Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 1 out of 4 pages
Exam (elaborations)

ITSS 4370 Final Exam | Questions and Answers

Document preview thumbnail
Preview 1 out of 4 pages

ITSS 4370 Final Exam | Questions and Answers Which of the following functions is NOT a key component in an organization's disaster recovery efforts? Disaster reaction Network equipment is usually not included as part of the configuration management because there is little need to document network hardware and network configurations False IT controls are the BEST detection method to limit fraud duration and loss TRUE What should the relationship be between business continuity policies and corporate policies? They should be strategically aligned One justification for choosing a hybrid cloud deployment model is the ability to support cloud bursting. What is cloud bursting? Spilling over to the public cloud to deal with spikes in demand Matching: Weakness that may be exploited Vulnerability Matching: Preventative measure Control Matching: Potential for exposure Threat Matching: An occurrence that actually or potentially results in adverse consequences to an information system or the information that the system stores, processes, or transmits, and that may require a response action to mitigate the consequences Incident Matching: Human originated penetration or penetration attempt Attack Matching: Actual harm or possible harm Exposure Which of these are methods for measuring availability? Percent uptime = (Actual uptime) / (Scheduled uptime) Measure uptime in terms meaningful to users Quantify amount of downtime Redundancy as a method for maximizing availability deals with ______ Eliminating, as much as possible, any single point of failure that could disrupt service availability Which of the following is NOT one of the three common service models in cloud computing? Broadband as a Service (BaaS) Defense in depth refers to _________ Establishing sufficient security controls and safeguards so that an intruder faces multiple layers of controls There are several approaches that can be taken to maximize availability - the seven R's of high availability. Which of the following is NOT one of these seven approaches? Recognition The rule of nines refers to Measurement of availability as a percentage of uptime Matching: It should be clear who accessed or changed information and when they did Accountability Matching: Information should only be provided to those who need access to it Confidentiality Matching: Information should be provided to users when they need it Availability Matching: Information should not be altered or changed unexpectedly Integrity The principal purpose of Business Impact Analysis is to ______________ Assess the impact that various risks or attacks can have on the organization's Data tiering determines where and how data is stored. Which of the following criteria may be used in determining data tiering needs? Performance Cost Availability Recovery or retrieval requirements Which of the following are key functions of the NIST Cybersecurity Framework?

Content preview

ITSS 4370 Final Exam



Which of the following functions is NOT a key component in an organization's disaster
recovery efforts?
Disaster reaction

Network equipment is usually not included as part of the configuration management
because there is little need to document network hardware and network configurations
False

IT controls are the BEST detection method to limit fraud duration and loss
TRUE

What should the relationship be between business continuity policies and corporate
policies?
They should be strategically aligned

One justification for choosing a hybrid cloud deployment model is the ability to support
cloud bursting. What is cloud bursting?
Spilling over to the public cloud to deal with spikes in demand

Matching: Weakness that may be exploited
Vulnerability

Matching: Preventative measure
Control

Matching: Potential for exposure
Threat

Matching: An occurrence that actually or potentially results in adverse consequences to
an information system or the information that the system stores, processes, or
transmits, and that may require a response action to mitigate the consequences
Incident

Matching: Human originated penetration or penetration attempt
Attack

Matching: Actual harm or possible harm
Exposure

Which of these are methods for measuring availability?

Document information

Uploaded on
December 5, 2024
Number of pages
4
Written in
2024/2025
Type
Exam (elaborations)
Contains
Questions & answers
$13.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
Jumuja
3.8
(119)
Sold
586
Followers
416
Items
2832
Last sold
3 weeks ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions