Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

An organization experiences a data breach involving personally identifiable information (PII) of European Union residents. According to GDPR, which THREE of the following are required actions?

⚠ Common exam trap

The trap here is mixing general IT/BCP practices (backup restore, BIA) with GDPR-specific legal obligations — candidates who are strong in IT operations may pick B or D, but the exam expects the three explicit GDPR articles: 33(5) documentation, 34 communication, and 33(1) 72-hour notification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the breach, its effects, and the remedial actions taken.

Option A is correct because GDPR Article 33(5) requires the controller to document all personal data breaches, including the facts, effects, and remedial actions taken, so the supervisory authority can verify compliance. Option C is correct because GDPR Articles 33(1) and 34(1) require communication to affected data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms. Option E is correct because GDPR Article 33(1) mandates notifying the relevant supervisory authority within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk. Option B is not a GDPR requirement; restoring from backup is a general recovery practice, not a breach-notification obligation. Option D is not required by GDPR; a BIA is a business continuity tool, whereas GDPR requires a Data Protection Impact Assessment (DPIA) in certain cases, not a BIA for breach response.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Document the breach, its effects, and the remedial actions taken.

    Why this is correct

    GDPR Article 33(5) requires controllers to document all breaches, including the facts, effects and remedial action taken. This record-keeping duty applies regardless of whether the breach is notifiable, satisfying the stem's requirement for a mandatory action following the PII incident.

  • ✗

    Restore all affected systems from the latest full backup.

    Why it's wrong here

    GDPR requires notifying the supervisory authority within 72 hours and informing affected data subjects where risk is high; restoring backups is a recovery action, not a mandated breach response. It is tempting because backup restoration is standard incident handling, but Article 33/34 obligations concern notification and documentation, not system recovery.

  • ✓

    Communicate the breach to affected data subjects without undue delay if it poses a risk to their rights and freedoms.

    Why this is correct

    GDPR Article 34 requires communication to data subjects without undue delay where a breach is likely to result in a high risk to their rights and freedoms. The stem's risk qualifier is the specific trigger, so notification is mandatory rather than discretionary.

  • ✗

    Conduct a Business Impact Analysis (BIA) to determine the financial impact.

    Why it's wrong here

    A BIA supports business continuity planning by quantifying financial impact, which GDPR does not require after a breach. It is tempting because impact assessment feels aligned with breach handling, yet the regulation mandates supervisory authority notification within 72 hours, data subject communication where risk is high, and documented records of the incident.

  • ✓

    Notify the relevant supervisory authority within 72 hours of becoming aware of the breach.

    Why this is correct

    Under GDPR Article 33, a controller must notify the competent supervisory authority of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it. This requirement applies directly because the breach involves PII of EU residents, triggering the territorial scope of the GDPR. The 72-hour notification window is a mandatory procedural obligation distinct from the separate duty to communicate the breach to affected data subjects under Article 34.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.