easyMultiple Select
BIA Primary Objectives
An organization is performing a business impact analysis (BIA) for its critical applications. Which TWO of the following are primary objectives of a BIA?
Quick Answer
The answer is identifying the maximum acceptable outage (MAO) for each process. This is correct because a primary objective of a business impact analysis is to quantify the operational and financial impacts of a disruption, which directly determines the maximum tolerable downtime for each critical function. The MAO then drives the recovery time objectives (RTOs) and prioritization of recovery efforts, ensuring the most vital processes are restored first. On the CRISC exam, this concept tests your understanding of how the BIA translates business needs into technical recovery targets; a common trap is confusing the BIA’s output (MAO) with the recovery strategy itself. Remember that the BIA identifies the “how long can we be down” before setting the “how fast we must recover.” A useful memory tip is: BIA finds the MAO, then RTO follows.
⚠ Common exam trap
Watch out — candidates often confuse the BIA with the broader risk assessment process, mistakenly selecting options like determining threat likelihood or calculating ALE, which are distinct activities performed after the BIA is complete.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Prioritize recovery of business processes based on criticality.
Option A is correct because a core purpose of the BIA is to rank business processes and their supporting applications by criticality, so that recovery efforts and resources are directed to the most essential functions first. Option C is correct because the BIA establishes the maximum acceptable outage (MAO), also expressed as maximum tolerable downtime (MTD), which defines how long a process can be unavailable before unacceptable impact occurs and drives the RTO/RPO targets. Option B is not a BIA objective; threat likelihood estimation belongs to risk assessment, not impact analysis. Option D is not a BIA objective; ALE is a quantitative risk calculation (SLE × ARO) performed during risk analysis. Option E is not a BIA objective; selecting risk response strategies (avoid, mitigate, transfer, accept) is part of risk treatment, which follows the assessment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Prioritize recovery of business processes based on criticality.
Why this is correct
A BIA determines which business processes are most critical by assessing disruption impact over time, so recovery sequencing follows business dependency rather than technical convenience. Prioritising process recovery by criticality is therefore a primary BIA objective, directly satisfying the stem's requirement.
- ✗
Determine the likelihood of each threat event.
Why it's wrong here
Threat likelihood estimation belongs to risk assessment, where probabilities are assigned per identified threat. A BIA instead establishes impact over time and recovery priorities, deliberately excluding likelihood so that criticality rankings remain independent of how probable an outage is. It tempts because likelihood feeds later risk analysis, but that occurs after the BIA.
- ✓
Identify the maximum acceptable outage (MAO) for each process.
Why this is correct
The BIA establishes maximum acceptable outage by correlating how long each process can be unavailable before impact becomes unacceptable. This duration drives RTO targets, making MAO identification a primary BIA objective and directly satisfying the stem's requirement for a core output.
- ✗
Calculate the annualized loss expectancy (ALE).
Why it's wrong here
ALE derives from single loss expectancy multiplied by annualised rate of occurrence, an output of quantitative risk analysis. A BIA measures operational impact and downtime tolerance, not financial loss frequency. It tempts because both quantify business consequences, but ALE requires likelihood data that a BIA deliberately omits, so it cannot be calculated from BIA findings alone.
- ✗
Select appropriate risk response strategies.
Why it's wrong here
Risk response selection happens during risk treatment, once assessed risks are compared against tolerance. A BIA only identifies critical processes, dependencies and maximum tolerable downtime; it neither evaluates controls nor chooses responses. It tempts because BIA outputs inform treatment decisions, but selecting strategies is a separate, later step in the risk management process.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CRISC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which of the following is the PRIMARY purpose of conducting a business impact analysis (BIA) during the IT risk assessment process?
easy- ✓ A.To determine the criticality and recovery time objectives of business processes
- B.To identify vulnerabilities in IT systems
- C.To identify potential threat actors
- D.To inventory all IT assets
Why A: The primary purpose of a business impact analysis (BIA) is to identify critical business processes, determine their recovery priorities, and establish recovery time objectives (RTOs) and recovery point objectives (RPOs). Option B is incorrect because identifying vulnerabilities is part of a vulnerability assessment, not a BIA. Option C is incorrect because identifying potential threat actors is part of threat modeling. Option D is incorrect because inventorying IT assets is part of asset management, not the primary goal of a BIA.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.