CSC Business Continuity & Disaster Recovery Planning 1 — Questions and Answers
Question 1: What is the primary purpose of a Business Impact Analysis (BIA) in a security consulting engagement?
- To identify and prioritize critical business functions and assess the impact of disruptions (Correct answer)
- To document all physical security vulnerabilities in a facility
- To create a budget for emergency response equipment
- To train staff on evacuation procedures
Correct answer: To identify and prioritize critical business functions and assess the impact of disruptions
A BIA identifies critical business functions and quantifies the potential impact of disruptions, forming the foundation for continuity planning.
Question 2: The Recovery Time Objective (RTO) is best defined as:
- The maximum tolerable amount of data loss measured in time
- The target duration within which a business process must be restored after a disruption (Correct answer)
- The time required to back up all critical data systems
- The period during which an organization can operate at reduced capacity
Correct answer: The target duration within which a business process must be restored after a disruption
RTO defines the maximum acceptable length of time that a business process can be down before the impact becomes unacceptable.
Question 3: Which of the following best describes a Recovery Point Objective (RPO)?
- The specific location designated as the alternate recovery site
- The maximum acceptable amount of data loss measured in time prior to a disaster (Correct answer)
- The number of personnel required to restore critical operations
- The time needed to test the disaster recovery plan
Correct answer: The maximum acceptable amount of data loss measured in time prior to a disaster
RPO defines the maximum age of data that an organization can afford to lose, essentially setting the backup frequency requirement.
Question 4: A security consultant recommending a 'hot site' as an alternate recovery facility is describing:
- A facility with basic infrastructure but no pre-installed equipment
- A fully equipped, immediately operational duplicate of the primary site (Correct answer)
- A mobile command center that can be deployed within 24 hours
- A shared facility leased with other organizations to reduce costs
Correct answer: A fully equipped, immediately operational duplicate of the primary site
A hot site is a fully equipped, immediately operational facility that mirrors the primary site and can take over operations with minimal delay.
Question 5: When developing a Business Continuity Plan (BCP), which step should be completed FIRST?
- Drafting evacuation procedures for all personnel
- Conducting a Business Impact Analysis (BIA) (Correct answer)
- Identifying alternate work-from-home policies
- Purchasing backup power generators
Correct answer: Conducting a Business Impact Analysis (BIA)
The BIA must be completed first to identify critical functions and set recovery priorities before any continuity strategies can be designed.
Question 6: In the context of disaster recovery, a 'tabletop exercise' is primarily used to:
- Physically simulate a full system shutdown and recovery
- Test network failover capabilities under live conditions
- Walk stakeholders through a simulated scenario to evaluate plan effectiveness (Correct answer)
- Measure the actual RTO of critical systems during a controlled outage
Correct answer: Walk stakeholders through a simulated scenario to evaluate plan effectiveness
A tabletop exercise is a discussion-based simulation where participants work through a scenario to identify gaps in the plan without operational disruption.
Question 7: Which standard provides internationally recognized guidelines for Business Continuity Management Systems?
- ISO 27001
- NFPA 1600
- ISO 22301 (Correct answer)
- ASIS SPC.1
Correct answer: ISO 22301
ISO 22301 is the international standard specifically for Business Continuity Management Systems (BCMS), outlining requirements for planning, implementing, and improving continuity capabilities.
What is the primary purpose of a Business Impact Analysis (BIA) in a security consulting engagement?