Spring Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: mxmas70

Home > BCI > CBCI 7.0 Certification Course > CBCI

CBCI Certificate of the Business Continuity Institute (CBCI) Question and Answers

Question # 4

Which of the following statements about an Activity Business Impact Analysis (BIA) is correct?

A.

An Activity BIA ensures that all of the activities undertaken by an organization can continue as usual during a disruption and sets out a detailed plan to enable continuity

B.

An Activity BIA determines the resources required to deliver the organization's prioritized products and services

C.

An Activity BIA identifies risks to delivery activities and establishes strategies to either prevent risks arising or to mitigate their effects should they arise

D.

An Activity BIA identifies and prioritizes the activities that deliver the most urgent products and services and determines the resources and dependencies required to enable continuity

Full Access
Question # 5

Which of the following is NOT a way in which an organization can use exercise programs to ensure and validate supply chain continuity?

A.

By including key suppliers in an internal exercise

B.

By requiring suppliers to share evidence that recovery plans and exercise programs have been developed and implemented

C.

By including a requirement in Service Level Agreements (SLAs) for suppliers to carry out exercise activities and share the outcomes

D.

By conducting internal exercises to assess the impact of supply chain failures

Full Access
Question # 6

When carrying out the Business Impact Analysis (BIA) process, the Business Continuity professional should use a consistent approach to determine priorities of products, services, and activities. Which of the following is a method that could be used?

A.

A gap analysis

B.

A risk assessment matrix

C.

Pre-defined impact thresholds

D.

A standardized risk rating table

Full Access
Question # 7

Which of the following is an outcome of personnel embracing Business Continuity and the organization's Business Continuity Management System (BCMS)?

A.

A Business Continuity programme that is tailored specifically for the organization, taking into account its organizational culture

B.

A reduction in the need to update and review the BCMS due to the commitment of personnel in the development stage

C.

Increased sales of products and services due to public confidence in the published information about the organization’s resilience capability

D.

Validation of plans is no longer needed due to the high level of commitment from relevant personnel to their effective implementation

Full Access
Question # 8

What should an organization do when it does not yet have fully developed Business Continuity (BC) solutions, response structures, and Business Continuity plans in place?

A.

Conduct an initial Business Impact Analysis (BIA)

B.

Develop and implement an interim crisis management plan

C.

Outsource the response to a Business Continuity service provider when a crisis or disruption occurs

D.

Implement a "go to" strategy and acquire the required resources, equipment, and services when disruption occurs

Full Access
Question # 9

Within the context of risk assessment, the identification of solutions is influenced by a variety of business relevant considerations, including:

A.

Delivering performance targets

B.

Timely production of quality assurance audit trails

C.

Compliance with regulatory requirements

D.

Ensuring that communication protocols are observed

Full Access
Question # 10

Size of the organization, the organization's culture and how people prefer to receive information are among the factors for the Business Continuity (BC) professional to consider when:

A.

Developing an awareness strategy

B.

Planning a live exercise

C.

Developing plans

D.

Designing solutions

Full Access
Question # 11

Which of the following would NOT be considered as part of the process to develop a Product and Services Business Impact Analysis (BIA)?

A.

Contractual requirements, including penalties for failure to deliver products and/or services

B.

Objectives and strategic direction of the organization

C.

Annual training and performance management arrangements

D.

Lessons learned from past disruptions and exercises

Full Access
Question # 12

Why is it important to use a warning or code word such as “exercise only” when providing communication injects during an exercise?

A.

To ensure that the information is not treated as a real message

B.

To ensure that the information is treated as confidential

C.

To indicate that the message has been approved by the exercise facilitator

D.

To indicate that all information should be treated as real during the exercise

Full Access
Question # 13

A strategic plan:

A.

May be supported by a separate crisis communications plan

B.

Should identify viable options to coordinate efforts of the operational teams

C.

Should contain procedures for responding to emergencies, including threats to life, or the environment

D.

May contain procedures for coordinating the transportation of personnel to alternate facilities

Full Access
Question # 14

The purpose of a Business Continuity policy is to:

A.

Initiate the development of an effective response structure in case of disruption to products or services within the scope of the Business Continuity Management System (BCMS)

B.

Enable the Business Continuity professional to issue instructions to all on the changes that they will be required to make

C.

Share the outcomes of a Business Impact Analysis with internal and external stakeholders

D.

Establish shared understanding of the importance of a BCMS and its relevance to the organization

Full Access
Question # 15

In order to enable Business Continuity solutions, it is necessary to:

A.

Measure capabilities to deliver the solutions by carrying out a gap analysis

B.

Create guidance documents that detail response activities and procedures that specific teams need to follow

C.

Establish and implement a strategy to ensure that business objectives are aligned to the agreed solutions

D.

Carry out a review of the Business Continuity policy to ensure that it is updated with the detail of the agreed solutions

Full Access
Question # 16

Which of the following is NOT part of the process to implement solutions to resume business operations?

A.

Ensuring alignment with the response structure and plans

B.

Providing training for users of solutions and support staff

C.

Updating the Activities Business Impact Analysis (BIA) to take into account the effect of the solutions on priority activities

D.

Complying with the organization's project management procedures

Full Access
Question # 17

Which of the following could the Business Continuity professional use to explain how embracing Business Continuity could add value to the organization?

A.

It will increase health and safety standards in the organization by reducing stress levels as personnel do not need to be concerned during disruptions

B.

It will resolve all conflicts between personnel and departments in the organization as personnel will re-focus their priorities to shared Business Continuity activities

C.

It increases competitive advantage by increasing the ability of the organization to remain operational in the face of a disruption

D.

It will enable senior managers to delegate their responsibilities to team members as personnel will be willing to take on additional accountabilities leaving senior managers free to develop new products and services

Full Access
Question # 18

In relation to the process for developing and managing an exercise, which of the following steps in the process of developing an exercise would come first?

A.

Assess and report the outcomes and lessons learned

B.

Plan and design the exercise, including setting a budget and time frame and conducting a risk assessment

C.

Agree on the exercise's scope, objectives, timeline and expected outcomes

D.

Conduct the exercise

Full Access
Question # 19

When creating an effective response structure, which of the following should be considered as a critical requirement?

A.

A summary of the outcomes of the Business Impact Analysis (BIA)

B.

A method to monitor incidents so that early action can be taken to prevent them from escalating further

C.

Procedures to activate and control the response to an incident

D.

Procedures for carrying out risk assessments following the end of an incident

Full Access
Question # 20

The three main steps involved in the risk assessment process are listing risk sources, performing a risk source analysis and:

A.

Identifying historical risks

B.

Categorising risks

C.

Assessing the consequences of risks

D.

Evaluating risks

Full Access
Question # 21

When developing solutions for people strategies, solutions to recover activities with a short Recovery Time Objective (RTO) requiring redeployment of personnel should be supported by:

A.

The development of training material including all relevant information and procedures so that this can be made available when required

B.

Links to social media so the organization can run an extensive recruitment campaign both inside and outside the organization if a disruptive event occurs

C.

Recruitment of additional personnel so that the organization always has access to surplus staff in case of an incident occurring

D.

Induction and training by an operational manager at the time when the disruption is underway so that individuals can build understanding and confidence prior to commencing the allocated tasks

Full Access
Question # 22

Which of the following explains the value that can be added when personnel embrace Business Continuity rather than seeing it as something embedded in their job role?

A.

Personnel complete tasks as instructed within the time allocated

B.

Personnel are aware of Business Continuity and attend meetings if required to

C.

Personnel feel committed to Business Continuity and ensure that their tasks are completed promptly and with attention to detail

D.

Personnel view Business Continuity as additional requirements which demand further training

Full Access
Question # 23

An effective response structure includes:

A.

Unlimited access to financial resources during a disruption

B.

Knowledge of when key suppliers and external stakeholders should be notified and included in the response

C.

Flexibility to change policies and procedures during a disruption without consulting top management

D.

Personnel in place to assess and measure the performance of responders during a disruption

Full Access
Question # 24

Which type of debrief is held immediately after an exercise, prior to personnel leaving the exercise location and is intended to capture issues from participants while concerns are still fresh in their minds?

A.

Formal debrief

B.

Interview

C.

Survey

D.

Hot debrief

Full Access
Question # 25

Which of the following is NOT an outcome that will result from an organization embracing Business Continuity?

A.

Business Continuity tasks being given greater priority and completed on time

B.

A Business Continuity programme that is fit for purpose and adequately sized for the organization

C.

A reduction in the need to carry out maintenance activities and regular plan reviews and updates

D.

Recognition by interested parties of areas where Business Continuity adds value to their operation

Full Access
Question # 26

Which of the types of review that can be used to review a Business Continuity Management System (BCMS) can be described as being designed to provide independent assurance on a set of processes without confirming that the solutions adopted are necessarily correct?

A.

Internal audit

B.

Performance appraisal

C.

Post-incident review

D.

Quality assurance

Full Access
Question # 27

When developing a system to measure Business Continuity culture, it is important to take into account:

A.

How to ensure that all personnel are required to respond to the process

B.

The aims of the activity and how the information will be collected and assessed

C.

The way that the outcomes will inform the design of Business Continuity solutions

D.

The need to present the outcomes in a positive way for top management and stakeholders

Full Access
Question # 28

When considering solutions for supplier strategies, the Business Continuity professional should ensure that:

A.

Suppliers have capability that aligns with the organization's Recovery Time Objectives (RTOs) that rely on them

B.

Suppliers can deliver high-quality products and services during business as usual situations

C.

The solutions are reviewed by procurement prior to approval

D.

Priority should be given to existing suppliers

Full Access
Question # 29

Which of the following statements about the methods used to collect information following an exercise is correct?

A.

Only senior level exercise participants should provide opinions during the debrief

B.

One-on-one interviews with all exercise participants should be conducted within one month following the exercise

C.

A hot debrief should be conducted within one month after the conclusion of an exercise

D.

Surveys are especially effective if an exercise and its participants are spread out over multiple locations

Full Access
Question # 30

Business as usual (BAU) plans document processes for restoring an organization to its original state and should:

A.

Be developed in detail prior to any incident occurring

B.

Focus on resuming activities in reverse order of Recovery Time Objectives (RTOs)

C.

Be based on the availability of primary resources prior to the incident

D.

Take into consideration possibility of new vulnerabilities resulting from impacted resources

Full Access
Question # 31

In relation to maintaining a Business Continuity (BC) culture, the first few minutes of every Business Continuity (BC) workshop and presentation can be used by the BC professional to:

A.

Allocate additional new BC responsibilities to participants

B.

Reconnect participants to the organization and raise awareness of the benefits of protecting the organization from harmful disruptions

C.

Demonstrate to participants how successful top management has been in addressing risks

D.

Enable the BC professional to re-design procedures and solutions

Full Access
Question # 32

Which of the following is a step that would be taken by the Business Continuity professional to support the process to advance an organization from embedding to embracing Business Continuity?

A.

Development and adoption of a Business Continuity policy to protect the organization from disruptions

B.

Assigning Business Continuity roles and responsibilities across the organization's hierarchy

C.

Gaining an understanding of the organization's culture

D.

Including funding in the Business Continuity budget to hire a consulting firm to run Business Continuity as a project

Full Access
Question # 33

Which of the following is included in the professional practice Enabling Solutions?

A.

Developing Business Continuity (BC) plans

B.

Exercising the Business Continuity (BC) plans

C.

Developing Business Continuity (BC) strategies

D.

Updating Business Continuity (BC) policy

Full Access
Question # 34

Where social media is a key element in an organization's communications response strategy, it is important for the organization to:

A.

Build up followers and establish a social media presence before an incident

B.

Empower all staff to engage with social media to ensure that information during a disruption can be delivered quickly

C.

Ensure all staff who engage with social media are aware of the need to keep a note of their engagement in case valuable contacts are secured through this route

D.

Limit social media engagement to one-way communications as only the organization's formal statements and opinions are required

Full Access
Question # 35

When implementing solutions, the Business Continuity (BC) professional should:

A.

Ensure that internal audit approves the project schedule prior to starting work

B.

Implement all solutions themselves and then advise the relevant teams that they must comply with the established arrangements

C.

Ensure solutions align with those specified and agreed at the design stage

D.

Empower operational team members to adjust solutions where they deem changes to be beneficial

Full Access
Question # 36

Reading the organization's mission statement, annual reports, corporate social media accounts, or newsletters can contribute to building a better understanding of the organization’s:

A.

Business Continuity Management System (BCMS)

B.

Emergency Response Strategy

C.

Culture

D.

Crisis Communication plan

Full Access
Question # 37

Why should a Business Continuity (BC) policy be written in a way that is easy to read and concise?

A.

To ensure that only minimum information is shared with personnel and other interested parties

B.

To ensure that the correct specialist jargon and acronyms are being used consistently across the organization

C.

To ensure that it sets out points in a way that is straightforward and engaging for staff involved in implementing Business Continuity (BC) in the organization

D.

To act as an accessible summary document to support the actions detailed in the Business Continuity Management System (BCMS)

Full Access
Question # 38

Which of the following statements about embracing Business Continuity is correct?

A.

Embracing Business Continuity is relevant only to top management as other personnel are required to comply with tasks in their role description

B.

Embracing Business Continuity can be described as a corporate mandate driven by policy

C.

Embracing Continuity is where personnel commit to Business Continuity because they believe that is necessary to protect the organization and its interested parties

D.

Embracing Business Continuity is a culture that exists separately from the organization's culture

Full Access
Question # 39

Which of the following statements describes a good practice Business Continuity (BC) culture?

A.

A situation where personnel follow procedures as set out by the organization but do not have a sense of ownership.

B.

A situation where Business Continuity (BC) professionals have significant influence in the organization and specify all actions to be taken and carry out all reviews as needed.

C.

A situation where all staff have a shared understanding of Business Continuity (BC) and everyone is involved.

D.

A situation where the workforce is sufficiently committed to Business Continuity (BC) that top management does not get involved.

Full Access
Question # 40

If a Business Continuity (BC) culture gap analysis shows that the gap between the existing culture and the desired BC culture is large, which of the following approaches would be the best one for the BC professional to take?

A.

Adopt a BC culture development approach that was successfully used by another organization.

B.

Introduce an aggressive training programme for all employees that focuses on details of the BCMS.

C.

Start with the basics, ensuring that employees' needs and perspectives are recognised, and then progress to more advanced topics.

D.

Expand and enhance BCMS information on the organization’s intranet and introduce a requirement that all employees review the information at least once a year.

Full Access
Question # 41

In relation to Business Continuity (BC) validation, where product or service delivery is outsourced, which of the following should be implemented?

A.

Take on the accountability for carrying out exercises at the supplier company

B.

Decide on replacement services in case the primary service provider fails

C.

Establish a Service Level Agreement (SLA) with the supplier that requires the supplier to carry out exercises

D.

Understand that the supplier is accountable and take no further action

Full Access
Question # 42

Which of the following describes an operational plan?

A.

Documented plans to protect people and property while supporting the recovery of the organization's prioritised activities

B.

Documented procedures that are still in draft form as they have not yet been tested via exercises or actual incidents

C.

Detailed information on any processes that have not been risk assessed by the organization and therefore present an increased risk

D.

Pre-prepared information to facilitate the coordination of response activities when several different operational teams are involved

Full Access
Question # 43

Following the completion of the Analysis stage of the Business Continuity Management System (BCMS), the next stage would be to:

A.

Establish governance for the BCMS.

B.

Identify strategies and solutions for resuming business operations.

C.

Conduct a risk assessment on prioritised activities.

D.

Develop the operational plans.

Full Access
Question # 44

Which of the following would NOT affect the scope of the Business Continuity Management System (BCMS) and lead to the need for the scope of the BCMS to be reviewed?

A.

A merger with another organization

B.

A change to legal or regulatory requirements

C.

A change to the way that products and services are delivered

D.

A new communications manager being appointed to lead a business promotion campaign on social media

Full Access
Question # 45

A shared understanding across the organization of the importance and relevance of the Business Continuity Management System (BCMS) and an understanding of how the BCMS will be used are outcomes of:

A.

Providing access to a risk assessment

B.

Defining the scope of the BCMS

C.

An effectively communicated Business Continuity policy

D.

Appointing a Business Continuity steering group

Full Access
Question # 46

Which of the following would NOT be considered when planning individual exercises?

A.

The budget required for the exercise

B.

The teams that will be required to participate

C.

The plausibility of the storyline to be used for the scenario

D.

The arrangements for external communications after the exercise has been completed

Full Access
Question # 47

When developing a response structure for an organization, the process should include:

A.

Consulting with customers and suppliers on the requirements for the structure

B.

Ensuring that appropriate and competent individuals are assigned to leadership roles in the structure

C.

Advising department heads that department structure will have to change to match the proposed response structure

D.

Implementing a supporting performance management system in the organization to ensure that all managers and personnel are complying with the new requirements

Full Access
Question # 48

A type of exercise where participants can explore relevant issues and walk through plans in a low-pressure environment is a:

A.

Scenario exercise

B.

Simulation exercise

C.

Investigative exercise

D.

Discussion-based exercise

Full Access
Question # 49

Analysing information about how an organization has responded to incidents, including engagement with those impacted and its approach to responsibility, can provide insight into the organization's:

A.

Culture

B.

Business targets

C.

Business plan

D.

Structure

Full Access
Question # 50

After all Business Impact Analyses (BIAs) have been completed, a consolidated analysis is carried out and a report is written to document the results. What is the purpose of this?

A.

For review by all BIA participants

B.

For submission to top management for final approval

C.

For planning an exercise

D.

For internal audit

Full Access
Question # 51

When developing a new response structure, how should the Business Continuity professional proceed where a pre-existing structure is already in place?

A.

All pre-existing teams and plans should be stood down immediately to prevent confusion or mixed loyalties as the new structure and plans are developed

B.

Teams and roles responsible for pre-existing plans should be assessed and, where appropriate, aligned and incorporated into the new structure with training provided

C.

All previous personnel and plans should be adopted without change in order to ensure continuity of approach, streamlining of costs and to encourage team members to embrace Business Continuity

D.

Personnel with existing roles should automatically be provided with senior roles in the new structure and provided with authority to change the new solutions that have been agreed by drawing on their previous experience

Full Access
Question # 52

Which of the following is an indicator that top management is embracing Business Continuity?

A.

Business Continuity is part of the organization's strategic planning and is reviewed regularly

B.

The organization's health and safety risk assessments are recorded as required

C.

The organization maintains full compliance with legal and regulatory requirements

D.

The organization's Business Continuity operational plans are kept up to date

Full Access