Courseiva

CISSP Security and Risk Management Practice Question

In the context of business continuity planning, which THREE of the following are typically identified during a business impact analysis (BIA)? (Select THREE.)

⚠ Common exam trap

CISSP often tests the confusion between BIA outputs and other planning artifacts, such as vendor contracts or HR metrics, which are not part of the BIA scope.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Critical business processes

A BIA identifies critical business processes (A) because it must determine which functions are essential to the organization's survival and prioritize them for recovery. It also establishes the maximum tolerable downtime (B), the longest time a process can be unavailable before causing unacceptable harm, which drives recovery strategies. The recovery point objective (D) is likewise derived during the BIA, defining the maximum acceptable data loss measured in time and setting backup frequency requirements. Preferred vendor contracts (C) are procurement/legal artifacts addressed during recovery planning or supply-chain review, not core BIA outputs. Employee performance metrics (E) belong to HR performance management and are unrelated to continuity impact analysis.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Critical business processes

    Why this is correct

    The primary objective of a Business Impact Analysis (BIA) is to identify and prioritize the organization's critical business processes. By distinguishing core operations from non-essential ones, the BIA allows planners to allocate recovery resources effectively and establish realistic recovery timelines. Without this inventory, the BCP cannot target the most vital survival functions of the enterprise.

  • ✓

    Maximum tolerable downtime (MTD)

    Why this is correct

    Maximum Tolerable Downtime (MTD) represents the total amount of time a business process can be disrupted before causing irreparable harm to the organization. Established during the BIA phase, MTD serves as the foundational threshold that constrains both the Recovery Time Objective (RTO) and the Recovery Point Objective (RPO). It is a critical metric for determining the viability of disaster recovery strategies.

  • ✗

    Preferred vendor contracts

    Why it's wrong here

    While third-party dependencies are evaluated during a BIA, the actual negotiation, management, and maintenance of preferred vendor contracts are operational procurement activities. These contracts are utilized during the implementation and execution phases of the disaster recovery plan rather than the analytical BIA phase. Consequently, they do not constitute a core metric or output of the initial BIA process itself.

  • ✓

    Recovery point objective (RPO)

    Why this is correct

    The Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss measured in time, which directly dictates the frequency of data backup operations. Determined during the BIA, RPO helps align technical recovery capabilities with business tolerance for data gaps. It ensures that backup strategies are engineered to prevent catastrophic data loss during a disruptive event.

  • ✗

    Employee performance metrics

    Why it's wrong here

    Employee performance metrics, such as key performance indicators (KPIs) and annual reviews, assess individual worker productivity and are managed by Human Resources. These metrics do not influence the systemic assessment of business process criticality, downtime tolerances, or resource requirements during a BIA. They are entirely out of scope for business continuity planning, which focuses on organizational resilience rather than individual performance management.

About these practice questions

One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.