Study. uk . com
  1. Home
  2. All questions
  3. Incident management

CISM study material: Incident management

328 questions of the 1000 in the CISM — Certified Information Security Manager quiz. Each opens with its answer, the reasoning and where that is written down.

Challenge yourself on this topic → Study as cards

The questions

  1. 47. A new senior information security officer reviews their remit. Which two duties does NIST place with that role? Choose two.
  2. 94. A board paper argues resilience is a technical property of no interest to executives. How does SP 800-39 frame resilience?
  3. 213. An analysis begins with the consequences the organisation most fears and its critical assets, drawing on business impact analysis results, then works back to the threats that could cause them. Which orientation is this?
  4. 224. A business process depends entirely on a system that cannot be adequately protected within budget. Which response does SP 800-30 identify as sometimes the most effective?
  5. 240. Which two channels does SP 800-39 name for exchanging threat and vulnerability information with parties outside the organisation? Choose two.
  6. 248. A researcher reports a flaw in the organisation's public application and receives no acknowledgement for weeks because no route exists to handle such reports. Which CSF 2.0 outcome is missing?
  7. 285. An organisation already maintains business impact analysis records for continuity planning. Which further use does IR 8286 suggest for that template?
  8. 296. A threat event assessed as highly likely nevertheless produces only minor consequences when it occurs. Which explanation does IR 8286 offer?
  9. 317. An organisation lacks the in-house expertise to recover from a serious cyber attack and cannot justify hiring for it permanently. Which mechanism does IR 8286 describe for this situation?
  10. 343. Which two internal sources does SP 800-30 name as providing insight into both threats and vulnerabilities? Choose two.
  11. 347. Business owners list the shared services they currently depend on. Which further category does SP 800-30 urge them to identify?
  12. 356. An organisation begins its risk assessment with a business impact analysis at the upper tiers rather than with threat identification. Is this consistent with SP 800-30?
  13. 382. Which two decisions taken at the organisation tier does SP 800-39 say constrain what the lower tiers can do? Choose two.
  14. 391. Which two uses does NIST identify for incident statistics in managing a security programme? Choose two.
  15. 447. Which two events does SP 800-137 say should cause monitoring priorities to be adjusted? Choose two.
  16. 477. A single cloud provider suffers a large-scale outage and several organisations in the same supply chain are disrupted at once. Which supply chain property does NIST use this to illustrate?
  17. 495. A supplier suffers a disruption but does not report it, arguing it was not serious. Which contract provision does NIST say should have prevented the dispute?
  18. 523. Which measurement does NIST say demonstrates that staff can actually recognise and report a potential security event, which completion rates cannot show?
  19. 531. Which two responsibilities does NIST assign to an ordinary system user? Choose two.
  20. 643. Which specific risk does NIST identify when two systems are interconnected?
  21. 647. Which two purposes does NIST give for maintaining clear lines of communication between interconnected parties? Choose two.
  22. 661. Which two things does NIST say both parties should examine closely when a new interconnection is activated? Choose two.
  23. 662. Which two activities does NIST include in maintaining an established interconnection? Choose two.
  24. 666. Which two conditions does NIST attach to an emergency disconnection performed without written notice? Choose two.
  25. 667. Which two things does NIST require after an emergency disconnection? Choose two.
  26. 668. An interconnection was terminated because of an attack and both parties now wish to restore it. Which two steps does NIST require first? Choose two.
  27. 699. An organisation trained on the earlier NIST incident response guidance is updating to Revision 3. What structural change must it explain to staff?
  28. 700. Which set correctly names the phases of the older SP 800-61 incident response life cycle?
  29. 701. Which two changes in the incident landscape did NIST cite to justify revising its incident response model? Choose two.
  30. 702. In the SP 800-61r3 model, which three CSF functions constitute incident response itself, as distinct from preparation?
  31. 703. An incident is still in recovery and a responder has identified a clear lesson. What does the current NIST guidance advise?
  32. 704. In NIST's mapping of the old model to CSF functions, what does the former detection and analysis phase correspond to?
  33. 705. The former containment, eradication and recovery phase maps onto which CSF functions, and what does that mapping reflect?
  34. 706. Where do lessons from all six CSF functions go in the SP 800-61r3 model, and what happens to them?
  35. 707. Does NIST mandate its own incident response life cycle model, and which organisations does it say benefit most from one stressing continuous improvement?
  36. 708. Which two decisions does NIST place with the organisation's leadership team during incident response? Choose two.
  37. 709. Which two duties does NIST assign to incident handlers? Choose two.
  38. 710. Which two sourcing arrangements does NIST recognise for incident handlers, beyond permanent staff? Choose two.
  39. 711. A large organisation operates several incident response teams by geographic segment. What does NIST advise?
  40. 712. Which two review roles does NIST assign to legal experts in incident response? Choose two.
  41. 713. Why does NIST say a media engagement strategy must be prepared in advance?
  42. 714. Which two ways does NIST say human resources is an incident response stakeholder? Choose two.
  43. 715. Which two reasons does NIST give for including physical security in incident response? Choose two.
  44. 716. Which two contributions do asset owners make during incident response, according to NIST? Choose two.
  45. 717. An organisation contracts a provider to perform incident detection and response. Which two things does NIST say the contract must define? Choose two.
  46. 718. Which two restrictions does NIST say an incident response provider contract should state? Choose two.
  47. 719. Which two advantages does NIST attribute to a service provider in detecting malicious activity? Choose two.
  48. 720. Which risk does NIST attach to engaging an incident response provider, and which deterrent does it name?
  49. 721. Which two elements does NIST say most incident response policies open with? Choose two.
  50. 722. Which two things does an incident response policy define, according to NIST? Choose two.
  51. 723. Which two further elements does NIST include in an incident response policy? Choose two.
  52. 724. How does NIST order policy, plan and procedures for incident response?
  53. 725. Since detailed procedures cannot cover every situation, which two kinds does NIST advise documenting? Choose two.
  54. 726. Which two purposes does NIST say periodic exercising of procedures serves? Choose two.
  55. 727. How does NIST characterise a playbook in relation to procedures?
  56. 728. How is SP 800-61r3 structured in relation to CSF 2.0?
  57. 729. In the incident response Community Profile, what does a priority of medium indicate about a CSF outcome?
  58. 730. In the incident response Community Profile, which tags distinguish an obligation from something to be weighed?
  59. 731. A recommendation appears against a CSF category rather than a specific subcategory. How does the Community Profile treat it?
  60. 732. Which Govern category does the incident response Community Profile rate as high priority, and on what basis?
  61. 733. Which three legal aspects does the Community Profile ask cybersecurity requirements to capture?
  62. 734. Which two kinds of dependency knowledge does the Community Profile say aid prioritisation of response and recovery? Choose two.
  63. 735. The Community Profile asks that incident decision-making be informed by more than cybersecurity risk. Which two other risk types does it name? Choose two.
  64. 736. Which two uses does the Community Profile identify for a standardised risk calculation method during incident response? Choose two.
  65. 737. Which two recommendations does the Community Profile make about incident response roles? Choose two.
  66. 738. What does the Community Profile recommend be taken into account when the organisation adjusts its cybersecurity risk management strategy?
  67. 739. Which two ways do asset inventories help incident responders, according to the Community Profile? Choose two.
  68. 740. Which three uses does the Community Profile give for automatically updated hardware and software inventories?
  69. 741. Why does the Community Profile recommend maintaining representations of authorised network data flows?
  70. 742. Which three attributes does the Community Profile say make data inventories most valuable to responders?
  71. 743. Which three forms does NIST say an evaluation of the incident response programme can take?
  72. 744. Which two things does a lessons-learned meeting held as recovery concludes achieve, according to NIST? Choose two.
  73. 745. Which two places can an improvement identified during incident response apply to, according to NIST? Choose two.
  74. 746. Which three plan types does NIST identify as relevant to incident response?
  75. 747. Why does NIST require business continuity plans to be synchronised with incident response plans?
  76. 748. Which five characteristics does NIST say each cybersecurity plan should be built around?
  77. 749. What does NIST say a cybersecurity plan must identify for it to be considered complete?
  78. 750. Which two contributions does NIST say business continuity planners can make to incident response? Choose two.
  79. 751. Which two benefits does NIST attribute to reducing the number of incidents, beyond preventing the incidents themselves? Choose two.
  80. 752. Which detection advantage does NIST attribute to understanding the protection mechanisms already in place?
  81. 753. Why does the incident response Community Profile rate backups as high priority when most Protect outcomes are rated medium?
  82. 754. Which record does the Community Profile single out as preserving the information that detection, response and recovery depend on?
  83. 755. An organisation delivers role-based training covering technical skills but omitting what each role must do during an incident. Which recommendation is unmet?
  84. 756. Which two asset types does the Community Profile include in continuous monitoring for incident response that a purely network-focused programme would omit? Choose two.
  85. 757. A monitoring team tunes its detection rules until false positives fall to an acceptable level and considers the work done. Which half of NIST's recommendation is missing?
  86. 758. Which two things does the Community Profile say network monitoring should include beyond wired traffic? Choose two.
  87. 759. Which two things does the Community Profile say monitoring the physical environment should record? Choose two.
  88. 760. Which two things does the Community Profile include in monitoring personnel activity and technology usage? Choose two.
  89. 761. Which two aspects of external provider behaviour does the Community Profile say should be monitored? Choose two.
  90. 762. An endpoint is found to have missing patches and unauthorised software. Which handling does the Community Profile recommend?
  91. 763. Why does the Community Profile recommend monitoring configurations against security baselines?
  92. 764. Given the volume of potentially adverse events, what does NIST recommend organisations rely on?
  93. 765. Which trade-off does NIST identify about the timing of incident detection?
  94. 766. A monitoring tool flags an anomaly and an analyst opens an incident record immediately. Which caution does NIST give?
  95. 767. Which two tool categories does the Community Profile name for continuously monitoring log events for known malicious and suspicious activity? Choose two.
  96. 768. Some technologies in the estate cannot be adequately monitored through automation. What does NIST recommend?
  97. 769. Which practice does NIST identify as what makes event correlation practical across many sources?
  98. 770. Which practice does NIST suggest so that response work is tracked from the moment of detection?
  99. 771. Which three sources does the Community Profile name for acquiring vulnerability disclosures about the organisation's own technologies?
  100. 772. Which two inputs does NIST say the decision to declare an incident should weigh? Choose two.
  101. 773. A team handles incidents strictly in the order they are reported. What does NIST say about this practice?
  102. 774. Which activity does NIST describe as perhaps the most critical decision point in the whole incident response process?
  103. 775. Which two risk evaluation factors does NIST name for prioritising an incident? Choose two.
  104. 776. Which two items does NIST say incident tracking should record alongside a summary? Choose two.
  105. 777. Which arrangement does NIST suggest to give a single point of ownership for each incident?
  106. 778. Which two plans might executing the incident response plan require the organisation to activate as well? Choose two.
  107. 779. Which two things does a preliminary triage review establish, according to NIST?
  108. 780. Which two examples does NIST give of incidents reported to an organisation by outsiders? Choose two.
  109. 781. Which two incident types does NIST give as examples of categorisation, and when does categorisation occur?
  110. 782. Which four factors does NIST say set how quickly response should be performed for each incident?
  111. 783. Which trade-off does NIST identify in selecting a response strategy for an active incident?
  112. 784. NIST distinguishes escalation from elevation in incident response. Which pairing is correct?
  113. 785. Beyond the incident's characteristics, which factor does NIST say must be weighed in deciding when to begin recovery?
  114. 786. What does the Incident Analysis category focus on, in CSF terms?
  115. 787. With what does NIST say root cause analysis of an incident begins?
  116. 788. A response team identifies the immediate trigger of an incident and closes the analysis. Which NIST recommendation is unmet?
  117. 789. Which three means of recording facts and actions during an investigation does NIST name?
  118. 790. Which two kinds of sensitive material do incident response records commonly contain, according to NIST? Choose two.
  119. 791. Formal chain-of-custody handling is not applied to a malware incident. Does NIST regard the collected data as evidence?
  120. 792. Which two factors does NIST say the decision on evidence retention should weigh? Choose two.
  121. 793. Which aspect of incident response does NIST describe as often one of the most challenging?
  122. 794. Where does NIST say responders should search when estimating an incident's magnitude?
  123. 795. Which consequence does NIST attach to skipping or performing magnitude estimation superficially?
  124. 796. What does the Detect function encompass in the incident response Community Profile?
  125. 797. How does NIST define a vulnerability disclosure?
  126. 798. What does NIST recommend detection technologies do with the incidents they have confirmed?
  127. 799. NIST sorts incident response communication into four kinds. Which set is correct?
  128. 800. How does NIST distinguish incident notification from incident coordination?
  129. 801. When does NIST say the mechanisms for coordinating with affected parties should be established?
  130. 802. Which two things should established incident coordination procedures state? Choose two.
  131. 803. Which two characteristics of the organisation does NIST say determine which incident notification laws apply? Choose two.
  132. 804. Which two conditions govern notifying law enforcement or a regulator, under NIST guidance? Choose two.
  133. 805. Why does NIST describe voluntary incident information sharing as mutually beneficial?
  134. 806. How does NIST frame the economic effect of sharing detection techniques between organisations?
  135. 807. Which two characteristics does NIST attribute to incident handlers coordinating across organisations? Choose two.
  136. 808. Which specific reporting path does NIST identify for malicious insider activity?
  137. 809. How does NIST characterise the duty to inform senior leadership about a major incident?
  138. 810. Which two factors does NIST say containment criteria may weigh? Choose two.
  139. 811. A team proposes redirecting an attacker into a sandbox to gather more evidence. Which consultation does NIST require first?
  140. 812. Which danger does NIST attach to deliberately delaying containment in order to observe an attacker?
  141. 813. Which two purposes does containment serve, according to NIST? Choose two.
  142. 814. Which two automatic containment actions does NIST give as examples? Choose two.
  143. 815. Which example does NIST give of an incident type a third party might be authorised to contain automatically on the organisation's behalf?
  144. 816. An organisation deploys fully automated containment and removes the handlers' ability to intervene. Which NIST recommendation does this breach?
  145. 817. Which three eradication actions does NIST give as examples of eliminating persistence mechanisms and entry points?
  146. 818. Why does NIST require every affected host and service to be identified during eradication?
  147. 819. Which three things does NIST say personnel do during incident recovery?
  148. 820. Which two operations does NIST include in incident recovery? Choose two.
  149. 821. An intrusion involves a highly sophisticated actor whose full set of techniques is not known. How far does NIST accept recovery may have to go?
  150. 822. Which two activities does NIST include in executing an incident recovery plan? Choose two.
  151. 823. Which two things must everyone with recovery responsibilities be told, according to NIST? Choose two.
  152. 824. Which three attributes does NIST say the choice of recovery actions should take into account?
  153. 825. Which three things are restoration assets checked for before use, under NIST guidance?
  154. 826. Recovery validates that essential services are restored in the appropriate order. What does NIST's guidance imply about when that order is decided?
  155. 827. After systems are restored and users are back online, which further NIST recommendation applies?
  156. 828. Which two checks does NIST require before a restored asset is placed back into production? Choose two.
  157. 829. Which three things does an after-action report document, and when is it produced?
  158. 830. How does NIST relate recovery communication to the communication performed during response?
  159. 831. Which two recommendations does NIST make about communicating with suppliers during recovery? Choose two.
  160. 832. Which two things should a public update on incident recovery explain, according to NIST? Choose two.
  161. 833. Which published resource does SP 800-61r3 cite as worked examples of incident response playbooks?
  162. 834. An organisation's monitoring surfaces adverse events but nobody can say when one becomes an incident. Which CSF 2.0 prerequisite is missing?
  163. 835. Which two outcomes belong to the CSF 2.0 Incident Management category? Choose two.
  164. 836. Which two requirements does CSF 2.0 place on the records of actions taken during an incident investigation? Choose two.
  165. 837. Under which CSF 2.0 function do containment and eradication sit, and which category holds them?
  166. 838. Why does CSF 2.0 require the integrity of backups to be verified before they are used to restore?
  167. 839. Which two things does CSF 2.0 require when incident recovery ends? Choose two.
  168. 840. How does CSF 2.0 treat public updates during incident recovery?
  169. 841. Under which CSF 2.0 function does the upkeep of the incident response plan sit, and what does that placement reflect?
  170. 842. Which source of improvement does CSF 2.0 name that involves parties outside the organisation?
  171. 843. Which two CSF functions does NIST say should be kept ready at all times and invoked when an incident occurs, rather than running continuously?
  172. 844. Which CSF 2.0 supply chain outcome addresses the involvement of suppliers in incident work?
  173. 845. How does CSF 2.0 treat the estimation of an adverse event's impact and scope?
  174. 846. How does NIST distinguish continuity planning from contingency planning?
  175. 847. Which two scoping options does NIST allow for a business continuity plan? Choose two.
  176. 848. Why must the business continuity planner coordinate with system owners?
  177. 849. What does a continuity of operations plan restore, where, and for how long?
  178. 850. A minor disruption is handled without moving to an alternate site. Does the continuity of operations plan apply?
  179. 851. Which two elements does NIST list as standard in a continuity of operations plan? Choose two.
  180. 852. Which plan type does NIST say non-government organisations generally use to cover their mission and business processes?
  181. 853. Which two things does a crisis communications plan provide, according to NIST? Choose two.
  182. 854. Why must crisis communications procedures be shared with the continuity and business continuity planners?
  183. 855. Which two statements about a cyber incident response plan are correct under NIST's plan taxonomy? Choose two.
  184. 856. Which two characteristics define the scope of a disaster recovery plan under NIST's taxonomy? Choose two.
  185. 857. What relationship does NIST describe between a disaster recovery plan and system contingency plans?
  186. 858. What is the primary difference between an information system contingency plan and a disaster recovery plan?
  187. 859. Which sequence does NIST describe when a disaster forces relocation of several systems?
  188. 860. Which two items does an information system contingency plan carry, according to NIST? Choose two.
  189. 861. Which two features characterise an occupant emergency plan under NIST's taxonomy? Choose two.
  190. 862. When is an occupant emergency plan executed relative to the continuity and disaster recovery plans, and why?
  191. 863. Which statement about a crisis communications plan is correct under NIST's plan taxonomy?
  192. 864. An attack spreads beyond the systems the response team first contained. Which relationship does NIST describe?
  193. 865. Why does NIST insist the various contingency-related plans be coordinated during development and update?
  194. 866. Which sequence matches NIST's seven-step contingency planning process?
  195. 867. Where in the system life cycle does NIST place the contingency planning policy and the business impact analysis, and why there?
  196. 868. Which two things does a contingency planning policy statement establish, and what does NIST say it needs to succeed?
  197. 869. Which two items does NIST name as key elements of contingency planning policy? Choose two.
  198. 870. With which functions does NIST say contingency planning must be coordinated?
  199. 871. What does a business impact analysis do, in NIST's formulation?
  200. 872. Which two outputs does NIST say business impact analysis results feed? Choose two.
  201. 873. A system's design and components change substantially during acquisition. What does NIST expect of the business impact analysis done earlier?
  202. 874. An auditor finds the organisation's plan types do not match NIST's descriptions exactly. Which NIST statement bears on this?
  203. 875. During a continuity of operations activation, what does the business continuity plan cover in NIST's model?
  204. 876. What does maximum tolerable downtime represent?
  205. 877. Which definition matches recovery time objective as NIST states it?
  206. 878. Which quantity does recovery point objective express?
  207. 879. Why is recovery point objective not counted as part of maximum tolerable downtime, while recovery time objective is?
  208. 880. Why does NIST expect recovery time objective to be shorter than maximum tolerable downtime?
  209. 881. What does NIST say determining the recovery time objective allows planners to do?
  210. 882. The achievable recovery time objective exceeds a maximum tolerable downtime that cannot be relaxed. What does NIST direct?
  211. 883. What became of the term maximum allowable outage used in an earlier NIST contingency guide?
  212. 884. How does NIST describe the two cost curves that determine an optimal recovery solution?
  213. 885. Why can't one organisation adopt another's cost balance point for recovery investment?
  214. 886. Which four inputs does NIST say determine system resource recovery priorities, and where does that step sit?
  215. 887. Where an outage can be prevented feasibly and cost-effectively, which does NIST prefer?
  216. 888. How does NIST treat power provision among preventive contingency controls?
  217. 889. Which preventive contingency control does NIST specify with placement both above and below the computer room?
  218. 890. Which preventive contingency control does NIST name for protecting backup media and vital paper records?
  219. 891. On what does NIST say the minimum frequency and scope of backups should be based?
  220. 892. Which two items does NIST expect a backup policy to designate beyond frequency and scope? Choose two.
  221. 893. Which two criteria does NIST give for selecting an offsite storage facility? Choose two.
  222. 894. Beyond confirming data is stored correctly, which further backup-media test does NIST recommend?
  223. 895. An organisation leases space with power, telecommunications connections and environmental controls but no system hardware. Which alternate site type is this?
  224. 896. Which description matches a warm site under NIST's definitions?
  225. 897. Which two attributes distinguish a hot site from a warm site under NIST's definitions? Choose two.
  226. 898. Which alternate site type does NIST describe as a self-contained transportable shell fitted with the equipment a particular recovery requires?
  227. 899. Which two characteristics define a mirrored site under NIST's definitions? Choose two.
  228. 900. How does NIST characterise the cost and readiness extremes of the alternate site options?
  229. 901. On NIST's alternate-site comparison, which row matches a warm site?
  230. 902. A plan relies on a mobile site delivered within a day. Which caveat does NIST attach?
  231. 903. Which two considerations govern where a fixed alternate site is located, per NIST? Choose two.
  232. 904. Which three ownership models for alternate sites does NIST name?
  233. 905. What must be negotiated in advance with a commercial alternate site provider serving many customers?
  234. 906. Which two considerations does NIST attach to entering a reciprocal agreement? Choose two.
  235. 907. Which two checks does NIST specify when testing a reciprocal arrangement? Choose two.
  236. 908. Why does NIST want the alternate site agreement to state what constitutes a disaster and how notification occurs?
  237. 909. Which contractual detail does NIST say determines whether an alternate site's capacity will actually be available?
  238. 910. Which review does NIST require before an alternate site agreement is relied on?
  239. 911. Which two occupancy terms does NIST expect an alternate site agreement to fix? Choose two.
  240. 912. Which three equipment replacement strategies does NIST name?
  241. 913. Which two provisions does NIST expect in a service level agreement for emergency equipment? Choose two.
  242. 914. When a catastrophe affects many of a vendor's clients at once, which organisations commonly receive the highest replacement priority?
  243. 915. Which trade-off does NIST describe between buying replacement equipment on demand and storing it in advance?
  244. 916. Which risk does NIST attach to a replacement strategy that depends on shipment after a catastrophic disaster?
  245. 917. Which two less obvious costs does NIST say a contingency budget must cover? Choose two.
  246. 918. Which role does NIST say a recovery strategy must include, and what decision rests with it?
  247. 919. Which three things must recovery team members understand, under NIST guidance?
  248. 920. Which two recovery technologies does NIST name alongside redundant arrays of independent disks? Choose two.
  249. 921. Which strategy does NIST pair with a moderate availability impact level?
  250. 922. Which systems must have a strategy for operating at an alternate facility for an extended period, under NIST guidance?
  251. 923. Which two external points of contact should a business impact analysis draw on? Choose two.
  252. 924. Which check does NIST require when evaluating whether an alternate site is adequate?
  253. 925. What distinguishes a test from other plan validation activities in NIST's usage?
  254. 926. Which two elements does NIST expect a contingency test to exercise? Choose two.
  255. 927. Without which two elements does NIST say a contingency test plan cannot show the plan is effective? Choose two.
  256. 928. Which scenario does NIST accept for a contingency test, and what quality does it require of it?
  257. 929. How does NIST distinguish contingency training from awareness?
  258. 930. Which training goal does NIST set for recovery personnel, and why?
  259. 931. Which two timing requirements does NIST set for contingency training? Choose two.
  260. 932. Beyond individual duties, which topic does NIST expect contingency training to cover?
  261. 933. Which description matches a tabletop exercise under NIST's usage?
  262. 934. What distinguishes a functional exercise from a tabletop exercise?
  263. 935. What separates an exercise from a test in NIST's terminology?
  264. 936. How does NIST characterise the way exercises are driven?
  265. 937. Which exercise rigour does NIST match to a moderate-impact system?
  266. 938. What must a full-scale functional exercise for a high-impact system include?
  267. 939. Which two things does NIST require of every test and exercise?
  268. 940. How do the results of a training, test or exercise event reach the plan, per NIST?
  269. 941. When does NIST say exercises and tests should be run?
  270. 942. To which organisational process does NIST tie contingency plan maintenance?
  271. 943. Which plan element does NIST single out as needing review more often than the plan as a whole?
  272. 944. Where does NIST say a copy of the contingency plan should be kept, and why?
  273. 945. Why does NIST require the distribution of a contingency plan to be marked and controlled, with a record of holders?
  274. 946. How does NIST recommend strict version control of the contingency plan be maintained?
  275. 947. Which material does NIST say should be stored with the contingency plan?
  276. 948. What does the record of changes in a contingency plan capture?
  277. 949. Which three phases structure an information system contingency plan under NIST?
  278. 950. Which criterion does NIST include among the bases for activating a contingency plan?
  279. 951. How many people does NIST say should hold the authority to activate the contingency plan?
  280. 952. Which range must notification procedures cover, per NIST?
  281. 953. Which operational benefit does NIST attribute to prompt notification of an impending disruption?
  282. 954. Why does NIST caution against relying on email for contingency notification?
  283. 955. Which detail must a call tree record beyond the assignment of notification duties?
  284. 956. Which content does NIST say a notification message may carry?
  285. 957. Why does NIST expect external organisations and interconnected system partners to be notified?
  286. 958. Which priority does NIST place above the speed of outage assessment?
  287. 959. Which element belongs in an outage assessment under NIST guidance?
  288. 960. What does NIST say may happen to notifications once outage assessment reveals the true impact?
  289. 961. What governs the sequence in which resources are recovered?
  290. 962. Which example does NIST give of the logical, as opposed to merely prioritised, ordering of recovery?
  291. 963. Which conditions should trigger escalation steps written into recovery procedures?
  292. 964. Which step does NIST include in typical recovery procedures before hardware installation begins?
  293. 965. Which documentation format does NIST recommend for recovery procedures, and why?
  294. 966. What may be running at the end of the recovery phase, under NIST's model?
  295. 967. Which two major activities make up the reconstitution phase?
  296. 968. What is concurrent processing in NIST's reconstitution guidance?
  297. 969. Which validation does NIST require to confirm files and databases are complete and current to the last backup?
  298. 970. Which judgement does NIST require after reconstitution?
  299. 971. Which activities does NIST include in deactivating the contingency plan?
  300. 972. Which further work can fall inside the reconstitution phase when the original facility is unrecoverable?
  301. 973. What must escalation procedures define, per NIST's recovery guidance?
  302. 974. Which three elements does NIST say a test, training and exercise programme needs to be repeatable rather than ad hoc?
  303. 975. How does NIST separate the plan coordinator's role from the exercise programme coordinator's?
  304. 976. Which four phases make up NIST's exercise event methodology, used for every event type?
  305. 977. Which activities belong to the design phase of an exercise, per NIST?
  306. 978. Which two subjects does the evaluation phase draw lessons for?
  307. 979. What ordering does NIST set between training sessions and exercises?
  308. 980. Which by-product does NIST attribute to running a training session?
  309. 981. How long does NIST say a tabletop exercise usually runs?
  310. 982. What does NIST say tabletop exercises are cost-effective tools for?
  311. 983. Which question does NIST put before scheduling a tabletop exercise?
  312. 984. Which approval does NIST treat as an essential development step for an exercise?
  313. 985. How far ahead does NIST say design should begin for a large, complex tabletop exercise?
  314. 986. Which sequencing does NIST advise for exercising senior-level and operational-level teams?
  315. 987. How does NIST differentiate the duration and pitch of senior-level and operational-level tabletop exercises?
  316. 988. What does NIST suggest accompany a tabletop exercise lasting more than four hours?
  317. 989. Which three standing objectives does NIST give a tabletop exercise?
  318. 990. Which two staff roles does a tabletop exercise require, and what must both know?
  319. 991. What does NIST have the facilitator and data collector do before a tabletop exercise?
  320. 992. How does NIST define a tabletop exercise scenario?
  321. 993. What does the facilitator guide contain for a tabletop exercise?
  322. 994. How does the participant guide differ from the facilitator guide?
  323. 995. Which misconception about exercise scenarios does NIST correct?
  324. 996. When must evaluation criteria for an exercise be written, and why?
  325. 997. How should exercise questions differ between senior and operational participants?
  326. 998. Why does NIST suggest seating participants away from their own teammates during a tabletop exercise?
  327. 999. Which facilitator skill does NIST call for when discussion drifts into the scenario's detail?
  328. 1000. Which three questions does the debrief immediately after a tabletop exercise put to participants?