UPDATED ACTUAL Exam Questions and
CORRECT Answers
business continuity plan - CORRECT ANSWER - a plan that defines the people and
procedures required to ensure timely and orderly resumption of an organization's essential
processes with minimal interruption
COBIT - CORRECT ANSWER - "Control Objectives for Info and Related Technology"
a set of guidelines whose goal is to align IT resources and processes with business objectives,
quality standards, monetary controls, and security needs
corporate governance - CORRECT ANSWER - the set of processes, customs, rules,
procedures, policies, and traditions that determine how to direct and control management
activities
disaster recovery as a service (DRaaS) - CORRECT ANSWER - the replication and
hosting of physical or virtual servers and other necessary hardware and software by a third- party
service provider to deliver IT services in the event of a disaster
disaster recovery plan - CORRECT ANSWER - a component of an organization's business
continuity plan that defines the process to recover an organization's business information system
assets including hardware, software, data, networks, and facilities in the event of a disaster
due diligence - CORRECT ANSWER - the effort made by an ordinarily prudent or
reasonable party to avoid harm to another party
internal control - CORRECT ANSWER - the process established by an organization's
board of directors, managers, and IT systems to provide reasonable assurance for the
effectiveness and efficiency of operations, the reliability of financial reporting, and compliance
with applicable laws and regulations
, International Standards Organizational standard ISO 22301:2012 - CORRECT
ANSWER - "Societal Security - Business Continuity Management Systems -
Requirements"
a standard that specifics requirements to plan, establish, implement, operate, monitor, review,
maintain and continually improve a documented management system to prepare for, respond to,
and recover from disruptive events when they arise
IT governance - CORRECT ANSWER - a framework that ensures that information
technology decisions are made while taking into account a businesses' goals and objectives
IT Infrastructure Library (ITIL) - CORRECT ANSWER - a set of guidelines initially
formulated by the U.K. government in the late 1980s and widely used today to standardize,
integrate, and manage IT service delivery
malware - CORRECT ANSWER - malicious software, usually installed without a
computer owner's knowledge
Plan-Do-Check-Act (PDCA) model - CORRECT ANSWER - a proven method that can be
applied to a specific targeted process that has been identified for improvement
recovery time objective - CORRECT ANSWER - the time within which a business
function must be recovered before an organization suffers a serious business interruption
resulting in the loss of sales and disgruntled customers
separation of duties - CORRECT ANSWER - a fundamental concept of good internal
controls that requires that the duties associated with a key process be performed by more than
one person
Who receives additional training in crowd control to help workers evacuate from a work area? -
CORRECT ANSWER - floor warden