Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

BCI CBCI - Certificate of the Business Continuity Institute (CBCI)

Page: 1 / 3
Total 90 questions

When carrying out the Business Impact Analysis (BIA) process, the Business Continuity professional should use a consistent approach to determine priorities of products, services, and activities. Which of the following is a method that could be used?

A.

A gap analysis

B.

A risk assessment matrix

C.

Pre-defined impact thresholds

D.

A standardized risk rating table

The purpose of a Business Continuity policy is to:

A.

Initiate the development of an effective response structure in case of disruption to products or services within the scope of the Business Continuity Management System (BCMS)

B.

Enable the Business Continuity professional to issue instructions to all on the changes that they will be required to make

C.

Share the outcomes of a Business Impact Analysis with internal and external stakeholders

D.

Establish shared understanding of the importance of a BCMS and its relevance to the organization

Why is a risk assessment usually conducted after a Business Impact Analysis (BIA) as part of the analysis stage?

A.

Conducting a BIA ties up personnel on this project; so resources are not available to conduct the risk assessment until after personnel are released from the BIA project

B.

Conducting the risk assessment after the BIA has identified priorities enables the risk assessment to maximise investment in risk treatments where they are most needed

C.

A risk assessment is not required until Business Continuity solutions based on the outcomes of the BIA have been developed for review

D.

Risk assessments are not required until after the organization's business plan has been updated to confirm any changes in plans as a result of the BIA

Business as usual (BAU) plans document processes for restoring an organization to its original state and should:

A.

Be developed in detail prior to any incident occurring

B.

Focus on resuming activities in reverse order of Recovery Time Objectives (RTOs)

C.

Be based on the availability of primary resources prior to the incident

D.

Take into consideration possibility of new vulnerabilities resulting from impacted resources

Which of the following is a factor that should be taken into consideration when developing an exercise program?

A.

It requires a series of events and activities scheduled over a period of time

B.

It is necessary to carry out exercises only once as initial tests will provide all of the required information

C.

A single type of exercise should be used for all so that participants become familiar with the structure and approach of the exercise activities

D.

It is necessary to carry out exercises for only a sample of the plans and recovery teams in place

Which of the following is NOT correct in relation to Business Continuity plans?

A.

They should contain detailed step-by-step instructions on what to do for every eventuality that could occur

B.

They may include scenario-specific plans that are designed to address a particular threat

C.

They should be validated before being deemed operational

D.

They should be kept up to date

One of the steps in the risk management process is to establish the risk treatment required. The purpose of risk treatment is to:

A.

Ensure that a named person within the organization takes responsibility for the monitoring and management of the risk

B.

Calculate a risk score based on the combination of the likelihood of the risk occurring and the consequences of this happening

C.

Mitigate each risk identified by reducing the likelihood of the risk occurring or by lowering the impact of disruption

D.

Ensure that regular updates on the current status of the risk are presented to top management

In relation to Solutions Design, a gap analysis is used to determine whether:

A.

The organization is performing at its optimum financial level

B.

Personnel are embracing Business Continuity sufficiently well to deliver Business Continuity requirements

C.

New strategies and solutions are in order to meet Business Continuity requirements

D.

The results of an external audit are justified in terms of internal evidence of Business Continuity achievements

Which of the following is essential to ensure the ongoing effectiveness and relevance of a Business Continuity Management System (BCMS) and should be built into the initial process to establish a BCMS?

A.

Determining how the BCMS will be monitored, reviewed and continually improved over time

B.

Developing internal and external communications systems to raise the profile of the BCMS and highlight successful steps in the development

C.

Carrying out health and safety risk assessments in all parts of the organization and making a commitment to repeat these assessments every year as part of the BCMS

D.

Ensuring compliance with legal requirements across the company and developing a register of any risks

The purpose of an external audit of the Business Continuity Management System (BCMS) is to:

A.

Confirm that the organization is fully prepared to respond to incidents

B.

Provide independent assurance on a set of Business Continuity processes and controls

C.

Assess the performance of the members of top management team in relation to Business Continuity

D.

Make recommendations on alternative ways of meeting recovery time objectives (RTOs)