Courseiva
mediumMultiple ChoiceObjective-mapped

CISSP Practice Question: During a business impact analysis (BIA), a…

During a business impact analysis (BIA), a department manager states that a critical process cannot be interrupted for more than 2 hours. However, the current backup system requires 8 hours to restore. What is the most appropriate risk management action?

⚠ Common exam trap

A common mix-up: candidates choose 'accept the risk' (Option C) thinking it is a valid risk management strategy, but the BIA has already defined an unacceptable downtime threshold, making acceptance inappropriate without a formal risk treatment plan that justifies the gap.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Mitigate the risk by implementing faster backup and restoration procedures.

The BIA identifies a maximum tolerable downtime (MTD) of 2 hours, but the current recovery time objective (RTO) is 8 hours, creating a gap. Mitigating the risk by implementing faster backup and restoration procedures directly reduces the RTO to meet the MTD, aligning recovery capability with business requirements. This is the most appropriate action because it addresses the root cause—insufficient recovery speed—without unnecessarily discarding or transferring the process.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Mitigate the risk by implementing faster backup and restoration procedures.

    Why this is correct

    The Business Impact Analysis (BIA) identified that the current 8-hour recovery time for a critical system far exceeds the required 2-hour Recovery Time Objective (RTO). Implementing faster backup technologies, such as incremental backups with rapid restore capabilities, or enhancing restoration procedures, directly addresses this gap. This strategy reduces the impact of an outage by bringing the actual recovery time within acceptable business parameters, thereby mitigating the identified risk.

  • Avoid the risk by discontinuing the process.

    Why it's wrong here

    Risk avoidance involves eliminating the activity or process that generates the risk. While this would certainly prevent the RTO violation, discontinuing a process identified as "critical" during a BIA is generally not a viable option, as it would severely disrupt core business operations and likely cause greater financial or reputational harm than the risk itself. This approach is only suitable for non-essential processes where the risk outweighs any business benefit.

  • Accept the risk and document the decision.

    Why it's wrong here

    Risk acceptance is a valid strategy when the cost of mitigation outweighs the potential impact of the risk, or when the risk is deemed low. However, in this scenario, an 8-hour recovery time for a system with a 2-hour RTO represents a significant and unacceptable gap. Accepting such a substantial deviation from a critical business requirement would expose the organization to severe operational, financial, and reputational consequences, making it an irresponsible decision.

  • Transfer the risk to a third-party service provider.

    Why it's wrong here

    Risk transfer involves shifting the financial burden or operational responsibility of a risk to another entity, often through insurance or outsourcing. While a third-party provider could manage backups and restoration, the organization's ultimate accountability for meeting its RTO remains. Simply transferring the risk does not inherently guarantee the 2-hour RTO will be met; the contract with the provider would still need to explicitly stipulate and enforce this critical recovery objective, effectively requiring the provider to implement the necessary mitigation.

About these practice questions

This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.