Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: geek65

CBCI Certificate of the Business Continuity Institute (CBCI) Questions and Answers

Questions 4

Which of the following is NOT correct in relation to the purpose of defining the scope of the Business Continuity Management System (BCMS)?

Options:

A.

It ensures a clear understanding of the areas of the organization that are, and are not, covered by the BCMS

B.

It establishes permanent parameters for the BCMS

C.

It defines the BCMS on the organization’s products, services, and activities

D.

It makes the best use of available time and finances

Buy Now
Questions 5

When developing a system to measure Business Continuity culture, it is important to take into account:

Options:

A.

How to ensure that all personnel are required to respond to the process

B.

The aims of the activity and how the information will be collected and assessed

C.

The way that the outcomes will inform the design of Business Continuity solutions

D.

The need to present the outcomes in a positive way for top management and stakeholders

Buy Now
Questions 6

When coordinating a Business Continuity Management System (BCMS), a steering group should be established to oversee, advise and make recommendations as the BCMS is established. The steering group should comprise:

Options:

A.

Only Business Continuity professionals and any available administrative support

B.

Only top management

C.

Customers and suppliers that are familiar with the way the organization works and can make recommendations from an external perspective

D.

Multi-disciplinary experts who are familiar with the operation of the organization

Buy Now
Questions 7

After all Business Impact Analyses (BIAs) have been completed, a consolidated analysis is carried out and a report is written to document the results. What is the purpose of this?

Options:

A.

For review by all BIA participants

B.

For submission to top management for final approval

C.

For planning an exercise

D.

For internal audit

Buy Now
Questions 8

Which of the following is the first step in the process for developing recovery strategies and solutions?

Options:

A.

Training personnel to carry out strategy determination activities

B.

Developing a Business Continuity policy

C.

Consulting relevant stakeholders on draft designs and proposals

D.

Carrying out a gap analysis to determine needs

Buy Now
Questions 9

When preparing to carry out a Business Impact Assessment (BIA), the Business Continuity professional should:

Options:

A.

Review all relevant organization documents to help assess the appropriate parameters and factors to be applied during the process

B.

Consult with personnel to determine preferred ways of working in different departments

C.

Consider the potential recovery strategies and solutions that may be implemented

D.

Ensure that the process includes an external communications procedure

Buy Now
Questions 10

Which type of exercise is always carried out in the normal operational environment, alternative premises, or command centres and is designed to include everyone that could be involved in the response if the incident were real?

Options:

A.

Simulation

B.

Discussion-based

C.

Scenario

D.

Live

Buy Now
Questions 11

The time period defined by the Recovery Time Objective (RTO) should always be less than which of the following?

Options:

A.

The Recovery Point Objective (RPO)

B.

The Maximum Tolerable Period of Disruption (MTPD)

C.

The Minimum Business Continuity Objective (MBCO)

D.

The standard timeline set by the organization's customer services charter

Buy Now
Questions 12

Which of the following parameters would NOT be considered by a resource or activity owner when evaluating and selecting solutions to meet an agreed strategy?

Options:

A.

The advantages and disadvantages of the proposed solution

B.

The type of exercises to be conducted to validate the strategies and solutions

C.

The estimated costs to prepare, implement, operate and maintain the solution

D.

The implementation time required

Buy Now
Questions 13

One of the steps in the risk management process is to establish the risk treatment required. The purpose of risk treatment is to:

Options:

A.

Ensure that a named person within the organization takes responsibility for the monitoring and management of the risk

B.

Calculate a risk score based on the combination of the likelihood of the risk occurring and the consequences of this happening

C.

Mitigate each risk identified by reducing the likelihood of the risk occurring or by lowering the impact of disruption

D.

Ensure that regular updates on the current status of the risk are presented to top management

Buy Now
Questions 14

Which of the following statements about embracing Business Continuity is correct?

Options:

A.

Embracing Business Continuity is relevant only to top management as other personnel are required to comply with tasks in their role description

B.

Embracing Business Continuity can be described as a corporate mandate driven by policy

C.

Embracing Continuity is where personnel commit to Business Continuity because they believe that is necessary to protect the organization and its interested parties

D.

Embracing Business Continuity is a culture that exists separately from the organization's culture

Buy Now
Questions 15

Consulting stakeholders, conducting a cost-benefit analysis, consulting with internal resources such as risk management and internal audit teams, and horizon scanning are some of the methods that might be used when:

Options:

A.

Measuring Business Continuity culture

B.

Identifying and assigning Business Continuity Management System (BCMS) roles and responsibilities

C.

Developing an exercise programme

D.

Defining the initial BCMS scope

Buy Now
Questions 16

When setting up any individual exercise, which of the following should be taken into consideration in relation to risks to business as usual?

Options:

A.

Personnel, including senior managers, should be instructed to consider the exercise as a priority and ignore any risks to business as usual that may arise during the exercise

B.

Pre-existing business as usual commitments should be treated as a secondary consideration to ensure that these commitments do not undermine the exercise activity

C.

The disruption caused by the exercise and any impact should be planned in advance, monitored and controlled during the exercise and minimised

D.

Any impacts of the exercise on business as usual should be written off in advance as an acceptable cost of carrying out the exercise

Buy Now
Questions 17

Analysing information about how an organization has responded to incidents, including engagement with those impacted and its approach to responsibility, can provide insight into the organization's:

Options:

A.

Culture

B.

Business targets

C.

Business plan

D.

Structure

Buy Now
Questions 18

Which of the following is NOT a critical requirement for an effective response structure?

Options:

A.

A plan to communicate with internal and external interested parties

B.

The number and type of teams required by the organization

C.

A plan to exercise the escalation and response

D.

Guidance on when regulators should be notified and be included in the response

Buy Now
Questions 19

Why is a risk assessment usually conducted after a Business Impact Analysis (BIA) as part of the analysis stage?

Options:

A.

Conducting a BIA ties up personnel on this project; so resources are not available to conduct the risk assessment until after personnel are released from the BIA project

B.

Conducting the risk assessment after the BIA has identified priorities enables the risk assessment to maximise investment in risk treatments where they are most needed

C.

A risk assessment is not required until Business Continuity solutions based on the outcomes of the BIA have been developed for review

D.

Risk assessments are not required until after the organization's business plan has been updated to confirm any changes in plans as a result of the BIA

Buy Now
Questions 20

Strategic, tactical, and operational plans should always be activated:

Options:

A.

Simultaneously

B.

Only after it is determined that full activation of all teams is necessary

C.

When cascaded down from the strategic team

D.

Based on the conditions or circumstances documented in the relevant team plan

Buy Now
Questions 21

What should an organization do when it does not yet have fully developed Business Continuity (BC) solutions, response structures, and Business Continuity plans in place?

Options:

A.

Conduct an initial Business Impact Analysis (BIA)

B.

Develop and implement an interim crisis management plan

C.

Outsource the response to a Business Continuity service provider when a crisis or disruption occurs

D.

Implement a "go to" strategy and acquire the required resources, equipment, and services when disruption occurs

Buy Now
Questions 22

In order to implement appropriate initiatives for influencing personnel to embrace Business Continuity and a Business Continuity culture, the Business Continuity professional should start by:

Options:

A.

Conducting a Business Impact Analysis (BIA) that can be shared with all personnel

B.

Carrying out a gap analysis to identify whether the Business Continuity resumption capabilities meet the Business Continuity needs

C.

Estimating the gap between the extent to which Business Continuity is currently embraced in the organization and the desired level at which Business Continuity should be embraced

D.

Implementing a communications strategy to share information about the gaps in the organization's current Business Continuity plans

Buy Now
Questions 23

In relation to governance roles and responsibilities, what should be put in place to ensure that the responsibilities of each Business Continuity Management System (BCMS) role holder will be fulfilled should the primary role holder be ill, out of the area, or be otherwise unavailable?

Options:

A.

The Business Continuity professional will temporarily take over the responsibilities of the absent role holder

B.

Responsibilities of the absent role holder will be put on hold while a substitute is located

C.

A subject matter expert will be assigned as the deputy for each primary BCMS role holder

D.

The Incident Response Team will assume responsibility for the responsibilities of the absent BCMS role holder

Buy Now
Questions 24

When establishing governance for a Business Continuity Management System (BCMS), which of the following will be responsible for developing and communicating the Business Continuity policy and for promoting a Business Continuity culture by leading by example?

Options:

A.

Business Continuity Plan Owners

B.

Departmental Representatives

C.

Top Management

D.

Business Continuity Professional

Buy Now
Questions 25

Which of the following is a principle to be adhered to when producing communications during a disruption?

Options:

A.

Communications should be consistent with the organization's beliefs, culture, values and value proposition

B.

Senior personnel in areas affected by the disruption should take the lead in producing and releasing accurate information via media

C.

Communications should be so that individuals involved in the disruption can be directly contacted by interested parties

D.

In order to ensure that communications are not delayed, only pre-agreed general statements, without any reference to the specific disruption, may be released to pre-agreed interested parties

Buy Now
Questions 26

Which of the following is NOT part of the process to implement solutions to resume business operations?

Options:

A.

Ensuring alignment with the response structure and plans

B.

Providing training for users of solutions and support staff

C.

Updating the Activities Business Impact Analysis (BIA) to take into account the effect of the solutions on priority activities

D.

Complying with the organization's project management procedures

Buy Now
Questions 27

Which of the following is an outcome of personnel embracing Business Continuity and the organization's Business Continuity Management System (BCMS)?

Options:

A.

A Business Continuity programme that is tailored specifically for the organization, taking into account its organizational culture

B.

A reduction in the need to update and review the BCMS due to the commitment of personnel in the development stage

C.

Increased sales of products and services due to public confidence in the published information about the organization’s resilience capability

D.

Validation of plans is no longer needed due to the high level of commitment from relevant personnel to their effective implementation

Buy Now
Exam Code: CBCI
Exam Name: Certificate of the Business Continuity Institute (CBCI)
Last Update: Aug 17, 2025
Questions: 90
CBCI pdf

CBCI PDF

$29.75  $84.99
CBCI Engine

CBCI Testing Engine

$35  $99.99
CBCI PDF + Engine

CBCI PDF + Testing Engine

$47.25  $134.99