Courseiva

ISC · domain

Contingency Management

Practise (ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) Contingency Management practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

24 questions4 easy12 medium8 hard

Focused practice

Practice Contingency Management questions

Scored sessions drawing only from this domain — pick a length below.

What this domain covers

What to know about Contingency Management

Contingency Management questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Contingency Management exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Contingency Management questions (24)

Click any question to see the full explanation, or start a practice session above.

1

Your organization uses a 'Warm Site' for its disaster recovery strategy. During a recent audit, you find that the site lacks the necessary bandwidth to support peak production traffic. What is the most appropriate management response?

Medium
2

You are auditing a third-party disaster recovery service provider. Which metric provides the most accurate evidence that the provider can meet your organization's required recovery point for a database cluster?

Medium
3

Which THREE of the following strategies should be included in a 'Disaster Recovery Program Oversight' function to ensure long-term viability?

Hard
4

Your organization has decided to use a 'Cloud Disaster Recovery' service. The vendor provides a 'Pilot Light' strategy. What does this mean for your organization's recovery capability?

Hard
5

When designing the Crisis Communication Plan, why is it essential to establish pre-approved communication templates?

Easy
6

You are implementing a disaster recovery strategy for a database that uses synchronous replication. What is the most significant trade-off you must accept by enforcing this configuration?

Medium
7

Which TWO of the following are primary risks associated with an 'asynchronous' data replication strategy?

Medium
8

Which document serves as the primary governing authority to define the triggers, escalation paths, and communication roles during a declared crisis event?

Easy
9

During a disaster recovery simulation for a hybrid cloud environment, you discover that the automated orchestration tool fails to restore dependencies in the correct order because the cloud provider's metadata tags were purged. What is the most effective administrative control to prevent this during a real event?

Hard
10

When classifying business processes for BCP, what is the 'Recovery Time Objective' (RTO) most effectively used for?

Medium
11

Your organization has adopted a cloud-native microservices architecture. Which strategy is most appropriate for maintaining business continuity in the event of a regional cloud provider outage?

Hard
12

An ISSMP is reviewing the Business Continuity Plan (BCP) for a critical application. Which TWO of the following factors should be considered when defining the 'Maximum Tolerable Downtime' (MTD)?

Medium
13

What is the primary objective of a 'lessons learned' meeting conducted after a disaster recovery exercise?

Easy
14

Your organization uses a 'Hot Site' with hardware-level replication. During a disaster, the primary site becomes unavailable, but the failover fails due to a 'Split-Brain' scenario. What is the fundamental cause of this?

Hard
15

An ISSMP is revising the BCP to account for 'Supply Chain Resiliency'. Which approach is best for verifying that critical third-party vendors can meet the organization's recovery requirements?

Medium
16

Which THREE of the following are essential components of a robust Crisis Management Plan?

Hard
17

Which of the following is the most effective method for testing the efficacy of a Business Continuity Plan without disrupting production operations?

Easy
18

When designing a Disaster Recovery Program, which THREE of the following represent common 'single points of failure' that must be addressed?

Hard
19

In a decentralized organization, which approach to BCP management ensures both local agility and global alignment?

Medium
20

During a BIA review, you need to identify critical assets and their recovery requirements. Which TWO of the following inputs are essential for this classification process?

Medium
21

Which TWO of the following are effective ways to improve 'Crisis Management Leadership' effectiveness during an incident?

Medium
22

During a BCP planning session, the executive team is debating the 'Maximum Tolerable Downtime' (MTD) for a legacy internal application. What is the correct way to define this metric?

Medium
23

An ISSMP is overseeing a BCP program and notes that the current Business Impact Analysis (BIA) is heavily focused on RTO but lacks a critical dependency mapping for cross-functional business processes. Which specific action should the ISSMP prioritize to address the systemic risk of cascading failure during a disaster?

Medium
24

Following a ransomware attack, the organization must decide whether to invoke the DRP or remain in a degraded state while security teams perform forensics. What is the ISSMP's primary responsibility in this decision-making process?

Hard

Frequently asked questions

What does the Contingency Management domain cover on the ISC exam?
Contingency Management questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 24 Contingency Management questions in the ISC question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Contingency Management questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
(ISC)2 Information Systems Security Management Professional (CISSP-ISSMP, Aug 2025 blueprint) (ISC) Contingency Management Practice Questions