Pre-Summer Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: exams65

ExamsBrite Dumps

Certificate of the Business Continuity Institute (CBCI) Question and Answers

Certificate of the Business Continuity Institute (CBCI)

Last Update Apr 15, 2026
Total Questions : 176

We are offering FREE CBCI BCI exam questions. All you do is to just go and sign up. Give your details, prepare CBCI free exam questions and then go for complete pool of Certificate of the Business Continuity Institute (CBCI) test questions that will help you more.

CBCI pdf

CBCI PDF

$36.75  $104.99
CBCI Engine

CBCI Testing Engine

$43.75  $124.99
CBCI PDF + Engine

CBCI PDF + Testing Engine

$57.75  $164.99
Questions 1

Why should a Business Continuity (BC) policy be written in a way that is easy to read and concise?

Options:

A.  

To ensure that only minimum information is shared with personnel and other interested parties

B.  

To ensure that the correct specialist jargon and acronyms are being used consistently across the organization

C.  

To ensure that it sets out points in a way that is straightforward and engaging for staff involved in implementing Business Continuity (BC) in the organization

D.  

To act as an accessible summary document to support the actions detailed in the Business Continuity Management System (BCMS)

Discussion 0
Questions 2

Which of the following is an indicator that top management is embracing Business Continuity?

Options:

A.  

Business Continuity is part of the organization's strategic planning and is reviewed regularly

B.  

The organization's health and safety risk assessments are recorded as required

C.  

The organization maintains full compliance with legal and regulatory requirements

D.  

The organization's Business Continuity operational plans are kept up to date

Discussion 0
Questions 3

Which of the following parameters would NOT be considered by a resource or activity owner when evaluating and selecting solutions to meet an agreed strategy?

Options:

A.  

The advantages and disadvantages of the proposed solution

B.  

The type of exercises to be conducted to validate the strategies and solutions

C.  

The estimated costs to prepare, implement, operate and maintain the solution

D.  

The implementation time required

Discussion 0
Questions 4

Which of the following will improve understanding of the benefits of Business Continuity (BC) and increase voluntary commitment to BC across the workforce?

Options:

A.  

Enforcing regular BC activities such as attendance at briefings or training

B.  

Establishing a system where BC is seen only as a corporate mandate driven by policy

C.  

Allocating additional responsibilities and objectives related to BC roles to existing workloads

D.  

Establishing BC as a culture underpinned by personal beliefs and corporate behaviours

Discussion 0
Questions 5

The most appropriate type of exercise for verifying if a critical system can be restored from backups within the expected Recovery Time Objective (RTO) is a:

Options:

A.  

Scenario exercise

B.  

Test

C.  

Discussion-based exercise

D.  

Simulation

Discussion 0
Questions 6

In order to enable Business Continuity solutions, it is necessary to:

Options:

A.  

Measure capabilities to deliver the solutions by carrying out a gap analysis

B.  

Create guidance documents that detail response activities and procedures that specific teams need to follow

C.  

Establish and implement a strategy to ensure that business objectives are aligned to the agreed solutions

D.  

Carry out a review of the Business Continuity policy to ensure that it is updated with the detail of the agreed solutions

Discussion 0
Questions 7

The process that ensures that an organization's Business Continuity arrangements are up to date and ready to respond to incidents and their impacts despite changes to its structure or changes in its operational context is:

Options:

A.  

Review

B.  

Gap analysis

C.  

Maintenance

D.  

Internal audit

Discussion 0
Questions 8

Which of the following is a way to ensure that personnel remain committed to Business Continuity and to protecting the organization from the effects of disruption?

Options:

A.  

Holding annual assessments of Business Continuity knowledge and understanding and setting minimum pass standards which personnel must meet

B.  

Making it a disciplinary offence for personnel to miss relevant Business Continuity meetings and training events

C.  

Including Business Continuity as part of the introduction to meetings and events in order to strengthen and maintain the relationship between personnel and the organization

D.  

Providing updates on Business Continuity activities via the intranet which personnel can find and read if they are interested

Discussion 0
Questions 9

An effective exercise programme should:

Options:

A.  

Be put in place as part of the outcome of the Business Impact Analysis (BIA) and the associated solutions design

B.  

Follow the same framework of activities each year so that progress can be compared over time

C.  

Be reviewed regularly at pre-defined intervals or following significant change

D.  

Reflect trends in customer concerns and feedback from stakeholders

Discussion 0
Questions 10

In relation to the development of solutions, the purpose of a gap analysis is to:

Options:

A.  

Identify a strategy to close the existing gaps

B.  

Design and select solutions to deliver strategies and close gaps

C.  

Assess whether or not current capabilities are sufficient to meet the Business Continuity (BC) requirements

D.  

Develop a risk mitigation strategy to address any identified single points of failure

Discussion 0
Questions 11

Which of the following is NOT a factor that should be considered when estimating the Maximum Tolerable Period of Disruption (MTPD) to a product or service?

Options:

A.  

Breach of legal or regulatory obligations

B.  

Damage to reputation

C.  

Threats that could cause disruption

D.  

Failure to meet business objectives

Discussion 0
Questions 12

Reading the organization's mission statement, annual reports, corporate social media accounts, or newsletters can contribute to building a better understanding of the organization’s:

Options:

A.  

Business Continuity Management System (BCMS)

B.  

Emergency Response Strategy

C.  

Culture

D.  

Crisis Communication plan

Discussion 0
Questions 13

Within the context of risk assessment, the identification of solutions is influenced by a variety of business relevant considerations, including:

Options:

A.  

Delivering performance targets

B.  

Timely production of quality assurance audit trails

C.  

Compliance with regulatory requirements

D.  

Ensuring that communication protocols are observed

Discussion 0
Questions 14

In order to effectively measure an organization’s Business Continuity (BC) culture:

Options:

A.  

A single method should be applied consistently regardless of roles and responsibilities

B.  

A separate, independent department should be established to oversee the process and summarise results

C.  

Measurement methods should be designed into day-to-day operations or Business Continuity (BC) activities

D.  

Personnel should be advised that performance will be judged and action taken if attitudes are unsatisfactory

Discussion 0
Questions 15

Which of the following is used to determine the organization's prioritised activities and the recovery timeframes and resource requirements?

Options:

A.  

A risk assessment

B.  

An exercise

C.  

A Business Impact Analysis (BIA)

D.  

A meeting with owners of product and services activities

Discussion 0
Questions 16

In relation to Business Continuity (BC), risk mitigation should focus on:

Options:

A.  

Acceptable levels of risk

B.  

All threats to an organization

C.  

Unacceptable levels of risk

D.  

Selected risks to the organization

Discussion 0
Questions 17

Recovery solutions that support an alternate location strategy for physical infrastructure that can be made available within hours include:

Options:

A.  

Personnel working from home

B.  

Repurposing other work areas and facilities

C.  

Ordering, delivering and installing replacement equipment

D.  

Rebuilding and reconnecting utility feeds

Discussion 0
Questions 18

When developing solutions for people strategies, solutions to recover activities with a short Recovery Time Objective (RTO) requiring redeployment of personnel should be supported by:

Options:

A.  

The development of training material including all relevant information and procedures so that this can be made available when required

B.  

Links to social media so the organization can run an extensive recruitment campaign both inside and outside the organization if a disruptive event occurs

C.  

Recruitment of additional personnel so that the organization always has access to surplus staff in case of an incident occurring

D.  

Induction and training by an operational manager at the time when the disruption is underway so that individuals can build understanding and confidence prior to commencing the allocated tasks

Discussion 0
Questions 19

When deciding whether or not to include a product or service in the initial scope of the Business Continuity Management System (BCMS), which of the following would be considered?

Options:

A.  

Financial value of the product or service to the organization

B.  

Consultation with, and feedback from, the organization's staff

C.  

How quickly and easily the product or service can be incorporated into the BCMS

D.  

Comparative approaches to the product or service taken by business competitors

Discussion 0
Questions 20

Which of the following elements would NOT be validated by an exercise?

Options:

A.  

The availability of key information when required

B.  

The design and effectiveness of the business impact analysis process

C.  

The effectiveness and usability of relevant procedures

D.  

The reliability of systems and equipment

Discussion 0
Questions 21

A key difference between “embedding” and “embracing” Business Continuity (BC) is that:

Options:

A.  

Embedding is focused on mandating and enforcing compliance whereas embracing is aimed at creating a greater understanding of the reason why BC is needed through cultural change

B.  

Embedding is mandated by top management within the BCMS whereas embracing is designed and implemented by operational teams

C.  

Embedding is only relevant for organizations that are new to BC whereas embracing should only be undertaken in organizations with well-established BCMS

D.  

Embedding relies on commitment from personnel whereas embracing is mandated and incorporates strict discipline

Discussion 0
Questions 22

An effective response structure includes:

Options:

A.  

Unlimited access to financial resources during a disruption

B.  

Knowledge of when key suppliers and external stakeholders should be notified and included in the response

C.  

Flexibility to change policies and procedures during a disruption without consulting top management

D.  

Personnel in place to assess and measure the performance of responders during a disruption

Discussion 0
Questions 23

Which of the following statements describes a good practice Business Continuity (BC) culture?

Options:

A.  

A situation where personnel follow procedures as set out by the organization but do not have a sense of ownership.

B.  

A situation where Business Continuity (BC) professionals have significant influence in the organization and specify all actions to be taken and carry out all reviews as needed.

C.  

A situation where all staff have a shared understanding of Business Continuity (BC) and everyone is involved.

D.  

A situation where the workforce is sufficiently committed to Business Continuity (BC) that top management does not get involved.

Discussion 0
Questions 24

Which of the following is a benefit of conducting an exercise?

Options:

A.  

Confirmation of how well Business Continuity is incorporated into the tasks pertaining to the Business Continuity Management System (BCMS)

B.  

Confirmation that personnel are familiar with their roles, and authority in response to an incident

C.  

Increased understanding of the requirements set out in the Activities Business Impact Analysis (BIA)

D.  

Validation of the Business Continuity Management System (BCMS) against standards, regulations and legislation

Discussion 0
Questions 25

Which of the following factors affects the way in which an organization selects and combines the different types of Business Impact Analysis (BIA)?

Options:

A.  

The outcomes of an organization's risk assessment to determine which part of the organization is at greatest risk

B.  

The scope of the Business Continuity Management System (BCMS)

C.  

The outcomes of a gap analysis to identify where there is greatest need for Business Continuity capability to be improved

D.  

Consultation with internal and external stakeholders on the extent of analysis that is required

Discussion 0
Questions 26

How is the Recovery Time Objective (RTO) defined?

Options:

A.  

The timeframe within the Maximum Tolerable Period of Disruption (MTPD) during which a product, service or activity must be suspended to avoid adverse impacts on customers

B.  

The timeframe within the Maximum Tolerable Period of Disruption (MTPD) for resuming disrupted activities at a specified minimum acceptable capacity

C.  

The period of time following a disruption during which a product, service or activity must be suspended while resources are recovered and operating standards are re-established

D.  

The point at which all products, services and activities must be fully resumed following a disruption

Discussion 0
Questions 27

As part of the preparation for responding to an incident, plans should be in place to enable the response team to meet. Which of the following is NOT correct in relation to arrangements for meeting facilities?

Options:

A.  

Meeting arrangements should be stated in plans that are made available to all team members

B.  

At least two meeting locations should be stated with the team leader deciding which to use at the time of the incident

C.  

Meetings must always take place in a physical rather than virtual location

D.  

A continuously available and stable power supply should be available to meeting locations

Discussion 0
Questions 28

Which of the following would NOT be considered when planning individual exercises?

Options:

A.  

The budget required for the exercise

B.  

The teams that will be required to participate

C.  

The plausibility of the storyline to be used for the scenario

D.  

The arrangements for external communications after the exercise has been completed

Discussion 0
Questions 29

Establishing governance arrangements for a Business Continuity Management System (BCMS) is essential in order to:

Options:

A.  

Develop a project risk register and carry out appropriate risk assessments in the workplace

B.  

Ensure that there is ongoing commitment across all organizational functions and levels

C.  

Commission research into approaches taken by organizations

D.  

Enable the Business Continuity professional to establish their authority and issue instructions on the actions that need to be taken

Discussion 0
Questions 30

Why is it important to establish governance for a Business Continuity Management System (BCMS)?

Options:

A.  

To provide the foundation for further development, effective operation, support and continual improvement

B.  

To monitor and review BC training programmes regularly to ensure that any skills gaps identified by the gap analysis are being addressed

C.  

To ensure that different parts of the organization can take independent approaches to reflect their preferences and timelines

D.  

To align the governance of the BCMS with the structure of the organization's business sector

Discussion 0
Questions 31

In relation to validation, which of the following is NOT an aim of an exercise programme?

Options:

A.  

Improved teamwork and competency of recovery team members

B.  

Verification that the expected Recovery Time Objectives (RTOs) can be achieved

C.  

Identification of outdated information in the Business Continuity (BC) plans and areas for improvement

D.  

Design of additional Business Continuity (BC) policies and solutions

Discussion 0
Questions 32

Which one of the following is a feature of an effective Business Continuity (BC) policy?

Options:

A.  

There is clear top management commitment to the policy and its continued improvement.

B.  

The policy details the incident management plans and the financial budgets available to support recovery plans.

C.  

The policy provides details of constraints on specific suppliers.

D.  

The policy can be validated by exercises and updated with the detailed learning that arises from carrying out the exercises.

Discussion 0
Questions 33

When coordinating a Business Continuity Management System (BCMS), a steering group should be established to oversee, advise and make recommendations as the BCMS is established. The steering group should comprise:

Options:

A.  

Only Business Continuity professionals and any available administrative support

B.  

Only top management

C.  

Customers and suppliers that are familiar with the way the organization works and can make recommendations from an external perspective

D.  

Multi-disciplinary experts who are familiar with the operation of the organization

Discussion 0
Questions 34

The time period defined by the Recovery Time Objective (RTO) should always be less than which of the following?

Options:

A.  

The Recovery Point Objective (RPO)

B.  

The Maximum Tolerable Period of Disruption (MTPD)

C.  

The Minimum Business Continuity Objective (MBCO)

D.  

The standard timeline set by the organization's customer services charter

Discussion 0
Questions 35

In relation to a disruption to activities, the Minimum Business Continuity Objective (MBCO):

Options:

A.  

Should be the Recovery Time Objective (RTO)

B.  

Should be attained either at the same time, or after, the RTO

C.  

Is the point identified in the risk assessment when risks have been successfully mitigated

D.  

Is the point set by top management for mobilizing response teams

Discussion 0
Questions 36

The organization's requirements for information and data resources should be considered as part of the Activity Business Impact Analysis (BIA). Which of the following is correct in relation to the Recovery Point Objective (RPO)?

Options:

A.  

All data users and activities have the same requirements; so only limited consultation is required to determine the RPO

B.  

The RPO should comply with data protection requirements

C.  

The RPO is the point to which information must be restored to enable all priority activities to operate on resumption

D.  

The RPO establishes the amount of time that IT services can be disrupted before the organization is impacted

Discussion 0
Questions 37

Which of the following would be undertaken as part of the process to ensure the effective implementation of agreed Business Continuity (BC) solutions?

Options:

A.  

Announcing the changes that have been made on the organization's external website

B.  

Encouraging personnel to adapt solutions to suit their particular situation in order to engage them in the process

C.  

Ensuring alignment with response structure and plans

D.  

Checking that printed versions of procedures have been made available to all organization personnel

Discussion 0
Questions 38

In relation to the care and wellbeing of staff during an incident, which of the following would NOT be an immediate requirement for the People and Culture Management team?

Options:

A.  

Accounting for the personnel on the site where the incident has occurred

B.  

Being able to contact personnel and their family members

C.  

Assigning responsibilities to staff who are working away from the site to enable recovery activities to commence

D.  

Enabling access to physical care if needed

Discussion 0
Questions 39

When identifying risk mitigation strategies and solutions in relation to unacceptable risk and/or single point dependencies, the Business Continuity (BC) professional should collaborate with:

Options:

A.  

Activity and resource owners

B.  

Top management

C.  

Incident response team leaders

D.  

Media and communication managers

Discussion 0
Questions 40

In which of the following situations would an organization conduct a Business Impact Analysis (BIA) at a high level and then use the outcomes to develop more detailed BIAs and to clarify the scope of the Business Continuity Management System (BCMS)?

Options:

A.  

Where the organization is experiencing rapid growth

B.  

Where the organization is conducting an initial BIA

C.  

Where there is a lack of top management support for Business Continuity (BC)

D.  

Where the organization has been through structural changes since the previous BIA

Discussion 0
Questions 41

One of the steps in the risk management process is to establish the risk treatment required. The purpose of risk treatment is to:

Options:

A.  

Ensure that a named person within the organization takes responsibility for the monitoring and management of the risk

B.  

Calculate a risk score based on the combination of the likelihood of the risk occurring and the consequences of this happening

C.  

Mitigate each risk identified by reducing the likelihood of the risk occurring or by lowering the impact of disruption

D.  

Ensure that regular updates on the current status of the risk are presented to top management

Discussion 0
Questions 42

If a Business Continuity (BC) culture gap analysis shows that the gap between the existing culture and the desired BC culture is large, which of the following approaches would be the best one for the BC professional to take?

Options:

A.  

Adopt a BC culture development approach that was successfully used by another organization.

B.  

Introduce an aggressive training programme for all employees that focuses on details of the BCMS.

C.  

Start with the basics, ensuring that employees' needs and perspectives are recognised, and then progress to more advanced topics.

D.  

Expand and enhance BCMS information on the organization’s intranet and introduce a requirement that all employees review the information at least once a year.

Discussion 0
Questions 43

In relation to governance roles and responsibilities, what should be put in place to ensure that the responsibilities of each Business Continuity Management System (BCMS) role holder will be fulfilled should the primary role holder be ill, out of the area, or be otherwise unavailable?

Options:

A.  

The Business Continuity professional will temporarily take over the responsibilities of the absent role holder

B.  

Responsibilities of the absent role holder will be put on hold while a substitute is located

C.  

A subject matter expert will be assigned as the deputy for each primary BCMS role holder

D.  

The Incident Response Team will assume responsibility for the responsibilities of the absent BCMS role holder

Discussion 0
Questions 44

The three main steps involved in the risk assessment process are listing risk sources, performing a risk source analysis and:

Options:

A.  

Identifying historical risks

B.  

Categorising risks

C.  

Assessing the consequences of risks

D.  

Evaluating risks

Discussion 0
Questions 45

The professional practice that aims to measure the competence of individuals, team cohesiveness and the effectiveness of Business Continuity (BC) capability is:

Options:

A.  

Solutions Design

B.  

Analysis

C.  

Validation

D.  

Enabling Solutions

Discussion 0
Questions 46

Which of the following is a process that analyses the impact over time of a disruption on an organization?

Options:

A.  

Business Impact Analysis

B.  

Recovery Time Analysis

C.  

Cost Benefit Analysis

D.  

Risk and Threat Analysis

Discussion 0
Questions 47

Analysing information about how an organization has responded to incidents, including engagement with those impacted and its approach to responsibility, can provide insight into the organization's:

Options:

A.  

Culture

B.  

Business targets

C.  

Business plan

D.  

Structure

Discussion 0
Questions 48

In order to implement appropriate initiatives for influencing personnel to embrace Business Continuity and a Business Continuity culture, the Business Continuity professional should start by:

Options:

A.  

Conducting a Business Impact Analysis (BIA) that can be shared with all personnel

B.  

Carrying out a gap analysis to identify whether the Business Continuity resumption capabilities meet the Business Continuity needs

C.  

Estimating the gap between the extent to which Business Continuity is currently embraced in the organization and the desired level at which Business Continuity should be embraced

D.  

Implementing a communications strategy to share information about the gaps in the organization's current Business Continuity plans

Discussion 0
Questions 49

Which of the following is NOT correct in relation to the purpose of defining the scope of the Business Continuity Management System (BCMS)?

Options:

A.  

It ensures a clear understanding of the areas of the organization that are, and are not, covered by the BCMS

B.  

It establishes permanent parameters for the BCMS

C.  

It defines the BCMS on the organization’s products, services, and activities

D.  

It makes the best use of available time and finances

Discussion 0
Questions 50

Which of the following is essential to ensure the ongoing effectiveness and relevance of a Business Continuity Management System (BCMS) and should be built into the initial process to establish a BCMS?

Options:

A.  

Determining how the BCMS will be monitored, reviewed and continually improved over time

B.  

Developing internal and external communications systems to raise the profile of the BCMS and highlight successful steps in the development

C.  

Carrying out health and safety risk assessments in all parts of the organization and making a commitment to repeat these assessments every year as part of the BCMS

D.  

Ensuring compliance with legal requirements across the company and developing a register of any risks

Discussion 0
Questions 51

Size of the organization, the organization's culture and how people prefer to receive information are among the factors for the Business Continuity (BC) professional to consider when:

Options:

A.  

Developing an awareness strategy

B.  

Planning a live exercise

C.  

Developing plans

D.  

Designing solutions

Discussion 0
Questions 52

A technique that the Business Continuity (BC) professional could use to help improve an organization's BC culture is:

Options:

A.  

Build and strengthen relationships with interested parties and get everyone to work towards a common goal

B.  

Conduct Business Impact Analysis (BIA) workshops with senior management

C.  

Increase the frequency and number of audits to ensure that all business areas comply with the Business Continuity (BC) policy

D.  

Make it mandatory for all personnel to attend Business Continuity (BC) exercises

Discussion 0