ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response
An organization is developing a Business Continuity Plan (BCP). Which analysis is performed first to identify critical business functions and their dependencies?
⚠ Common exam trap
The trap is assuming risk assessment comes first because it sounds foundational — but BCP best practice (and ISO 22301) places the BIA first to define what matters before assessing threats.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Business Impact Analysis (BIA)
The Business Impact Analysis (BIA) is performed first in BCP development because it identifies critical business functions, their dependencies, and the impact of disruption over time. This data drives recovery time objectives (RTO) and recovery point objectives (RPO), which then inform the rest of the BCP. Risk assessment and other analyses come after the BIA because you must know what to protect before assessing threats to it.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk assessment
Why it's wrong here
A risk assessment evaluates threats and vulnerabilities to determine potential impacts, but it does not identify which business functions are critical or how they depend on each other; that is the role of a Business Impact Analysis (BIA), which must precede risk assessment in BCP development. It is tempting because risk assessment is a foundational step in security planning, and would be the correct choice if the question asked for the first analysis to prioritise threats after critical functions are already known.
- ✓
Business Impact Analysis (BIA)
Why this is correct
A Business Impact Analysis identifies critical business functions, quantifies the impact of their disruption, and maps dependencies on systems, people and suppliers, producing the foundation from which recovery priorities and continuity strategies are later derived.
- ✗
Vulnerability assessment
Why it's wrong here
A vulnerability assessment enumerates weaknesses in assets, not the critical business functions and their dependencies that a BCP must rank first. It is tempting because vulnerability data feeds later risk treatment, where it is the right choice, but the initial BCP step requires business impact analysis to establish function criticality and interdependencies.
- ✗
Gap analysis
Why it's wrong here
Gap analysis compares current capabilities against a target state, so it presupposes the critical functions and dependencies already identified. It is tempting because it shapes remediation planning later in the BCP lifecycle, where it is correct, but the first step is business impact analysis, which establishes which functions matter and what they rely on.
Go deeper
Related to this question
Learn chapter
Business Continuity and Disaster Recovery
Key term
Business continuity plan
A Business continuity plan (BCP) is a documented strategy that outlines how an organization will continue critical operations during and after a disruptive event.
Key term
Business continuity
Business continuity is the capability of an organization to continue delivering essential services during and after a disruptive event.
About these practice questions
Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.