CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 150


Which of the following should be done at a disaster site before any item is removed, repaired, or replaced?

Show Answer
Correct Answer: C

Before any item is removed, repaired, or replaced at a disaster site, it is crucial to document the damage through photographs. This step is critical for maintaining an accurate record of the situation, which can be useful for insurance claims, legal purposes, and internal evaluations. Once the scene is altered, it becomes challenging to recreate the original state of damage for any investigation or claim process. Hence, taking photos of the damage provides a clear, documented reference of the incident as it originally occurred.

Discussion

28 comments
Sign in to comment
trojixOption: C
Jan 14, 2023

From a CISSP perspective, it is important to document the state of the disaster site before any item is removed, repaired, or replaced. This documentation, in the form of photographs, can be used as evidence in the event of an investigation or lawsuit.

Delab202Option: C
Jan 2, 2023

Notify all of the Board of Directors=How? Do you know all the board members? Are they available for your notification? Take photos, use your communication channel to send it up

dev46Option: D
Sep 23, 2022

Communication would be the key here, presuming notifying to board of directors include the change of asset inventory

jackdryan
May 12, 2023

C is correct

stickerbush1970Option: D
Sep 26, 2022

They are all right at some point. I would go D, B, C, A

brb77
Sep 22, 2022

it's C; assets are tracked in an asset inventory further damage is possible if not handled with care theft could occur etc; some form of evidence for asset conditions should be captured

Alex71Option: C
Feb 27, 2023

C. Take photos of the damage should be done at a disaster site before any item is removed, repaired, or replaced. Taking photos of the damage at a disaster site is important because it provides a record of the initial conditions and can help in the assessment of the extent of the damage. This record can be used to document the damage for insurance purposes and for use in any investigations that may be required. It can also be used to assist in the recovery process by providing a reference for what needs to be replaced or repaired. Communicating with the press (A), dispatching personnel to the disaster recovery (DR) site (B), and notifying all of the Board of Directors (D) are all important actions that may need to be taken in the event of a disaster, but they are not the first step that should be taken. The priority should be to assess the damage and document it by taking photos. In summary, taking photos of the damage is an important step that should be done at a disaster site before any item is removed, repaired, or replaced.

somkiatrOption: B
Jan 1, 2023

Why does we need to notify BOD ? Should we notify the crisis management team instead ?

74gjd_37Option: C
Sep 23, 2023

From the point of view of a Certified Information Systems Security Professional (CISSP), the best answer would be C: "Take photos of the damage". This is because photographic documentation is important for maintaining the integrity of the disaster site, as well as for insurance and legal purposes. It is also important to document the damage before any remediation work is done, as this can help to support any insurance claims or legal actions that may be necessary. As a CISSP, it is important to follow best practices for disaster recovery and to ensure that all necessary documentation is collected and preserved.

lferolmOption: B
Apr 23, 2023

It is not clear at all. D makes no sense, the recovery cannot be stop in case a BOD member is not located. C, pictures of a software? of the memory of a computer or files? the only that can have some logic is B.

Bach1968Option: D
Jul 6, 2023

this situation raise a valid point. In some cases, it may be necessary to notify the Board of Directors or senior management immediately after a disaster occurs, especially if the impact is significant and has the potential to affect the organization's operations, reputation, or financials. The decision of whether to notify the Board of Directors at the disaster site before any item is removed, repaired, or replaced would depend on the specific circumstances and the organization's incident response protocols. It's important to have clear communication channels and predefined roles and responsibilities in place to ensure effective decision-making and timely reporting to key stakeholders during a disaster. taking photo and documenting, is also very important prior of any action on ground

629f731Option: D
Jan 9, 2024

The answer as technicians is obvious "C", remember, we must think like a Manager, The manager would first notify the board of directors of the disaster. D is the answer

TheManiacOption: D
May 18, 2024

Guys yes, photos must be taken. But if the disaster is an outage, what are you gonna do with them? And you are not a technician. You are a manager. You first inform the Board of Directors

IT_Guy23Option: B
Sep 26, 2022

I'll go with B, we need to get DRP team employees on the site.

omarin25
Dec 25, 2022

C , you must take picture , asking about specific thing

oudmaster
Dec 26, 2022

If we look from human safety point of view, wont option B be the correct answer? ! what is the disaster site causes threat to human life?

omarin25
Jan 2, 2023

C , before remove anything you should picture it

Marzie
Apr 2, 2023

B makes most sense, cant take pictures without people on-site. Nothing to indicate that board are not aware of this already. Question is specifically about what to do before items are removed.

The1BelowAllOption: C
Apr 18, 2023

C is the answer. BOD has already been notified once DR is declared.

MShaaban
Aug 7, 2023

I would say C. What are you going to notify the board of directors with. You need to know what the damage is so that you have something to say to them.

georgegeorge125487Option: B
Aug 18, 2023

Secure the site material.

homeyslOption: C
Oct 17, 2023

C. Take evidence. Also BOD are just after the stocks.

DapengZhangOption: B
Nov 26, 2023

The sequence shall be, B>C>D>A send someone into site and cross check if the damage severity whether fulfill the criteria of disaster. if positive, the record the proof and notify top management, then align with press via PR channels.

[Removed]
Feb 20, 2024

There are 2 sites mentioned: disaster and disaster recovery

GuardianAngel
Feb 11, 2024

Answer: Send someone to the site. In studying with one of the udemy courses, I came across this outline of typical Diaster Recovery plan activation steps. I had selected 'take pictures, but now rethinking this questions based on new knowledge, the answer is send someone to the site. DR plan activation Steps: 1. Declaration of disaster 2. Activation of the DR team 3. Internal communications (ongoing from here on out) 4. Protection of human safety (e.g., evacuation) 5. Damage assessment 6. Execution of appropriate system-specific DRPs (each system and network should have its own DRP) 7. Recovery of mission-critical business processes/functions 8. Recovery of all other business processes/functions

homeyslOption: D
Mar 17, 2024

What's the use of the picture if the outage is from the service provider's end?

Vasyamba1Option: B
Mar 23, 2024

Human life and safety are on the first place! If the disaster site is the site where disaster occured and the disaster recovery site is the spare site, we need to dispatch personnel to the safe place first.

8b48948
Apr 24, 2024

C - preserve evidence

adc9365
Aug 28, 2024

D correct. You do the CISSP exam from the point of view of a CISO not a forensic analyst. Directors is your first action

BigITGuyOption: C
Apr 2, 2025

Not D - Notifying the Board is important for governance, but it is not an immediate step before handling physical assets at the disaster site.