hardMultiple Select
CISSP Practice Question: Which THREE are key components of a business…
Which THREE are key components of a business continuity plan (BCP)?
⚠ Common exam trap
ISC2 often tests the distinction between BCP components (recovery-focused) and security controls (prevention-focused), so candidates mistakenly select vendor assessments or hardening standards because they sound like 'planning' activities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Backup strategies
Backup strategies (B) are a core BCP component because they define how data and systems are preserved and restored so critical operations can resume after disruption. Recovery time objectives (C) are essential because they set the maximum acceptable downtime for each business function, driving recovery priorities and resource allocation. Emergency response procedures (E) belong in a BCP because they specify the immediate actions, roles, and communications needed to protect people and stabilize operations during an incident. Vendor risk assessments (A) are more closely tied to third-party risk management, and system hardening standards (D) are technical security controls, so neither is one of the three key BCP components in this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vendor risk assessments
Why it's wrong here
While critical for overall organizational resilience, vendor risk assessments primarily fall under third-party risk management, focusing on evaluating the security posture and operational reliability of external service providers. A Business Continuity Plan (BCP) leverages the *results* of these assessments to inform strategies for managing supply chain disruptions, but the assessment process itself is distinct from the core BCP components that define internal recovery actions and targets.
- ✓
Backup strategies
Why this is correct
Backup strategies are fundamental components of a Business Continuity Plan, detailing the systematic process of creating and storing copies of critical data and systems. These strategies specify backup frequency, storage locations (on-site, off-site, cloud), retention policies, and the methods for restoring data, ensuring the availability and integrity of information required for business operations post-disruption.
- ✓
Recovery time objectives (RTOs)
Why this is correct
Recovery Time Objectives (RTOs) are crucial elements within a Business Continuity Plan, establishing the maximum tolerable duration for restoring business functions and IT systems after a disruption to avoid unacceptable consequences. RTOs are derived from Business Impact Analysis (BIA) and dictate the urgency and resources allocated to recovery efforts, directly influencing the choice of recovery strategies and technologies.
- ✗
System hardening standards
Why it's wrong here
System hardening standards are foundational security practices aimed at reducing vulnerabilities by configuring systems to minimize attack surfaces and enhance their resilience against threats. While essential for preventing disruptions, these standards are part of an organization's overall information security program and operational baselines, rather than a direct component of a Business Continuity Plan, which focuses on *responding to* and *recovering from* events that bypass or overcome these preventative measures.
- ✓
Emergency response procedures
Why this is correct
Emergency response procedures are vital components of a Business Continuity Plan, outlining the immediate actions to be taken by personnel during and immediately after an incident to protect life, property, and critical assets. These procedures include initial incident assessment, activation of crisis communication plans, evacuation protocols, and initial damage containment, setting the stage for subsequent recovery activities defined by the BCP.
Go deeper
Related to this question
Learn chapter
Secure Network Architecture and Components
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Incident
An incident is a security event that violates an organization's policies or threatens its data, systems, or operations, requiring a structured response.
About these practice questions
This CISSP question is part of Courseiva's 816-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.