Courseiva

ISC2 CC Practice Question: Business Continuity, Disaster Recovery, and Incident Response

An organization is developing a Business Continuity Plan (BCP). Which analysis is performed first to identify critical business functions and their dependencies?

⚠ Common exam trap

The trap is assuming risk assessment comes first because it sounds foundational — but BCP best practice (and ISO 22301) places the BIA first to define what matters before assessing threats.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Business Impact Analysis (BIA)

The Business Impact Analysis (BIA) is performed first in BCP development because it identifies critical business functions, their dependencies, and the impact of disruption over time. This data drives recovery time objectives (RTO) and recovery point objectives (RPO), which then inform the rest of the BCP. Risk assessment and other analyses come after the BIA because you must know what to protect before assessing threats to it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk assessment

    Why it's wrong here

    A risk assessment evaluates threats and vulnerabilities to determine potential impacts, but it does not identify which business functions are critical or how they depend on each other; that is the role of a Business Impact Analysis (BIA), which must precede risk assessment in BCP development. It is tempting because risk assessment is a foundational step in security planning, and would be the correct choice if the question asked for the first analysis to prioritise threats after critical functions are already known.

  • ✓

    Business Impact Analysis (BIA)

    Why this is correct

    A Business Impact Analysis identifies critical business functions, quantifies the impact of their disruption, and maps dependencies on systems, people and suppliers, producing the foundation from which recovery priorities and continuity strategies are later derived.

  • ✗

    Vulnerability assessment

    Why it's wrong here

    A vulnerability assessment enumerates weaknesses in assets, not the critical business functions and their dependencies that a BCP must rank first. It is tempting because vulnerability data feeds later risk treatment, where it is the right choice, but the initial BCP step requires business impact analysis to establish function criticality and interdependencies.

  • ✗

    Gap analysis

    Why it's wrong here

    Gap analysis compares current capabilities against a target state, so it presupposes the critical functions and dependencies already identified. It is tempting because it shapes remediation planning later in the BCP lifecycle, where it is correct, but the first step is business impact analysis, which establishes which functions matter and what they rely on.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.