GRC Business Continuity and Resilience 4 — Questions and Answers
Question 1: A GRC analyst is assessing which business functions to prioritize in recovery. Which tool best supports this decision?
- Vulnerability scan
- Business Impact Analysis (BIA) (Correct answer)
- Penetration test
- Risk register update
Correct answer: Business Impact Analysis (BIA)
The BIA identifies critical business functions, their dependencies, and the impact of disruption, directly informing recovery prioritization.
Question 2: What term describes the maximum time a business process can be disrupted before the impact becomes unacceptable?
- Recovery Point Objective
- Recovery Time Objective
- Maximum Tolerable Downtime (MTD) (Correct answer)
- Service Level Agreement target
Correct answer: Maximum Tolerable Downtime (MTD)
MTD (also called MTPD — Maximum Tolerable Period of Disruption) defines the absolute maximum time a process can be unavailable before causing irreversible harm.
Question 3: During a parallel test, IT successfully restored systems at the alternate site while production remained online. What is the main limitation of this test?
- It is too expensive to conduct
- It does not verify that staff can actually shift to the alternate site under real conditions (Correct answer)
- It reveals too many vulnerabilities publicly
- It cannot test data backup integrity
Correct answer: It does not verify that staff can actually shift to the alternate site under real conditions
A parallel test validates technical recovery but does not prove the organization can fully operate from the alternate site since production is still running.
Question 4: Which BCP element ensures that third-party vendors critical to operations also maintain adequate continuity plans?
- Vendor risk management and supply chain continuity requirements (Correct answer)
- Internal audit checklist
- Data classification policy
- Incident response retainer
Correct answer: Vendor risk management and supply chain continuity requirements
Vendor risk management provisions in BCP require suppliers and critical third parties to demonstrate their own business continuity capabilities.
Question 5: A firm experiences a ransomware attack that encrypts all production data. Which BCP/DRP control would be most immediately useful?
- Updated risk register
- Clean, tested, and isolated data backups (Correct answer)
- Business impact analysis report
- Tabletop exercise results from last year
Correct answer: Clean, tested, and isolated data backups
Isolated and regularly tested backups allow data restoration without paying ransom, making them the primary recovery control for ransomware incidents.
Question 6: Which concept refers to the ability of an organization to anticipate, prepare for, respond to, and adapt to incremental change and sudden disruptions?
- Risk avoidance
- Organizational resilience (Correct answer)
- Business continuity compliance
- Fault tolerance
Correct answer: Organizational resilience
Organizational resilience encompasses the adaptive capacity of a business to withstand and recover from both gradual changes and abrupt disruptions.
Question 7: What should happen to a BCP immediately after an organization undergoes a major merger or acquisition?
- The plan remains valid since core processes do not change
- The plan must be reviewed and updated to reflect new organizational scope and dependencies (Correct answer)
- Testing frequency can be reduced during the integration period
- The acquired company's BCP automatically supersedes the existing one
Correct answer: The plan must be reviewed and updated to reflect new organizational scope and dependencies
Major organizational changes like mergers alter critical processes, personnel, systems, and dependencies, requiring immediate BCP review and revision.
A GRC analyst is assessing which business functions to prioritize in recovery.
Which tool best supports this decision?