ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response
An organization is creating a Business Continuity Plan (BCP). Which analysis should be performed first to identify critical business functions and their dependencies?
⚠ Common exam trap
Test-takers frequently confuse the sequence of BCP steps: many candidates assume Risk Assessment comes first because it sounds like the starting point for security planning, but in BCP, the BIA must precede risk assessment to identify what is critical.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Business Impact Analysis
The Business Impact Analysis (BIA) is the foundational step in BCP development because it systematically identifies critical business functions, their dependencies, and the impact of their disruption over time. It quantifies the consequences of downtime, helping prioritize recovery objectives like RTO and RPO. Without a BIA, subsequent risk assessment and recovery strategies lack a business-driven focus.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk Assessment
Why it's wrong here
A risk assessment evaluates likelihood and impact of threats to assets; it does not first establish which business functions are critical or how they depend on each other. It is tempting because risk assessment underpins most security programmes and would correctly follow once critical functions are known; business impact analysis must come first.
- ✓
Business Impact Analysis
Why this is correct
A Business Impact Analysis identifies critical business functions and maps their dependencies, plus tolerable downtime and recovery priorities. It is performed first because its output — the RTO and RPO figures — drives every subsequent BCP and recovery strategy decision.
- ✗
Vulnerability Assessment
Why it's wrong here
A vulnerability assessment identifies weaknesses in assets, not the critical business functions and dependencies a BCP must prioritise. It is tempting because vulnerability findings feed later risk treatment and resilience planning, and it would be the right first step when hardening systems; business impact analysis precedes it here.
- ✗
Gap Analysis
Why it's wrong here
A gap analysis compares the current state of business continuity capabilities against a desired target state, but it presupposes that critical functions and dependencies have already been identified. Performing a gap analysis first would lack the baseline of which processes are essential, making it impossible to assess what is missing. It is tempting because gap analysis is a standard early step in many compliance audits, such as ISO 22301, where it correctly identifies deficiencies after the scope of critical activities is defined.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
RPO
Recovery Point Objective (RPO) is the maximum acceptable amount of data loss measured in time, defining how recent data must be to resume operations after a disruption.
Key term
Risk assessment
Risk assessment is the process of identifying, analyzing, and evaluating potential threats to an organization's assets to determine the likelihood and impact of those threats, and to decide on appropriate treatment measures.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.