DRI INTERNATIONAL BCP EXAM QUESTIONS &
ANSWERS
Business Continuity - Answer -An ongoing process to ensure that the necessary steps
are taken to identify the impact of potential losses and maintain viable recovery
strategies, recovery plans, and continuity of services. (NFPA 1600)
Disaster Recovery - Answer -The technical aspect of business continuity. The
collection of resources and activities to re-establish information technology services
(including components such as infrastructure, telecommunications, systems,
applications and data) at an alternate site following a disruption of IT services. Disaster
recovery includes subsequent resumption and restoration of those operations at a more
permanent site. (DRJ)
Risk Assessment - Answer -The quantification of threats to an organization and the
probability of them being realized. (BCI)
Business Impact Analysis - Answer -A method of identifying the effects of failing to
perform a function or requirement. (FCD-1)
Recovery Time Objective - Answer -Time goal for the restoration and recovery of
functions or resources based on the acceptable down time and acceptable level of
performance in case of a disruption of operations. (ASIS)
Recovery Point Objective - Answer -Point to which information used by an activity must
be restored to enable the activity to operate on resumption. ISO Editor's Note: Can also
be referred to as "maximum data loss". (ISO 22301)
Crisis Management - Answer -The overall coordination of an organization's response to
a crisis, in an effective, timely manner, with the goal of avoiding or minimizing damage
to the organization's profitability, reputation, and ability to operate. (DRJ)
Incident Management - Answer -The process by which an organization responds to and
controls an incident using emergency response procedures or plans. (DRJ)
Incident Response - Answer -The response of an organization to a disaster or other
significant event that may significantly impact the organization, its people, or its ability to
function productively. An incident response may include evacuation of a facility, initiating
a disaster recovery plan, performing damage assessment, and any other measures
necessary to bring an organization to a more stable status.
(DRJ)
, The Business Continuity Professional's Role - Answer -1. Establish the need for a
business continuity program
2. Obtain support and funding for the business continuity program
3. Build the organizational framework to support the business continuity program
Scope - Answer -The boundary, or extent, to which a process, procedure, certification,
or contract applies - considers the whole entity.
Objectives - Answer -Documents what will be delivered at the end of the project and
what benefit that will provide to the entity.
Assumptions - Answer -Documents the assumptions you are making regarding the
program.
The steering committee should .. - Answer -Determine/establish objectives, program
structure, critical success factors and be involved in project/program management
In which area of the professional practices would you develop teams for the Business
Continuity program? - Answer -Program initiation and management
Leadership is accountable/liable for? - Answer -Understanding their legal
responsibilities to the business continuity program. The laws, regulations,
contractual/employment agreements.
How often should you conduct a risk assessment? - Answer -Annually or as significant
changes occur.
What is the first professional practice for Business Continuity Management? - Answer -
Program Initiation and Management
What is the second professional practice for Business Continuity Management? -
Answer -Risk Assessment
What is the third professional practice for Business Continuity Management? - Answer -
Business Impact Analysis
What is the fourth professional practice for Business Continuity Management? - Answer
-Business Continuity Strategies
What is the fifth professional practice for Business Continuity Management? - Answer -
Incident Response
What is the sixth professional practice for Business Continuity Management? - Answer
-Plan development and implementation
ANSWERS
Business Continuity - Answer -An ongoing process to ensure that the necessary steps
are taken to identify the impact of potential losses and maintain viable recovery
strategies, recovery plans, and continuity of services. (NFPA 1600)
Disaster Recovery - Answer -The technical aspect of business continuity. The
collection of resources and activities to re-establish information technology services
(including components such as infrastructure, telecommunications, systems,
applications and data) at an alternate site following a disruption of IT services. Disaster
recovery includes subsequent resumption and restoration of those operations at a more
permanent site. (DRJ)
Risk Assessment - Answer -The quantification of threats to an organization and the
probability of them being realized. (BCI)
Business Impact Analysis - Answer -A method of identifying the effects of failing to
perform a function or requirement. (FCD-1)
Recovery Time Objective - Answer -Time goal for the restoration and recovery of
functions or resources based on the acceptable down time and acceptable level of
performance in case of a disruption of operations. (ASIS)
Recovery Point Objective - Answer -Point to which information used by an activity must
be restored to enable the activity to operate on resumption. ISO Editor's Note: Can also
be referred to as "maximum data loss". (ISO 22301)
Crisis Management - Answer -The overall coordination of an organization's response to
a crisis, in an effective, timely manner, with the goal of avoiding or minimizing damage
to the organization's profitability, reputation, and ability to operate. (DRJ)
Incident Management - Answer -The process by which an organization responds to and
controls an incident using emergency response procedures or plans. (DRJ)
Incident Response - Answer -The response of an organization to a disaster or other
significant event that may significantly impact the organization, its people, or its ability to
function productively. An incident response may include evacuation of a facility, initiating
a disaster recovery plan, performing damage assessment, and any other measures
necessary to bring an organization to a more stable status.
(DRJ)
, The Business Continuity Professional's Role - Answer -1. Establish the need for a
business continuity program
2. Obtain support and funding for the business continuity program
3. Build the organizational framework to support the business continuity program
Scope - Answer -The boundary, or extent, to which a process, procedure, certification,
or contract applies - considers the whole entity.
Objectives - Answer -Documents what will be delivered at the end of the project and
what benefit that will provide to the entity.
Assumptions - Answer -Documents the assumptions you are making regarding the
program.
The steering committee should .. - Answer -Determine/establish objectives, program
structure, critical success factors and be involved in project/program management
In which area of the professional practices would you develop teams for the Business
Continuity program? - Answer -Program initiation and management
Leadership is accountable/liable for? - Answer -Understanding their legal
responsibilities to the business continuity program. The laws, regulations,
contractual/employment agreements.
How often should you conduct a risk assessment? - Answer -Annually or as significant
changes occur.
What is the first professional practice for Business Continuity Management? - Answer -
Program Initiation and Management
What is the second professional practice for Business Continuity Management? -
Answer -Risk Assessment
What is the third professional practice for Business Continuity Management? - Answer -
Business Impact Analysis
What is the fourth professional practice for Business Continuity Management? - Answer
-Business Continuity Strategies
What is the fifth professional practice for Business Continuity Management? - Answer -
Incident Response
What is the sixth professional practice for Business Continuity Management? - Answer
-Plan development and implementation