CIM Disaster Recovery & Business Continuity 5 — Questions and Answers
Question 1: After a declared disaster, the incident manager activates the BCP. What is typically the FIRST operational step?
- Conduct a post-incident review
- Notify and assemble the Business Continuity Team and assess the scope of impact (Correct answer)
- Restore all IT systems to full production capacity
- Issue a press release to customers
Correct answer: Notify and assemble the Business Continuity Team and assess the scope of impact
The first operational step upon BCP activation is mobilizing the BC team and performing an initial damage and impact assessment to guide all subsequent recovery actions.
Question 2: Which of the following best describes 'cyber resilience' in the context of incident management and business continuity?
- The ability to prevent all cyberattacks through technical controls alone
- The capacity to anticipate, withstand, recover from, and adapt to adverse cyber conditions (Correct answer)
- The practice of encrypting all organizational data at rest
- A compliance framework mandated by federal law for financial institutions
Correct answer: The capacity to anticipate, withstand, recover from, and adapt to adverse cyber conditions
Cyber resilience integrates cybersecurity and business continuity principles, acknowledging that some incidents will succeed and focusing on minimizing impact and enabling rapid recovery.
Question 3: A company's RTO for its order management system is 4 hours, but testing shows actual recovery takes 7 hours. What is the most appropriate corrective action?
- Extend the RTO to 7 hours to match actual performance
- Invest in capabilities (automation, pre-staged resources) to reduce actual recovery time to meet the 4-hour RTO (Correct answer)
- Cancel future DR tests to avoid exposing the gap
- Accept the gap and update the BIA to reflect lower system criticality
Correct answer: Invest in capabilities (automation, pre-staged resources) to reduce actual recovery time to meet the 4-hour RTO
The RTO is set by business need; when actual recovery time exceeds it, the organization must improve its recovery capabilities rather than relaxing the objective.
Question 4: What is the purpose of a 'call tree' (or notification cascade) in a business continuity plan?
- To map all network connections between the primary and recovery sites
- To provide a structured, sequential notification process ensuring all key personnel are contacted rapidly during an incident (Correct answer)
- To document the escalation path for IT help desk tickets
- To outline the decision logic for declaring a disaster
Correct answer: To provide a structured, sequential notification process ensuring all key personnel are contacted rapidly during an incident
A call tree distributes the notification burden by having each person contact a small group, accelerating communication to all stakeholders without relying on a single point of contact.
Question 5: Which element of a BCP ensures that recovery priorities remain aligned with current business strategy as the organization evolves?
- Annual BIA reviews and plan updates triggered by significant business changes (Correct answer)
- A one-time executive sign-off during initial plan creation
- Storing the plan in a secure vault with restricted access
- Outsourcing all BC responsibilities to a third-party vendor
Correct answer: Annual BIA reviews and plan updates triggered by significant business changes
Regular BIA reviews and change-triggered plan updates ensure that recovery priorities, RTOs, and RPOs reflect the organization's current critical functions and strategic priorities.
Question 6: In a multi-tenant cloud environment, who is primarily responsible for ensuring business continuity for customer workloads?
- The cloud provider is solely responsible for all continuity and recovery
- Responsibility is shared: the cloud provider ensures platform availability while the customer designs and manages application-level continuity (Correct answer)
- The customer's cyber insurance carrier
- Government regulators who license the cloud provider
Correct answer: Responsibility is shared: the cloud provider ensures platform availability while the customer designs and manages application-level continuity
The shared responsibility model means cloud providers guarantee infrastructure availability, but customers must architect their applications for resilience, backup, and recovery.
Question 7: Which type of BCP exercise involves actual evacuation of a facility and physical movement of staff to an alternate location to validate logistical assumptions?
- Tabletop exercise
- Walkthrough drill
- Full-scale simulation exercise (Correct answer)
- Structured walk-through review
Correct answer: Full-scale simulation exercise
A full-scale simulation (or live-play) exercise physically enacts the BCP, including evacuation and relocation, making it the most realistic and costly test type.
After a declared disaster, the incident manager activates the BCP.
What is typically the FIRST operational step?