Courseiva
easyMultiple Choice

CISA Practice Question: Is the PRIMARY purpose of a business impact…

Which of the following is the PRIMARY purpose of a business impact analysis (BIA) in business continuity planning?

⚠ Common exam trap

CISA often tests the distinction between the BIA (which determines criticality and recovery requirements) and the subsequent recovery strategy development (which identifies resources and procedures), so candidates must not confuse outputs of the BIA with activities that follow it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To determine the criticality of business processes and their recovery requirements

The primary purpose of a BIA is to identify and prioritize business processes based on their criticality to the organization and to determine the recovery time objectives (RTOs) and recovery point objectives (RPOs) for each. This analysis forms the foundation for the business continuity plan by establishing what must be recovered and how quickly, before any recovery strategies or resource requirements are defined.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    To determine the criticality of business processes and their recovery requirements

    Why this is correct

    A BIA identifies which business processes are most critical and quantifies their recovery time and recovery point objectives, prioritising continuity investment. This determines criticality and recovery requirements, distinguishing it from risk assessment, which evaluates threat likelihood and impact.

  • ✗

    To create a list of emergency contacts

    Why it's wrong here

    Emergency contact lists belong to the business continuity plan's response procedures, not the BIA, which quantifies the operational and financial impact of disruption over time. Contact compilation is tempting because it is a visible BCP artefact, but it neither prioritises processes nor establishes recovery time objectives.

  • ✗

    To identify the resources required for recovery

    Why it's wrong here

    Identifying recovery resources is a BCP strategy output derived after the BIA determines impact and RTO/RPO; the BIA itself establishes which processes matter and the consequences of their loss. Resource identification is tempting because it feels preparatory, yet it answers 'how', not the BIA's 'what and how much' question.

  • ✗

    To document the technical recovery procedures

    Why it's wrong here

    Technical recovery procedures are written into the continuity and disaster recovery plans after the BIA has set priorities and objectives; the BIA determines impact, not remediation steps. Documenting procedures is tempting because it is tangible BCP work, but it follows the BIA rather than constituting its purpose.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.