CISSP Security and Risk Management Practice Question
Which of the following is a key objective of a business impact analysis (BIA)?
⚠ Common exam trap
CISSP often tests the confusion between BIA outputs (MTD, RTO, RPO) and downstream activities like control implementation or DR testing, so candidates must remember BIA is an analysis, not an action.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Determine the maximum tolerable downtime for critical processes
A BIA is a foundational step in business continuity planning (BCP) that identifies critical business functions and quantifies the impact of their disruption over time. Its primary output is the maximum tolerable downtime (MTD), also called maximum allowable outage, along with recovery time objectives (RTO) and recovery point objectives (RPO) for each critical process. Determining MTD lets the organization prioritize recovery efforts and justify continuity investments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement security controls
Why it's wrong here
Implementing security controls is a risk-treatment activity performed after the BIA identifies impact; the BIA itself quantifies disruption and recovery priorities, not control deployment. Control selection suits the risk response stage, where identified critical processes are matched to safeguards.
- ✗
Identify vulnerabilities in the network
Why it's wrong here
A BIA quantifies the operational and financial impact of disrupting business processes, establishing recovery priorities and tolerances; it does not enumerate network weaknesses. Vulnerability identification belongs to risk assessment or scanning. The option tempts because BIA feeds risk analysis, but its axis is impact over time, not flaw discovery.
- ✗
Test the disaster recovery plan
Why it's wrong here
Testing the disaster recovery plan validates recovery capability and occurs after the BIA has set recovery time and point objectives. The BIA determines impact and criticality; it does not execute tests. DR testing suits the later validation phase, once continuity strategies are built from BIA findings.
- ✓
Determine the maximum tolerable downtime for critical processes
Why this is correct
The BIA quantifies how long each critical process can be unavailable before unacceptable impact, producing the maximum tolerable downtime that shapes recovery time objectives and continuity strategies. This directly satisfies the objective of prioritising recovery efforts by business impact.
Go deeper
Related to this question
Learn chapter
Disaster Recovery Planning
Key term
Maximum tolerable downtime
Maximum tolerable downtime (MTD) is the total amount of time a business process or system can be unavailable before causing irreparable harm to the organization.
Key term
Business impact analysis
A systematic process used to identify and evaluate the potential effects of an interruption to critical business operations as a result of a disaster, accident, or emergency.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.