Pre-Summer Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

BCI CBCI - Certificate of the Business Continuity Institute (CBCI)

Page: 4 / 6
Total 176 questions

Which of the following is essential to ensure the ongoing effectiveness and relevance of a Business Continuity Management System (BCMS) and should be built into the initial process to establish a BCMS?

A.

Determining how the BCMS will be monitored, reviewed and continually improved over time

B.

Developing internal and external communications systems to raise the profile of the BCMS and highlight successful steps in the development

C.

Carrying out health and safety risk assessments in all parts of the organization and making a commitment to repeat these assessments every year as part of the BCMS

D.

Ensuring compliance with legal requirements across the company and developing a register of any risks

When establishing a Business Continuity Management System (BCMS), engagement with stakeholders is important. Which of the following is NOT a reason for engaging with internal stakeholders?

A.

Existing policies and procedures may be relevant to the BCMS so early identification will reduce the risk for duplication of work

B.

Early collaboration with colleagues will engage them in the process and secure support for the ongoing development and implementation of the BCMS

C.

Engagement of stakeholders will reduce the potential for conflict at later stages of the programme

D.

Involving stakeholders will reduce the workload and responsibilities of the Business Continuity Professional as administrative activities can be delegated to other staff

One of the steps in the risk management process is to establish the risk treatment required. The purpose of risk treatment is to:

A.

Ensure that a named person within the organization takes responsibility for the monitoring and management of the risk

B.

Calculate a risk score based on the combination of the likelihood of the risk occurring and the consequences of this happening

C.

Mitigate each risk identified by reducing the likelihood of the risk occurring or by lowering the impact of disruption

D.

Ensure that regular updates on the current status of the risk are presented to top management

Which of the following is NOT correct in relation to Business Continuity plans?

A.

They should contain detailed step-by-step instructions on what to do for every eventuality that could occur

B.

They may include scenario-specific plans that are designed to address a particular threat

C.

They should be validated before being deemed operational

D.

They should be kept up to date

When establishing governance for a Business Continuity Management System (BCMS), which of the following will be responsible for developing and communicating the Business Continuity policy and for promoting a Business Continuity culture by leading by example?

A.

Business Continuity Plan Owners

B.

Departmental Representatives

C.

Top Management

D.

Business Continuity Professional

Which of the following is an indicator that top management is embracing Business Continuity?

A.

Business Continuity is part of the organization's strategic planning and is reviewed regularly

B.

The organization's health and safety risk assessments are recorded as required

C.

The organization maintains full compliance with legal and regulatory requirements

D.

The organization's Business Continuity operational plans are kept up to date

Business as usual (BAU) plans document processes for restoring an organization to its original state and should:

A.

Be developed in detail prior to any incident occurring

B.

Focus on resuming activities in reverse order of Recovery Time Objectives (RTOs)

C.

Be based on the availability of primary resources prior to the incident

D.

Take into consideration possibility of new vulnerabilities resulting from impacted resources

Which of the following is NOT part of the process to implement solutions to resume business operations?

A.

Ensuring alignment with the response structure and plans

B.

Providing training for users of solutions and support staff

C.

Updating the Activities Business Impact Analysis (BIA) to take into account the effect of the solutions on priority activities

D.

Complying with the organization's project management procedures

Analysing information about how an organization has responded to incidents, including engagement with those impacted and its approach to responsibility, can provide insight into the organization's:

A.

Culture

B.

Business targets

C.

Business plan

D.

Structure

Which of the following will determine the way that an organization uses Business Impact Analysis (BIA)?

A.

Consultation with internal and external stakeholders on their views of priorities and risks

B.

The size, complexity and type of organization

C.

The outcomes of exercises testing existing BC plans

D.

Feedback from risk management professionals