Practice ISC Contingency Management questions with full explanations on every answer.
Start practicing
Contingency Management — choose a session length
Free · No account required
Click any question to see the full explanation and answer options, or start a focused practice session above.
Your organization uses a 'Warm Site' for its disaster recovery strategy. During a recent audit, you find that the site lacks the necessary bandwidth to support peak production traffic. What is the most appropriate management response?
2Following a ransomware attack, the organization must decide whether to invoke the DRP or remain in a degraded state while security teams perform forensics. What is the ISSMP's primary responsibility in this decision-making process?
3You are auditing a third-party disaster recovery service provider. Which metric provides the most accurate evidence that the provider can meet your organization's required recovery point for a database cluster?
4During a disaster recovery simulation for a hybrid cloud environment, you discover that the automated orchestration tool fails to restore dependencies in the correct order because the cloud provider's metadata tags were purged. What is the most effective administrative control to prevent this during a real event?
5Which document serves as the primary governing authority to define the triggers, escalation paths, and communication roles during a declared crisis event?
6Which of the following is the most effective method for testing the efficacy of a Business Continuity Plan without disrupting production operations?
7Your organization has adopted a cloud-native microservices architecture. Which strategy is most appropriate for maintaining business continuity in the event of a regional cloud provider outage?
8An ISSMP is overseeing a BCP program and notes that the current Business Impact Analysis (BIA) is heavily focused on RTO but lacks a critical dependency mapping for cross-functional business processes. Which specific action should the ISSMP prioritize to address the systemic risk of cascading failure during a disaster?
9You are implementing a disaster recovery strategy for a database that uses synchronous replication. What is the most significant trade-off you must accept by enforcing this configuration?
10Your organization uses a 'Hot Site' with hardware-level replication. During a disaster, the primary site becomes unavailable, but the failover fails due to a 'Split-Brain' scenario. What is the fundamental cause of this?
11When designing the Crisis Communication Plan, why is it essential to establish pre-approved communication templates?
12What is the primary objective of a 'lessons learned' meeting conducted after a disaster recovery exercise?
13When classifying business processes for BCP, what is the 'Recovery Time Objective' (RTO) most effectively used for?
14An ISSMP is revising the BCP to account for 'Supply Chain Resiliency'. Which approach is best for verifying that critical third-party vendors can meet the organization's recovery requirements?
15During a BCP planning session, the executive team is debating the 'Maximum Tolerable Downtime' (MTD) for a legacy internal application. What is the correct way to define this metric?
16Your organization has decided to use a 'Cloud Disaster Recovery' service. The vendor provides a 'Pilot Light' strategy. What does this mean for your organization's recovery capability?
17An ISSMP is reviewing the Business Continuity Plan (BCP) for a critical application. Which TWO of the following factors should be considered when defining the 'Maximum Tolerable Downtime' (MTD)?
18In a decentralized organization, which approach to BCP management ensures both local agility and global alignment?
19Which THREE of the following are essential components of a robust Crisis Management Plan?
20During a BIA review, you need to identify critical assets and their recovery requirements. Which TWO of the following inputs are essential for this classification process?
21Which TWO of the following are primary risks associated with an 'asynchronous' data replication strategy?
22Which THREE of the following strategies should be included in a 'Disaster Recovery Program Oversight' function to ensure long-term viability?
23When designing a Disaster Recovery Program, which THREE of the following represent common 'single points of failure' that must be addressed?
24Which TWO of the following are effective ways to improve 'Crisis Management Leadership' effectiveness during an incident?
The Contingency Management domain covers the key concepts tested in this area of the ISC exam blueprint published by (ISC)². Courseiva provides free domain-focused practice, mock exams, missed-question review, and readiness tracking across all ISC domains — no account required.
The Courseiva ISC question bank contains 24 questions in the Contingency Management domain. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Contingency Management domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included