Home › Certifications › CISM › Business Continuity, Recovery and Resilience
60 multiple-choice questions and 17 flashcards on Business Continuity, Recovery and Resilience, about 15% of the CISM bank. Every one carries a written rationale.
Business Continuity, Recovery and Resilience is one of 6 chapters in CoStudy's CISM — Certified Information Security Manager bank, and it holds 60 of the bank's 400 multiple-choice questions — roughly 15% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.
Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.
10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.
Which statement about the relationship between the business continuity plan and the disaster recovery plan is MOST accurate?
Answer: A — Continuity sustains business processes; recovery restores the supporting technology
A) Correct — continuity planning keeps critical business processes running by any means, including manual workarounds, while disaster recovery is the technology restoration discipline supporting it. B) reverses the hierarchy; continuity governs and DR serves it. C) is a persistent misconception; the two have distinct scopes and owners. D) invents a cause-based split that neither discipline uses.
Which condition would MOST justify raising a process's maximum tolerable downtime rather than investing in faster recovery?
Answer: B — A validated manual workaround can sustain the process longer
B) Correct — MTD reflects how long the business can survive without the process, so a proven workaround genuinely extends that tolerance and legitimately revises the figure. A) is a technology lifecycle issue that argues for investment, not for relaxing business tolerance. C) tempts because a clean history feels reassuring, but absence of past outages does not change the impact of a future one. D) is the classic trap of letting budget rewrite business impact rather than surfacing an underfunded risk for acceptance.
Post-incident lessons learned should be:
Answer: D — Blameless and structured, with owned actions tracked to closure
D is the key: a blameless review with tracked actions is what converts an incident into improvement. A suppresses future reporting. B withholds the findings from those who fund remediation. C skips the frequent, cheaper lessons.
A recovery strategy meets the recovery time objective but consistently fails the service delivery objective during tests. This means that:
Answer: A — Service resumes on time but below the capacity the business needs
A) Correct — the service delivery objective sets the acceptable degraded throughput during recovery operation, so failing it means the service is technically available but cannot carry the business. B) describes a recovery point objective failure. C) would be a recovery time objective failure, which the scenario states is met. D) tempts because a capacity shortfall causes business harm, but MTD measures duration of outage rather than level of service.
Which sequence correctly orders the constraints among recovery objectives for a given process?
Answer: C — The business sets MTD; RTO falls within it; RPO is a separate judgement
C) Correct — the business defines the outer tolerance for downtime, the recovery time objective must sit inside it, and the recovery point objective is a separate judgement about acceptable data loss. A) is a common misconception; an RPO can legitimately exceed an RTO, for example fast restoration of a system that tolerates a day of data loss. B) reverses the derivation, since MTD comes from impact analysis rather than from technical targets. D) inverts ownership entirely, letting technology set business tolerance.
The maximum tolerable outage is four days, but the organisation can only sustain reduced operations at its alternate site for three days before capacity is exhausted. This gap is BEST described as a shortfall against the:
Answer: C — Maximum tolerable outage in interim mode
C) Correct — maximum tolerable outage in interim operating mode captures how long the organisation can run in degraded alternate mode, and here that limit falls short of the recovery timeline required. A) concerns data loss and is not implicated. B) is the business tolerance for the disruption overall, which is not itself the constrained quantity here. D) describes the level of service sustained, not the duration for which it can be sustained.
What distinguishes a business continuity plan from a disaster recovery plan?
Answer: D — Continuity keeps business processes operating during disruption; recovery restores IT systems
D states the relationship correctly: continuity is the enterprise-wide plan covering people, premises, suppliers and communication, and disaster recovery is the technology subset that restores systems and data. Both derive their targets from the BIA. A denies a distinction the exam tests directly. B narrows continuity to IT. C and E simply reverse the two scopes, which is the most frequently seen error.
The HIGHEST-VALUE outcome of a mature incident management program is:
Answer: D — Reducing impact and recovery time through preparedness and learning
D is the key: maturity is measured by how well the organization absorbs and learns from incidents. A sets an unattainable goal. B optimizes cost rather than risk. C treats a legal obligation as something to evade.
BCP and DR plans should be TESTED:
Answer: D — Regularly and progressively, from tabletop through to full interruption
D is the key: escalating test methods build confidence and expose gaps before they matter. A treats the disaster as the test. B lets assurance scheduling drive readiness. C ignores that environments drift continuously.
An organisation reports that its recovery point objective is four hours, but backups are taken nightly and replicated once daily. The MOST accurate assessment is that:
Answer: A — The stated objective is not supported by the backup architecture
A) Correct — with a daily cycle, up to twenty-four hours of data can be lost, so the declared four-hour objective is aspirational rather than achievable and must be corrected or the architecture changed. B) confuses the recovery point objective with the recovery time objective, the most frequent error with these terms. C) confuses offsite placement with recovery currency. D) tempts because scoping by criticality is legitimate, but it does not rescue an objective stated for data the current design cannot protect.
4 cards from the 17 in this chapter.
Backup strategies?
3-2-1: 3 copies, 2 media types, 1 offsite. Test restores regularly.
What is a post-incident review meant to produce, and what makes it fail?
A validated timeline, identified root and contributing causes, an assessment of whether recovery objectives were met, and assigned corrective actions with owners and dates that feed back into the risk register and the plan. It fails when it becomes attribution of blame, or when actions are recorded without owners and never verified as closed.
RTO vs RPO?
RTO: max downtime acceptable. RPO: max data loss acceptable.
Rank the main business continuity and disaster recovery test types by rigour and state what each proves.
Desk check or document review proves the plan is current and complete. Walkthrough or tabletop proves roles, decisions and escalation are understood. Simulation proves the team can execute procedures under realistic pressure. Parallel test proves recovery systems produce correct results while production keeps running. Full interruption proves genuine recovery by transferring live operations, and carries real business risk.
These are a sample. The full Business Continuity, Recovery and Resilience chapter runs 77 items with per-chapter progress tracking, on the web and in the iOS app.