mediumMultiple Choice
CRISC Practice Question: A business continuity manager wants to identify…
A business continuity manager wants to identify risks that could disrupt critical business processes. Which source of information would be MOST valuable for identifying such risks?
⚠ Common exam trap
A common mix-up: candidates choose historical incident reports (D) thinking past failures are the best predictor, but CRISC emphasizes proactive identification of all risks—including those never experienced—which only a BIA can systematically uncover by analyzing process criticality and dependencies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Business impact analysis (BIA) documentation
The Business Impact Analysis (BIA) documentation is the most valuable source because it systematically identifies critical business processes, their dependencies (e.g., specific servers, databases, network links), and the maximum tolerable downtime (MTD) for each. This directly pinpoints which risks would cause unacceptable disruption, making it the foundational input for risk identification in continuity planning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Organizational charts
Why it's wrong here
Organisational charts show reporting lines and role ownership; they reveal nothing about the threats, vulnerabilities or dependencies that could interrupt a process. Charts would be useful when assigning risk owners or escalation paths, not when identifying the disruptive risks themselves.
- ✗
Industry benchmarks on downtime
Why it's wrong here
Industry benchmarks on downtime quantify typical outage durations and frequencies across sectors; they describe generic exposure rather than the specific threats facing this organisation's processes. Benchmarks would be valuable for justifying resilience investment or comparing maturity, not for identifying which risks could disrupt particular critical processes.
- ✓
Business impact analysis (BIA) documentation
Why this is correct
A BIA identifies and prioritises critical business processes and their dependencies, including the resources, systems and single points of failure whose disruption halts those processes. This directly supplies the risk scenarios a continuity manager needs, unlike asset inventories or audit findings that lack process-level impact context.
- ✗
Historical incident reports
Why it's wrong here
Historical incident reports document events that have already occurred, so they capture realised disruptions rather than the full range of plausible future risks. They would be the right source for validating likelihood estimates or post-incident reviews, but identifying risks requires forward-looking input such as process-level dependency analysis.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CRISC question from scratch — 1,062 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.