Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresEasy

An organization relies heavily on cloud services for its operations. A recent security assessment revealed that several cloud-based applications are not regularly backed up, and there is no clear process for restoring data in the event of a service outage or cyberattack. Which aspect of security policies and procedures is most directly impacted by this finding?

  1. APhysical security controls
  2. BBusiness continuity and disaster recovery planning
  3. CAcceptable use policy enforcement
  4. DSecurity awareness and training programs
Show answer & explanation

Correct answer: B. Business continuity and disaster recovery planning

The lack of regular backups and a data restoration process directly impacts the organization's ability to continue operations and recover data after a disruptive event, which falls under business continuity and disaster recovery planning.

Why the other options are wrong

  • A. Physical security protects physical assets, which is distinct from cloud data backup and restoration.
  • C. Acceptable use policies govern user behavior, not data backup and recovery infrastructure.
  • D. Security awareness and training focus on educating users, not directly on data backup and restoration procedures.

Business Continuity Planning (BCP)

The process of creating systems of prevention and recovery to deal with potential threats to a company. It ensures that personnel and assets are protected and are able to function quickly in the event of a disaster.

  • Focuses on keeping business functions operational during disruptions.
  • Includes disaster recovery as a critical component.
  • Aims to minimize downtime and data loss.

Memory trick: Resilience is built on a strong plan to bounce back.

More Security Policies and Procedures questions