Courseiva

ISC · topic practice

Contingency Management practice questions

Practise (ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) Contingency Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Reviewed byJohnson Ajibi· MSc IT Security
20 questionsDomain: Contingency Management

What the exam tests

What to know about Contingency Management

Contingency Management questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Contingency Management exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Practice set

Contingency Management questions

20 questions · select your answer, then reveal the explanation

Your organization uses a 'Warm Site' for its disaster recovery strategy. During a recent audit, you find that the site lacks the necessary bandwidth to support peak production traffic. What is the most appropriate management response?

Following a ransomware attack, the organization must decide whether to invoke the DRP or remain in a degraded state while security teams perform forensics. What is the ISSMP's primary responsibility in this decision-making process?

You are auditing a third-party disaster recovery service provider. Which metric provides the most accurate evidence that the provider can meet your organization's required recovery point for a database cluster?

During a disaster recovery simulation for a hybrid cloud environment, you discover that the automated orchestration tool fails to restore dependencies in the correct order because the cloud provider's metadata tags were purged. What is the most effective administrative control to prevent this during a real event?

Which document serves as the primary governing authority to define the triggers, escalation paths, and communication roles during a declared crisis event?

Which of the following is the most effective method for testing the efficacy of a Business Continuity Plan without disrupting production operations?

Your organization has adopted a cloud-native microservices architecture. Which strategy is most appropriate for maintaining business continuity in the event of a regional cloud provider outage?

An ISSMP is overseeing a BCP program and notes that the current Business Impact Analysis (BIA) is heavily focused on RTO but lacks a critical dependency mapping for cross-functional business processes. Which specific action should the ISSMP prioritize to address the systemic risk of cascading failure during a disaster?

You are implementing a disaster recovery strategy for a database that uses synchronous replication. What is the most significant trade-off you must accept by enforcing this configuration?

Your organization uses a 'Hot Site' with hardware-level replication. During a disaster, the primary site becomes unavailable, but the failover fails due to a 'Split-Brain' scenario. What is the fundamental cause of this?

When designing the Crisis Communication Plan, why is it essential to establish pre-approved communication templates?

What is the primary objective of a 'lessons learned' meeting conducted after a disaster recovery exercise?

When classifying business processes for BCP, what is the 'Recovery Time Objective' (RTO) most effectively used for?

An ISSMP is revising the BCP to account for 'Supply Chain Resiliency'. Which approach is best for verifying that critical third-party vendors can meet the organization's recovery requirements?

During a BCP planning session, the executive team is debating the 'Maximum Tolerable Downtime' (MTD) for a legacy internal application. What is the correct way to define this metric?

Your organization has decided to use a 'Cloud Disaster Recovery' service. The vendor provides a 'Pilot Light' strategy. What does this mean for your organization's recovery capability?

An ISSMP is reviewing the Business Continuity Plan (BCP) for a critical application. Which TWO of the following factors should be considered when defining the 'Maximum Tolerable Downtime' (MTD)?

In a decentralized organization, which approach to BCP management ensures both local agility and global alignment?

Which THREE of the following are essential components of a robust Crisis Management Plan?

During a BIA review, you need to identify critical assets and their recovery requirements. Which TWO of the following inputs are essential for this classification process?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Contingency Management sessions

Start a Contingency Management only practice session

Every question in these sessions is drawn from the Contingency Management domain — nothing else.

Related practice questions

Related ISC topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the ISC exam test about Contingency Management?
Contingency Management questions test whether you can apply the concept in context, not just recognise a definition.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Contingency Management questions in a focused session?
Yes — the session launcher on this page draws every question from the Contingency Management domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other ISC topics?
Use the topic links above to move to related areas, or go back to the ISC question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the ISC exam covers. They are not copied from any real exam or dump site.