CAP CAP Business Continuity & Disaster Recovery Planning 2 — Questions and Answers
Question 1: A Business Impact Analysis (BIA) is a critical input to contingency planning. What is its primary output?
- A list of all software vulnerabilities in the system
- Identification of mission-critical functions, their recovery priorities, and maximum tolerable downtime (Correct answer)
- A detailed network architecture diagram
- Employee contact lists for emergency notifications
Correct answer: Identification of mission-critical functions, their recovery priorities, and maximum tolerable downtime
The BIA identifies which business functions are most critical, establishes recovery priorities, quantifies the impact of disruptions, and determines MTD, RTO, and RPO for each function.
Question 2: Maximum Tolerable Downtime (MTD) is the metric that defines which boundary in continuity planning?
- The point at which data loss becomes unrecoverable
- The absolute longest period a mission-essential function can be disrupted before causing catastrophic impact (Correct answer)
- The time required to activate an alternate processing site
- The number of hours between scheduled system maintenance windows
Correct answer: The absolute longest period a mission-essential function can be disrupted before causing catastrophic impact
MTD (also called Maximum Tolerable Period of Disruption) represents the threshold beyond which operational disruption would result in unacceptable mission, business, or legal consequences.
Question 3: Which contingency plan test type involves the least disruption to operations and tests only the plan documentation and personnel knowledge?
- Parallel test
- Failover test
- Tabletop exercise (Correct answer)
- Full interruption test
Correct answer: Tabletop exercise
A tabletop exercise is a discussion-based test where personnel walk through contingency plan scenarios without activating systems, making it the least disruptive form of contingency plan testing.
Question 4: Under FISMA, which federal publication serves as the primary guidance for federal information system contingency planning?
- NIST SP 800-53
- NIST SP 800-34 (Correct answer)
- NIST SP 800-30
- NIST SP 800-137
Correct answer: NIST SP 800-34
NIST SP 800-34, Contingency Planning Guide for Federal Information Systems, is the authoritative guidance for developing, testing, and maintaining federal IT contingency plans.
Question 5: When a federal agency activates its contingency plan and transitions operations to an alternate processing site, which activity should occur first?
- Notifying the Inspector General
- Activating the notification and escalation procedures per the contingency plan (Correct answer)
- Restoring all non-critical systems before mission-critical ones
- Decommissioning the primary site hardware
Correct answer: Activating the notification and escalation procedures per the contingency plan
Contingency plan activation begins with executing the notification and escalation procedures to alert key personnel, leadership, and stakeholders before beginning system recovery activities.
Question 6: What is the purpose of a 'warm site' in disaster recovery planning compared to a cold site?
- A warm site is geographically closer to the primary site than a cold site
- A warm site has pre-installed hardware and software but requires data restoration, unlike a cold site which has only space and power (Correct answer)
- A warm site is only used for classified systems
- A warm site provides full redundancy with live data replication
Correct answer: A warm site has pre-installed hardware and software but requires data restoration, unlike a cold site which has only space and power
A warm site has necessary hardware and software infrastructure pre-configured, reducing activation time compared to a cold site, but still requires restoring data from backups before operations resume.
A Business Impact Analysis (BIA) is a critical input to contingency planning.
What is its primary output?