Courseiva
hardMultiple Select

CISA Practice Question: Is evaluating its business continuity plan (BCP)…

An organization is evaluating its business continuity plan (BCP) to ensure alignment with the IT disaster recovery plan. Which TWO of the following are critical elements that should be included in the BCP to support effective business resilience?

⚠ Common exam trap

CISA often tests the boundary between BCP and DRP, causing candidates to select technical IT recovery items (application lists, network restoration steps) as BCP elements when the BCP should focus on business processes, manual workarounds, and stakeholder communication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Procedures for manual operations during system unavailability.

Option B is correct because a BCP must define manual workaround procedures (e.g., paper-based processing, offline approvals) so that essential business functions can continue while IT systems are unavailable, directly supporting business resilience during a disaster. Option D is correct because the BCP must include up-to-date contact information for key stakeholders, business unit owners, and emergency response teams so that activation, escalation, and coordination can occur quickly when an incident strikes. Option A is not the best fit because application recovery priorities belong primarily to the IT disaster recovery plan, which the BCP aligns with rather than duplicates. Option C is not a critical BCP element; a hardware and software license inventory is an asset management concern and does not by itself ensure continuity of business operations. Option E is also not appropriate because detailed network restoration procedures are technical DR runbooks, not business continuity content.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A list of all critical IT applications with their recovery priorities.

    Why it's wrong here

    A prioritised application list is a recovery dependency input, not a BCP element covering business processes, people and facilities. It is tempting because application criticality drives recovery sequencing, and the list would be correct as part of the IT disaster recovery plan.

  • ✓

    Procedures for manual operations during system unavailability.

    Why this is correct

    Manual workaround procedures let critical business functions continue while systems are unavailable, bridging the gap between IT recovery timelines and business tolerances. This satisfies the BCP requirement to sustain operations during disruption, ensuring resilience does not depend solely on restoring technology.

  • ✗

    A complete inventory of hardware and software licenses.

    Why it's wrong here

    Hardware and software licence inventories support asset and compliance management, not business resilience planning. It is tempting because recovery sites need licensed software, and the inventory would be correct for a software asset audit or licence true-up exercise.

  • ✓

    Contact information for key stakeholders and emergency response teams.

    Why this is correct

    Contact details for stakeholders and emergency response teams enable rapid activation, escalation and coordination when disruption occurs. This satisfies the BCP requirement for effective communication during incidents, ensuring decision-makers and responders can be reached immediately to execute recovery and continuity arrangements.

  • ✗

    Detailed step-by-step procedures for restoring network connectivity.

    Why it's wrong here

    Network restoration procedures belong in the IT disaster recovery plan, which the BCP aligns with rather than duplicates. It is tempting because connectivity underpins recovery, and such procedures would be correct within the technical DR runbook executed by infrastructure teams.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.