Spring Sale Discount Flat 70% Offer - Ends in 0d 00h 00m 00s - Coupon code: 70diswrap

BCI CBCI Dumps

Page: 1 / 18
Total 176 questions

Certificate of the Business Continuity Institute (CBCI) Questions and Answers

Question 1

After all Business Impact Analyses (BIAs) have been completed, a consolidated analysis is carried out and a report is written to document the results. What is the purpose of this?

Options:

A.

For review by all BIA participants

B.

For submission to top management for final approval

C.

For planning an exercise

D.

For internal audit

Question 2

A strategic plan:

Options:

A.

May be supported by a separate crisis communications plan

B.

Should identify viable options to coordinate efforts of the operational teams

C.

Should contain procedures for responding to emergencies, including threats to life, or the environment

D.

May contain procedures for coordinating the transportation of personnel to alternate facilities

Question 3

Which of the types of review that can be used to review a Business Continuity Management System (BCMS) can be described as being designed to provide independent assurance on a set of processes without confirming that the solutions adopted are necessarily correct?

Options:

A.

Internal audit

B.

Performance appraisal

C.

Post-incident review

D.

Quality assurance

Question 4

The three main steps involved in the risk assessment process are listing risk sources, performing a risk source analysis and:

Options:

A.

Identifying historical risks

B.

Categorising risks

C.

Assessing the consequences of risks

D.

Evaluating risks

Question 5

A shared understanding across the organization of the importance and relevance of the Business Continuity Management System (BCMS) and an understanding of how the BCMS will be used are outcomes of:

Options:

A.

Providing access to a risk assessment

B.

Defining the scope of the BCMS

C.

An effectively communicated Business Continuity policy

D.

Appointing a Business Continuity steering group

Question 6

Which of the following is a principle to be adhered to when producing communications during a disruption?

Options:

A.

Communications should be consistent with the organization's beliefs, culture, values and value proposition

B.

Senior personnel in areas affected by the disruption should take the lead in producing and releasing accurate information via media

C.

Communications should be so that individuals involved in the disruption can be directly contacted by interested parties

D.

In order to ensure that communications are not delayed, only pre-agreed general statements, without any reference to the specific disruption, may be released to pre-agreed interested parties

Question 7

Which of the following actions will lead to the protection of priority activities with respect to their Recovery Time Objectives (RTOs) and will limit the impacts of disruptions to prioritised activities?

Options:

A.

Conducting a risk assessment

B.

Conducting an Activity Business Impact Analysis (BIA)

C.

Creating a set of approved strategies and solutions to mitigate unacceptable risks and single points of failure

D.

Grouping unacceptable risks and single points of failure by owner and having discussions with each activity and resource owner

Question 8

In relation to the maintenance of Business Continuity Management Systems (BCMS), which of the following would be a trigger for maintenance activities?

Options:

A.

Changes to the environment in which the organization operates

B.

Changes to the performance appraisal process

C.

Changes to the external auditor

D.

Changes to the structure of a competitor organization

Question 9

Business as usual (BAU) plans document processes for restoring an organization to its original state and should:

Options:

A.

Be developed in detail prior to any incident occurring

B.

Focus on resuming activities in reverse order of Recovery Time Objectives (RTOs)

C.

Be based on the availability of primary resources prior to the incident

D.

Take into consideration possibility of new vulnerabilities resulting from impacted resources

Question 10

When establishing a Business Continuity Management System (BCMS), which of the following activities should be carried out first?

Options:

A.

Establish high-level governance of the BCMS.

B.

Carry out a risk assessment.

C.

Determine the scope of the BCMS.

D.

Develop a Business Continuity (BC) policy.

Question 11

When establishing a Business Continuity Management System (BCMS), engagement with stakeholders is important. Which of the following is NOT a reason for engaging with internal stakeholders?

Options:

A.

Existing policies and procedures may be relevant to the BCMS so early identification will reduce the risk for duplication of work

B.

Early collaboration with colleagues will engage them in the process and secure support for the ongoing development and implementation of the BCMS

C.

Engagement of stakeholders will reduce the potential for conflict at later stages of the programme

D.

Involving stakeholders will reduce the workload and responsibilities of the Business Continuity Professional as administrative activities can be delegated to other staff

Question 12

The process that ensures that an organization's Business Continuity arrangements are up to date and ready to respond to incidents and their impacts despite changes to its structure or changes in its operational context is:

Options:

A.

Review

B.

Gap analysis

C.

Maintenance

D.

Internal audit

Question 13

Following all Business Impact Analyses (BIAs), what information should be provided to top management in a consolidated analysis?

Options:

A.

Feedback from staff on organizational concerns

B.

Confirmation and information about the frequency of previous disruptions

C.

Products and services by order of priority and the priority of related activities (and processes if relevant)

D.

Review of external conditions and a determination of the probability of disruption for each threat identified

Question 14

In relation to maintaining a Business Continuity (BC) culture, the first few minutes of every Business Continuity (BC) workshop and presentation can be used by the BC professional to:

Options:

A.

Allocate additional new BC responsibilities to participants

B.

Reconnect participants to the organization and raise awareness of the benefits of protecting the organization from harmful disruptions

C.

Demonstrate to participants how successful top management has been in addressing risks

D.

Enable the BC professional to re-design procedures and solutions

Question 15

Establishing governance arrangements for a Business Continuity Management System (BCMS) is essential in order to:

Options:

A.

Develop a project risk register and carry out appropriate risk assessments in the workplace

B.

Ensure that there is ongoing commitment across all organizational functions and levels

C.

Commission research into approaches taken by organizations

D.

Enable the Business Continuity professional to establish their authority and issue instructions on the actions that need to be taken

Question 16

Strategies to resume business operations following a disruption are based on the outcomes of the:

Options:

A.

Negotiations with stakeholders regarding their minimum requirements in a disruption

B.

Governance structures established for the Business Continuity Management System (BCMS)

C.

Analysis of Maximum Tolerable Period of Disruption (MTPD) and Recovery Time Objectives (RTO)

D.

Collaborations generated by the organization's Business Continuity culture

Question 17

Which of the following statements about the methods used to collect information following an exercise is correct?

Options:

A.

Only senior level exercise participants should provide opinions during the debrief

B.

One-on-one interviews with all exercise participants should be conducted within one month following the exercise

C.

A hot debrief should be conducted within one month after the conclusion of an exercise

D.

Surveys are especially effective if an exercise and its participants are spread out over multiple locations

Question 18

Which one of the following is a feature of an effective Business Continuity (BC) policy?

Options:

A.

There is clear top management commitment to the policy and its continued improvement.

B.

The policy details the incident management plans and the financial budgets available to support recovery plans.

C.

The policy provides details of constraints on specific suppliers.

D.

The policy can be validated by exercises and updated with the detailed learning that arises from carrying out the exercises.

Question 19

In order to enable Business Continuity solutions, it is necessary to:

Options:

A.

Measure capabilities to deliver the solutions by carrying out a gap analysis

B.

Create guidance documents that detail response activities and procedures that specific teams need to follow

C.

Establish and implement a strategy to ensure that business objectives are aligned to the agreed solutions

D.

Carry out a review of the Business Continuity policy to ensure that it is updated with the detail of the agreed solutions

Question 20

The purpose of a Business Continuity policy is to:

Options:

A.

Initiate the development of an effective response structure in case of disruption to products or services within the scope of the Business Continuity Management System (BCMS)

B.

Enable the Business Continuity professional to issue instructions to all on the changes that they will be required to make

C.

Share the outcomes of a Business Impact Analysis with internal and external stakeholders

D.

Establish shared understanding of the importance of a BCMS and its relevance to the organization

Question 21

Which of the following is a possible outcome of a gap analysis to establish whether new strategies and solutions are required?

Options:

A.

Validation exercises to confirm the findings of the gap analysis that can be presented to top management as part of the decision-making process

B.

Agreement from top management that a Business Impact Analysis (BIA) should be completed to determine the new procedures required

C.

A determination that Business Continuity capabilities exceed requirements and resources could be redistributed

D.

A schedule for sharing the outcomes with all personnel to invite their comments and encourage them to embrace Business Continuity

Question 22

The method to measure Business Continuity (BC) culture that assesses levels of response and performance in similar situations across all levels and the breadth of an organization is:

Options:

A.

Behavioural Consistency

B.

Pre-mortem Checks

C.

Business Continuity Awareness

D.

Unstructured Observations

Question 23

The role of a spokesperson for an organization during an incident includes:

Options:

A.

Advising top management on lines to take

B.

Supporting the operational team in developing communications for social media

C.

Representing the organization at press conferences

D.

Representing the organization at post-incident reviews with regulators

Question 24

If a Business Continuity (BC) culture gap analysis shows that the gap between the existing culture and the desired BC culture is large, which of the following approaches would be the best one for the BC professional to take?

Options:

A.

Adopt a BC culture development approach that was successfully used by another organization.

B.

Introduce an aggressive training programme for all employees that focuses on details of the BCMS.

C.

Start with the basics, ensuring that employees' needs and perspectives are recognised, and then progress to more advanced topics.

D.

Expand and enhance BCMS information on the organization’s intranet and introduce a requirement that all employees review the information at least once a year.

Question 25

When developing solutions for people strategies, solutions to recover activities with a short Recovery Time Objective (RTO) requiring redeployment of personnel should be supported by:

Options:

A.

The development of training material including all relevant information and procedures so that this can be made available when required

B.

Links to social media so the organization can run an extensive recruitment campaign both inside and outside the organization if a disruptive event occurs

C.

Recruitment of additional personnel so that the organization always has access to surplus staff in case of an incident occurring

D.

Induction and training by an operational manager at the time when the disruption is underway so that individuals can build understanding and confidence prior to commencing the allocated tasks

Question 26

The Process Business Impact Analysis (BIA):

Options:

A.

Is conducted prior to the Product and Services BIA

B.

Excludes processes that have been outsourced

C.

Identifies resource requirements and interdependencies

D.

Is optional and may be omitted

Question 27

Which of the following is a technique for collecting Business Impact Analysis (BIA) information?

Options:

A.

Workplace observation

B.

Workplace health and safety reviews

C.

Monthly budget reviews

D.

Questionnaires and surveys

Question 28

A type of exercise where participants can explore relevant issues and walk through plans in a low-pressure environment is a:

Options:

A.

Scenario exercise

B.

Simulation exercise

C.

Investigative exercise

D.

Discussion-based exercise

Question 29

When considering solutions for supplier strategies, the Business Continuity professional should ensure that:

Options:

A.

Suppliers have capability that aligns with the organization's Recovery Time Objectives (RTOs) that rely on them

B.

Suppliers can deliver high-quality products and services during business as usual situations

C.

The solutions are reviewed by procurement prior to approval

D.

Priority should be given to existing suppliers

Question 30

It is important to measure Business Continuity culture because this:

Options:

A.

Can determine whether or not the organization needs to continue reviewing and making improvements to its Business Continuity Management System (BCMS)

B.

Indicates how well personnel are likely to engage with, and follow Business Continuity plans and procedures

C.

Indicates whether or not there is a need to validate and update operational plans

D.

Provides data that can be used when promoting the organization to potential new recruits

Question 31

In order to ensure that priority is given to activities with the shortest Recovery Time Objectives (RTOs), strategies can:

Options:

A.

Include relevant extracts from the Business Impact Analysis (BIA)

B.

Highlight activities with short RTOs by categorising strategies by timeframe

C.

Include a risk assessment to identify the best treatment option

D.

Identify workarounds for all activities other than those with short RTOs

Question 32

Which of the following describes an operational plan?

Options:

A.

Documented plans to protect people and property while supporting the recovery of the organization's prioritised activities

B.

Documented procedures that are still in draft form as they have not yet been tested via exercises or actual incidents

C.

Detailed information on any processes that have not been risk assessed by the organization and therefore present an increased risk

D.

Pre-prepared information to facilitate the coordination of response activities when several different operational teams are involved

Question 33

In order to implement appropriate initiatives for influencing personnel to embrace Business Continuity and a Business Continuity culture, the Business Continuity professional should start by:

Options:

A.

Conducting a Business Impact Analysis (BIA) that can be shared with all personnel

B.

Carrying out a gap analysis to identify whether the Business Continuity resumption capabilities meet the Business Continuity needs

C.

Estimating the gap between the extent to which Business Continuity is currently embraced in the organization and the desired level at which Business Continuity should be embraced

D.

Implementing a communications strategy to share information about the gaps in the organization's current Business Continuity plans

Question 34

In relation to the process for developing and managing an exercise, which of the following steps in the process of developing an exercise would come first?

Options:

A.

Assess and report the outcomes and lessons learned

B.

Plan and design the exercise, including setting a budget and time frame and conducting a risk assessment

C.

Agree on the exercise's scope, objectives, timeline and expected outcomes

D.

Conduct the exercise

Question 35

In relation to governance roles and responsibilities, what should be put in place to ensure that the responsibilities of each Business Continuity Management System (BCMS) role holder will be fulfilled should the primary role holder be ill, out of the area, or be otherwise unavailable?

Options:

A.

The Business Continuity professional will temporarily take over the responsibilities of the absent role holder

B.

Responsibilities of the absent role holder will be put on hold while a substitute is located

C.

A subject matter expert will be assigned as the deputy for each primary BCMS role holder

D.

The Incident Response Team will assume responsibility for the responsibilities of the absent BCMS role holder

Question 36

Which of the following suppliers should be prioritised by the Business Continuity (BC) professional when developing solutions?

Options:

A.

Those with longer Recovery Time Objectives (RTO)

B.

Those with shorter Recovery Time Objectives (RTO)

C.

Those who are located closest to the organization and are therefore easiest to manage

D.

Those who have previously been contracted with the organization and would be able to provide support in an emergency

Question 37

Which method of measuring culture requires periodic checks to determine the percentage of the organization's personnel currently covered by existing Business Continuity culture initiatives?

Options:

A.

Unstructured observation

B.

Culture index

C.

Behavioural consistency

D.

Business Continuity awareness

Question 38

Which of the following is a factor that should be taken into consideration when developing an exercise program?

Options:

A.

It requires a series of events and activities scheduled over a period of time

B.

It is necessary to carry out exercises only once as initial tests will provide all of the required information

C.

A single type of exercise should be used for all so that participants become familiar with the structure and approach of the exercise activities

D.

It is necessary to carry out exercises for only a sample of the plans and recovery teams in place

Question 39

A technique that the Business Continuity (BC) professional could use to help improve an organization's BC culture is:

Options:

A.

Build and strengthen relationships with interested parties and get everyone to work towards a common goal

B.

Conduct Business Impact Analysis (BIA) workshops with senior management

C.

Increase the frequency and number of audits to ensure that all business areas comply with the Business Continuity (BC) policy

D.

Make it mandatory for all personnel to attend Business Continuity (BC) exercises

Question 40

When developing a response structure for an organization, the process should include:

Options:

A.

Consulting with customers and suppliers on the requirements for the structure

B.

Ensuring that appropriate and competent individuals are assigned to leadership roles in the structure

C.

Advising department heads that department structure will have to change to match the proposed response structure

D.

Implementing a supporting performance management system in the organization to ensure that all managers and personnel are complying with the new requirements

Question 41

An effective response structure includes:

Options:

A.

Unlimited access to financial resources during a disruption

B.

Knowledge of when key suppliers and external stakeholders should be notified and included in the response

C.

Flexibility to change policies and procedures during a disruption without consulting top management

D.

Personnel in place to assess and measure the performance of responders during a disruption

Question 42

Which of the following is an outcome of personnel embracing Business Continuity (BC) and the organization's Business Continuity Management System (BCMS)?

Options:

A.

A programme that is bespoke to the organization and its culture

B.

A strong financial performance due to increased investment in Business Continuity (BC)

C.

Reductions in staff turnover due to additional rewards and recognitions made available for supporting Business Continuity (BC)

D.

A reduction in the need for support for Business Continuity (BC) from external customers and partners

Question 43

Which of the following is NOT a factor that should be considered when estimating the Maximum Tolerable Period of Disruption (MTPD) to a product or service?

Options:

A.

Breach of legal or regulatory obligations

B.

Damage to reputation

C.

Threats that could cause disruption

D.

Failure to meet business objectives

Question 44

In order to effectively measure an organization’s Business Continuity (BC) culture:

Options:

A.

A single method should be applied consistently regardless of roles and responsibilities

B.

A separate, independent department should be established to oversee the process and summarise results

C.

Measurement methods should be designed into day-to-day operations or Business Continuity (BC) activities

D.

Personnel should be advised that performance will be judged and action taken if attitudes are unsatisfactory

Question 45

What should an organization do when it does not yet have fully developed Business Continuity (BC) solutions, response structures, and Business Continuity plans in place?

Options:

A.

Conduct an initial Business Impact Analysis (BIA)

B.

Develop and implement an interim crisis management plan

C.

Outsource the response to a Business Continuity service provider when a crisis or disruption occurs

D.

Implement a "go to" strategy and acquire the required resources, equipment, and services when disruption occurs

Question 46

“Collective beliefs, values, attitudes and behaviours of an organization that contribute to the unique social and psychological environment in which it operates” is a description of:

Options:

A.

Organizational structure

B.

Embracing Business Continuity (BC)

C.

Organizational culture

D.

Mission statements

Question 47

Which of the following is a process that analyses the impact over time of a disruption on an organization?

Options:

A.

Business Impact Analysis

B.

Recovery Time Analysis

C.

Cost Benefit Analysis

D.

Risk and Threat Analysis

Question 48

Which of the following is an outcome of a situation where top management embraces Business Continuity (BC)?

Options:

A.

The Business Continuity Management System (BCMS) is independent from organizational objectives

B.

Business continuity training and awareness initiatives are promoted across the organization

C.

Personnel do not embrace Business Continuity (BC)

D.

Reviews of BC performance are carried out if time permits and follow-up actions are phased in slowly to minimise disruption to existing priorities

Question 49

When implementing solutions, the Business Continuity (BC) professional should:

Options:

A.

Ensure that internal audit approves the project schedule prior to starting work

B.

Implement all solutions themselves and then advise the relevant teams that they must comply with the established arrangements

C.

Ensure solutions align with those specified and agreed at the design stage

D.

Empower operational team members to adjust solutions where they deem changes to be beneficial

Question 50

How is the Recovery Time Objective (RTO) defined?

Options:

A.

The timeframe within the Maximum Tolerable Period of Disruption (MTPD) during which a product, service or activity must be suspended to avoid adverse impacts on customers

B.

The timeframe within the Maximum Tolerable Period of Disruption (MTPD) for resuming disrupted activities at a specified minimum acceptable capacity

C.

The period of time following a disruption during which a product, service or activity must be suspended while resources are recovered and operating standards are re-established

D.

The point at which all products, services and activities must be fully resumed following a disruption

Question 51

When selecting solutions to mitigate unacceptable risks and single points of failure, the activity/resource owner will take into account:

Options:

A.

Findings from the Business Impact Analysis (BIA)

B.

The risks expected to materialise in the future

C.

Advantages and disadvantages of the solution

D.

The Business Continuity culture index

Question 52

In relation to the development of solutions, the purpose of a gap analysis is to:

Options:

A.

Identify a strategy to close the existing gaps

B.

Design and select solutions to deliver strategies and close gaps

C.

Assess whether or not current capabilities are sufficient to meet the Business Continuity (BC) requirements

D.

Develop a risk mitigation strategy to address any identified single points of failure

Page: 1 / 18
Total 176 questions