nerdexam
(ISC)2

CGRC · Question #19

A written plan for recovering one or more information systems at an alternate facility in response to a major hardware or software failure or destruction of facilities. Response:

The correct answer is A. Disaster Recovery Plan (DRP). A Disaster Recovery Plan (DRP) is specifically designed to restore an organization's critical IT infrastructure and systems following a major disruption, often involving relocation to an alternate facility, focusing on technical recovery.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

A written plan for recovering one or more information systems at an alternate facility in response to a major hardware or software failure or destruction of facilities. Response:

Options

  • ADisaster Recovery Plan (DRP)
  • BCommon Vulnerability Scoring System (CVSS)
  • CContinuity of Operations Plan (COOP)
  • DCommon Vulnerability and Exposures (CVE)

How the community answered

(31 responses)
  • A
    90% (28)
  • C
    6% (2)
  • D
    3% (1)

Why each option

A Disaster Recovery Plan (DRP) is specifically designed to restore an organization's critical IT infrastructure and systems following a major disruption, often involving relocation to an alternate facility, focusing on technical recovery.

ADisaster Recovery Plan (DRP)Correct

A Disaster Recovery Plan (DRP) is a comprehensive document outlining the procedures and resources needed to restore information systems, applications, and data to operational status after a catastrophic event. Its primary focus is on the technical recovery of IT systems, often at an alternate processing site.

BCommon Vulnerability Scoring System (CVSS)

Common Vulnerability Scoring System (CVSS) is a standardized method for rating the severity of software vulnerabilities, not a plan for system recovery.

CContinuity of Operations Plan (COOP)

A Continuity of Operations Plan (COOP) focuses on maintaining mission-essential functions of an organization during and after a disruption, which is broader than just IT system recovery, though IT plays a part.

DCommon Vulnerability and Exposures (CVE)

Common Vulnerability and Exposures (CVE) is a list of publicly known cybersecurity vulnerabilities, not a detailed plan for recovering information systems.

Concept tested: Disaster Recovery Plan (DRP)

Source: https://csrc.nist.gov/glossary/term/disaster_recovery_plan

Topics

#Disaster Recovery Plan#DRP#Information System Recovery#Business Continuity

Community Discussion

No community discussion yet for this question.

Full CGRC Practice