Courseiva
hardMultiple Select

CAS-004 Practice Question: Which THREE of the following are required…

Which THREE of the following are required components of a Business Continuity Plan (BCP) per ISO 22301?

⚠ Common exam trap

CompTIA often tests the distinction between a BCP (organizational continuity) and a DRP (technical recovery), leading candidates to mistakenly select detailed IT recovery procedures as a BCP component.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Scope and policy for business continuity

Option B is correct because ISO 22301 requires the BCMS to define its scope and establish a business continuity policy that sets the organization's objectives, commitments, and top-management direction for continuity. Option E is correct because the Business Impact Analysis (BIA) is a mandatory core element of ISO 22301; it identifies critical business functions, dependencies, and the maximum tolerable period of disruption (MTPD) that drive recovery priorities and objectives. Option D is correct because ISO 22301 requires documented communication and notification arrangements, including internal and external stakeholder warning, escalation, and crisis communication procedures during and after a disruption. Option A is not a required BCP component per ISO 22301 because detailed technical IT recovery procedures belong to IT disaster recovery planning (e.g., ISO/IEC 27031), which supports but is distinct from the business continuity management system. Option C is not required because vulnerability scanner configuration is a technical security control from vulnerability management, not a BCP element under ISO 22301.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Detailed technical recovery procedures for IT systems

    Why it's wrong here

    ISO 22301 requires strategic elements such as scope, objectives, risk assessment, business impact analysis and recovery priorities; detailed technical recovery procedures belong to IT disaster recovery plans supporting the BCP. It is tempting because recovery procedures are genuinely needed after disruption, but they sit below the BCP's management-system level.

  • ✓

    Scope and policy for business continuity

    Why this is correct

    ISO 22301 requires documented scope and policy as the foundation of the BCMS, defining which parts of the organisation, locations and services the plan covers and the top-management commitment governing it. This satisfies the stem's requirement for a mandatory BCP component under the standard.

  • ✗

    Vulnerability scanner configuration

    Why it's wrong here

    Vulnerability scanner configuration is a security control activity, not a BCP component; ISO 22301 expects business impact analysis, risk assessment, recovery objectives and documented continuity arrangements. It is tempting because scanners support resilience, but they address threat detection rather than the continuity planning requirements the standard specifies.

  • ✓

    Communication and notification plan

    Why this is correct

    A communication and notification plan satisfies ISO 22301's requirement for documented procedures to warn stakeholders, authorities and staff during disruption. It defines escalation paths, contact hierarchies and message templates, ensuring timely, accurate information flow. Without it, response coordination fails, so ISO 22301 mandates it as a core BCP component.

  • ✓

    Business Impact Analysis (BIA)

    Why this is correct

    A Business Impact Analysis identifies critical business functions and their recovery priorities, directly satisfying ISO 22301's requirement to determine recovery time objectives and dependencies. Without a BIA, the BCP cannot prioritise resources or justify recovery strategies, making it a mandatory foundational component of the management system.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.