Pre-Summer Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

BCI CBCI Certificate of the Business Continuity Institute (CBCI) Exam Practice Test

Page: 1 / 18
Total 176 questions

Certificate of the Business Continuity Institute (CBCI) Questions and Answers

Question 1

The purpose of an external audit of the Business Continuity Management System (BCMS) is to:

Options:

A.

Confirm that the organization is fully prepared to respond to incidents

B.

Provide independent assurance on a set of Business Continuity processes and controls

C.

Assess the performance of the members of top management team in relation to Business Continuity

D.

Make recommendations on alternative ways of meeting recovery time objectives (RTOs)

Question 2

Business as usual (BAU) plans document processes for restoring an organization to its original state and should:

Options:

A.

Be developed in detail prior to any incident occurring

B.

Focus on resuming activities in reverse order of Recovery Time Objectives (RTOs)

C.

Be based on the availability of primary resources prior to the incident

D.

Take into consideration possibility of new vulnerabilities resulting from impacted resources

Question 3

Which of the following is NOT a way in which an organization can use exercise programs to ensure and validate supply chain continuity?

Options:

A.

By including key suppliers in an internal exercise

B.

By requiring suppliers to share evidence that recovery plans and exercise programs have been developed and implemented

C.

By including a requirement in Service Level Agreements (SLAs) for suppliers to carry out exercise activities and share the outcomes

D.

By conducting internal exercises to assess the impact of supply chain failures

Question 4

When considering solutions for supplier strategies, the Business Continuity professional should ensure that:

Options:

A.

Suppliers have capability that aligns with the organization's Recovery Time Objectives (RTOs) that rely on them

B.

Suppliers can deliver high-quality products and services during business as usual situations

C.

The solutions are reviewed by procurement prior to approval

D.

Priority should be given to existing suppliers

Question 5

When establishing a Business Continuity Management System (BCMS), engagement with stakeholders is important. Which of the following is NOT a reason for engaging with internal stakeholders?

Options:

A.

Existing policies and procedures may be relevant to the BCMS so early identification will reduce the risk for duplication of work

B.

Early collaboration with colleagues will engage them in the process and secure support for the ongoing development and implementation of the BCMS

C.

Engagement of stakeholders will reduce the potential for conflict at later stages of the programme

D.

Involving stakeholders will reduce the workload and responsibilities of the Business Continuity Professional as administrative activities can be delegated to other staff

Question 6

In relation to Business Impact Analysis (BIA), why is the risk assessment conducted after the BIA has been completed?

Options:

A.

To ensure that personnel and resources are not distracted from the primary purpose of delivering the BIA

B.

To enable the risk assessment to focus on the risks associated with prioritised products and services as determined by the BIA

C.

To prevent the risk assessment information leaking to external stakeholders before the BIA is available

D.

To ensure that there is sufficient time and focus available to complete a full organizational risk assessment that is not biased by ongoing work on the BIA

Question 7

The purpose of a Business Continuity policy is to:

Options:

A.

Initiate the development of an effective response structure in case of disruption to products or services within the scope of the Business Continuity Management System (BCMS)

B.

Enable the Business Continuity professional to issue instructions to all on the changes that they will be required to make

C.

Share the outcomes of a Business Impact Analysis with internal and external stakeholders

D.

Establish shared understanding of the importance of a BCMS and its relevance to the organization

Question 8

The process that ensures that an organization's Business Continuity arrangements are up to date and ready to respond to incidents and their impacts despite changes to its structure or changes in its operational context is:

Options:

A.

Review

B.

Gap analysis

C.

Maintenance

D.

Internal audit

Question 9

Strategic, tactical, and operational plans should always be activated:

Options:

A.

Simultaneously

B.

Only after it is determined that full activation of all teams is necessary

C.

When cascaded down from the strategic team

D.

Based on the conditions or circumstances documented in the relevant team plan

Question 10

Which of the following is NOT correct in relation to Business Continuity plans?

Options:

A.

They should contain detailed step-by-step instructions on what to do for every eventuality that could occur

B.

They may include scenario-specific plans that are designed to address a particular threat

C.

They should be validated before being deemed operational

D.

They should be kept up to date

Question 11

Which of the following explains the purpose of strategies and solutions in the context of Business Continuity (BC)?

Options:

A.

To ensure that the professionals involved in developing the strategy have appropriate levels of expertise

B.

To enable the organization to resume business operations within the approved continuity requirements

C.

To check how well the organization has carried out exercises to manage information restoration during a disruption

D.

To ensure that the organization's current procedures have sufficient clarity and accessibility to be effective during a disruption

Question 12

Which one of the following should be implemented when updating Business Continuity (BC) plans?

Options:

A.

A copy should be placed on the organization's shared drive so that personnel can identify it for themselves when they look at the system

B.

A formal version control process to identify the date of review and bring attention to changes

C.

A brief note about the update in a staff newsletter that is printed and placed on noticeboards

D.

An internal email to all personnel stating that a new version is available and suggesting that personnel request a copy of the new version if they are interested in seeing it

Question 13

A type of exercise where participants can explore relevant issues and walk through plans in a low-pressure environment is a:

Options:

A.

Scenario exercise

B.

Simulation exercise

C.

Investigative exercise

D.

Discussion-based exercise

Question 14

In your role as a Business Continuity (BC) professional you have submitted your company's first gap analysis to top management for their review and approval. The response is a decision not to address some gaps even though you had recommended some new strategies and solutions. The best course of action is to:

Options:

A.

Request a meeting to further discuss the importance of the recommendations.

B.

Recommend that the business pursues adjusted strategies and solutions that will partially close the identified gaps.

C.

Search for ways to lower the cost of carrying out the recommendations.

D.

Plan to resubmit the strategies and solutions during the validation phase.

Question 15

An effective response structure includes:

Options:

A.

Unlimited access to financial resources during a disruption

B.

Knowledge of when key suppliers and external stakeholders should be notified and included in the response

C.

Flexibility to change policies and procedures during a disruption without consulting top management

D.

Personnel in place to assess and measure the performance of responders during a disruption

Question 16

It is important to measure Business Continuity culture because this:

Options:

A.

Can determine whether or not the organization needs to continue reviewing and making improvements to its Business Continuity Management System (BCMS)

B.

Indicates how well personnel are likely to engage with, and follow Business Continuity plans and procedures

C.

Indicates whether or not there is a need to validate and update operational plans

D.

Provides data that can be used when promoting the organization to potential new recruits

Question 17

Which of the following is a step that would be taken by the Business Continuity professional to support the process to advance an organization from embedding to embracing Business Continuity?

Options:

A.

Development and adoption of a Business Continuity policy to protect the organization from disruptions

B.

Assigning Business Continuity roles and responsibilities across the organization's hierarchy

C.

Gaining an understanding of the organization's culture

D.

Including funding in the Business Continuity budget to hire a consulting firm to run Business Continuity as a project

Question 18

In relation to the care and wellbeing of staff during an incident, which of the following would NOT be an immediate requirement for the People and Culture Management team?

Options:

A.

Accounting for the personnel on the site where the incident has occurred

B.

Being able to contact personnel and their family members

C.

Assigning responsibilities to staff who are working away from the site to enable recovery activities to commence

D.

Enabling access to physical care if needed

Question 19

The scope of the Business Continuity Management System (BCMS) should be reviewed if:

Options:

A.

A new Business Continuity professional is appointed and they provide a fresh focus on the approach to be taken

B.

An exercise activity reveals that changes to operational procedures are needed

C.

There is a change to the internal or external operating context

D.

Personnel are not embracing Business Continuity and a new approach to engage them is required

Question 20

Which of the following could the Business Continuity professional use to explain how embracing Business Continuity could add value to the organization?

Options:

A.

It will increase health and safety standards in the organization by reducing stress levels as personnel do not need to be concerned during disruptions

B.

It will resolve all conflicts between personnel and departments in the organization as personnel will re-focus their priorities to shared Business Continuity activities

C.

It increases competitive advantage by increasing the ability of the organization to remain operational in the face of a disruption

D.

It will enable senior managers to delegate their responsibilities to team members as personnel will be willing to take on additional accountabilities leaving senior managers free to develop new products and services

Question 21

Which of the following is an indicator that top management is embracing Business Continuity?

Options:

A.

Business Continuity is part of the organization's strategic planning and is reviewed regularly

B.

The organization's health and safety risk assessments are recorded as required

C.

The organization maintains full compliance with legal and regulatory requirements

D.

The organization's Business Continuity operational plans are kept up to date

Question 22

Where social media is a key element in an organization's communications response strategy, it is important for the organization to:

Options:

A.

Build up followers and establish a social media presence before an incident

B.

Empower all staff to engage with social media to ensure that information during a disruption can be delivered quickly

C.

Ensure all staff who engage with social media are aware of the need to keep a note of their engagement in case valuable contacts are secured through this route

D.

Limit social media engagement to one-way communications as only the organization's formal statements and opinions are required

Question 23

The Process Business Impact Analysis (BIA):

Options:

A.

Is conducted prior to the Product and Services BIA

B.

Excludes processes that have been outsourced

C.

Identifies resource requirements and interdependencies

D.

Is optional and may be omitted

Question 24

Following all Business Impact Analyses (BIAs), what information should be provided to top management in a consolidated analysis?

Options:

A.

Feedback from staff on organizational concerns

B.

Confirmation and information about the frequency of previous disruptions

C.

Products and services by order of priority and the priority of related activities (and processes if relevant)

D.

Review of external conditions and a determination of the probability of disruption for each threat identified

Question 25

When identifying risk mitigation strategies and solutions in relation to unacceptable risk and/or single point dependencies, the Business Continuity (BC) professional should collaborate with:

Options:

A.

Activity and resource owners

B.

Top management

C.

Incident response team leaders

D.

Media and communication managers

Question 26

Why is it important to use a warning or code word such as “exercise only” when providing communication injects during an exercise?

Options:

A.

To ensure that the information is not treated as a real message

B.

To ensure that the information is treated as confidential

C.

To indicate that the message has been approved by the exercise facilitator

D.

To indicate that all information should be treated as real during the exercise

Question 27

When developing an exercise programme, it is important to include:

Options:

A.

All employees of the organization

B.

Only members of the response team

C.

Only Business Continuity (BC) professionals

D.

Everyone with a role in a team relevant to the scenario being exercised

Question 28

Which one of the following is a feature of an effective Business Continuity (BC) policy?

Options:

A.

There is clear top management commitment to the policy and its continued improvement.

B.

The policy details the incident management plans and the financial budgets available to support recovery plans.

C.

The policy provides details of constraints on specific suppliers.

D.

The policy can be validated by exercises and updated with the detailed learning that arises from carrying out the exercises.

Question 29

Consulting stakeholders, conducting a cost-benefit analysis, consulting with internal resources such as risk management and internal audit teams, and horizon scanning are some of the methods that might be used when:

Options:

A.

Measuring Business Continuity culture

B.

Identifying and assigning Business Continuity Management System (BCMS) roles and responsibilities

C.

Developing an exercise programme

D.

Defining the initial BCMS scope

Question 30

Which of the following would NOT be taken into account when developing and drafting a Business Continuity policy?

Options:

A.

Providing detailed background information in the introduction to the policy which explains, with examples, how the new approach will be different from past approaches

B.

Setting expectations for how the BCMS will be operationalized

C.

Using concise and straightforward language that is accessible to all personnel

D.

Designing the policy to be appropriate to the type of organization and to reflect the culture and operating environment

Question 31

Strategies to resume business operations following a disruption are based on the outcomes of the:

Options:

A.

Negotiations with stakeholders regarding their minimum requirements in a disruption

B.

Governance structures established for the Business Continuity Management System (BCMS)

C.

Analysis of Maximum Tolerable Period of Disruption (MTPD) and Recovery Time Objectives (RTO)

D.

Collaborations generated by the organization's Business Continuity culture

Question 32

In relation to validation, which of the following is NOT an aim of an exercise programme?

Options:

A.

Improved teamwork and competency of recovery team members

B.

Verification that the expected Recovery Time Objectives (RTOs) can be achieved

C.

Identification of outdated information in the Business Continuity (BC) plans and areas for improvement

D.

Design of additional Business Continuity (BC) policies and solutions

Question 33

When selecting solutions to mitigate unacceptable risks and single points of failure, the activity/resource owner will take into account:

Options:

A.

Findings from the Business Impact Analysis (BIA)

B.

The risks expected to materialise in the future

C.

Advantages and disadvantages of the solution

D.

The Business Continuity culture index

Question 34

For a strategic response team to be effective, its members should have:

Options:

A.

Ability to identify commercial opportunities in adverse situations

B.

A detailed understanding of each requirement set out in Business Continuity plans

C.

Skill in coordinating resources, operations and suppliers

D.

Decisiveness and the ability to make decisions quickly

Question 35

Which of the following is a benefit of conducting an exercise?

Options:

A.

Confirmation of how well Business Continuity is incorporated into the tasks pertaining to the Business Continuity Management System (BCMS)

B.

Confirmation that personnel are familiar with their roles, and authority in response to an incident

C.

Increased understanding of the requirements set out in the Activities Business Impact Analysis (BIA)

D.

Validation of the Business Continuity Management System (BCMS) against standards, regulations and legislation

Question 36

Within the context of risk assessment, the identification of solutions is influenced by a variety of business relevant considerations, including:

Options:

A.

Delivering performance targets

B.

Timely production of quality assurance audit trails

C.

Compliance with regulatory requirements

D.

Ensuring that communication protocols are observed

Question 37

Size of the organization, the organization's culture and how people prefer to receive information are among the factors for the Business Continuity (BC) professional to consider when:

Options:

A.

Developing an awareness strategy

B.

Planning a live exercise

C.

Developing plans

D.

Designing solutions

Question 38

A shared understanding across the organization of the importance and relevance of the Business Continuity Management System (BCMS) and an understanding of how the BCMS will be used are outcomes of:

Options:

A.

Providing access to a risk assessment

B.

Defining the scope of the BCMS

C.

An effectively communicated Business Continuity policy

D.

Appointing a Business Continuity steering group

Question 39

In relation to Business Continuity (BC) solutions, which of the following would be included in the procedure for communications with people outside of the organization during a disruption?

Options:

A.

Clarification that all personnel have the responsibility of keeping social media information up to date and should treat this as a priority activity

B.

Identification of the team, group or individual with the responsibility, authority and technical knowledge to deliver communications via each available method

C.

Instruction that external communications should not take place until after the incident is over

D.

Permission for communications personnel to make decisions on how the organization is represented in a crisis without prior agreement with top management

Question 40

Which of the following parameters would NOT be considered by a resource or activity owner when evaluating and selecting solutions to meet an agreed strategy?

Options:

A.

The advantages and disadvantages of the proposed solution

B.

The type of exercises to be conducted to validate the strategies and solutions

C.

The estimated costs to prepare, implement, operate and maintain the solution

D.

The implementation time required

Question 41

Which of the following is NOT correct in relation to plans for returning to business as usual (BAU)?

Options:

A.

It provides a general outline for returning to BAU in various situations that can be further developed during a disruption.

B.

It demonstrates that the organization understands what is required to prepare for a return to BAU.

C.

It should be regularly reviewed and included in training and exercises.

D.

It details the specific requirements and procedures that should be applied in all situations.

Question 42

In the context of transport and logistics resources being affected by an incident, which of the following would be a prerequisite for a Business Continuity (BC) solution that requires staff to use their own vehicles for company business requirements?

Options:

A.

Confirm that business insurance arrangements are available for staff who are likely to be asked to use their own vehicles during a disruption.

B.

Purchase vehicles for all staff to ensure that vehicles will be available.

C.

Ask customers to assist during the disruption and to use their vehicles to undertake the organization's priority activities.

D.

Introduce a new employment clause into the contracts of all current employees requiring all employees to own vehicles and make them available in case of disruption.

Question 43

Which of the following describes the focus of the strategic team as part of a response structure?

Options:

A.

Addressing issues and crises threatening the organization's viability and integrity

B.

Dealing with the immediate effects of an incident by containing it where possible and managing direct consequences

C.

Developing a step-by-step plan for managing the response to a physical disruption or incident

D.

Consolidating information from the operational teams

Question 44

Which of the following statements best describes the relationship between Business Continuity strategies and solutions?

Options:

A.

Strategies align to the direction set out in the Business Continuity policy whilst solutions address the outlined objectives in the Business Continuity Management System (BCMS)

B.

Strategies are based on the outcomes of the Business Impact Analysis (BIA) whereas solutions are based on the outcomes of the risk assessment

C.

Strategies are high-level approaches for meeting the organization's Business Continuity requirements whereas solutions detail how the strategies will be implemented

D.

Strategies focus on the methods and procedures for business as usual activities whereas solutions focus on the treatments and actions to minimize risks

Question 45

In relation to the development of solutions, the purpose of a gap analysis is to:

Options:

A.

Identify a strategy to close the existing gaps

B.

Design and select solutions to deliver strategies and close gaps

C.

Assess whether or not current capabilities are sufficient to meet the Business Continuity (BC) requirements

D.

Develop a risk mitigation strategy to address any identified single points of failure

Question 46

In order to ensure that priority is given to activities with the shortest Recovery Time Objectives (RTOs), strategies can:

Options:

A.

Include relevant extracts from the Business Impact Analysis (BIA)

B.

Highlight activities with short RTOs by categorising strategies by timeframe

C.

Include a risk assessment to identify the best treatment option

D.

Identify workarounds for all activities other than those with short RTOs

Question 47

Which of the following is an action that the Business Continuity professional will take as part of the process of strategy determination?

Options:

A.

Design a strategy for agreement with top management that can then be delegated to the relevant owners of priority products, services, activities, and processes

B.

Prepare a communications brief to advise all external stakeholders of the outcome of the gap analysis and the plan for acting on the findings

C.

Develop a mandatory training schedule to ensure that all personnel are required to address any skills gaps relevant to the delivery of priority products, services, activities, and processes

D.

Work with the relevant product, services, activity, or process owner to develop a specification for an appropriate solution

Question 48

Which of the following is NOT an outcome that will result from an organization embracing Business Continuity?

Options:

A.

Business Continuity tasks being given greater priority and completed on time

B.

A Business Continuity programme that is fit for purpose and adequately sized for the organization

C.

A reduction in the need to carry out maintenance activities and regular plan reviews and updates

D.

Recognition by interested parties of areas where Business Continuity adds value to their operation

Question 49

Which of the following would NOT be included in plans at all levels?

Options:

A.

Guidance for escalation

B.

Risk assessments for each possible scenario

C.

Purpose, scope, assumptions and objectives of the plan

D.

Procedures for standing down the teams when the incident has been resolved

Question 50

Which of the following statements about the methods used to collect information following an exercise is correct?

Options:

A.

Only senior level exercise participants should provide opinions during the debrief

B.

One-on-one interviews with all exercise participants should be conducted within one month following the exercise

C.

A hot debrief should be conducted within one month after the conclusion of an exercise

D.

Surveys are especially effective if an exercise and its participants are spread out over multiple locations

Question 51

Which of the following would be the most effective and motivating way to share information that is intended to influence personnel to embrace Business Continuity?

Options:

A.

Use language that is clear and easily accessible to all when producing documents, presentations or training materials

B.

Provide detailed explanations on all of the organization and set regular tests to ensure that personnel are taking sufficient interest

C.

Ensure that attendance at meetings is recorded and reflected in the staff performance appraisals

D.

Send all information via email or the intranet on the assumption that this will be everyone’s preferred, and most convenient, form of communication

Question 52

When defining the scope of the Business Continuity Management System (BCMS), which one of the following is true?

Options:

A.

Scope should take into consideration all external suppliers and customers

B.

Once the scope is defined, it remains static until completion of the BCMS development process

C.

The scope provides a clear understanding of areas of the organization covered by the BCMS and those not covered

D.

The scope sets out the high-level principles which underpin the organization's approach to BC

Page: 1 / 18
Total 176 questions