Courseiva

CC · domain

Business Continuity, DR & Incident Response

Practise ISC2 Certified in Cybersecurity CC Business Continuity, DR & Incident Response practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

81 questions24 easy33 medium24 hard

Focused practice

Practice Business Continuity, DR & Incident Response questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Business Continuity, DR & Incident Response

Business Continuity, DR & Incident Response questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Business Continuity, DR & Incident Response exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Business Continuity, DR & Incident Response questions (81)

Click any question to see the full explanation, or start a practice session above.

1

Refer to the exhibit. What does this indicate?

Medium
2

Refer to the exhibit. Which statement best describes compliance with the recovery objectives?

Hard
3

A company's BCP requires that critical systems be restored within 2 hours of disruption. Which metric defines this?

Medium
4

A mid-sized e-commerce company has a primary data center in New York and a disaster recovery site in Dallas. The application stack includes a web server, application server, and a PostgreSQL database. The database uses synchronous replication to the DR site. During a routine failover test, the IT team discovers that after failing over to Dallas, the web servers in New York continue to attempt connections to the original database IP, causing application errors. The DNS records have been updated to point to the DR database IP, but the web servers are not refreshing their DNS cache. The company uses a standard TTL of 300 seconds. The IT manager needs a solution that ensures minimal disruption during future failovers. Which action should be taken?

Easy
5

An organization's incident response plan specifies containment, eradication, and recovery phases. During containment, the team isolates a compromised server from the network. However, the server is a domain controller. What is the PRIMARY risk of this action?

Hard
6

Your organization runs a critical e-commerce platform on a private cloud. The database server is located in a data center in a seismic zone. The current DR plan uses a warm site with daily differential backups and a 12-hour RTO. A recent earthquake caused a power outage but no physical damage. The database corruption was discovered after 6 hours. The backups from last night are intact but restoring involves applying transaction logs. The RTO is now at risk. What should be done FIRST?

Hard
7

Which TWO of the following are primary objectives of an incident response plan? (Choose two.)

Hard
8

Match each cryptographic concept to its definition.

Medium
9

During a tabletop exercise, the IT team realizes that the backup tapes are stored in the same building as the servers. Which risk does this highlight?

Hard
10

An organization has detected a ransomware infection. What is the FIRST step in the incident response process?

Medium
11

A company is developing a disaster recovery plan for its database server. The database is updated transactionally and cannot tolerate any data loss. Which backup strategy meets this requirement?

Medium
12

Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?

Easy
13

An online retailer has a DR plan that includes active-active data centers. During a major DDoS attack, one data center's external connectivity is saturated. The internal network is operational. The security team has identified the attack traffic pattern and is working with the ISP to filter. To maintain service availability, what action should be taken?

Medium
14

Refer to the exhibit. An administrator needs to restore a database file from two weeks ago, but the backup log shows success. What is the most likely reason the file cannot be restored?

Medium
15

During a disaster recovery exercise, the system fails to achieve the RTO. Analysis shows that restoring the database from tape takes 3 hours, but the RTO is 2 hours. Which is the most effective solution?

Hard
16

Which TWO are essential elements of a business impact analysis (BIA)?

Medium
17

During a disaster recovery test, the team discovers that the backup generator fails to start. What is the BEST immediate action?

Easy
18

Which TWO are primary objectives of a Business Continuity Plan (BCP)? (Select two.)

Medium
19

Which TWO are appropriate methods to test a disaster recovery plan?

Hard
20

An organization's backup strategy includes daily full backups. However, recovery tests show that restoring from tape takes 6 hours longer than expected. What is the most likely cause?

Medium
21

Refer to the exhibit. What is the effect of this ACL?

Hard
22

Which THREE elements are essential components of a business continuity plan (BCP)?

Medium
23

During a disaster recovery test, backup tapes fail to restore data due to format incompatibility. Which element of the Business Continuity Plan should be updated?

Medium
24

Drag and drop the steps for the TCP three-way handshake into the correct order.

Medium
25

The exhibit shows a syslog-ng client configuration and a firewall rule on the central logging server (IP 10.0.0.10). The client (192.168.1.100) is not sending logs to the server. What is the most likely cause?

Hard
26

A multinational financial services organization operates three data centers in different geographic regions. Each data center runs a mix of critical and non-critical applications. The DR plan specifies Recovery Time Objectives (RTOs) ranging from 4 hours for critical applications to 72 hours for non-critical. During a scheduled DR test, the team attempts to fail over the primary customer database to the secondary site. The failover fails because the replication link between sites was saturated due to a large data synchronization job running concurrently. The test is declared a failure, and senior management is concerned about the DR plan's reliability. The IT director suggests increasing bandwidth between sites. The security architect proposes implementing network prioritization for replication traffic. The business continuity manager recommends revising the RTOs to be more realistic based on current bandwidth. The system administrator thinks the issue will resolve if the test is repeated during off-peak hours. Which of the following is the BEST course of action to address the root cause of the failure?

Hard
27

Which is a key benefit of a cold site as a recovery location?

Medium
28

Match each access control model to its key characteristic.

Medium
29

An organization discovers a ransomware infection on a critical server. According to the incident response phases, what should be the first action after detection?

Easy
30

Which TWO are phases of the NIST incident response life cycle? (Select exactly 2.)

Easy
31

Which THREE are commonly defined in a disaster recovery plan? (Select exactly 3.)

Medium
32

Which statement best describes a warm site in disaster recovery?

Hard
33

Refer to the exhibit. Based on the report, which improvement is most appropriate?

Medium
34

Which TWO are best practices for managing backup media?

Medium
35

Which THREE are primary phases of the incident response lifecycle?

Hard
36

Refer to the exhibit. A security analyst observes repeated outbound connection attempts from an internal server to external IP addresses on a non-standard port. What is the MOST likely interpretation?

Medium
37

Refer to the exhibit. An SOC analyst pulled this log snippet. Which type of attack is most likely in progress?

Easy
38

In incident response, which TWO are considered volatile data that should be collected first? (Select exactly 2.)

Hard
39

Based on the backup schedule, what is the maximum potential data loss?

Medium
40

During a ransomware incident, the incident response team isolates affected systems. Which of the following is the NEXT best step?

Easy
41

During a disaster recovery exercise, the team discovers that the backup site does not have the latest security patches applied. Which of the following steps should be taken FIRST?

Hard
42

A healthcare organization experiences a ransomware attack that encrypts all files on file servers and workstations. The incident response team has isolated the infected systems. The backup policy includes daily incremental backups and weekly full backups stored on a separate network segment. The most recent full backup is 5 days old. The incremental backups from the past 4 days are available but are stored on the same backup server that might be compromised. To restore data with minimal loss, what should the team do?

Medium
43

During an incident, an organization needs to preserve volatile data. Which of the following should be collected FIRST?

Medium
44

A company's primary data center experiences a complete power failure, and operations are shifted to a secondary site. The failover process takes 4 hours, but the recovery point objective (RPO) is set to 1 hour. Which of the following is the most likely consequence of this incident?

Medium
45

After a ransomware attack, which team is primarily responsible for coordinating the response?

Easy
46

A small manufacturing company's IT infrastructure consists of a single server running ERP and file services, with a nightly backup to an external hard drive. The server fails due to hardware failure. The company's BCP states that the ERP system must be restored within 8 hours. The backup is 12 hours old. The IT administrator has a spare server of similar configuration. What is the BEST course of action?

Easy
47

An organization uses a warm site for disaster recovery. Which of the following is the MOST significant risk of this approach?

Hard
48

An organization experiences a ransomware attack that encrypts critical file servers. The backups are stored on a separate network segment but are also encrypted. The incident response team suspects the attacker compromised the backup system using stored credentials. Which best practice should have been implemented to prevent this?

Medium
49

A company's primary data center is destroyed by a natural disaster. The backup site has been fully synchronized but needs to be activated. Which process addresses the activation of the backup site?

Easy
50

A security analyst receives an alert of unusual network traffic from an internal host to an external IP known for command-and-control. After isolating the host, what should be the next step?

Medium
51

Based on the incident log, at which step did the incident response team contain the threat?

Easy
52

Which TWO actions are most effective in reducing the mean time to detect (MTTD) a security incident?

Medium
53

You are the cybersecurity lead for a mid-sized retail company. One morning, employees report that they cannot access files on the shared drive, and a ransom note appears on several screens demanding $50,000 in Bitcoin. The company has a formal incident response plan that was last updated two years ago and has never been tested. Backups are taken nightly to an on-premises tape library and also replicated to a cloud storage service but have not been verified recently. The CEO is insisting on paying the ransom to avoid business disruption. Which of the following is the MOST appropriate first course of action?

Easy
54

A company's primary data center is located in a region prone to hurricanes. The IT team is designing a disaster recovery plan to ensure critical applications resume within 4 hours of a declared disaster. Which of the following is the MOST appropriate recovery strategy?

Easy
55

Refer to the exhibit. Based on the backup log, what is the most likely corrective action?

Medium
56

Which metric defines the maximum acceptable amount of data loss measured in time?

Easy
57

Which TWO are key outputs of a Business Impact Analysis (BIA)?

Easy
58

A company has a disaster recovery plan that includes a hot site. Which of the following is the PRIMARY advantage of a hot site over a cold site?

Easy
59

Drag and drop the steps for the proper disposal of a hard drive containing sensitive data into the correct order.

Medium
60

During a disaster recovery exercise, the backup systems are not available because the storage array failed. Which of the following should be done FIRST?

Hard
61

A company's business continuity plan requires a maximum tolerable downtime of 2 hours for the ERP system. The current backup process takes 3 hours to restore. Which of the following is the BEST corrective action?

Hard
62

A company's backup strategy involves daily full backups only. What is the primary risk associated with this approach?

Easy
63

According to the NIST 800-61 incident response lifecycle, after containment and eradication have been performed, what is the next phase?

Hard
64

Which document outlines the procedures for maintaining critical business functions during a disruption?

Easy
65

A company's business continuity plan includes an alternate work site with full IT capabilities. Which type of recovery site does this describe?

Easy
66

You are the incident response lead for a financial services company. At 09:00, the SOC detects unusual outbound traffic from a server in the DMZ to an external IP known to be a command-and-control (C2) server. The server runs a legacy application that cannot be patched. The server is critical for customer transactions, but an alternate manual process can sustain operations for up to 4 hours. The CTO wants to keep the server online to avoid customer impact. The CEO is concerned about data exfiltration. The compliance officer reminds you of regulatory requirements to report breaches within 72 hours. Which action should you take FIRST?

Hard
67

An organization uses a primary data center and a backup site 500 miles away. The backup site replicates data synchronously. Which risk is MOST likely introduced by this configuration?

Medium
68

Refer to the exhibit. What is the first action the incident responder should take?

Easy
69

Which THREE are phases of the incident response process according to NIST SP 800-61?

Easy
70

During an incident, the incident response team discovers that an attacker has exfiltrated sensitive customer data. According to incident response best practices, whose approval is REQUIRED before contacting law enforcement?

Easy
71

Which metric is used to define the maximum amount of data loss an organization can tolerate during a disaster?

Easy
72

During a tabletop exercise for a data center outage, the IT manager realizes that the disaster recovery plan does not specify how to failover the database cluster. The primary data center fails completely. The standby site has a replica of the database, but the application team cannot promote it because they lack the necessary privileges. What is the most likely cause of this gap?

Hard
73

Refer to the exhibit. A security analyst observes that users from the 192.168.1.0/24 network cannot access HTTPS websites, but HTTP access works fine. What is the most likely cause?

Easy
74

Refer to the exhibit. A DBA is investigating a replication issue. What should be the FIRST action?

Hard
75

A primary data center is destroyed. The disaster recovery plan calls for activation of a hot standby site. If the RTO is 2 hours, what is the expected recovery time?

Medium
76

Which TWO actions are appropriate during the identification phase of incident response?

Hard
77

A company is developing a business continuity plan (BCP). Which TWO of the following are essential components that must be included in a BCP?

Medium
78

Which TWO are true about a differential backup? (Select two.)

Medium
79

Which THREE are differences between a hot site and a cold site? (Select three.)

Hard
80

During an incident, the IR team identifies that the root cause is a zero-day vulnerability. Which of the following is the best immediate action?

Hard
81

A small business with limited budget wants to ensure critical business functions can resume within 24 hours of a disaster. Their data changes infrequently. Which recovery solution is MOST cost-effective?

Medium

Frequently asked questions

What does the Business Continuity, DR & Incident Response domain cover on the CC exam?
Business Continuity, DR & Incident Response questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 81 Business Continuity, DR & Incident Response questions in the CC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Business Continuity, DR & Incident Response questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-cc ISC2-CC bc dr ir Practice Questions