
Certified Information Systems Security Professional
Domain 1Objective 7
1.7 - Identify, Analyze, Assess, Prioritize, and Implement Business Continuity (BC) Requirements CISSP Practice Questions (Page 1)
Part of the Security and Risk Management domain, which accounts for 16% of the CISSP exam. ISC2 does not publish an official question count, but from its 180-minute exam (~70–120 total, ~11–19 in this domain), expect 1–2 from this objective — we provide 31 practice questions to prepare you well beyond it. (estimate)
31questions here
7free pages
8concepts
16%of the exam
Questions 1–5
- 1
A financial services firm relies on a cloud-based SaaS provider for its customer relationship management (CRM) system. The BIA identifies this as a critical dependency with an RTO of 4 hours. The provider's standard SLA guarantees 99.9% uptime but does not specify restoration time after an outage. The firm's BC plan must ensure the CRM is recoverable within the RTO. What is the most effective strategy to incorporate this external dependency into the BC plan?
Select an answer first - 2
A retail company's BIA identifies three critical functions: online order processing (RTO of 2 hours), in-store point-of-sale (POS) transactions (RTO of 8 hours), and inventory management (RTO of 24 hours). The company has a limited budget and can only fully fund recovery strategies for one function in the current fiscal year. Which function should receive the highest priority for funding?
Select an answer first - 3
In the context of impact assessment, what does the Recovery Point Objective (RPO) define?
Select an answer first - 4
A global manufacturer's BIA identifies a single specialized component supplier as critical. This supplier is the only source for a part used in the company's flagship product. The supplier is located in a region prone to earthquakes. The company's risk appetite allows a maximum of 3 days of production downtime. The supplier's lead time for the component is 2 weeks, and the company maintains a 5-day inventory buffer. What is the most significant risk to the company's continuity?
Select an answer first - 5
A hospital is conducting a BIA for its patient-record system. The BIA team has collected data from department heads, including the maximum downtime each department can tolerate and the financial and operational impacts of a disruption. The team is now analyzing the data to identify the criticality of each department's reliance on the system. What is the next step in the BIA process after data collection and analysis?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISC2. “CISSP” is a trademark of its owner, used for identification only.