CISSP Security Operations Practice Question
A business continuity plan (BCP) differs from a disaster recovery plan (DRP) in that the BCP primarily focuses on:
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Maintaining critical business processes during a disruption
BCP aims to maintain business functions during and after a disruption, while DRP focuses on IT restoration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Securing physical facilities
Why it's wrong here
Securing physical facilities, while a critical aspect of an organization's overall security and risk management, is a preventative measure that precedes a disruption and is not the primary distinguishing focus of a Business Continuity Plan (BCP). A BCP primarily addresses the operational strategies and procedures for sustaining business functions *after* a facility may have been compromised or rendered unavailable, rather than solely on its initial physical protection.
- ✗
Restoring IT systems and infrastructure
Why it's wrong here
Restoring IT systems and infrastructure, including servers, networks, and applications, is the specific and primary objective of a Disaster Recovery Plan (DRP). A DRP details the technical steps and procedures required to bring critical technology components back online after a disruptive event. While essential for supporting business operations, this technical restoration is a tactical component of the broader BCP, which addresses the continuity of the entire business, not just its IT backbone.
- ✓
Maintaining critical business processes during a disruption
Why this is correct
Maintaining critical business processes during a disruption is the defining characteristic and primary objective of a Business Continuity Plan (BCP). A BCP outlines the strategies, procedures, and resources necessary to ensure that an organization's essential functions continue to operate, even when faced with significant outages or disasters. This involves identifying critical processes, determining acceptable downtime, and establishing alternative methods to sustain operations until full recovery is achieved.
- ✗
Replacing hardware and software
Why it's wrong here
Replacing hardware and software components, such as damaged servers, workstations, or corrupted applications, is a specific task typically outlined within a Disaster Recovery Plan (DRP). This activity falls under the technical recovery efforts aimed at rebuilding or restoring the technological infrastructure. While vital for eventual operational resumption, it represents a tactical step in the IT recovery process rather than the overarching strategic goal of a BCP to sustain business functions through various means.
Go deeper
Related to this question
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.