Skip to content
CY-604 (A) · IT Business & Disaster Recovery Planning/Important Questions

IT Business & Disaster Recovery Planning (CY-604 (A)) - Important Questions

  1. Unit 414 Marks High Priority

    Explain the various laws and acts relevant to Disaster Recovery (DR) planning, including Data Protection legislation and CAN-SPAM. Discuss how these laws influence the design and execution of DR strategies and the obligations they impose on organizations.

    Core topic from Unit 4: Frequent analytic hit on laws and acts affecting disaster recovery planning (Data Protection laws, CAN-SPAM, etc.).

  2. Unit 410 Marks Medium Priority

    Discuss the regulatory compliance requirements of GDPR, HIPAA, SOX, and PCI DSS as they relate to backup, retention, recovery time objectives (RTO), and recovery point objectives (RPO). Explain practical measures to ensure compliance in DR plans.

    Focuses on major regulatory frameworks that commonly affect DR requirements (privacy, health, financial sectors).

  3. Unit 47 Marks Medium Priority

    Describe the procedures for preserving chain of custody, conducting e-discovery, and implementing legal holds during incident response and disaster recovery. Explain why these procedures are critical for compliance and litigation readiness.

    Legal evidence and investigation actions during incidents—important for both legal compliance and forensic readiness.

  4. Unit 414 Marks Medium Priority

    Compare and contrast ISO 22301 and NIST guidance relevant to Business Continuity and Disaster Recovery (for example, NIST SP 800-34 or NIST SP 800-61). Highlight key requirements, control objectives, and how organizations map these standards into their DR programmes.

    Standards comparison is a typical exam requirement to test understanding of international guidance and frameworks.

  5. Unit 47 Marks Medium Priority

    Explain the contractual and commercial considerations in DR planning, including Service Level Agreements (SLAs), vendor liability clauses, insurance coverage for business interruption, and third-party risk management. Illustrate with examples how these affect recovery decisions.

    Contracts, SLAs and third-party risk are core operational/legal topics in Unit 4.

  6. Unit 410 Marks Medium Priority

    Design a compliance checklist for disaster recovery testing and audits. List the types of evidence and documentation regulators or auditors typically require, and describe how to maintain this evidence to demonstrate compliance over time.

    Audit and evidencing of DR tests is important for regulatory proof and continuous improvement.

  7. Unit 47 Marks Medium Priority

    Discuss the legal penalties and consequences of non-compliance with data protection and breach notification laws following a security incident. Provide examples of regulatory fines and civil liabilities that may result from inadequate DR and incident response.

    Regulatory consequences and real-world examples help students apply legal theory to incidents.

  8. Unit 47 Marks Medium Priority

    Explain the issues surrounding cross-border data transfers and data residency in the context of disaster recovery solutions (including cloud backups and offsite replication). Describe compliance strategies to address differing national data protection requirements.

    Cross-border data movement is a recurring compliance challenge when using offsite/cloud DR resources.

  9. Unit 410 Marks Medium Priority

    Prepare a detailed incident notification and reporting procedure for a DR plan that meets common statutory and contractual requirements. Include timelines, stakeholder roles (internal and external), content of notifications, and escalation criteria.

    Covers coordination between legal, compliance and technical teams—important for exam scenarios and practical plans.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in