CoStudy

HomeCertificationsCISM › Business Continuity, Recovery and Resilience

Business Continuity, Recovery and Resilience — CISM practice questions

60 multiple-choice questions and 17 flashcards on Business Continuity, Recovery and Resilience, about 15% of the CISM bank. Every one carries a written rationale.

Written and maintained by Nick Burton · last updated 2026-08-22 · how we write and review questions

What this chapter covers

Business Continuity, Recovery and Resilience is one of 6 chapters in CoStudy's CISM — Certified Information Security Manager bank, and it holds 60 of the bank's 400 multiple-choice questions — roughly 15% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.

Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.

Free Business Continuity, Recovery and Resilience practice questions

10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.

Which statement about the relationship between the business continuity plan and the disaster recovery plan is MOST accurate?

  1. Continuity sustains business processes; recovery restores the supporting technology
  2. The disaster recovery plan governs the business continuity plan's invocation criteria
  3. They are alternative names for the same plan in different jurisdictions
  4. The continuity plan applies to cyber events and the recovery plan to natural events

Answer: A — Continuity sustains business processes; recovery restores the supporting technology

A) Correct — continuity planning keeps critical business processes running by any means, including manual workarounds, while disaster recovery is the technology restoration discipline supporting it. B) reverses the hierarchy; continuity governs and DR serves it. C) is a persistent misconception; the two have distinct scopes and owners. D) invents a cause-based split that neither discipline uses.

Which condition would MOST justify raising a process's maximum tolerable downtime rather than investing in faster recovery?

  1. The recovery infrastructure is nearing end of support
  2. A validated manual workaround can sustain the process longer
  3. The process has not experienced an outage in five years
  4. The business owner considers the current recovery cost excessive

Answer: B — A validated manual workaround can sustain the process longer

B) Correct — MTD reflects how long the business can survive without the process, so a proven workaround genuinely extends that tolerance and legitimately revises the figure. A) is a technology lifecycle issue that argues for investment, not for relaxing business tolerance. C) tempts because a clean history feels reassuring, but absence of past outages does not change the impact of a future one. D) is the classic trap of letting budget rewrite business impact rather than surfacing an underfunded risk for acceptance.

Post-incident lessons learned should be:

  1. Used to identify which individuals were responsible for the failure
  2. Kept within the response team rather than shared with leadership
  3. Optional, and conducted only after incidents of the highest severity
  4. Blameless and structured, with owned actions tracked to closure

Answer: D — Blameless and structured, with owned actions tracked to closure

D is the key: a blameless review with tracked actions is what converts an incident into improvement. A suppresses future reporting. B withholds the findings from those who fund remediation. C skips the frequent, cheaper lessons.

A recovery strategy meets the recovery time objective but consistently fails the service delivery objective during tests. This means that:

  1. Service resumes on time but below the capacity the business needs
  2. Data loss has exceeded the agreed recovery point tolerance
  3. The alternate site could not be activated within the planned window
  4. The maximum tolerable downtime for the process has been exceeded

Answer: A — Service resumes on time but below the capacity the business needs

A) Correct — the service delivery objective sets the acceptable degraded throughput during recovery operation, so failing it means the service is technically available but cannot carry the business. B) describes a recovery point objective failure. C) would be a recovery time objective failure, which the scenario states is met. D) tempts because a capacity shortfall causes business harm, but MTD measures duration of outage rather than level of service.

Which sequence correctly orders the constraints among recovery objectives for a given process?

  1. RPO must always be shorter than the RTO, which must be shorter than the MTD
  2. MTD is derived from the RTO, which is in turn derived from the RPO
  3. The business sets MTD; RTO falls within it; RPO is a separate judgement
  4. RTO and RPO are set by IT; MTD is then calculated from their sum

Answer: C — The business sets MTD; RTO falls within it; RPO is a separate judgement

C) Correct — the business defines the outer tolerance for downtime, the recovery time objective must sit inside it, and the recovery point objective is a separate judgement about acceptable data loss. A) is a common misconception; an RPO can legitimately exceed an RTO, for example fast restoration of a system that tolerates a day of data loss. B) reverses the derivation, since MTD comes from impact analysis rather than from technical targets. D) inverts ownership entirely, letting technology set business tolerance.

The maximum tolerable outage is four days, but the organisation can only sustain reduced operations at its alternate site for three days before capacity is exhausted. This gap is BEST described as a shortfall against the:

  1. Recovery point objective for the process
  2. Maximum tolerable outage for the process
  3. Maximum tolerable outage in interim mode
  4. Service delivery objective during the recovery period

Answer: C — Maximum tolerable outage in interim mode

C) Correct — maximum tolerable outage in interim operating mode captures how long the organisation can run in degraded alternate mode, and here that limit falls short of the recovery timeline required. A) concerns data loss and is not implicated. B) is the business tolerance for the disruption overall, which is not itself the constrained quantity here. D) describes the level of service sustained, not the duration for which it can be sustained.

What distinguishes a business continuity plan from a disaster recovery plan?

  1. The two terms describe the same plan and differ only in the vocabulary the auditor happens to prefer
  2. The continuity plan addresses information technology recovery and nothing outside that boundary
  3. The disaster recovery plan is the broader of the two and contains the continuity plan within it
  4. Continuity keeps business processes operating during disruption; recovery restores IT systems
  5. The disaster recovery plan governs business processes while continuity governs the technology estate

Answer: D — Continuity keeps business processes operating during disruption; recovery restores IT systems

D states the relationship correctly: continuity is the enterprise-wide plan covering people, premises, suppliers and communication, and disaster recovery is the technology subset that restores systems and data. Both derive their targets from the BIA. A denies a distinction the exam tests directly. B narrows continuity to IT. C and E simply reverse the two scopes, which is the most frequently seen error.

The HIGHEST-VALUE outcome of a mature incident management program is:

  1. Eliminating security incidents entirely across the whole estate
  2. Minimizing total security spend while sustaining control coverage
  3. Avoiding any contact with regulators about incidents that have occurred
  4. Reducing impact and recovery time through preparedness and learning

Answer: D — Reducing impact and recovery time through preparedness and learning

D is the key: maturity is measured by how well the organization absorbs and learns from incidents. A sets an unattainable goal. B optimizes cost rather than risk. C treats a legal obligation as something to evade.

BCP and DR plans should be TESTED:

  1. Only after a real disaster has exercised the plan under live conditions
  2. When the internal or external auditor requests evidence of a test
  3. Once at plan creation, then again only if the plan is materially rewritten
  4. Regularly and progressively, from tabletop through to full interruption

Answer: D — Regularly and progressively, from tabletop through to full interruption

D is the key: escalating test methods build confidence and expose gaps before they matter. A treats the disaster as the test. B lets assurance scheduling drive readiness. C ignores that environments drift continuously.

An organisation reports that its recovery point objective is four hours, but backups are taken nightly and replicated once daily. The MOST accurate assessment is that:

  1. The stated objective is not supported by the backup architecture
  2. The objective is met if restoration completes within four hours
  3. The objective is met because the backup is replicated offsite
  4. The objective applies only to data classified as critical

Answer: A — The stated objective is not supported by the backup architecture

A) Correct — with a daily cycle, up to twenty-four hours of data can be lost, so the declared four-hour objective is aspirational rather than achievable and must be corrected or the architecture changed. B) confuses the recovery point objective with the recovery time objective, the most frequent error with these terms. C) confuses offsite placement with recovery currency. D) tempts because scoping by criticality is legitimate, but it does not rescue an objective stated for data the current design cannot protect.

Business Continuity, Recovery and Resilience flashcards

4 cards from the 17 in this chapter.

Backup strategies?

3-2-1: 3 copies, 2 media types, 1 offsite. Test restores regularly.

What is a post-incident review meant to produce, and what makes it fail?

A validated timeline, identified root and contributing causes, an assessment of whether recovery objectives were met, and assigned corrective actions with owners and dates that feed back into the risk register and the plan. It fails when it becomes attribution of blame, or when actions are recorded without owners and never verified as closed.

RTO vs RPO?

RTO: max downtime acceptable. RPO: max data loss acceptable.

Rank the main business continuity and disaster recovery test types by rigour and state what each proves.

Desk check or document review proves the plan is current and complete. Walkthrough or tabletop proves roles, decisions and escalation are understood. Simulation proves the team can execute procedures under realistic pressure. Parallel test proves recovery systems produce correct results while production keeps running. Full interruption proves genuine recovery by transferring live operations, and carries real business risk.

Practise the full chapter

These are a sample. The full Business Continuity, Recovery and Resilience chapter runs 77 items with per-chapter progress tracking, on the web and in the iOS app.

Open CISM in CoStudy →

Other CISM chapters

All CISM practice questions →