nerdexam
CompTIA

SY0-301 · Question #359

Key elements of a business impact analysis should include which of the following tasks?

The correct answer is D. Identify critical assets systems and functions, identify dependencies, determine critical downtime limit. A business impact analysis (BIA) focuses on understanding what is critical to the organization and the consequences of losing it. The key tasks involve identifying critical assets, mapping dependencies, and quantifying downtime tolerance.

Security program management and oversight

Question

Key elements of a business impact analysis should include which of the following tasks?

Options

  • ADevelop recovery strategies, prioritize recovery, create test plans, post-test evaluation, and update processes.
  • BIdentify institutional and regulatory reporting requirements, develop response teams and communication
  • CEmploy regular preventive measures such as patch management, change management, antivirus and
  • DIdentify critical assets systems and functions, identify dependencies, determine critical downtime limit,

How the community answered

(42 responses)
  • A
    5% (2)
  • B
    5% (2)
  • C
    12% (5)
  • D
    79% (33)

Why each option

A business impact analysis (BIA) focuses on understanding what is critical to the organization and the consequences of losing it. The key tasks involve identifying critical assets, mapping dependencies, and quantifying downtime tolerance.

ADevelop recovery strategies, prioritize recovery, create test plans, post-test evaluation, and update processes.

Developing recovery strategies, prioritizing recovery, and creating test plans are activities that occur after the BIA is complete and belong to the continuity planning and testing phases.

BIdentify institutional and regulatory reporting requirements, develop response teams and communication

Identifying regulatory reporting requirements and developing response teams are communications planning and organizational preparedness activities, not BIA tasks.

CEmploy regular preventive measures such as patch management, change management, antivirus and

Patch management, change management, and antivirus are ongoing preventive security operations activities, not BIA components.

DIdentify critical assets systems and functions, identify dependencies, determine critical downtime limit,Correct

A BIA identifies critical assets, systems, and business functions; maps their dependencies on each other and on supporting infrastructure; determines the maximum tolerable downtime (MTD) or recovery time objective (RTO) for each; and quantifies the financial and operational loss potential of disruption. These outputs drive all subsequent recovery strategy decisions.

Concept tested: Business impact analysis key tasks and outputs

Source: https://www.ready.gov/business-impact-analysis

Topics

#BIA#business impact analysis#critical assets#recovery prioritization

Community Discussion

No community discussion yet for this question.

Full SY0-301 Practice