
Easily To Pass New CBCP-002 Premium Exam Updated [May 03, 2024]
CBCP-002 Certification All-in-One Exam Guide May-2024
NEW QUESTION # 23
A formal "disaster" can only be declared by the firm owners or by the IT Department Manager.
- A. False
- B. True
Answer: A
Explanation:
Explanation
A formal "disaster" can only be declared by the firm owners or by the IT Department Manager. This is false because a formal "disaster" can be declared by any authorized person who has the responsibility and authority to activate the business continuity and disaster recovery plan. The authorized person may vary depending on the type, scope, and severity of the disaster, but it should be clearly defined in the plan who can declare a disaster and under what circumstances. The authorized person should also communicate the declaration of a disaster to all relevant stakeholders, such as employees, customers, suppliers, partners, regulators, media, or the public. Verified References:
https://www.ready.gov/business-continuity-planhttps://www.csoonline.com/article/515730/business-continuity-a
NEW QUESTION # 24
Damage assessment includes all but which of the following steps?
- A. Estimate the time it will take to restore critical business functions.
- B. Having the insurance company declare the total extent of the damages.
- C. Identifying the affected business functions.
- D. Evaluating the time to restore operations and if greater than the MTD, a disaster should be declared and BCP enacted
Answer: B
Explanation:
Explanation
Damage assessment is the process of evaluating the extent and severity of the damage caused by a disruption to an organization's facilities, equipment, systems, data, records, or personnel. It includes identifying the affected business functions and processes, estimating the time it will take to restore them to normal or acceptable levels of operation, and evaluating whether the recovery time exceeds the maximum tolerable downtime (MTD) for each function or process. If so, a disaster should be declared and the business continuity plan should be activated. Having the insurance company declare the total extent of the damages is not part of the damage assessment process, as it may take longer than the MTD and may not reflect the operational impact of the damage. Verified References:
https://www.fema.gov/pdf/emergency/nims/Damage_Assessment.pdfhttps://drii.org/resources/professionalpracti
NEW QUESTION # 25
Which of the following is a low-pressure exercise that uses presentation techniques including videos, slides, and handouts, so that participants fully understand their plans?
- A. Virtualization
- B. Single team simulation
- C. Plan walkthrough
- D. Facilitated discussion
Answer: C
Explanation:
Explanation
A plan walkthrough is a low-pressure exercise that uses presentation techniques including videos, slides and handouts, so that participants fully understand their plans1.
NEW QUESTION # 26
Which of the following should NOT be released in a publicly released BCP?
- A. Process flows
- B. BIA results
- C. All of the above
- D. Contact lists
Answer: C
Explanation:
Explanation
A publicly released BCP is a version of a business continuity plan that is intended for external audiences, such as customers, suppliers, partners, regulators, media, or the public. It should not contain sensitive or confidential information that may compromise the security or privacy of theorganization or its stakeholders.
Therefore, it should not include process flows that detail how each function or process is performed; contact lists that reveal personal or organizational information; BIA results that show criticality ratings or recovery time objectives; or any other information that may expose vulnerabilities or risks. Verified References:
https://www.ready.gov/business-continuity-planhttps://drii.org/resources/professionalpractices/EN
NEW QUESTION # 27
Which of the following exercises involve all teams?
- A. Full-scale exercise
- B. Plan walkthrough
- C. Facilitated discussion
- D. Multi-team simulation
Answer: A
Explanation:
Explanation
A full-scale exercise is a type of exercise that involves all teams. A full-scale exercise is a high-pressure exercise that simulates a realistic scenario of a disruption that affects all or most of the organization's functions and processes. A full-scale exercise tests the effectiveness and efficiency of the plans, procedures, systems, teams, and resources that are required to respond to and recover from a disruption. A full-scale exercise also evaluates the coordination and communication among all the teams and stakeholders involved.
Verified References:
https://www.ready.gov/business-continuity-planhttps://www.csoonline.com/article/515730/business-continuity-a
NEW QUESTION # 28
When should the Business Continuity Planning be reviewed?
- A. Whenever encountering a disaster
- B. Whenever the company gets audited
- C. At least annually or whenever significant changes occur
- D. Whenever the legal department declares it is time
Answer: C
Explanation:
Explanation
Business continuity planning is not a one-time activity, but a dynamic and ongoing process that needs to be reviewed and updated regularly to reflect changes in the internal and external environment. The frequency of review may vary depending on the nature and size of the organization, but it is generally recommended to conduct a review at least annually or whenever significant changes occur that may affect the continuity of the organization's functions and processes. Such changes may include organizational restructuring, new products or services, new technologies, new regulations, new threats or vulnerabilities, or lessons learned from incidents or exercises. Verified References:
https://www.ready.gov/business-continuity-planhttps://drii.org/resources/professionalpractices/EN
NEW QUESTION # 29
Which of the following four are action approach crisis and post-crisis management? (Choose four R's)
- A. Recovery
- B. Reduction
- C. Readiness
- D. Rustic
- E. Response
- F. Rss Feed
Answer: A,B,C,E
Explanation:
Explanation
The four R's are action approaches for crisis and post-crisis management. They are:
Reduction: This approach aims to prevent or mitigate the occurrence or impact of a crisis by identifying and addressing the root causes, vulnerabilities, and risks.
Readiness: This approach aims to prepare for a potential crisis by developing plans, policies, procedures, systems, teams, and resources that can enable a timely and effective response.
Response: This approach aims to manage a crisis by activating the plans, policies, procedures, systems, teams, and resources that can contain, control, and resolve the situation.
Recovery: This approach aims to restore normal operations after a crisis by implementing actions that can repair damages, restore functions and processes, resume services and products, recover losses, and learn lessons. Verified References:
https://www.cisco.com/c/en/us/solutions/hybrid-work/what-is-business-continuity.html
https://phoenixnap.com/blog/what-is-business-continuity-management
NEW QUESTION # 30
Which type of management is an often used term, but has so many different connotations to different people that invariably the message of its meaning gets confused?
- A. Functional
- B. Technical
- C. Strategic
- D. Operational
Answer: C
Explanation:
Explanation
Strategic management is the type of management that is an often used term, but has so many different connotations to different people that invariably the message of its meaning gets confused. Strategic management is the process of defining and executing the long-term vision, goals, plans, and actions of an organization. Strategic management involves analyzing the internal and external environment, formulating strategies, implementing them, and evaluating their outcomes. Strategic management can be complex and challenging, as it requires alignment and integration of various aspects of the organization, such as culture, structure, resources, capabilities, stakeholders, markets, competitors, or regulations. Verified References:
https://www.investopedia.com/terms/s/strategic-management.asp
https://phoenixnap.com/blog/what-is-business-continuity-management
NEW QUESTION # 31
Which certification centre provides the physical infrastructure?
- A. Facility
- B. Service
Answer: A
Explanation:
Explanation
A facility certification center is a center that provides the physical infrastructure for testing and certifying the functionality and performance of products, systems, or services. A facility certification center may have specialized equipment, tools, environments, or standards that can simulate real-world conditions or scenarios.
A facility certification center may also have qualified staff, experts, or auditors who can conduct the testing and certification process. Verified References:
https://www.iso.org/publication/PUB100442.htmlhttps://www.cisco.com/c/en/us/solutions/hybrid-work/what-is-
NEW QUESTION # 32
Which type of continuity planning will enhance the functioning relationship with the organization's key suppliers, creating stronger assurances of continuous supply of information, material product and services?
- A. Unilateral
- B. Bilateral
- C. Multilateral
Answer: B
Explanation:
Explanation
Bilateral continuity planning is the type of continuity planning that will enhance the functioning relationship with the organization's key suppliers, creating stronger assurances of continuous supply of information, material product and services. Bilateral continuity planning is the process of developing and maintaining mutual agreements and arrangements between an organization and its key suppliers to ensure the continuity of their respective functions and processes in the event of a disruption. Bilateral continuity planning can help to reduce risks, costs, and dependencies, as well as to improve communication, coordination, and collaboration.
Verified References:
https://www.iso.org/publication/PUB100442.htmlhttps://phoenixnap.com/blog/what-is-business-continuity-mana
NEW QUESTION # 33
Which risk group is associated with risk of physical assets failing/being damaged or enhanced?
- A. Strategic
- B. Financial
- C. Technical
- D. Operational
Answer: C
Explanation:
Explanation
Technical risk is the type of risk that is associated with risk of physical assets failing/being damaged or enhanced. Technical risk is the uncertainty or variability of the performance or reliability of physical assets, such as equipment, systems, infrastructure, or data. Technical risk can result from factors such as design flaws, manufacturing defects, maintenance issues, obsolescence, human error, natural disasters, or cyberattacks.
Technical risk can affect an organization's operational efficiency, quality, safety, security, or profitability.
Verified References:
https://www.investopedia.com/terms/t/technical-risk.asphttps://www.thebci.org/training-qualifications/good-prac
NEW QUESTION # 34
BIA helps you identify
- A. Critical interdependencies and interested parties
- B. Tangible and intangible impact of a disruption over period of time
- C. Critical services and products
- D. All of the above
Answer: D
Explanation:
Explanation
BIA helps to identify all of the above aspects of an organization's functions and processes. It helps to identify the critical services and products that the organization delivers to its customers and stakeholders, and the functions and processes that support them. It also helps to identify the critical interdependencies and interested parties that are involved in or affected by the organization's functions and processes, such as suppliers, partners, regulators, or employees. Moreover, it helps to identify the tangible and intangible impacts of a disruption tothe organization's functions and processes over a period of time, such as financial losses, reputational damage, legal liabilities, or customer dissatisfaction. Verified References:
https://www.ready.gov/business-impact-analysishttps://drii.org/resources/professionalpractices/EN
NEW QUESTION # 35
There are several reasons why a company would develop and implement a business continuity plan. Which of the following properly describes the best reason?
- A. Properly react to disasters
- B. Compliance with regulations
- C. To increase liability
- D. The continuation of a company
Answer: D
Explanation:
Explanation
The primary reason for developing and implementing a business continuity plan is to ensure the continuation of a company's critical functions and processes in the face of a disruption that may otherwise cause severe losses or damage to the company's reputation, assets, customers,or stakeholders. A business continuity plan can help a company to resume operations as quickly as possible after a disruption, minimize the impact on its performance and profitability, protect its brand and image, and fulfill its legal and contractual obligations.
Verified References:
https://www.ready.gov/business-continuity-planhttps://drii.org/resources/professionalpractices/EN
NEW QUESTION # 36
Which Process can be both time consuming and expensive as a result, management will expect tangible benefits to be achieved by the process?
- A. Business Process Planning
- B. Business Continuity Planning
- C. Business Ethical Planning
- D. Business Contingency Planning
Answer: B
Explanation:
Explanation
Business continuity planning is the process of identifying, developing, and implementing strategies and plans to ensure the continuity of an organization's critical functions and processes in the event of a disruption. It can be both time consuming and expensive, as it requires a thorough analysis of risks, impacts, resources, and recovery options. However, management will expect tangible benefits from the process, such as reduced losses, increased resilience, improved reputation, and compliance with regulations. Verified References:
https://www.ready.gov/business-continuity-plan https://drii.org/resources/professionalpractices/EN
NEW QUESTION # 37
Individual accountability for the management of the risk should be clearly established.
- A. True
- B. False
Answer: A
Explanation:
Explanation
Individual accountability for the management of the risk should be clearly established. This is true because accountability is one of the key principles of business continuity management. Accountability means that each person involved in the business continuity management program has a clear understanding of their roles and responsibilities, as well as the authorityand resources to perform them. Accountability also means that each person is held responsible for their actions and outcomes, and that they report on their performance and progress regularly. Verified References:
https://www.iso.org/publication/PUB100442.htmlhttps://phoenixnap.com/blog/what-is-business-continuity-mana
NEW QUESTION # 38
BIA helps you identify
- A. Critical interdependencies and interested parties
- B. Tangible and intangible impact of a disruption over period of time
- C. Critical services and products
- D. All of the above
Answer: D
Explanation:
Explanation
BIA helps to identify all of the above aspects of an organization's functions and processes. It helps to identify the critical services and products that the organization delivers to its customers and stakeholders, and the functions and processes that support them. It also helps to identify the critical interdependencies and interested parties that are involved in or affected by the organization's functions and processes, such as suppliers, partners, regulators, or employees. Moreover, it helps to identify the tangible and intangible impacts of a disruption tothe organization's functions and processes over a period of time, such as financial losses, reputational damage, legal liabilities, or customer dissatisfaction. Verified References:
https://www.ready.gov/business-impact-analysishttps://drii.org/resources/professionalpractices/EN
NEW QUESTION # 39
......
Last CBCP-002 practice test reviews: Practice Test GAQM dumps: https://freetorrent.itpass4sure.com/CBCP-002-practice-exam.html

