Courseiva
mediumMultiple Select

SSCP Practice Question: Which TWO of the following are key components of…

Which TWO of the following are key components of a Business Impact Analysis (BIA)?

⚠ Common exam trap

ISC2 often tests the distinction between BIA components (RTO, criticality analysis) and risk assessment components (vulnerability assessment, likelihood, threat modeling), causing candidates to conflate impact analysis with risk analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Recovery time objective.

A Business Impact Analysis (BIA) identifies the critical business functions and the maximum tolerable downtime, so the Recovery Time Objective (RTO) is a core output — it defines how quickly a process or system must be restored after disruption, directly driving continuity and recovery strategies. Criticality analysis is also a key BIA component because it ranks business processes and assets by their importance to the organization, typically using impact categories such as financial, operational, legal, and reputational, which determines prioritization for recovery. Vulnerability assessment (B) is a risk-assessment activity that identifies weaknesses in systems, not a BIA component, and it focuses on exposure rather than business impact. Likelihood estimation (D) belongs to risk analysis, where the probability of a threat event is evaluated, whereas the BIA focuses on consequences and tolerances. Threat modeling (E) is a security design technique for identifying threats and attack paths, not a BIA element, since the BIA is threat-agnostic and centers on business process impact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Recovery time objective.

    Why this is correct

    The recovery time objective defines the maximum tolerable downtime for a business process, directly satisfying the BIA's need to quantify impact over time. It links process criticality to recovery priorities, which is why it counts as a key BIA component rather than a purely technical recovery metric.

  • ✗

    Vulnerability assessment.

    Why it's wrong here

    Vulnerability assessment identifies weaknesses in systems, which supports risk analysis rather than business impact analysis. A BIA instead determines the operational and financial consequences of disrupting critical business processes, deriving RTO, RPO and MTD. It is tempting because both inform continuity planning, but vulnerability scanning addresses exposure, not impact severity.

  • ✓

    Criticality analysis.

    Why this is correct

    Criticality analysis ranks business functions by the impact of their disruption, directly satisfying the BIA's need to identify which processes and resources are most essential. It feeds recovery time objectives and recovery point objectives, ensuring continuity planning prioritises the systems whose failure would most severely affect the organisation's operations and obligations.

  • ✗

    Likelihood estimation.

    Why it's wrong here

    Likelihood estimation belongs to risk assessment, which gauges how probable a threat event is; a BIA instead determines impact over time from disruption, identifying critical processes and recovery priorities. It is tempting because likelihood feeds overall risk analysis, but the BIA's components are impact criteria such as RTO, RPO and MTD.

  • ✗

    Threat modeling.

    Why it's wrong here

    Threat modelling identifies adversary tactics and attack paths against systems, feeding risk assessment; a BIA instead quantifies the impact of process disruption over time, producing RTO, RPO and MTD figures. It is tempting because both support resilience planning, but threat modelling addresses cause and likelihood, not business consequence.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.