ISC Exam Questions

Which of the following is not an example of an operation control?

Which of the following is not an example of an operation control?

A.
backup and recovery

B.
audit trails

C.
contingency planning

D.
operations procedures

Explanation:
“Operation controls are the mechanisms and daily procedures that provide protection for systems.”
When designing a protection scheme for resources, it is important to keep the following aspects or
elements of the IT infrastructure in mind: Communication hardware/software Boundary devices
Processing equipment Password files Application program libraries Application source code Vendor
software Operating System System Utilities Directories and address tables Proprietary packages
Main storage Removable storage Sensitive/critical data System logs/audit trails Violation reports

Backup files and media Sensitive forms and printouts Isolated devices, such as printers and faxes
Telephone network” Pg 406-407 Tittel: CISSP Study Guide