easyMultiple Choice
CISA Practice Question: Is the PRIMARY purpose of a business impact…
Which of the following is the PRIMARY purpose of a business impact analysis (BIA) in business continuity planning?
⚠ Common exam trap
CISA often tests the distinction between the BIA (which determines criticality and recovery requirements) and the subsequent recovery strategy development (which identifies resources and procedures), so candidates must not confuse outputs of the BIA with activities that follow it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To determine the criticality of business processes and their recovery requirements
The primary purpose of a BIA is to identify and prioritize business processes based on their criticality to the organization and to determine the recovery time objectives (RTOs) and recovery point objectives (RPOs) for each. This analysis forms the foundation for the business continuity plan by establishing what must be recovered and how quickly, before any recovery strategies or resource requirements are defined.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
To determine the criticality of business processes and their recovery requirements
Why this is correct
A BIA identifies which business processes are most critical and quantifies their recovery time and recovery point objectives, prioritising continuity investment. This determines criticality and recovery requirements, distinguishing it from risk assessment, which evaluates threat likelihood and impact.
- ✗
To create a list of emergency contacts
Why it's wrong here
Emergency contact lists belong to the business continuity plan's response procedures, not the BIA, which quantifies the operational and financial impact of disruption over time. Contact compilation is tempting because it is a visible BCP artefact, but it neither prioritises processes nor establishes recovery time objectives.
- ✗
To identify the resources required for recovery
Why it's wrong here
Identifying recovery resources is a BCP strategy output derived after the BIA determines impact and RTO/RPO; the BIA itself establishes which processes matter and the consequences of their loss. Resource identification is tempting because it feels preparatory, yet it answers 'how', not the BIA's 'what and how much' question.
- ✗
To document the technical recovery procedures
Why it's wrong here
Technical recovery procedures are written into the continuity and disaster recovery plans after the BIA has set priorities and objectives; the BIA determines impact, not remediation steps. Documenting procedures is tempting because it is tangible BCP work, but it follows the BIA rather than constituting its purpose.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.