Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

Free and Premium BCI CBCI Dumps Questions Answers

Page: 1 / 13
Total 176 questions

Certificate of the Business Continuity Institute (CBCI) Questions and Answers

Question 1

Which of the following is NOT correct in relation to the purpose of defining the scope of the Business Continuity Management System (BCMS)?

Options:

A.

It ensures a clear understanding of the areas of the organization that are, and are not, covered by the BCMS

B.

It establishes permanent parameters for the BCMS

C.

It defines the BCMS on the organization’s products, services, and activities

D.

It makes the best use of available time and finances

Buy Now
Question 2

Which of the following is a process that analyses the impact over time of a disruption on an organization?

Options:

A.

Business Impact Analysis

B.

Recovery Time Analysis

C.

Cost Benefit Analysis

D.

Risk and Threat Analysis

Question 3

Establishing governance arrangements for a Business Continuity Management System (BCMS) is essential in order to:

Options:

A.

Develop a project risk register and carry out appropriate risk assessments in the workplace

B.

Ensure that there is ongoing commitment across all organizational functions and levels

C.

Commission research into approaches taken by organizations

D.

Enable the Business Continuity professional to establish their authority and issue instructions on the actions that need to be taken

Question 4

When developing solutions for people strategies, solutions to recover activities with a short Recovery Time Objective (RTO) requiring redeployment of personnel should be supported by:

Options:

A.

The development of training material including all relevant information and procedures so that this can be made available when required

B.

Links to social media so the organization can run an extensive recruitment campaign both inside and outside the organization if a disruptive event occurs

C.

Recruitment of additional personnel so that the organization always has access to surplus staff in case of an incident occurring

D.

Induction and training by an operational manager at the time when the disruption is underway so that individuals can build understanding and confidence prior to commencing the allocated tasks

Question 5

Why should a Business Continuity (BC) policy be written in a way that is easy to read and concise?

Options:

A.

To ensure that only minimum information is shared with personnel and other interested parties

B.

To ensure that the correct specialist jargon and acronyms are being used consistently across the organization

C.

To ensure that it sets out points in a way that is straightforward and engaging for staff involved in implementing Business Continuity (BC) in the organization

D.

To act as an accessible summary document to support the actions detailed in the Business Continuity Management System (BCMS)

Question 6

Which of the following is an outcome of personnel embracing Business Continuity (BC) and the organization's Business Continuity Management System (BCMS)?

Options:

A.

A programme that is bespoke to the organization and its culture

B.

A strong financial performance due to increased investment in Business Continuity (BC)

C.

Reductions in staff turnover due to additional rewards and recognitions made available for supporting Business Continuity (BC)

D.

A reduction in the need for support for Business Continuity (BC) from external customers and partners

Question 7

What is the purpose of assigning roles and responsibilities as part of the Business Continuity Management System (BCMS)?

Options:

A.

To take pressure off the organization's top management by delegating tasks

B.

To ensure that all essential tasks are allocated to identified and competent individuals

C.

To assist the Business Continuity (BC) professional in implementing the BCMS

D.

To create a highly trained team who can then cascade their expertise by training other members of staff

Question 8

Which of the types of review that can be used to review a Business Continuity Management System (BCMS) can be described as being designed to provide independent assurance on a set of processes without confirming that the solutions adopted are necessarily correct?

Options:

A.

Internal audit

B.

Performance appraisal

C.

Post-incident review

D.

Quality assurance

Question 9

Which of the following is a possible outcome of a gap analysis to establish whether new strategies and solutions are required?

Options:

A.

Validation exercises to confirm the findings of the gap analysis that can be presented to top management as part of the decision-making process

B.

Agreement from top management that a Business Impact Analysis (BIA) should be completed to determine the new procedures required

C.

A determination that Business Continuity capabilities exceed requirements and resources could be redistributed

D.

A schedule for sharing the outcomes with all personnel to invite their comments and encourage them to embrace Business Continuity

Question 10

Which one of the following should be implemented when updating Business Continuity (BC) plans?

Options:

A.

A copy should be placed on the organization's shared drive so that personnel can identify it for themselves when they look at the system

B.

A formal version control process to identify the date of review and bring attention to changes

C.

A brief note about the update in a staff newsletter that is printed and placed on noticeboards

D.

An internal email to all personnel stating that a new version is available and suggesting that personnel request a copy of the new version if they are interested in seeing it

Question 11

Which of the following statements best describes the relationship between Business Continuity strategies and solutions?

Options:

A.

Strategies align to the direction set out in the Business Continuity policy whilst solutions address the outlined objectives in the Business Continuity Management System (BCMS)

B.

Strategies are based on the outcomes of the Business Impact Analysis (BIA) whereas solutions are based on the outcomes of the risk assessment

C.

Strategies are high-level approaches for meeting the organization's Business Continuity requirements whereas solutions detail how the strategies will be implemented

D.

Strategies focus on the methods and procedures for business as usual activities whereas solutions focus on the treatments and actions to minimize risks

Question 12

Which type of Business Impact Analysis (BIA) identifies and prioritises the tasks that deliver the most urgent products and services and determines the resources and dependencies required in order to enable these tasks to be completed?

Options:

A.

Product and Service BIA

B.

Process BIA

C.

Activity BIA

D.

Priority BIA

Question 13

In relation to the process for developing and managing an exercise, which of the following steps in the process of developing an exercise would come first?

Options:

A.

Assess and report the outcomes and lessons learned

B.

Plan and design the exercise, including setting a budget and time frame and conducting a risk assessment

C.

Agree on the exercise's scope, objectives, timeline and expected outcomes

D.

Conduct the exercise

Question 14

Which of the following is demonstrated where an organization includes Business Continuity in induction processes and sets Business Continuity objectives for personnel?

Options:

A.

The organization's approach to risk assessment

B.

The organization's Business Continuity culture

C.

The role of the Business Continuity professional

D.

The use of validation

Question 15

An effective exercise programme should:

Options:

A.

Be put in place as part of the outcome of the Business Impact Analysis (BIA) and the associated solutions design

B.

Follow the same framework of activities each year so that progress can be compared over time

C.

Be reviewed regularly at pre-defined intervals or following significant change

D.

Reflect trends in customer concerns and feedback from stakeholders

Question 16

An effective response structure includes:

Options:

A.

Unlimited access to financial resources during a disruption

B.

Knowledge of when key suppliers and external stakeholders should be notified and included in the response

C.

Flexibility to change policies and procedures during a disruption without consulting top management

D.

Personnel in place to assess and measure the performance of responders during a disruption

Question 17

Which of the following is a benefit of conducting an exercise?

Options:

A.

Confirmation of how well Business Continuity is incorporated into the tasks pertaining to the Business Continuity Management System (BCMS)

B.

Confirmation that personnel are familiar with their roles, and authority in response to an incident

C.

Increased understanding of the requirements set out in the Activities Business Impact Analysis (BIA)

D.

Validation of the Business Continuity Management System (BCMS) against standards, regulations and legislation

Question 18

The process that ensures that an organization's Business Continuity arrangements are up to date and ready to respond to incidents and their impacts despite changes to its structure or changes in its operational context is:

Options:

A.

Review

B.

Gap analysis

C.

Maintenance

D.

Internal audit

Question 19

Which of the following is an indicator that top management is embracing Business Continuity?

Options:

A.

Business Continuity is part of the organization's strategic planning and is reviewed regularly

B.

The organization's health and safety risk assessments are recorded as required

C.

The organization maintains full compliance with legal and regulatory requirements

D.

The organization's Business Continuity operational plans are kept up to date

Question 20

The most appropriate type of exercise for verifying if a critical system can be restored from backups within the expected Recovery Time Objective (RTO) is a:

Options:

A.

Scenario exercise

B.

Test

C.

Discussion-based exercise

D.

Simulation

Question 21

The scope of the Business Continuity Management System (BCMS) should be reviewed if:

Options:

A.

A new Business Continuity professional is appointed and they provide a fresh focus on the approach to be taken

B.

An exercise activity reveals that changes to operational procedures are needed

C.

There is a change to the internal or external operating context

D.

Personnel are not embracing Business Continuity and a new approach to engage them is required

Question 22

Which of the following is essential to ensure the ongoing effectiveness and relevance of a Business Continuity Management System (BCMS) and should be built into the initial process to establish a BCMS?

Options:

A.

Determining how the BCMS will be monitored, reviewed and continually improved over time

B.

Developing internal and external communications systems to raise the profile of the BCMS and highlight successful steps in the development

C.

Carrying out health and safety risk assessments in all parts of the organization and making a commitment to repeat these assessments every year as part of the BCMS

D.

Ensuring compliance with legal requirements across the company and developing a register of any risks

Question 23

When implementing solutions so that they can be deployed to respond to disruption, the Business Continuity professional should:

Options:

A.

Review and revise the specifications for each solution developed in the design phase prior to launching them

B.

Work with the teams who will utilize the solutions to develop any new systems or tools required to enable implementation

C.

Allocate implementation to the relevant teams and instruct them to manage the implementation as they see fit and to their own timelines

D.

Empower the implementation team to make changes to specifications without referring back to top management

Question 24

When considering solutions for supplier strategies, the Business Continuity professional should ensure that:

Options:

A.

Suppliers have capability that aligns with the organization's Recovery Time Objectives (RTOs) that rely on them

B.

Suppliers can deliver high-quality products and services during business as usual situations

C.

The solutions are reviewed by procurement prior to approval

D.

Priority should be given to existing suppliers

Question 25

Which of the following could the Business Continuity professional use to explain how embracing Business Continuity could add value to the organization?

Options:

A.

It will increase health and safety standards in the organization by reducing stress levels as personnel do not need to be concerned during disruptions

B.

It will resolve all conflicts between personnel and departments in the organization as personnel will re-focus their priorities to shared Business Continuity activities

C.

It increases competitive advantage by increasing the ability of the organization to remain operational in the face of a disruption

D.

It will enable senior managers to delegate their responsibilities to team members as personnel will be willing to take on additional accountabilities leaving senior managers free to develop new products and services

Question 26

Which of the following would NOT be taken into account when developing and drafting a Business Continuity policy?

Options:

A.

Providing detailed background information in the introduction to the policy which explains, with examples, how the new approach will be different from past approaches

B.

Setting expectations for how the BCMS will be operationalized

C.

Using concise and straightforward language that is accessible to all personnel

D.

Designing the policy to be appropriate to the type of organization and to reflect the culture and operating environment

Question 27

Recording and counting the number of hours spent by personnel in participating in Business Continuity (BC) training is a way for the BC professional to measure the:

Options:

A.

Business continuity culture in an organization

B.

Amount of knowledge and understanding that individuals have gained through their study

C.

Effectiveness of the People and Culture department

D.

Reduction in risks related to Business Continuity (BC)

Question 28

Which of the following actions will lead to the protection of priority activities with respect to their Recovery Time Objectives (RTOs) and will limit the impacts of disruptions to prioritised activities?

Options:

A.

Conducting a risk assessment

B.

Conducting an Activity Business Impact Analysis (BIA)

C.

Creating a set of approved strategies and solutions to mitigate unacceptable risks and single points of failure

D.

Grouping unacceptable risks and single points of failure by owner and having discussions with each activity and resource owner

Question 29

The purpose of an external audit of the Business Continuity Management System (BCMS) is to:

Options:

A.

Confirm that the organization is fully prepared to respond to incidents

B.

Provide independent assurance on a set of Business Continuity processes and controls

C.

Assess the performance of the members of top management team in relation to Business Continuity

D.

Make recommendations on alternative ways of meeting recovery time objectives (RTOs)

Question 30

When developing a response structure for an organization, the process should include:

Options:

A.

Consulting with customers and suppliers on the requirements for the structure

B.

Ensuring that appropriate and competent individuals are assigned to leadership roles in the structure

C.

Advising department heads that department structure will have to change to match the proposed response structure

D.

Implementing a supporting performance management system in the organization to ensure that all managers and personnel are complying with the new requirements

Question 31

Which of the following should be included in a post-incident review of a Business Continuity Management System (BCMS)?

Options:

A.

Information from those involved in the event and also from those involved in the response and recovery activities.

B.

Consideration of responsibility and allocation of accountability for errors made either before or during the incident.

C.

A review of the BCMS implementation and an action plan for improvement.

D.

Information from a related audit report.

Question 32

Validation is achieved through a combination of activities. Which one of following options lists the three activities?

Options:

A.

Exercising, debriefing, and peer review

B.

Exercising, maintenance and analysing

C.

Exercising, updating, and stakeholder review

D.

Exercising, maintenance, and review

Question 33

In order to make it easier to manage risk, complexity and cost when establishing a Business Continuity Management System (BCMS), the initial scope of the BCMS should:

Options:

A.

Include as many of the organization's products and services as possible

B.

Be limited to information technology disaster recovery plans

C.

Be limited to specific high-value areas of the organization

D.

Focus on crisis management

Question 34

When defining the scope of the Business Continuity Management System (BCMS), which one of the following is true?

Options:

A.

Scope should take into consideration all external suppliers and customers

B.

Once the scope is defined, it remains static until completion of the BCMS development process

C.

The scope provides a clear understanding of areas of the organization covered by the BCMS and those not covered

D.

The scope sets out the high-level principles which underpin the organization's approach to BC

Question 35

The professional practice that aims to measure the competence of individuals, team cohesiveness and the effectiveness of Business Continuity (BC) capability is:

Options:

A.

Solutions Design

B.

Analysis

C.

Validation

D.

Enabling Solutions

Question 36

In relation to the care and wellbeing of staff during an incident, which of the following would NOT be an immediate requirement for the People and Culture Management team?

Options:

A.

Accounting for the personnel on the site where the incident has occurred

B.

Being able to contact personnel and their family members

C.

Assigning responsibilities to staff who are working away from the site to enable recovery activities to commence

D.

Enabling access to physical care if needed

Question 37

The organization's requirements for information and data resources should be considered as part of the Activity Business Impact Analysis (BIA). Which of the following is correct in relation to the Recovery Point Objective (RPO)?

Options:

A.

All data users and activities have the same requirements; so only limited consultation is required to determine the RPO

B.

The RPO should comply with data protection requirements

C.

The RPO is the point to which information must be restored to enable all priority activities to operate on resumption

D.

The RPO establishes the amount of time that IT services can be disrupted before the organization is impacted

Question 38

Which of the following statements describes a good practice Business Continuity (BC) culture?

Options:

A.

A situation where personnel follow procedures as set out by the organization but do not have a sense of ownership.

B.

A situation where Business Continuity (BC) professionals have significant influence in the organization and specify all actions to be taken and carry out all reviews as needed.

C.

A situation where all staff have a shared understanding of Business Continuity (BC) and everyone is involved.

D.

A situation where the workforce is sufficiently committed to Business Continuity (BC) that top management does not get involved.

Question 39

What should an organization do when it does not yet have fully developed Business Continuity (BC) solutions, response structures, and Business Continuity plans in place?

Options:

A.

Conduct an initial Business Impact Analysis (BIA)

B.

Develop and implement an interim crisis management plan

C.

Outsource the response to a Business Continuity service provider when a crisis or disruption occurs

D.

Implement a "go to" strategy and acquire the required resources, equipment, and services when disruption occurs

Question 40

The three main steps involved in the risk assessment process are listing risk sources, performing a risk source analysis and:

Options:

A.

Identifying historical risks

B.

Categorising risks

C.

Assessing the consequences of risks

D.

Evaluating risks

Question 41

Which method of measuring culture requires periodic checks to determine the percentage of the organization's personnel currently covered by existing Business Continuity culture initiatives?

Options:

A.

Unstructured observation

B.

Culture index

C.

Behavioural consistency

D.

Business Continuity awareness

Question 42

Which of the following is a factor to be taken into consideration when developing and using risk assessments?

Options:

A.

Risk assessments will need to work undertaken during the Business Impact Analysis (BIA) to determine the products, services, and activities that need to be

B.

The time that has elapsed since the last assessment of risks in order to maintain its currency

C.

Risk assessments are primarily produced as information for regulators and auditors to provide evidence that the organization is monitoring and managing risks

D.

Risk assessments are based on estimations of the likelihood and consequences of a risk occurring

Question 43

Which one of the following is a feature of an effective Business Continuity (BC) policy?

Options:

A.

There is clear top management commitment to the policy and its continued improvement.

B.

The policy details the incident management plans and the financial budgets available to support recovery plans.

C.

The policy provides details of constraints on specific suppliers.

D.

The policy can be validated by exercises and updated with the detailed learning that arises from carrying out the exercises.

Question 44

Following all Business Impact Analyses (BIAs), what information should be provided to top management in a consolidated analysis?

Options:

A.

Feedback from staff on organizational concerns

B.

Confirmation and information about the frequency of previous disruptions

C.

Products and services by order of priority and the priority of related activities (and processes if relevant)

D.

Review of external conditions and a determination of the probability of disruption for each threat identified

Question 45

When developing a system to measure Business Continuity culture, it is important to take into account:

Options:

A.

How to ensure that all personnel are required to respond to the process

B.

The aims of the activity and how the information will be collected and assessed

C.

The way that the outcomes will inform the design of Business Continuity solutions

D.

The need to present the outcomes in a positive way for top management and stakeholders

Question 46

If a Business Continuity (BC) culture gap analysis shows that the gap between the existing culture and the desired BC culture is large, which of the following approaches would be the best one for the BC professional to take?

Options:

A.

Adopt a BC culture development approach that was successfully used by another organization.

B.

Introduce an aggressive training programme for all employees that focuses on details of the BCMS.

C.

Start with the basics, ensuring that employees' needs and perspectives are recognised, and then progress to more advanced topics.

D.

Expand and enhance BCMS information on the organization’s intranet and introduce a requirement that all employees review the information at least once a year.

Question 47

Which of the following will determine the way that an organization uses Business Impact Analysis (BIA)?

Options:

A.

Consultation with internal and external stakeholders on their views of priorities and risks

B.

The size, complexity and type of organization

C.

The outcomes of exercises testing existing BC plans

D.

Feedback from risk management professionals

Question 48

Which of the following is a technique for collecting Business Impact Analysis (BIA) information?

Options:

A.

Workplace observation

B.

Workplace health and safety reviews

C.

Monthly budget reviews

D.

Questionnaires and surveys

Question 49

When identifying risk mitigation strategies and solutions in relation to unacceptable risk and/or single point dependencies, the Business Continuity (BC) professional should collaborate with:

Options:

A.

Activity and resource owners

B.

Top management

C.

Incident response team leaders

D.

Media and communication managers

Question 50

Which of the following is an outcome of personnel embracing Business Continuity and the organization's Business Continuity Management System (BCMS)?

Options:

A.

A Business Continuity programme that is tailored specifically for the organization, taking into account its organizational culture

B.

A reduction in the need to update and review the BCMS due to the commitment of personnel in the development stage

C.

Increased sales of products and services due to public confidence in the published information about the organization’s resilience capability

D.

Validation of plans is no longer needed due to the high level of commitment from relevant personnel to their effective implementation

Question 51

A strategic plan:

Options:

A.

May be supported by a separate crisis communications plan

B.

Should identify viable options to coordinate efforts of the operational teams

C.

Should contain procedures for responding to emergencies, including threats to life, or the environment

D.

May contain procedures for coordinating the transportation of personnel to alternate facilities

Question 52

Why is a risk assessment usually conducted after a Business Impact Analysis (BIA) as part of the analysis stage?

Options:

A.

Conducting a BIA ties up personnel on this project; so resources are not available to conduct the risk assessment until after personnel are released from the BIA project

B.

Conducting the risk assessment after the BIA has identified priorities enables the risk assessment to maximise investment in risk treatments where they are most needed

C.

A risk assessment is not required until Business Continuity solutions based on the outcomes of the BIA have been developed for review

D.

Risk assessments are not required until after the organization's business plan has been updated to confirm any changes in plans as a result of the BIA

Page: 1 / 13
Total 176 questions