Courseiva

CISSP Security and Risk Management Practice Question

Which of the following is a key objective of a business impact analysis (BIA)?

⚠ Common exam trap

CISSP often tests the confusion between BIA outputs (MTD, RTO, RPO) and downstream activities like control implementation or DR testing, so candidates must remember BIA is an analysis, not an action.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Determine the maximum tolerable downtime for critical processes

A BIA is a foundational step in business continuity planning (BCP) that identifies critical business functions and quantifies the impact of their disruption over time. Its primary output is the maximum tolerable downtime (MTD), also called maximum allowable outage, along with recovery time objectives (RTO) and recovery point objectives (RPO) for each critical process. Determining MTD lets the organization prioritize recovery efforts and justify continuity investments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement security controls

    Why it's wrong here

    Implementing security controls is a risk-treatment activity performed after the BIA identifies impact; the BIA itself quantifies disruption and recovery priorities, not control deployment. Control selection suits the risk response stage, where identified critical processes are matched to safeguards.

  • ✗

    Identify vulnerabilities in the network

    Why it's wrong here

    A BIA quantifies the operational and financial impact of disrupting business processes, establishing recovery priorities and tolerances; it does not enumerate network weaknesses. Vulnerability identification belongs to risk assessment or scanning. The option tempts because BIA feeds risk analysis, but its axis is impact over time, not flaw discovery.

  • ✗

    Test the disaster recovery plan

    Why it's wrong here

    Testing the disaster recovery plan validates recovery capability and occurs after the BIA has set recovery time and point objectives. The BIA determines impact and criticality; it does not execute tests. DR testing suits the later validation phase, once continuity strategies are built from BIA findings.

  • ✓

    Determine the maximum tolerable downtime for critical processes

    Why this is correct

    The BIA quantifies how long each critical process can be unavailable before unacceptable impact, producing the maximum tolerable downtime that shapes recovery time objectives and continuity strategies. This directly satisfies the objective of prioritising recovery efforts by business impact.

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.