CISSP Security and Risk Management Practice Question
Which of the following is the PRIMARY goal of a Business Impact Analysis (BIA) in business continuity planning?
⚠ Common exam trap
CISSP often tests the confusion between the BIA and other BCP phases, such as plan testing or role assignment, so candidates must remember that the BIA is strictly about identifying critical processes and their impact over time, not about implementing or testing recovery strategies.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To determine the maximum acceptable outage for each process
The primary goal of a Business Impact Analysis (BIA) is to identify the critical business processes and determine the maximum acceptable outage (MAO) or maximum tolerable downtime (MTD) for each. This involves assessing the financial, operational, and legal impacts of disruptions over time. The BIA provides the data needed to set recovery time objectives (RTOs) and recovery point objectives (RPOs), which drive the overall business continuity strategy. Thus, determining the maximum acceptable outage is the core purpose of a BIA.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
To determine the maximum acceptable outage for each process
Why this is correct
The primary goal of a Business Impact Analysis (BIA) is to systematically identify and quantify the potential impacts of business disruptions and, crucially, to determine the Maximum Acceptable Outage (MAO), also known as Maximum Tolerable Downtime (MTD), for each critical business process. This analysis establishes the absolute longest period a business function can be unavailable before suffering unacceptable consequences, thereby setting critical recovery time objectives (RTOs) that guide subsequent disaster recovery planning and resource allocation.
- ✗
To test the disaster recovery plan
Why it's wrong here
Testing the disaster recovery plan is a distinct phase that occurs *after* the Business Impact Analysis (BIA) and the development of the Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP). The BIA focuses on identifying critical processes and their recovery requirements, while testing validates the effectiveness and viability of the implemented recovery strategies and procedures. Conflating these activities would prematurely attempt to validate a plan that hasn't been fully designed based on proper impact assessment.
- ✗
To assign roles and responsibilities during a disaster
Why it's wrong here
Assigning roles and responsibilities during a disaster is a critical component of the Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP) development and implementation phases, not the primary goal of the Business Impact Analysis (BIA). The BIA's purpose is to identify the impacts of disruptions and prioritize processes, providing the foundational data upon which roles, responsibilities, and specific recovery tasks are subsequently defined within the actionable recovery plans. Without the BIA's output, roles would be assigned without a clear understanding of the most critical functions or their required recovery timelines.
- ✗
To select a hot site vendor
Why it's wrong here
Selecting a hot site vendor is an implementation decision that follows the completion of a Business Impact Analysis (BIA) and the subsequent determination of recovery strategies. The BIA identifies the organization's critical recovery time objectives (RTOs), recovery point objectives (RPOs), and resource requirements, which then inform the specifications for potential recovery sites. Only after these requirements are clearly defined by the BIA can an informed decision be made regarding the selection of an appropriate vendor or recovery solution.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
MTD
MTD (Maximum Tolerable Downtime) is the longest period a business can function without a specific system or service before the damage becomes unacceptable.
Key term
Business impact analysis
A systematic process used to identify and evaluate the potential effects of an interruption to critical business operations as a result of a disaster, accident, or emergency.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.