CC · domain
Business Continuity, DR & Incident Response
This domain covers business continuity planning, disaster recovery, and incident response. For the CC exam, expect scenario-based questions on BCP components, site types like hot/cold, and IR steps. You must know how to prioritize immediate actions, such as isolating systems or applying patches, and understand the purpose of each plan.
Focused practice
Practice Business Continuity, DR & Incident Response questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Business Continuity, DR & Incident Response
You must be able to apply BCP, DRP, and IR concepts to scenarios. The most important thing is to know the correct order of incident response steps and when to use each recovery site type.
Ordering the TCP three-way handshake: SYN, SYN-ACK, ACK.
Identifying essential BCP components, such as risk assessment and recovery strategies.
Comparing disaster recovery site types: hot site offers immediate failover.
Choosing immediate IR actions for zero-day vulnerabilities, like isolation or mitigation.
Watch out for
Common Business Continuity, DR & Incident Response exam traps
- ▸Confusing BCP with DRP: BCP covers all business functions, while DRP focuses on IT recovery.
- ▸Assuming a hot site is always best; it is costly and may not be necessary for all recovery objectives.
- ▸For zero-day exploits, delaying action to fully analyze before containing, which allows further damage.
Question index
All Business Continuity, DR & Incident Response questions (64)
Click any question to see the full explanation, or start a practice session above.
Refer to the exhibit. Which statement best describes compliance with the recovery objectives?
Hard2A company's BCP requires that critical systems be restored within 2 hours of disruption. Which metric defines this?
Medium3A multinational corporation is reviewing its business continuity plan (BCP) and disaster recovery plan (DRP). The chief information security officer (CISO) wants to clarify the distinct roles of each plan. Which of the following statements accurately describe the relationship between the BCP and DRP? (Choose two.)
Hard4An organization's incident response plan specifies containment, eradication, and recovery phases. During containment, the team isolates a compromised server from the network. However, the server is a domain controller. What is the PRIMARY risk of this action?
Hard5A financial services firm suffers a ransomware outbreak that encrypts file servers and the backup catalog. The incident response team must decide the immediate next step while the attack is still spreading. Which action BEST aligns with the containment objective of the incident response plan?
Medium6During a tabletop exercise, the IT team realizes that the backup tapes are stored in the same building as the servers. Which risk does this highlight?
Hard7An organization has detected a ransomware infection. What is the FIRST step in the incident response process?
Medium8An organization's BCP identifies a customer-facing order system as critical. The BIA shows the business can tolerate 12 hours of downtime and 1 hour of data loss. The current architecture uses nightly full backups to tape with a 10-hour restore time. Which change BEST closes the gap between current capability and the stated requirements?
Hard9Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?
Easy10Refer to the exhibit. An administrator needs to restore a database file from two weeks ago, but the backup log shows success. What is the most likely reason the file cannot be restored?
Medium11A financial services firm conducts an annual test of its business continuity plan. Management wants to evaluate how well the team performs its roles and procedures during a simulated disruption without actually moving operations to alternate sites. Which type of exercise BEST meets this requirement?
Hard12During a disaster recovery exercise, the system fails to achieve the RTO. Analysis shows that restoring the database from tape takes 3 hours, but the RTO is 2 hours. Which is the most effective solution?
Hard13Which TWO are essential elements of a business impact analysis (BIA)?
Medium14A healthcare provider's incident response team is handling a breach of patient records. The team has contained the breach and is now eradicating the threat. Which of the following activities is MOST appropriate during the eradication phase?
Medium15A cloud-hosted retailer's disaster recovery plan relies on backups stored in the same cloud region as production. A regional outage takes the production environment offline. Which weakness does this scenario PRIMARILY expose in the disaster recovery strategy?
Medium16A mid-sized hospital experiences a ransomware outbreak that encrypts its electronic health record (EHR) servers on a Friday night. The incident response plan designates a severity classification of 'Critical'. According to established incident response practices, which action should the incident response team take FIRST?
Medium17Which TWO are appropriate methods to test a disaster recovery plan?
Hard18During a disaster recovery test, backup tapes fail to restore data due to format incompatibility. Which element of the Business Continuity Plan should be updated?
Medium19Drag and drop the steps for the TCP three-way handshake into the correct order.
Medium20The exhibit shows a syslog-ng client configuration and a firewall rule on the central logging server (IP 10.0.0.10). The client (192.168.1.100) is not sending logs to the server. What is the most likely cause?
Hard21A multinational financial services organization operates three data centers in different geographic regions. Each data center runs a mix of critical and non-critical applications. The DR plan specifies Recovery Time Objectives (RTOs) ranging from 4 hours for critical applications to 72 hours for non-critical. During a scheduled DR test, the team attempts to fail over the primary customer database to the secondary site. The failover fails because the replication link between sites was saturated due to a large data synchronization job running concurrently. The test is declared a failure, and senior management is concerned about the DR plan's reliability. The IT director suggests increasing bandwidth between sites. The security architect proposes implementing network prioritization for replication traffic. The business continuity manager recommends revising the RTOs to be more realistic based on current bandwidth. The system administrator thinks the issue will resolve if the test is repeated during off-peak hours. Which of the following is the BEST course of action to address the root cause of the failure?
Hard22Which is a key benefit of a cold site as a recovery location?
Medium23An organization discovers a ransomware infection on a critical server. According to the incident response phases, what should be the first action after detection?
Easy24Which statement best describes a warm site in disaster recovery?
Hard25A hospital's incident response team is drafting the post-incident activity phase of its plan after a recent malware outbreak. Which two activities belong in this phase? (Choose two.)
Medium26An organization's recovery time objective (RTO) for its customer database is 4 hours. During a disaster, the backup restore process takes 2 hours, but reconfigure and test tasks add another 3 hours. Which action best addresses this gap?
Medium27Which TWO are best practices for managing backup media?
Medium28Refer to the exhibit. A security analyst observes repeated outbound connection attempts from an internal server to external IP addresses on a non-standard port. What is the MOST likely interpretation?
Medium29Refer to the exhibit. An SOC analyst pulled this log snippet. Which type of attack is most likely in progress?
Easy30In incident response, which TWO are considered volatile data that should be collected first? (Select exactly 2.)
Hard31During a ransomware incident, the incident response team isolates affected systems. Which of the following is the NEXT best step?
Easy32During a disaster recovery exercise, the team discovers that the backup site does not have the latest security patches applied. Which of the following steps should be taken FIRST?
Hard33A mid-sized law firm experiences a ransomware attack that encrypts its document management system. The IT director wants to ensure the firm can resume operations quickly. Which of the following BEST describes the primary purpose of a disaster recovery plan in this scenario?
Easy34A healthcare organization experiences a ransomware attack that encrypts all files on file servers and workstations. The incident response team has isolated the infected systems. The backup policy includes daily incremental backups and weekly full backups stored on a separate network segment. The most recent full backup is 5 days old. The incremental backups from the past 4 days are available but are stored on the same backup server that might be compromised. To restore data with minimal loss, what should the team do?
Medium35During an incident, an organization needs to preserve volatile data. Which of the following should be collected FIRST?
Medium36After a ransomware attack, which team is primarily responsible for coordinating the response?
Easy37A company's primary data center is destroyed by a natural disaster. The backup site has been fully synchronized but needs to be activated. Which process addresses the activation of the backup site?
Easy38An organization's business continuity plan (BCP) requires that its payroll system be operational within 8 hours of a disruption, but the system can tolerate losing up to 4 hours of payroll transaction data. Which pair of metrics BEST represents these two requirements?
Easy39A security analyst receives an alert of unusual network traffic from an internal host to an external IP known for command-and-control. After isolating the host, what should be the next step?
Medium40Based on the incident log, at which step did the incident response team contain the threat?
Easy41Which TWO actions are most effective in reducing the mean time to detect (MTTD) a security incident?
Medium42Which metric defines the maximum acceptable amount of data loss measured in time?
Easy43Which TWO are key outputs of a Business Impact Analysis (BIA)?
Easy44A company has a disaster recovery plan that includes a hot site. Which of the following is the PRIMARY advantage of a hot site over a cold site?
Easy45Drag and drop the steps for the proper disposal of a hard drive containing sensitive data into the correct order.
Medium46During a disaster recovery exercise, the backup systems are not available because the storage array failed. Which of the following should be done FIRST?
Hard47A company's business continuity plan requires a maximum tolerable downtime of 2 hours for the ERP system. The current backup process takes 3 hours to restore. Which of the following is the BEST corrective action?
Hard48A small retail company is developing its first incident response plan. The owner asks which phase of the incident response lifecycle involves developing policies, assigning roles, and acquiring tools. Which phase should be recommended?
Easy49According to the NIST 800-61 incident response lifecycle, after containment and eradication have been performed, what is the next phase?
Hard50Which document outlines the procedures for maintaining critical business functions during a disruption?
Easy51A company's business continuity plan includes an alternate work site with full IT capabilities. Which type of recovery site does this describe?
Easy52You are the incident response lead for a financial services company. At 09:00, the SOC detects unusual outbound traffic from a server in the DMZ to an external IP known to be a command-and-control (C2) server. The server runs a legacy application that cannot be patched. The server is critical for customer transactions, but an alternate manual process can sustain operations for up to 4 hours. The CTO wants to keep the server online to avoid customer impact. The CEO is concerned about data exfiltration. The compliance officer reminds you of regulatory requirements to report breaches within 72 hours. Which action should you take FIRST?
Hard53Refer to the exhibit. What is the first action the incident responder should take?
Easy54Which THREE are phases of the incident response process according to NIST SP 800-61?
Easy55Which metric is used to define the maximum amount of data loss an organization can tolerate during a disaster?
Easy56During a tabletop exercise for a data center outage, the IT manager realizes that the disaster recovery plan does not specify how to failover the database cluster. The primary data center fails completely. The standby site has a replica of the database, but the application team cannot promote it because they lack the necessary privileges. What is the most likely cause of this gap?
Hard57A financial services company's business continuity plan includes a recovery time objective (RTO) of 4 hours for its trading platform. During a recent test, the platform was restored in 6 hours. Which of the following should be the PRIMARY focus of the after-action review?
Medium58Refer to the exhibit. A DBA is investigating a replication issue. What should be the FIRST action?
Hard59Which TWO actions are appropriate during the identification phase of incident response?
Hard60A company is developing a business continuity plan (BCP). Which TWO of the following are essential components that must be included in a BCP?
Medium61Which TWO are true about a differential backup? (Select two.)
Medium62Which THREE are differences between a hot site and a cold site? (Select three.)
Hard63After a security incident has been contained and eradicated, which of the following should be done to improve future incident response?
Medium64During an incident, the IR team identifies that the root cause is a zero-day vulnerability. Which of the following is the best immediate action?
HardOther domains
All CC exam domains
Frequently asked questions
- What does the Business Continuity, DR & Incident Response domain cover on the CC exam?
- You must be able to apply BCP, DRP, and IR concepts to scenarios. The most important thing is to know the correct order of incident response steps and when to use each recovery site type.
- How many questions are in this domain?
- This page lists all 64 Business Continuity, DR & Incident Response questions in the CC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Business Continuity, DR & Incident Response questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.