or a defined event...
Known as ____, procedures for regaining control of systems and...
In a "block" containment strategy, in which the...
A ____ is a small quantity of data kept by a Web site as a means of...
Forensic investigators use ____ copying when making a forensic image...
A continuously changing process presents challenges in acquisition, as...
____ is the determination of the initial flaw or vulnerability that...
The forensic tool ____ does extensive pre-processing of evidence items...
A ____ is a description of the disasters that may befall an...
The ____ assembles a disaster recovery team.
An ____ may escalate into a disaster when it grows in scope and...
____ disasters include acts of terrorism and acts of war.
Which of the following is not usually an insurable loss?
Deciding which technical contingency strategies are selected,...
Useful resources in the DR planning process are the ____ provided by...
____ is the deactivation of the disaster recovery teams, releasing...
____ is a set of focused steps that deal primarily with the safety and...
The ____ team is responsible for providing the initial assessments of...
____ means making an organization ready for possible contingencies...
A ____ is a document that describes how, in the event of a disaster,...
A favorite pastime of information security professionals is ____,...
The ____ is the point in the past to which the recovered applications...
____ is a tactic that deliberately permits an attack to continue while...
A(n) ____ is any clearly identified attack on the organization's...
The last stage of a business impact analysis is prioritizing the...
Which of the following collects and provides reports on failed login...
The final component to the CPMT planning process is to deal with ____.
The ____ is the period of time within which systems, applications, or...
A(n) ____ is an extension of an organization's intranet into cloud...
A ____ is an agency that provides physical facilities in the event of...
A(n) ____ covers the confidentiality of information from everyone...
The ____ of an organization defines the roles and responsibilities for...
In contingency planning, an adverse event that threatens the security...
The responsibility for creating an organization's IR plan often...
New systems can respond to an incident threat autonomously, based on...
A(n) ____ is any system resource that is placed onto a functional...
Two dominantly recognized professional institutions certifying...
A BC subteam called the ____ is responsible for establishing the core...
The ____ section of the business continuity policy identifies the...
The ____ section of the business continuity policy provides an...
Identifying measures, called ____, that reduce the effects of system...
The CSIRT must have a clear and concise ____ statement that, in a few...
The champion for the CSIRT may be the same person as the champion for...
A ____ attack is much more substantial than a DoS attack because of...
When a second attack, using the means and methods of the first attack...
Essentially a DoS attack, a ____ is a message aimed at causing...
A(n) ____ attack is a method of combining attacks with rootkits and...
There are a number of professional IR agencies, such as ____, that can...
In evidence handling, specifically designed ____ are helpful because...
The ____ is a detailed examination of the events that occurred, from...
One way to identify a particular digital item (collection of bits) is...
The primary vehicle for articulating the purpose of a disaster...
The ____ team is responsible for recovering and reestablishing...
The purpose of the ____ is to provide a way for management to obtain...
A(n) ____ occurs when a situation results in service disruptions for...
The ____ is the phase associated with implementing the initial...
____ of risk is the choice to do nothing to protect an information...
A(n) ____ is a plan or course of action used by an organization to...
____ (sometimes referred to as avoidance) is the risk control strategy...
A(n) ____...
A ____ deals with the preparation for and recovery from a disaster,...
A manual alternative to the normal way of accomplishing an IT task...
In a CPMT, a(n) ____ leads the project to make sure a sound project...
The ____ job functions and organizational roles focus on costs of...
What is a common approach used in the discipline of systems analysis...
The ____ is the point in time, determined by the business unit, from...
One modeling technique drawn from systems analysis and design that can...
A ____ is commonly a single device or server that attaches to a...
A(n) ____ backup only archives the files that have been modified since...
RAID 0 creates one logical volume across several available hard disk...
A potential disadvantage of a ____ site-resumption strategy is that...
A ____ is a contractual document guaranteeing certain minimal levels...
The ____ Department of an organization needs to review the procedures...
The IR plan is usually ____ when an incident causes minimal damage...
____ incident responses enables the organization to react to a...
Should an incident begin to escalate, the CSIRT team leader continues...
Incident analysis resources include network diagrams and lists of...
The ____ approach for detecting intrusions is based on the frequency...
In the event that a definite indicator is recognized, the...
____ are closely monitored network decoys serving that can distract...
The use of IDPS sensors and analysis systems can be quite complex. One...
The ongoing activity from alarm events that are accurate and...
Most organizations will find themselves awash in incident candidates...
The ____ is the amount of time that a business can tolerate losing...
____ planning represents the final response of the organization when...
In the ____ section of the business continuity policy, the training...
The CSIRT should be available for contact by anyone who discovers or...
A CSIRT model that is effective for large organizations and for...
One way to build and maintain staff skills is to develop...
The announcement of an operational CSIRT should minimally include...
____ incidents are predominantly characterized as a violation of...
____ is a common indicator of a DoS attack.
Which of the following is the most suitable as a response strategy for...
The CSIRT may not wish to "tip off" attackers that they have...
A forensics team typically uses two methods to document a scene as it...
Grounds for challenging the results of a digital investigation can...
A search is constitutional if it does not violate a person's...
____ are those that occur suddenly, with little warning, taking the...
In disaster recovery, the ____ is the point at which a management...
The ____ team is responsible for providing any needed supplies, space,...
During the ____ phase, the organization begins the recovery of the...
The ____ team is responsible for working with the remainder of the...
The ____ involves providing copies of the DR plan to all teams and...
Companies may want to consider budgeting for contributions to employee...
A(n) ____ is an agreement in which the client agrees not to use the...
A recommended practice for the implementation of the physical IR plan...
The committees of the CPMT follow a set of general stages to develop...
A recommended practice for the implementation of the physical IR plan...
A(n) ____ is the set of rules and configuration guidelines governing...
A(n) ____ , a type of IDPS that is similar to the NIDPS, reviews the...
A ____ rootkit is one that becomes a part of the system bootstrap...
A(n) ____ is a sign that an adverse event is underway and has a...
When the measured activity is outside the baseline parameters in a...
The ____ is the group responsible for initiating the occupation of the...
Essential BC supplies needed at an alternate site include portable...
The U.S. Department of Homeland Security's Federal Emergency...
The organization must first understand what skills are needed to...
If a user receives a message whose tone and terminology seems intended...
The number-one IU preparation-and-prevention strategy is ____.
Many malware attacks are ____ attacks, which involve more than one...
____ involves an attempt made by those who may become subject to...
The stability of information over time is called its ____.
Many private sector organizations require a formal statement, called...
The functional part of forensics called ____ is about assessing the...
A ____ is a collection of nodes in which the segments are...
____ occur over time and slowly deteriorate the organization's...
____ may be caused by earthquakes, floods, storm winds, tornadoes, or...
The part of a disaster recovery policy that identifies the...
Once the incident has been contained, and all signs of the incident...