Business Impact Analysis (BIA) Essentials
Which TWO are essential elements of a business impact analysis (BIA)?
Quick Answer
The answer is the determination of maximum acceptable outage (MAO) and the identification of critical business functions. These are essential elements of a business impact analysis (BIA) because the BIA’s core purpose is to quantify the operational and financial consequences of disruptions, and without knowing which functions are critical and how long they can be down, you cannot prioritize recovery or allocate resources effectively. On the ISC2 Certified in Cybersecurity CC exam, this concept tests your understanding of disaster recovery fundamentals; a common trap is confusing the BIA with the risk assessment itself—remember, the BIA focuses on impact and recovery time objectives, not on threats or vulnerabilities. A useful memory tip is to think “BIA = Business Impact = what breaks first and how long can it stay broken.”
⚠ Common exam trap
ISC2 often tests the distinction between BIA elements (like critical functions and MAO) and technical implementation details (like IP addresses or network diagrams), so candidates mistakenly choose options that sound technical but are irrelevant to the BIA process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Identification of critical business functions
Identifying critical business functions is a core element of a BIA. The BIA determines which systems and processes are essential for business operations, and without this identification, you cannot prioritize recovery efforts or allocate resources effectively during a disaster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A network topology diagram
Why it's wrong here
May be helpful but not essential.
- ✗
List of all employees
Why it's wrong here
HR-related, not BIA.
- ✓
Identification of critical business functions
Why this is correct
A core element of BIA.
- ✗
Assignment of IP addresses
Why it's wrong here
Not a BIA activity.
- ✓
Determination of maximum acceptable outage (MAO)
Why this is correct
Also known as RTO, key BIA output.
Go deeper
Related to this question
Learn chapter
Security Operations Basics
Key term
Recovery
Recovery is the process of restoring systems, data, and operations after a security incident, failure, or disaster to return to normal functioning.
Key term
Analysis
In incident response, analysis is the process of examining data and events to determine what happened, how it happened, and what actions to take.
About these practice questions
Courseiva writes every CC question from scratch — 976 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CC
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?
easy- A.Determine the cost of implementing security controls
- B.List all IT assets
- ✓ C.Identify critical business processes and their recovery priorities
- D.Assign incident response roles
Why C: The primary purpose of a business impact analysis (BIA) is to identify critical business processes and quantify the impact of their disruption, which directly determines recovery priorities and objectives (RTO/RPO). This output drives the business continuity and disaster recovery strategy, not asset inventory or cost estimation.
Variation 2. Which TWO are key outputs of a Business Impact Analysis (BIA)?
easy- ✓ A.List of critical business processes
- B.Password policy
- C.Network diagram
- D.Risk register
- ✓ E.Recovery Time Objectives
Why A: BIA identifies critical business processes and determines their recovery requirements, such as Recovery Time Objectives (RTO).
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.