ISC2 CC Business Continuity, DR & Incident Response Practice Question
A multinational corporation is reviewing its business continuity plan (BCP) and disaster recovery plan (DRP). The chief information security officer (CISO) wants to clarify the distinct roles of each plan. Which of the following statements accurately describe the relationship between the BCP and DRP? (Choose two.)
⚠ Common exam trap
The trap here is assuming that the BCP and DRP are either independent or that one takes precedence, when in fact the DRP is a subordinate component of the BCP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The DRP is a component of the BCP and provides detailed procedures for recovering technology assets.
The BCP is the overarching plan that ensures critical business functions continue during a disruption, covering people, processes, and facilities. The DRP is a component of the BCP that focuses specifically on restoring IT infrastructure and systems. These two statements accurately reflect the relationship, while the others misstate the scope or interdependence of the plans.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The DRP takes precedence over the BCP during a disaster.
Why it's wrong here
The BCP is the overarching plan, and the DRP supports it. There is no inherent precedence; they are designed to work together. During a disaster, the BCP guides overall business response, and the DRP executes the technical recovery. Claiming DRP precedence could lead to a disjointed response that ignores business priorities. The CISO should ensure both plans are coordinated, not ranked.
- ✗
The BCP is only concerned with IT systems, while the DRP covers all business units.
Why it's wrong here
This statement reverses the scope. The BCP covers all aspects of the organization, including business units, personnel, facilities, and IT. The DRP is the IT-focused subset. Saying the BCP is only concerned with IT systems is incorrect and misleading. The CISO should recognize that the BCP is enterprise-wide, while the DRP is technology-centric.
- ✓
The DRP is a component of the BCP and provides detailed procedures for recovering technology assets.
Why this is correct
The DRP is indeed a component of the broader BCP. It provides the technical procedures and steps necessary to restore IT infrastructure and applications. The BCP relies on the DRP to recover the technology that supports critical business functions. This nested relationship ensures that business continuity and technology recovery are integrated, preventing gaps between business and IT recovery efforts.
- ✓
The BCP focuses on maintaining critical business functions during a disruption, while the DRP focuses on restoring IT infrastructure and systems.
Why this is correct
This statement correctly distinguishes the two plans. The BCP addresses business processes, people, and facilities to keep essential functions running during and after a disruption. The DRP is a subset of the BCP that specifically deals with recovering technology assets, such as servers, networks, and data. Understanding this hierarchy helps the CISO allocate resources and ensure both plans are aligned.
- ✗
The BCP and DRP are mutually exclusive and should be developed independently.
Why it's wrong here
The BCP and DRP are interdependent and should be developed in alignment. The DRP's recovery objectives must support the BCP's critical business functions. Developing them independently risks mismatched RTOs and RPOs, leading to ineffective recovery. The CISO should promote collaboration between business and IT teams to ensure the plans complement each other and are tested together.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
Business continuity plan
A Business continuity plan (BCP) is a documented strategy that outlines how an organization will continue critical operations during and after a disruptive event.
Key term
Business continuity
Business continuity is the capability of an organization to continue delivering essential services during and after a disruptive event.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.