Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

BCI CBCI Certificate of the Business Continuity Institute (CBCI) Exam Practice Test

Demo: 52 questions
Total 176 questions

Certificate of the Business Continuity Institute (CBCI) Questions and Answers

Question 1

Which one of the following should be implemented when updating Business Continuity (BC) plans?

Options:

A.

A copy should be placed on the organization's shared drive so that personnel can identify it for themselves when they look at the system

B.

A formal version control process to identify the date of review and bring attention to changes

C.

A brief note about the update in a staff newsletter that is printed and placed on noticeboards

D.

An internal email to all personnel stating that a new version is available and suggesting that personnel request a copy of the new version if they are interested in seeing it

Question 2

Why is it important to establish governance for a Business Continuity Management System (BCMS)?

Options:

A.

To provide the foundation for further development, effective operation, support and continual improvement

B.

To monitor and review BC training programmes regularly to ensure that any skills gaps identified by the gap analysis are being addressed

C.

To ensure that different parts of the organization can take independent approaches to reflect their preferences and timelines

D.

To align the governance of the BCMS with the structure of the organization's business sector

Question 3

A strategic plan:

Options:

A.

May be supported by a separate crisis communications plan

B.

Should identify viable options to coordinate efforts of the operational teams

C.

Should contain procedures for responding to emergencies, including threats to life, or the environment

D.

May contain procedures for coordinating the transportation of personnel to alternate facilities

Question 4

Which type of debrief is held immediately after an exercise, prior to personnel leaving the exercise location and is intended to capture issues from participants while concerns are still fresh in their minds?

Options:

A.

Formal debrief

B.

Interview

C.

Survey

D.

Hot debrief

Question 5

Which of the following is NOT a reason why it is important for organizations to have effective internal and external communications in place during a crisis?

Options:

A.

It provides vital information to those who have been impacted.

B.

It provides assurance to interested parties that the organization is in control of the situation.

C.

It positions the organization as the central source of information.

D.

It enables the organization to take advantage of increased public interest to identify new business opportunities.

Question 6

Which of the following parameters would NOT be considered by a resource or activity owner when evaluating and selecting solutions to meet an agreed strategy?

Options:

A.

The advantages and disadvantages of the proposed solution

B.

The type of exercises to be conducted to validate the strategies and solutions

C.

The estimated costs to prepare, implement, operate and maintain the solution

D.

The implementation time required

Question 7

When implementing solutions, the Business Continuity (BC) professional should:

Options:

A.

Ensure that internal audit approves the project schedule prior to starting work

B.

Implement all solutions themselves and then advise the relevant teams that they must comply with the established arrangements

C.

Ensure solutions align with those specified and agreed at the design stage

D.

Empower operational team members to adjust solutions where they deem changes to be beneficial

Question 8

When coordinating the activities to establish a Business Continuity Management System (BCMS), it is good practice for the Business Continuity (BC) professional to:

Options:

A.

Advise top management to establish strict rules to ensure that stakeholders participate in the process.

B.

Establish a mandatory obligation for all staff members to provide input.

C.

Set up a steering group consisting of different subject matter experts to provide advice and recommendations on the BCMS.

D.

Invite external parties such as clients, suppliers and regulators to provide inputs to the BCMS.

Question 9

When developing a response structure for an organization, the process should include:

Options:

A.

Consulting with customers and suppliers on the requirements for the structure

B.

Ensuring that appropriate and competent individuals are assigned to leadership roles in the structure

C.

Advising department heads that department structure will have to change to match the proposed response structure

D.

Implementing a supporting performance management system in the organization to ensure that all managers and personnel are complying with the new requirements

Question 10

Which of the following is a way to ensure that personnel remain committed to Business Continuity and to protecting the organization from the effects of disruption?

Options:

A.

Holding annual assessments of Business Continuity knowledge and understanding and setting minimum pass standards which personnel must meet

B.

Making it a disciplinary offence for personnel to miss relevant Business Continuity meetings and training events

C.

Including Business Continuity as part of the introduction to meetings and events in order to strengthen and maintain the relationship between personnel and the organization

D.

Providing updates on Business Continuity activities via the intranet which personnel can find and read if they are interested

Question 11

Which of the following will improve understanding of the benefits of Business Continuity (BC) and increase voluntary commitment to BC across the workforce?

Options:

A.

Enforcing regular BC activities such as attendance at briefings or training

B.

Establishing a system where BC is seen only as a corporate mandate driven by policy

C.

Allocating additional responsibilities and objectives related to BC roles to existing workloads

D.

Establishing BC as a culture underpinned by personal beliefs and corporate behaviours

Question 12

Which of the following is NOT an activity that is undertaken as part of the governance of the Business Continuity Management System (BCMS)?

Options:

A.

Carrying out specific operational activities relevant to BCMS priorities

B.

Monitoring and evaluating the performance of the BCMS

C.

Supporting continual improvement to the BCMS

D.

Ensuring that the BCMS meets any related regulatory requirements

Question 13

In relation to governance roles and responsibilities, what should be put in place to ensure that the responsibilities of each Business Continuity Management System (BCMS) role holder will be fulfilled should the primary role holder be ill, out of the area, or be otherwise unavailable?

Options:

A.

The Business Continuity professional will temporarily take over the responsibilities of the absent role holder

B.

Responsibilities of the absent role holder will be put on hold while a substitute is located

C.

A subject matter expert will be assigned as the deputy for each primary BCMS role holder

D.

The Incident Response Team will assume responsibility for the responsibilities of the absent BCMS role holder

Question 14

An effective exercise programme should:

Options:

A.

Be put in place as part of the outcome of the Business Impact Analysis (BIA) and the associated solutions design

B.

Follow the same framework of activities each year so that progress can be compared over time

C.

Be reviewed regularly at pre-defined intervals or following significant change

D.

Reflect trends in customer concerns and feedback from stakeholders

Question 15

Which of the following is a step that would be taken by the Business Continuity professional to support the process to advance an organization from embedding to embracing Business Continuity?

Options:

A.

Development and adoption of a Business Continuity policy to protect the organization from disruptions

B.

Assigning Business Continuity roles and responsibilities across the organization's hierarchy

C.

Gaining an understanding of the organization's culture

D.

Including funding in the Business Continuity budget to hire a consulting firm to run Business Continuity as a project

Question 16

Why is a risk assessment usually conducted after a Business Impact Analysis (BIA) as part of the analysis stage?

Options:

A.

Conducting a BIA ties up personnel on this project; so resources are not available to conduct the risk assessment until after personnel are released from the BIA project

B.

Conducting the risk assessment after the BIA has identified priorities enables the risk assessment to maximise investment in risk treatments where they are most needed

C.

A risk assessment is not required until Business Continuity solutions based on the outcomes of the BIA have been developed for review

D.

Risk assessments are not required until after the organization's business plan has been updated to confirm any changes in plans as a result of the BIA

Question 17

When setting up any individual exercise, which of the following should be taken into consideration in relation to risks to business as usual?

Options:

A.

Personnel, including senior managers, should be instructed to consider the exercise as a priority and ignore any risks to business as usual that may arise during the exercise

B.

Pre-existing business as usual commitments should be treated as a secondary consideration to ensure that these commitments do not undermine the exercise activity

C.

The disruption caused by the exercise and any impact should be planned in advance, monitored and controlled during the exercise and minimised

D.

Any impacts of the exercise on business as usual should be written off in advance as an acceptable cost of carrying out the exercise

Question 18

The Recovery Time Objective (RTO), competency of team members, and complexity of the processes to be recovered are factors that will play a role in determining the level of detail contained in:

Options:

A.

Operational plans

B.

Strategic plans

C.

Crisis communication plans

D.

Emergency response plans

Question 19

Which of the following is NOT an outcome that will result from an organization embracing Business Continuity?

Options:

A.

Business Continuity tasks being given greater priority and completed on time

B.

A Business Continuity programme that is fit for purpose and adequately sized for the organization

C.

A reduction in the need to carry out maintenance activities and regular plan reviews and updates

D.

Recognition by interested parties of areas where Business Continuity adds value to their operation

Question 20

Which of the following is a benefit of conducting an exercise?

Options:

A.

Confirmation of how well Business Continuity is incorporated into the tasks pertaining to the Business Continuity Management System (BCMS)

B.

Confirmation that personnel are familiar with their roles, and authority in response to an incident

C.

Increased understanding of the requirements set out in the Activities Business Impact Analysis (BIA)

D.

Validation of the Business Continuity Management System (BCMS) against standards, regulations and legislation

Question 21

Which of the following suppliers should be prioritised by the Business Continuity (BC) professional when developing solutions?

Options:

A.

Those with longer Recovery Time Objectives (RTO)

B.

Those with shorter Recovery Time Objectives (RTO)

C.

Those who are located closest to the organization and are therefore easiest to manage

D.

Those who have previously been contracted with the organization and would be able to provide support in an emergency

Question 22

Establishing governance for a new Business Continuity Management System (BCMS) is an iterative process because:

Options:

A.

The roles, responsibilities and accountabilities for the BCMS can only be fully defined after the first validation exercise has been completed.

B.

The organization may not fully understand all of the roles, responsibilities and authorities required to operate the BCMS in the early stages of development and may need to revise them over time.

C.

The governance structure needs to be approved by the organization’s Board and this is often a time-consuming process.

D.

Those who have been assigned BCMS roles and responsibilities have to undergo training and assessment over time.

Question 23

After all Business Impact Analyses (BIAs) have been completed, a consolidated analysis is carried out and a report is written to document the results. What is the purpose of this?

Options:

A.

For review by all BIA participants

B.

For submission to top management for final approval

C.

For planning an exercise

D.

For internal audit

Question 24

Which of the following statements about an Activity Business Impact Analysis (BIA) is correct?

Options:

A.

An Activity BIA ensures that all of the activities undertaken by an organization can continue as usual during a disruption and sets out a detailed plan to enable continuity

B.

An Activity BIA determines the resources required to deliver the organization's prioritized products and services

C.

An Activity BIA identifies risks to delivery activities and establishes strategies to either prevent risks arising or to mitigate their effects should they arise

D.

An Activity BIA identifies and prioritizes the activities that deliver the most urgent products and services and determines the resources and dependencies required to enable continuity

Question 25

Which of the following is an outcome of a situation where top management embraces Business Continuity (BC)?

Options:

A.

The Business Continuity Management System (BCMS) is independent from organizational objectives

B.

Business continuity training and awareness initiatives are promoted across the organization

C.

Personnel do not embrace Business Continuity (BC)

D.

Reviews of BC performance are carried out if time permits and follow-up actions are phased in slowly to minimise disruption to existing priorities

Question 26

How is the Recovery Time Objective (RTO) defined?

Options:

A.

The timeframe within the Maximum Tolerable Period of Disruption (MTPD) during which a product, service or activity must be suspended to avoid adverse impacts on customers

B.

The timeframe within the Maximum Tolerable Period of Disruption (MTPD) for resuming disrupted activities at a specified minimum acceptable capacity

C.

The period of time following a disruption during which a product, service or activity must be suspended while resources are recovered and operating standards are re-established

D.

The point at which all products, services and activities must be fully resumed following a disruption

Question 27

In order to ensure that priority is given to activities with the shortest Recovery Time Objectives (RTOs), strategies can:

Options:

A.

Include relevant extracts from the Business Impact Analysis (BIA)

B.

Highlight activities with short RTOs by categorising strategies by timeframe

C.

Include a risk assessment to identify the best treatment option

D.

Identify workarounds for all activities other than those with short RTOs

Question 28

In relation to the care and wellbeing of staff during an incident, which of the following would NOT be an immediate requirement for the People and Culture Management team?

Options:

A.

Accounting for the personnel on the site where the incident has occurred

B.

Being able to contact personnel and their family members

C.

Assigning responsibilities to staff who are working away from the site to enable recovery activities to commence

D.

Enabling access to physical care if needed

Question 29

Why is it important to use a warning or code word such as “exercise only” when providing communication injects during an exercise?

Options:

A.

To ensure that the information is not treated as a real message

B.

To ensure that the information is treated as confidential

C.

To indicate that the message has been approved by the exercise facilitator

D.

To indicate that all information should be treated as real during the exercise

Question 30

Business as usual (BAU) plans document processes for restoring an organization to its original state and should:

Options:

A.

Be developed in detail prior to any incident occurring

B.

Focus on resuming activities in reverse order of Recovery Time Objectives (RTOs)

C.

Be based on the availability of primary resources prior to the incident

D.

Take into consideration possibility of new vulnerabilities resulting from impacted resources

Question 31

Which of the following is a technique for collecting Business Impact Analysis (BIA) information?

Options:

A.

Workplace observation

B.

Workplace health and safety reviews

C.

Monthly budget reviews

D.

Questionnaires and surveys

Question 32

Which of the following would NOT be considered when planning individual exercises?

Options:

A.

The budget required for the exercise

B.

The teams that will be required to participate

C.

The plausibility of the storyline to be used for the scenario

D.

The arrangements for external communications after the exercise has been completed

Question 33

In relation to the maintenance of Business Continuity Management Systems (BCMS), which of the following would be a trigger for maintenance activities?

Options:

A.

Changes to the environment in which the organization operates

B.

Changes to the performance appraisal process

C.

Changes to the external auditor

D.

Changes to the structure of a competitor organization

Question 34

Horizon scanning, cost-benefit analysis, and consulting with information from risk assessments are examples of activities undertaken when:

Options:

A.

Establishing the Business Continuity Management System (BCMS)

B.

Defining the initial scope of the BCMS

C.

Developing the Business Continuity (BC) policy

D.

Assessing the viability of BC strategies and solutions

Question 35

Which of the following is NOT a benefit of using tools to automate the Business Impact Analysis (BIA) process?

Options:

A.

Storage of the BIA results for future reference

B.

Quick and comprehensive analysis of the results of the BIA and production of reports

C.

Reduction of the work involved in collating the outcomes of the BIA

D.

Elimination of the need for direct engagement with relevant personnel

Question 36

A type of exercise where participants can explore relevant issues and walk through plans in a low-pressure environment is a:

Options:

A.

Scenario exercise

B.

Simulation exercise

C.

Investigative exercise

D.

Discussion-based exercise

Question 37

One of the steps in the risk management process is to establish the risk treatment required. The purpose of risk treatment is to:

Options:

A.

Ensure that a named person within the organization takes responsibility for the monitoring and management of the risk

B.

Calculate a risk score based on the combination of the likelihood of the risk occurring and the consequences of this happening

C.

Mitigate each risk identified by reducing the likelihood of the risk occurring or by lowering the impact of disruption

D.

Ensure that regular updates on the current status of the risk are presented to top management

Question 38

When considering solutions for supplier strategies, the Business Continuity professional should ensure that:

Options:

A.

Suppliers have capability that aligns with the organization's Recovery Time Objectives (RTOs) that rely on them

B.

Suppliers can deliver high-quality products and services during business as usual situations

C.

The solutions are reviewed by procurement prior to approval

D.

Priority should be given to existing suppliers

Question 39

The three main steps involved in the risk assessment process are listing risk sources, performing a risk source analysis and:

Options:

A.

Identifying historical risks

B.

Categorising risks

C.

Assessing the consequences of risks

D.

Evaluating risks

Question 40

A shared understanding across the organization of the importance and relevance of the Business Continuity Management System (BCMS) and an understanding of how the BCMS will be used are outcomes of:

Options:

A.

Providing access to a risk assessment

B.

Defining the scope of the BCMS

C.

An effectively communicated Business Continuity policy

D.

Appointing a Business Continuity steering group

Question 41

Recovery solutions that support an alternate location strategy for physical infrastructure that can be made available within hours include:

Options:

A.

Personnel working from home

B.

Repurposing other work areas and facilities

C.

Ordering, delivering and installing replacement equipment

D.

Rebuilding and reconnecting utility feeds

Question 42

Which of the following is NOT correct in relation to the purpose of defining the scope of the Business Continuity Management System (BCMS)?

Options:

A.

It ensures a clear understanding of the areas of the organization that are, and are not, covered by the BCMS

B.

It establishes permanent parameters for the BCMS

C.

It defines the BCMS on the organization’s products, services, and activities

D.

It makes the best use of available time and finances

Question 43

Strategic, tactical, and operational plans should always be activated:

Options:

A.

Simultaneously

B.

Only after it is determined that full activation of all teams is necessary

C.

When cascaded down from the strategic team

D.

Based on the conditions or circumstances documented in the relevant team plan

Question 44

Which of the following would NOT be included in plans at all levels?

Options:

A.

Guidance for escalation

B.

Risk assessments for each possible scenario

C.

Purpose, scope, assumptions and objectives of the plan

D.

Procedures for standing down the teams when the incident has been resolved

Question 45

Which of the following should be included in a post-incident review of a Business Continuity Management System (BCMS)?

Options:

A.

Information from those involved in the event and also from those involved in the response and recovery activities.

B.

Consideration of responsibility and allocation of accountability for errors made either before or during the incident.

C.

A review of the BCMS implementation and an action plan for improvement.

D.

Information from a related audit report.

Question 46

When establishing a Business Continuity Management System (BCMS), engagement with stakeholders is important. Which of the following is NOT a reason for engaging with internal stakeholders?

Options:

A.

Existing policies and procedures may be relevant to the BCMS so early identification will reduce the risk for duplication of work

B.

Early collaboration with colleagues will engage them in the process and secure support for the ongoing development and implementation of the BCMS

C.

Engagement of stakeholders will reduce the potential for conflict at later stages of the programme

D.

Involving stakeholders will reduce the workload and responsibilities of the Business Continuity Professional as administrative activities can be delegated to other staff

Question 47

Which of the following is included in the professional practice Enabling Solutions?

Options:

A.

Developing Business Continuity (BC) plans

B.

Exercising the Business Continuity (BC) plans

C.

Developing Business Continuity (BC) strategies

D.

Updating Business Continuity (BC) policy

Question 48

Which of the following statements about embracing Business Continuity is correct?

Options:

A.

Embracing Business Continuity is relevant only to top management as other personnel are required to comply with tasks in their role description

B.

Embracing Business Continuity can be described as a corporate mandate driven by policy

C.

Embracing Continuity is where personnel commit to Business Continuity because they believe that is necessary to protect the organization and its interested parties

D.

Embracing Business Continuity is a culture that exists separately from the organization's culture

Question 49

The role of a spokesperson for an organization during an incident includes:

Options:

A.

Advising top management on lines to take

B.

Supporting the operational team in developing communications for social media

C.

Representing the organization at press conferences

D.

Representing the organization at post-incident reviews with regulators

Question 50

Which of the following is an outcome of personnel embracing Business Continuity and the organization's Business Continuity Management System (BCMS)?

Options:

A.

A Business Continuity programme that is tailored specifically for the organization, taking into account its organizational culture

B.

A reduction in the need to update and review the BCMS due to the commitment of personnel in the development stage

C.

Increased sales of products and services due to public confidence in the published information about the organization’s resilience capability

D.

Validation of plans is no longer needed due to the high level of commitment from relevant personnel to their effective implementation

Question 51

In relation to the roles and responsibilities that need to be undertaken to ensure the Business Impact Analysis (BIA) process meets its purpose, which of the following would be responsible for preparing, planning, managing, delivering and ensuring consistency throughout the BIA process?

Options:

A.

Activity Owner

B.

Business Continuity Professional

C.

Risk Assessment Professional

D.

Top Management

Question 52

Which method of measuring culture requires periodic checks to determine the percentage of the organization's personnel currently covered by existing Business Continuity culture initiatives?

Options:

A.

Unstructured observation

B.

Culture index

C.

Behavioural consistency

D.

Business Continuity awareness

Demo: 52 questions
Total 176 questions