Courseiva

ISC2 CC Business Continuity, DR & Incident Response Practice Question

Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?

⚠ Common exam trap

ISC2 often tests the distinction between a BIA (which identifies critical processes and their recovery priorities) and a risk assessment (which identifies threats and vulnerabilities), leading candidates to confuse the BIA's purpose with asset listing or cost analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Identify critical business processes and their recovery priorities

The primary purpose of a business impact analysis (BIA) is to identify critical business processes and quantify the impact of their disruption, which directly determines recovery priorities and objectives (RTO/RPO). This output drives the business continuity and disaster recovery strategy, not asset inventory or cost estimation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Determine the cost of implementing security controls

    Why it's wrong here

    Costing security controls is a risk-treatment and budgeting activity; a BIA establishes impact over time and derives recovery objectives instead. It is tempting because BIA findings do justify control spend, and costing controls would be correct when performing a cost-benefit analysis to select safeguards.

  • ✗

    List all IT assets

    Why it's wrong here

    Asset inventory is an input to the BIA, not its purpose; the BIA determines which functions are critical and the impact of their loss. It is tempting because you must know your assets before assessing impact, and listing assets would be correct during the asset identification phase of risk assessment.

  • ✓

    Identify critical business processes and their recovery priorities

    Why this is correct

    A BIA determines which business processes are most critical and sets their recovery priorities, typically through impact ratings over time. This directly satisfies the stem's focus on prioritisation, distinguishing it from risk assessment or purely technical recovery sequencing activities.

  • ✗

    Assign incident response roles

    Why it's wrong here

    A BIA identifies critical business functions and quantifies disruption impact, producing RTO and RPO figures; role assignment belongs to the incident response plan. It is tempting because BIA outputs do inform response planning, and assigning roles would be correct when building the incident response team structure itself.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.