Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 337 discussion

Actual exam question from ISC's CISSP
Question #: 337
Topic #: 1
[All CISSP Questions]

What is the MAIN purpose of conducting a business impact analysis (BIA)?

  • A. To determine the cost for restoration of damaged information system
  • B. To determine the controls required to return to business critical operations
  • C. To determine the critical resources required to recover from an incident within a specified time period
  • D. To determine the effect of mission-critical information system failures on core business processes
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
CuteRabbit168
Highly Voted 2 years, 1 month ago
Selected Answer: D
A business impact analysis (BIA) is a systematic process to determine and evaluate the potential effects of an interruption to critical business operations as a result of a disaster, accident or emergency. A business impact analysis (BIA) predicts the consequences of a disruption or outage of a business function, system or process and gathers information needed to develop recovery strategies.
upvoted 8 times
jackdryan
1 year, 6 months ago
D is correct
upvoted 1 times
...
...
sandeepghadge
Highly Voted 2 years, 1 month ago
Conducting the Business Impact Analysis (BIA) The next step in the planning process is to have the planning team perform a BIA. The BIA will help the company decide what needs to be recovered, and how quickly. Mission functions are typically designated with terms such as critical, essential, supporting, and nonessential to help determine the appropriate prioritization. I will go with C
upvoted 6 times
Goseu
1 year, 7 months ago
I agree with you.
upvoted 2 times
...
...
TheManiac
Most Recent 6 months, 1 week ago
Selected Answer: D
BIA is not made for infosec systems. answer is D
upvoted 1 times
TheManiac
6 months, 1 week ago
I meant C :( but there is no edit button
upvoted 1 times
...
...
eboehm
7 months, 2 weeks ago
Selected Answer: C
Interesting everyone went with D. The problem I have with answer d is that it mentions Information systems when a bia is about all business processes. I honestly think C is a better answer. Why do you identify critical processes? its for part 2(identify resource requirements) and 3(identify recovery priorities) of the BIA process. Ultimately, part 1 feeds into part 2. Everyone can claim their system is the most critical but once faced with how much recovery costs would be, this often changes. The critical outcomes of BIA will be a series of time measurements: MTD, RTO, RPO, WRT. None of the other BCP planing steps can be done without these values. Infact the MTD is what escalates incident to being a disaster
upvoted 2 times
...
franbarpro
2 years, 1 month ago
Selected Answer: D
Failures on core business processes sounds like it could have a huge impact on the business.
upvoted 2 times
...
WiDeBarulho
2 years, 1 month ago
Selected Answer: D
Going with "D" on this one. Option "C" falls more towards the DR aspect of BIA.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...