nerdexam
Isaca

CISA · Question #88

Which of the following is the PRIMARY objective of cyber resiliency?

The correct answer is C. To limit the severity of security breaches and maintain continuous operations. Cyber resiliency aims to enable an organization to anticipate, withstand, recover from, and adapt to adverse cyber events, primarily focusing on maintaining critical operations despite incidents.

Submitted by kevin_r· Apr 18, 2026Information Systems Operations and Business Resilience

Question

Which of the following is the PRIMARY objective of cyber resiliency?

Options

  • ATo efficiently and effectively recover from an incident with limited operational impact
  • BTo prevent potential attacks or disruptions in operations
  • CTo limit the severity of security breaches and maintain continuous operations
  • DTo resume normal operations after service disruptions

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    3% (1)
  • C
    92% (36)

Why each option

Cyber resiliency aims to enable an organization to anticipate, withstand, recover from, and adapt to adverse cyber events, primarily focusing on maintaining critical operations despite incidents.

ATo efficiently and effectively recover from an incident with limited operational impact

While recovery is a part of resiliency, the primary objective is broader, encompassing the ability to *limit* the initial impact and *maintain* operations, not just recover.

BTo prevent potential attacks or disruptions in operations

Prevention is a component of security, but cyber resiliency assumes that prevention may fail and focuses on the ability to survive and operate *despite* successful attacks or disruptions.

CTo limit the severity of security breaches and maintain continuous operationsCorrect

Cyber resiliency encompasses the ability to not only withstand attacks but also to limit the damage and maintain critical functions or quickly restore them, ensuring continuous operation even in the face of successful breaches. It's about enduring and adapting, not just recovering.

DTo resume normal operations after service disruptions

Resuming normal operations is a goal of disaster recovery or business continuity, but cyber resiliency has a more proactive and continuous element of maintaining operations during an event.

Concept tested: Cyber resiliency objectives

Source: https://learn.microsoft.com/en-us/compliance/assurance/cyber-resilience

Topics

#Cyber resiliency#Business continuity#Operational resilience#Incident management

Community Discussion

No community discussion yet for this question.

Full CISA Practice