20+ practice questions focused on Business Continuity, DR & Incident Response — one of the most tested topics on the ISC2 Certified in Cybersecurity CC exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Business Continuity, DR & Incident Response PracticeA SOC analyst receives an alert indicating a user executed a PowerShell script that initiated outbound connections to an external IP. The script was delivered via email attachment. Which incident response phase is MOST appropriate for containing this threat?
Explanation: When an alert is received, identification has already occurred. The next step is to contain the threat, which is typically part of the eradication phase in the ISC2 CC framework. Containment activities such as isolating the system and blocking connections are performed during the eradication phase. Therefore, option B (Eradication phase) is the most appropriate for containing the threat.
An organization uses a primary data center and a backup site 500 miles away. The backup site replicates data synchronously. Which risk is MOST likely introduced by this configuration?
Explanation: Synchronous replication requires the primary site to wait for an acknowledgment from the backup site before completing each write operation. The 500-mile distance introduces a minimum round-trip latency of approximately 8-10 ms (based on fiber optic propagation at ~200 km/ms), which directly increases the time taken for write operations. This latency impact is the most likely risk introduced by this configuration.
Which THREE elements are essential components of a business continuity plan (BCP)?
Explanation: A business continuity plan must be grounded in a business impact analysis (BIA), so option B is correct because the BIA identifies critical business functions, recovery time objectives (RTOs), and recovery point objectives (RPOs) that drive the entire continuity strategy. Option A is correct because data backup schedules and procedures are essential to restore systems and data within the RTO/RPO targets defined by the BIA, directly enabling recovery of operations. Option D is correct because emergency contact lists ensure the right personnel, vendors, and stakeholders can be reached immediately during a disruption to activate and coordinate the BCP. Option C is not essential to a BCP because an incident response team roster belongs to the incident response plan, which handles detection and containment of security events rather than long-term business continuity. Option E is not essential because detailed network topology diagrams are supporting technical documentation, not a core BCP element, and continuity planning focuses on business processes and recovery priorities rather than network design detail.
Based on the backup schedule, what is the maximum potential data loss?
Explanation: Maximum potential data loss is determined by the interval between the last successful backup and the point of failure. In a differential backup scheme, each differential contains all changes since the last full backup. If the most recent differential backup fails or is unavailable, the last successful backup becomes the previous differential. Here, the backup schedule includes a full backup on Monday at 01:00 and differential backups every 12 hours starting Tuesday at 01:00 (i.e., Tuesday 01:00, Tuesday 13:00, Wednesday 01:00, etc.). To maximize potential data loss, we assume the most recent differential backup (Tuesday 13:00) is lost, so the last successful backup is the differential from Tuesday 01:00. If a failure occurs just before the next scheduled differential (Wednesday 10:00), the data loss spans from Tuesday 01:00 to Wednesday 10:00, which is 33 hours. This is the maximum possible data loss given the schedule. Answer C correctly identifies this.
An organization experiences a ransomware attack that encrypts critical file servers. The backups are stored on a separate network segment but are also encrypted. The incident response team suspects the attacker compromised the backup system using stored credentials. Which best practice should have been implemented to prevent this?
Explanation: Enabling multi-factor authentication (MFA) on backup system access would have prevented the attacker from using stored credentials to compromise the backup system. MFA requires an additional authentication factor beyond just a password or stored token, making credential theft or reuse insufficient for access. This directly addresses the attack vector described—stolen credentials—rather than relying solely on network segmentation or encryption.
+15 more Business Continuity, DR & Incident Response questions available
Practice all Business Continuity, DR & Incident Response questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Business Continuity, DR & Incident Response. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Business Continuity, DR & Incident Response questions on the CC frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Business Continuity, DR & Incident Response is tested as part of the ISC2 Certified in Cybersecurity CC blueprint. Practicing with targeted Business Continuity, DR & Incident Response questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CC practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Business Continuity, DR & Incident Response is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Business Continuity, DR & Incident Response practice session with instant scoring and detailed explanations.
Start Business Continuity, DR & Incident Response Practice →