Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

An organization is creating a Business Continuity Plan (BCP). Which analysis should be performed first to identify critical business functions and their dependencies?

⚠ Common exam trap

Test-takers frequently confuse the sequence of BCP steps: many candidates assume Risk Assessment comes first because it sounds like the starting point for security planning, but in BCP, the BIA must precede risk assessment to identify what is critical.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Business Impact Analysis

The Business Impact Analysis (BIA) is the foundational step in BCP development because it systematically identifies critical business functions, their dependencies, and the impact of their disruption over time. It quantifies the consequences of downtime, helping prioritize recovery objectives like RTO and RPO. Without a BIA, subsequent risk assessment and recovery strategies lack a business-driven focus.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk Assessment

    Why it's wrong here

    A risk assessment evaluates likelihood and impact of threats to assets; it does not first establish which business functions are critical or how they depend on each other. It is tempting because risk assessment underpins most security programmes and would correctly follow once critical functions are known; business impact analysis must come first.

  • ✓

    Business Impact Analysis

    Why this is correct

    A Business Impact Analysis identifies critical business functions and maps their dependencies, plus tolerable downtime and recovery priorities. It is performed first because its output — the RTO and RPO figures — drives every subsequent BCP and recovery strategy decision.

  • ✗

    Vulnerability Assessment

    Why it's wrong here

    A vulnerability assessment identifies weaknesses in assets, not the critical business functions and dependencies a BCP must prioritise. It is tempting because vulnerability findings feed later risk treatment and resilience planning, and it would be the right first step when hardening systems; business impact analysis precedes it here.

  • ✗

    Gap Analysis

    Why it's wrong here

    A gap analysis compares the current state of business continuity capabilities against a desired target state, but it presupposes that critical functions and dependencies have already been identified. Performing a gap analysis first would lack the baseline of which processes are essential, making it impossible to assess what is missing. It is tempting because gap analysis is a standard early step in many compliance audits, such as ISO 22301, where it correctly identifies deficiencies after the scope of critical activities is defined.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.