Courseiva

ISC2 CC Business Continuity, DR & Incident Response Practice Question

A multinational corporation is reviewing its business continuity plan (BCP) and disaster recovery plan (DRP). The chief information security officer (CISO) wants to clarify the distinct roles of each plan. Which of the following statements accurately describe the relationship between the BCP and DRP? (Choose two.)

⚠ Common exam trap

The trap here is assuming that the BCP and DRP are either independent or that one takes precedence, when in fact the DRP is a subordinate component of the BCP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The DRP is a component of the BCP and provides detailed procedures for recovering technology assets.

The BCP is the overarching plan that ensures critical business functions continue during a disruption, covering people, processes, and facilities. The DRP is a component of the BCP that focuses specifically on restoring IT infrastructure and systems. These two statements accurately reflect the relationship, while the others misstate the scope or interdependence of the plans.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The DRP takes precedence over the BCP during a disaster.

    Why it's wrong here

    The BCP is the overarching plan, and the DRP supports it. There is no inherent precedence; they are designed to work together. During a disaster, the BCP guides overall business response, and the DRP executes the technical recovery. Claiming DRP precedence could lead to a disjointed response that ignores business priorities. The CISO should ensure both plans are coordinated, not ranked.

  • ✗

    The BCP is only concerned with IT systems, while the DRP covers all business units.

    Why it's wrong here

    This statement reverses the scope. The BCP covers all aspects of the organization, including business units, personnel, facilities, and IT. The DRP is the IT-focused subset. Saying the BCP is only concerned with IT systems is incorrect and misleading. The CISO should recognize that the BCP is enterprise-wide, while the DRP is technology-centric.

  • ✓

    The DRP is a component of the BCP and provides detailed procedures for recovering technology assets.

    Why this is correct

    The DRP is indeed a component of the broader BCP. It provides the technical procedures and steps necessary to restore IT infrastructure and applications. The BCP relies on the DRP to recover the technology that supports critical business functions. This nested relationship ensures that business continuity and technology recovery are integrated, preventing gaps between business and IT recovery efforts.

  • ✓

    The BCP focuses on maintaining critical business functions during a disruption, while the DRP focuses on restoring IT infrastructure and systems.

    Why this is correct

    This statement correctly distinguishes the two plans. The BCP addresses business processes, people, and facilities to keep essential functions running during and after a disruption. The DRP is a subset of the BCP that specifically deals with recovering technology assets, such as servers, networks, and data. Understanding this hierarchy helps the CISO allocate resources and ensure both plans are aligned.

  • ✗

    The BCP and DRP are mutually exclusive and should be developed independently.

    Why it's wrong here

    The BCP and DRP are interdependent and should be developed in alignment. The DRP's recovery objectives must support the BCP's critical business functions. Developing them independently risks mismatched RTOs and RPOs, leading to ineffective recovery. The CISO should promote collaboration between business and IT teams to ensure the plans complement each other and are tested together.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.