ISO 3166-2:2020 Country Codes - Part 2: Subdivision code Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

During a simulated ransomware attack against \"Stellar Dynamics,\" a multinational engineering firm, the incident response team successfully contained and eradicated the malware, following the guidelines outlined in ISO 27035-2:2016. The team is now in the recovery phase. Elara Vance, the Chief Information Security Officer (CISO), is leading the recovery efforts. A key decision point arises: should the recovery phase, as defined by ISO 27035-2, primarily focus on restoring the affected systems to their pre-incident state, or should it also encompass broader business continuity objectives outlined in Stellar Dynamics\' Business Continuity Plan (BCP)? Considering the interconnectedness of IT infrastructure and business operations, and acknowledging that the ransomware attack has exposed vulnerabilities that could impact future business disruptions, which approach best aligns with the principles of ISO 27035-2:2016 and promotes organizational resilience?

The recovery phase should align with and contribute to the overarching recovery strategies defined in the BCP, ensuring that recovery efforts not only restore immediate functionality but also support the organization's long-term operational resilience, focusing on technical restoration and security hardening in alignment with the BCP's business process restoration framework.
The recovery phase should strictly adhere to the technical restoration of systems and data as defined within the immediate scope of the incident, without necessarily considering the broader business continuity objectives, as the BCP addresses separate, longer-term disruptions.
The recovery phase should prioritize the immediate restoration of systems to a minimally viable state, deferring comprehensive security hardening and alignment with the BCP to a later, separate project to expedite the return to operational status.
The recovery phase should focus on identifying and documenting all vulnerabilities exploited during the incident, postponing actual system restoration until a complete vulnerability assessment and remediation plan is implemented, regardless of the impact on business operations.

About the ISO 3166-2:2020 Country Codes - Part 2: Subdivision code Certification

These free practice questions are designed to help you assess your readiness for the ISO 3166-2:2020 Country Codes - Part 2: Subdivision code exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.