Courseiva

ISC2 CC Business Continuity, DR & Incident Response Practice Question

A mid-sized law firm experiences a ransomware attack that encrypts its document management system. The IT director wants to ensure the firm can resume operations quickly. Which of the following BEST describes the primary purpose of a disaster recovery plan in this scenario?

⚠ Common exam trap

A common mix-up: candidates confuse disaster recovery with broader business continuity or incident response activities, such as crisis communication or asset classification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To restore IT infrastructure and critical data after a disruption

A disaster recovery plan is specifically designed to restore IT infrastructure, applications, and data after a disruption. In a ransomware scenario, the plan details how to recover encrypted systems from backups, rebuild servers, and verify data integrity. The other options describe asset classification, HR discipline, and media communication, which are not the primary focus of disaster recovery.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To define penalties for employees who violate security policies

    Why it's wrong here

    Disciplinary actions belong to HR policy and security awareness enforcement, not disaster recovery. The ransomware attack may have resulted from a policy violation, but the immediate need is to recover the encrypted system. Defining penalties does nothing to restore operations or data, so it is not the primary purpose of a DRP here.

  • ✗

    To identify and classify information assets by their sensitivity

    Why it's wrong here

    Asset classification is part of risk management and data governance, not disaster recovery. While knowing which documents are sensitive can inform recovery priorities, classification alone does not restore systems after ransomware. This option describes an inventory and labeling activity, which is a prerequisite for planning but not the plan's primary purpose in this scenario.

  • ✓

    To restore IT infrastructure and critical data after a disruption

    Why this is correct

    A disaster recovery plan focuses specifically on restoring IT systems, applications, and data after an incident. In this ransomware scenario, the plan would guide steps to recover the encrypted document management system from backups, rebuild affected servers, and validate data integrity so the firm can resume work. It directly addresses the technical recovery of technology assets, which is the core objective here.

  • ✗

    To outline steps for communicating with the media during a crisis

    Why it's wrong here

    Crisis communication is typically part of a business continuity or incident response plan, not the disaster recovery plan. While communication is important, it does not address the technical restoration of the document management system. The primary purpose of DR is to recover IT assets, making this option a supporting activity rather than the main goal.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.