Courseiva

CC · domain

Business Continuity, Disaster Recovery, and Incident Response

This domain covers how organizations keep operating and recover when disruption hits. For CC, it is tested through scenario questions on business impact analysis, recovery objectives, plan components, and incident response steps. You must distinguish continuity from recovery, understand RTO versus RPO, and know the sequence of detecting, containing, eradicating, and recovering from incidents.

83 questions23 easy37 medium23 hard

Focused practice

Practice Business Continuity, Disaster Recovery, and Incident Response questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Business Continuity, Disaster Recovery, and Incident Response

Be able to select the correct first step, usually business impact analysis, and correctly apply RTO and RPO to backup and restoration scenarios. The single most important thing is knowing that BIA comes before plan development and that RTO is downtime while RPO is data loss.

Business impact analysis identifying critical business functions and their dependencies

Recovery time objective versus recovery point objective for critical systems

Incident response lifecycle phases: preparation, detection, containment, eradication, recovery, lessons learned

Crisis communications components including notification, escalation, and stakeholder messaging

Watch out for

Common Business Continuity, Disaster Recovery, and Incident Response exam traps

  • ▸Confusing RTO with RPO: RTO is acceptable downtime, RPO is acceptable data loss measured in time.
  • ▸Assuming disaster recovery and business continuity are the same; DR restores IT, BCP keeps the whole business running.
  • ▸Skipping business impact analysis and jumping straight to plan writing, so critical functions and dependencies are missed.

Question index

All Business Continuity, Disaster Recovery, and Incident Response questions (83)

Click any question to see the full explanation, or start a practice session above.

1

An organization is developing a Business Continuity Plan (BCP). Which analysis is performed first to identify critical business functions and their dependencies?

Easy
2

During a disaster recovery test, the IT team successfully restored systems from backups and achieved the recovery time objective (RTO). However, users could not resume normal work because additional configuration and data validation were needed. Which metric was NOT met?

Medium
3

During a ransomware incident, the incident response team needs to communicate with stakeholders. According to best practices, which TWO groups should be notified immediately? (Select TWO.)

Medium
4

After an incident is resolved, which phase involves reviewing what happened, documenting lessons learned, and updating procedures?

Easy
5

An organization is selecting a recovery site strategy that offers the fastest recovery time, measured in hours, to minimize downtime for critical applications. Which recovery site type best meets this requirement?

Medium
6

A company experiences a data breach involving personal data of EU residents. Under GDPR, what is the maximum time within which the organization must notify the supervisory authority?

Medium
7

During a data breach incident, the incident response team discovers that personally identifiable information (PII) of European Union residents was compromised. According to GDPR, what is the maximum time frame for notifying the supervisory authority?

Medium
8

Which phase of the incident response process involves restoring systems to normal operation and applying patches to prevent recurrence?

Medium
9

An organization wants to ensure that its critical business functions can continue operating during a disruption. Which plan specifically addresses keeping the business running during a disruption?

Easy
10

A security analyst detects unusual outbound traffic from a server that suggests a data breach. According to GDPR, within what timeframe must the organization notify the supervisory authority?

Hard
11

A company is creating a backup strategy for its critical database. The database is updated continuously, and the company can tolerate up to 2 hours of data loss. Which TWO backup methods would best help achieve a recovery point objective (RPO) of 2 hours? (Select TWO.)

Medium
12

An organization's recovery time objective (RTO) for its customer database is 4 hours, and the recovery point objective (RPO) is 1 hour. The database is backed up every hour using full backups. A disaster occurs at 2:00 PM, and the last successful backup was at 1:00 PM. The system is restored and operational at 5:30 PM, but data from 1:00 PM to 2:00 PM is lost. Which statement is correct?

Medium
13

A company uses a reciprocal agreement for disaster recovery. What is a primary risk of this strategy?

Medium
14

An organization uses a 3-2-1 backup strategy. They have a primary full backup on a local NAS, a second copy on tape stored offsite, and a third copy in the cloud. During a ransomware attack, the local NAS and the tape library are both encrypted. Which copy should be used for recovery?

Hard
15

A financial institution's incident response team is handling a denial-of-service (DoS) attack that is affecting customer access. The team has identified the attack source IPs and implemented filtering rules on the perimeter firewall. Which phase of incident response is being performed?

Medium
16

An organization has an RTO of 4 hours and an RPO of 1 hour for its customer database. After a disaster, the IT team restores the database from backups that are 2 hours old, and the system becomes operational in 3 hours. Which of the following is true?

Hard
17

A financial services firm has a recovery time objective (RTO) of 2 hours for its trading platform and a recovery point objective (RPO) of 15 minutes. The disaster recovery team is evaluating whether a warm site can meet these requirements. Which statement best describes the limitation of a warm site in this scenario?

Hard
18

Which recovery site strategy provides the shortest recovery time objective (RTO), typically measured in hours, by maintaining a fully mirrored environment that can be activated immediately?

Easy
19

A software company's incident response plan defines a severity level of 'Critical' for incidents that cause a complete outage of customer-facing services. A developer accidentally deploys a faulty update that crashes the production web servers, making the service unavailable to all customers. Which incident response phase should the team be in when they apply a rollback to the previous working version?

Medium
20

Which recovery site strategy provides the fastest Recovery Time Objective (RTO), typically within hours, by maintaining a fully operational mirrored environment?

Easy
21

A retail company experiences a distributed denial-of-service (DDoS) attack that overwhelms its online store. The incident response team successfully mitigates the attack, and the store is back online. Which activity should the team perform as part of the post-incident activity phase?

Easy
22

An organization is creating a Business Continuity Plan (BCP). Which analysis should be performed first to identify critical business functions and their dependencies?

Easy
23

An organization is updating its incident response plan. Which THREE elements should be included in the preparation phase? (Select THREE.)

Hard
24

A security analyst detects unusual outbound network traffic from a server that normally does not communicate externally. After confirming a malware infection, the analyst isolates the server from the network. Which incident response phase is the analyst performing?

Medium
25

A mid-sized hospital's disaster recovery team is reviewing its incident response plan after a ransomware attack encrypted the electronic health record (EHR) system. The team determines that the attack began 36 hours before it was detected. Which incident response phase was most directly compromised by this delay?

Medium
26

A healthcare organization experiences a data breach involving protected health information (PHI). Under GDPR, within how many hours must the organization notify the relevant supervisory authority?

Medium
27

A financial services firm has activated its disaster recovery plan after a ransomware attack encrypted its primary data center. The incident response team has contained the attack, but the recovery team must restore operations. Which action should the recovery team take FIRST to ensure a successful restoration?

Hard
28

After a ransomware attack, the IT team restores systems from backups. The CEO asks how quickly data can be recovered. Which metric addresses the acceptable amount of data loss?

Medium
29

A company is planning its backup strategy and wants to balance storage efficiency with restore speed. Which TWO backup strategies should the company consider? (Select TWO)

Hard
30

During an incident, the incident response team identifies that a malware infection is spreading. They isolate affected systems to prevent further damage. Which phase of the incident response process are they performing?

Medium
31

Which type of backup copies all data that has changed since the last full backup, regardless of any subsequent incremental or differential backups?

Easy
32

A company is developing a business continuity plan. Which document identifies critical business functions and their dependencies, including the maximum acceptable downtime?

Easy
33

Which backup strategy offers the fastest restore time but requires the most storage space?

Medium
34

During an incident, a security analyst identifies a SQL injection attack. The team contains the threat by blocking the attacker's IP. Which step should be performed next in the incident response process?

Hard
35

A retail company's business continuity plan includes a requirement to test its disaster recovery capabilities annually. The IT team proposes conducting a tabletop exercise with key stakeholders. Which benefit does this type of test provide?

Medium
36

Which incident category involves an attempt to make a system or network resource unavailable to its intended users?

Medium
37

A company performs a full backup every Sunday and incremental backups on other days. On Wednesday, a server failure occurs. Which backups are needed to restore the server to its state at Tuesday's backup?

Medium
38

Which type of incident involves an attacker attempting to make a system or network resource unavailable to legitimate users?

Medium
39

During a security incident, a company must notify stakeholders without revealing sensitive details that could worsen the situation. Which TWO groups should typically be notified immediately according to incident response best practices? (Select TWO)

Medium
40

Which incident category involves an attacker tricking an employee into revealing their login credentials through a fraudulent email?

Easy
41

An organization is adopting the 3-2-1 backup rule. They currently have data on a primary server and a daily backup to an external hard drive. To comply with the rule, what is the minimum additional requirement?

Medium
42

An organization adopts the 3-2-1 backup rule. Which combination of backups satisfies this rule?

Medium
43

A security analyst detects unusual outbound network traffic from a server that typically only handles internal file sharing. The traffic appears to be exfiltrating sensitive data. Which phase of the incident response process should the analyst initiate next?

Medium
44

A security analyst is prioritizing incidents based on severity. Which TWO factors are most important for determining incident severity?

Medium
45

An organization experiences a ransomware attack that encrypts critical files. The incident response team follows the standard IR phases. After containing the infection and eradicating the malware, what is the next phase?

Medium
46

During a security incident, the crisis communication team must notify stakeholders. According to best practices, which THREE groups should always be included in initial notifications? (Select THREE.)

Hard
47

A company’s backup strategy: Full backup every Sunday, differential backups Monday through Saturday. On Thursday, the system fails. How many backups are needed to restore the data?

Medium
48

Which phase of the incident response process involves actions to stop the incident from causing further damage, such as isolating affected systems?

Easy
49

During a data breach investigation, the incident response team discovers that personally identifiable information (PII) of EU residents was exfiltrated. Under GDPR, what is the maximum time frame for notifying the supervisory authority?

Hard
50

A hospital's electronic health record (EHR) system must be available 24/7. The disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour. Which combination of backup and site strategy best meets these objectives?

Medium
51

Which of the following best describes a Disaster Recovery Plan (DRP)?

Easy
52

Which of the following is a key component of the 3-2-1 backup rule?

Easy
53

A company has a reciprocal agreement with another organization for disaster recovery. During a major outage, the company attempts to activate the agreement but finds that the partner's facility is also impacted by the same disaster. This scenario highlights a primary disadvantage of which recovery strategy?

Hard
54

A company is creating a business continuity plan. Which analysis should be performed first to identify critical business functions and their dependencies?

Easy
55

An organization stores backup data on a tape drive (onsite) and also replicates critical data to a cloud storage service. This practice best exemplifies which backup rule?

Medium
56

An organization is preparing its Business Continuity Plan (BCP). Which process identifies critical business functions and the impact of disruptions?

Easy
57

A company follows the 3-2-1 backup rule. It has two full backups: one on an external hard drive in the server room and one on tape in a safe on-site. Which step should be taken to fully comply with the rule?

Hard
58

A financial institution requires near-instantaneous recovery of its trading platform after a disaster. The recovery time objective (RTO) is 2 hours, and the recovery point objective (RPO) is 15 minutes. Which recovery site strategy best meets these requirements?

Hard
59

A company’s disaster recovery plan specifies an RTO of 4 hours and an RPO of 1 hour for its critical database. The database is backed up every hour using incremental backups. After a catastrophic failure, restoration takes 3 hours, but the database must be rolled forward using transaction logs. The total time to make the database fully operational is 5 hours. Which statement is correct?

Hard
60

Which incident category involves an attacker tricking an employee into revealing credentials?

Easy
61

During a disaster recovery test, an organization uses a warm site. The site has partially configured servers and network infrastructure but lacks recent data. The recovery team expects to have the system operational within 2 days. Which recovery metric is most directly addressed by the warm site's capabilities?

Hard
62

An organization experiences a data breach involving personally identifiable information (PII) of European Union residents. According to GDPR, which THREE of the following are required actions?

Hard
63

An organization is developing an incident response plan. Which TWO phases are part of the incident response lifecycle according to the NIST framework? (Select two.)

Medium
64

A security team is developing an incident response plan. Which THREE of the following are essential components of crisis communications during a data breach? (Choose three.)

Hard
65

A multinational corporation is reviewing its incident response plan after a recent data breach. The security team wants to ensure that during future incidents, evidence is properly preserved for potential legal action. Which TWO actions should be included in the incident response plan to support forensic readiness? (Choose two.)

Hard
66

An organization is evaluating recovery site options. Which TWO factors are most critical when selecting between a hot site and a warm site? (Select TWO.)

Medium
67

Which phase of the incident response process involves restoring systems to normal operations and confirming they are functioning correctly?

Easy
68

During an incident, a security analyst detects unusual network traffic from a workstation that is exfiltrating data to an external IP address. The analyst isolates the workstation. Which incident response phase does the isolation action belong to?

Hard
69

A company is selecting a recovery site strategy. They need to balance cost and recovery time. Which THREE factors should they consider when choosing between hot, warm, and cold sites? (Select three.)

Hard
70

Which backup method copies all data that has changed since the last full backup, regardless of subsequent incremental or differential backups?

Easy
71

A financial services company is conducting a Business Impact Analysis (BIA) for its online banking platform. Which THREE of the following are correctly defined metrics used in BIA?

Medium
72

After a major power outage, an organization needs to declare a disaster and activate its DRP. Which THREE elements should be included in the initial crisis communication?

Hard
73

During which phase of the incident response process would the team identify the root cause of a security incident?

Easy
74

A company's Business Impact Analysis (BIA) determines that its online payment system can tolerate a maximum of 2 hours of downtime. The IT team estimates that restoring the system from backups will take 1 hour, and the team needs another 30 minutes to verify data integrity and resume normal operations. Which metric does the 30-minute verification period represent?

Medium
75

A regional hospital's emergency department relies on a patient tracking system. The BIA shows the system's maximum tolerable downtime (MTD) is 2 hours. The recovery time objective (RTO) is currently 6 hours, and the recovery point objective (RPO) is 24 hours. Which action best aligns the recovery capability with the business requirement?

Medium
76

A company uses a backup strategy where on Monday a full backup is taken, and on Tuesday only data changed since Monday is backed up. On Wednesday, the backup includes all data changed since Monday. What type of backup is the Wednesday backup?

Medium
77

Which type of recovery site is pre-configured with hardware and software, but does not have live data, typically requiring days to become operational?

Easy
78

Which recovery site strategy provides the fastest recovery time, typically within hours, and is a fully mirrored environment ready to take over operations immediately?

Easy
79

An organization experiences a denial-of-service (DoS) attack. Which TWO actions should the incident response team take during the containment phase? (Select two.)

Easy
80

During a disaster, an organization activates a reciprocal agreement with another company. What is a primary risk associated with this strategy?

Hard
81

An organization's BIA determines that the payroll system has a Maximum Tolerable Downtime (MTD) of 4 hours. The current recovery plan has an RTO of 2 hours and an RPO of 1 hour. What is the maximum Work Recovery Time (WRT) allowed to meet the MTD?

Hard
82

A software-as-a-service (SaaS) provider is developing its business continuity plan (BCP). The company wants to ensure it can continue operating during a prolonged power outage at its primary data center. Which element of the BCP should address the alternate power source and its regular testing?

Medium
83

Which backup strategy requires the least amount of time to perform a daily backup but the most time to perform a full restore?

Easy

Frequently asked questions

What does the Business Continuity, Disaster Recovery, and Incident Response domain cover on the CC exam?
Be able to select the correct first step, usually business impact analysis, and correctly apply RTO and RPO to backup and restoration scenarios. The single most important thing is knowing that BIA comes before plan development and that RTO is downtime while RPO is data loss.
How many questions are in this domain?
This page lists all 83 Business Continuity, Disaster Recovery, and Incident Response questions in the CC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Business Continuity, Disaster Recovery, and Incident Response questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isc2-cc ISC2-CC cc bc dr ir Practice Questions