PDA

View Full Version : ques on BCP/DR


CISSP_Candidate
08-29-2006, 04:52 PM
here are some questions from cccure quizes which are confusing me, can someone help me understand what i'm missing.

1) Question 1167 | Difficulty level: 4/5 | Relevancy: 3/3
Which of the following steps should be performed first in a business impact analysis (BIA)?
A Identify all business units within the organization.
B Evaluate the impact of disruptive events.
C Estimate the Recovery Time Objectives (RTO).
D Evaluate the criticality of business functions.

The answer is A, but what i feel is that the business units are identified during the development of policy& goals of the BCP along with the management which happens before the BIA stage, whereas within BIA, the first step would be D. Can someone explain where am I going wrong.

2) Question 283 | Difficulty level: 4/5 | Relevancy: 3/3
Which of the following steps is NOT one of the four steps of a Business Impact Assessment (BIA):
A Notifying senior management.
B Gathering the needed assessment materials.
C Performing the vulnerability assessment.
D Analyzing the information compiled.

The answer is A, dont know how, cause all the steps mentioned above are performed in BIA

3) Question 358 | Difficulty level: 4/5 | Relevancy: 3/3
Business continuity plan development depends most on:
A Directives of Senior Management
B Business Impact Analysis (BIA)
C Scope and Plan Initiation
D Skills of BCP committee

The answer is B, shouldnt it be dependent on senior management directives?

I have read shon Harris before solving the quizes on BCP/DR topic, and have performed very poorly, can someone suggest a book which I should refer for this topic ?

Jescoi
08-29-2006, 04:53 PM
1. A is correct because, like the phantom said, you have to ID the business units BEFORE you ID their functions.

2. A again. Simply stated: Notifying management is NOT part of the analysis process. The other three are. Kinda tricky because Shon and the Official guide always pound the "senior management' angle.

3. yeah, I like B here. To address your concern, all management will direct at this point is "have a plan." The BIA is crucial to the plan. If you have any size to your company, you can not have a sound plan without the BIA.

Shon's 3rd ed. is a pretty darn definitive source for BCP/DR domain. If you have the time and money you might want to invest in the official guide. That is the only thing I can think of that might possibly give you more insight for study purposes. However some of the others may have other/better sources in mind.