Deck 1: Certified Business Continuity Professional

Full screen (f)
exit full mode
Question
Which of the following are required to be a part of the Crisis Management Center? (Select all that apply.)

A)Emergency electrical generator
B)Telephone access
C)State of the art computer systems
D)Access control measures
Use Space or
up arrow
down arrow
to flip the card.
Question
Mr) Indecisive has been given the task of ensuring that critical papers and records that are required to operate the business are available in the event of a crisis. What advice should you give him to help him determine how to complete this task?

A)Save electronic backup copies of all documents
B)Keep multiple copies of the documents in different areas of the building
C)Set up a fire-proof safe in the building to store the documents
D)Set up an off-site storage to store the documents
Question
Damage and Impact Assessment is part of which stage of the Business Continuity Plan?

A)Readiness
B)Prevention
C)Response
D)Recovery and Resumption
Question
How would you explain the purpose of the Recovery and Resumption phase of the Business Continuity Plan to a new hire in your organization, such as Mr. Newbie?

A)It is the process of responding when a crisis happens
B)It is the process of bringing the organization out of the crisis and returning it to normal operations
C)It is the process of cleaning up after a crisis has occurred
D)It is the process of identifying the root cause for the crisis and preventing it from reoccurring
Question
Which of these should be included in the Damage and Impact Assessment immediately after a crisis? (Select all that apply.)

A)Physical damage to the facility
B)Financial cost of all damages
C)Potential long term reputation damages
D)None of the above
Question
When planning and implementing recovery/resumption procedures, what is the most important aspect?

A)That work proceed as quickly as possible
B)That business proceed as normal regardless of the cost
C)That each Crisis Team member is contacted prior to work beginning
D)That all decisions are document with justification
Question
When is a crisis normally declared "over"?

A)When the business is no longer under continued threat from the crisis
B)When the business has a plan to implement to recover from the crisis
C)When the business is able to function with its core processes up and running
D)When the business is able to operate as it was pre-crisis
Question
Which of these tasks are appropriate tasks for declaring a crisis to be "over"? (Select all that apply.)

A)Holding a press conference
B)Sending communication to employees
C)Documenting the decision
D)None of the above
Question
Mr) Indecisive wants to return the organization back to its normal, pre-crisis state. However, he is unable to do this as a result of the impact of the crisis. What should he do instead?

A)Continue to try to achieve pre-crisis normal state regardless of the cost
B)Declare the organization failed and file for bankruptcy
C)Declare a "new normal" state for the organization to operate in
D)Continue to react in crisis mode indefinitely
Question
Which of these best describes the Business Continuity Plan?

A)It should be reviewed on a yearly basis
B)It should be a living document that is constantly updated and renewed
C)Once created, the BCP does not need additional reviews
D)A new BCP needs to be created each time something in the organization changes
Question
Mr) Indecisive is unsure of who should be trained on the new Business Continuity Plan that was developed. What should you recommend to him?

A)Only Crisis Team members should be trained
B)Only Business Continuity team members should be trained
C)Only those who play a part in the Business Continuity Plan implementation should be trained
D)Every employee should be trained
Question
How often is it recommended for the Crisis and Response teams to be trained on the Business Continuity Plan?

A)Monthly
B)Annually
C)Every two years
D)Only when a significant change occurs
Question
Management has set the recovery time objective (RTO) to 24 hours for Joe's process. What does this mean?

A)Joe's people must be in the office performing the process 24 hours after a disaster or disruption.
B)Joe has 24 hours to decide what to do in event of an emergency.
C)No more than 24 hours of data can be lost.
D)All data related to the process must be recovered within 24 hours.
E)Joe's process must be restored after 24 hours.
Question
Mr) Newbie has recently joined the Crisis Management team as part of his work on the Business Continuity Plan. When should he schedule his training on the current version of the Business Continuity Plan?

A)As soon as possible
B)During the next regularly scheduled training session
C)Official training is not needed
Question
What documentation is recommended for use when training the Crisis Management and Response teams on the BCP? (Select all that apply.)

A)The Business Continuity Plan itself
B)Checklists of critical actions for the teams
C)Explanation of responsibilities
D)None of the above
Question
External resources such as Fire and Public Health officials should not be trained in portions of the company's Business Continuity Plan.
Question
Why should testing be a key component of a successful Business Continuity Plan?

A)Because it is a regulatory mandate
B)Because it will improve the effectiveness of the BCP implementation during a crisis
C)Because senior management requires it
D)Testing is not a key component to BCP success
Question
What should be the first step in testing the Business Continuity Plan?

A)Assigning responsibility for the testing
B)Schedule testing date and time
C)Establishing test goals and expectations
D)Define the scope of the test
Question
When developing test scope, which recommendation should be followed?

A)Test the entire BCP immediately to determine outages and then focus on those outages with subsequent tests
B)Pick the most likely aspects of the BCP to fail and test those first
C)Begin the testing with small, simple tests and then based on the results of those tests, increase scope accordingly
D)Testing should be randomized to provide accurate results
Question
When monitoring the testing of the Business Continuity Plan strategies, which of the following strategies is the ideal method for monitoring the test?

A)No test monitoring is needed
B)Participant feedback at the end of the test
C)Official observers notes about the test
D)Video or audio recording equipment
Question
BCP testing scenarios should be designed using input from the _______________ .

A)Risk Assessment
B)Damage and Impact Assessment
C)Business Impact Analysis
D)Mitigation Plan
Question
A risk trigger is what triggers a contingency response.
Question
Which of these test exercises should be completed first?

A)Functional
B)Tabletop
C)Orientation
D)Full Scale
Question
Which of these testing types is a practical or simulated exercise and takes approximately 2 - 4 hours to complete?

A)Orientation
B)Full Scale
C)Functional
D)Tabletop
Question
Which of these testing types will allow the participants to make decisions and respond in real time to learn the consequences of those decisions and its impact on other participants in the test?

A)Full Scale
B)Orientation
C)Functional
D)Tabletop
Question
Which of these testing types does not require a debriefing period after the test scenario? (Select all that apply.)

A)Orientation
B)Tabletop
C)Functional
D)Full Scale
Question
Which of these testing types will provide the most feedback and information on whether the Business Continuity Plan will be implemented successfully in the event of an actual crisis?

A)Orientation
B)Functional
C)Tabletop
D)Full Scale
Question
In testing scenarios, there are different roles. Which of these roles acts to add realism to the scenario?

A)Facilitator
B)Controller
C)Simulator
D)Observer
Question
Who is responsible for helping to eliminate safety and property damage issues during a testing scenario?

A)Facilitator
B)Controller
C)Simulator
D)Observer
Question
Which of these testing scenario roles would include the role of Crisis Management team leader during a testing exercise?

A)Participant
B)Controller
C)Simulator
D)Observer
Question
Which of these roles is intended to evaluate the actions of the participants and the overall effectiveness of the Business Continuity Plan?

A)Facilitator
B)Controller
C)Simulator
D)Observer
Question
Developing a Business Continuity Plan review schedule is part of which stage of BCP planning?

A)Readiness
B)Prevention
C)Response
D)Evaluation and Maintenance
Question
Mr) Indecisive is in charge of the testing phase of the Business Continuity Plan. He is debating whether or not he should schedule his test ahead of time with the participants or create a surprise test instead. What advice should you give him?

A)All tests should be previously scheduled with the participants so that they can clear their schedules
B)Depending on the nature of the test, it might make sense to create a surprise test
C)All tests should be surprise tests - this will best simulate a real crisis
D)It does not matter whether the test is a surprise or planned since the results will be the same either way
Question
The Crisis Management team must consist of members from Human Resources.
Question
Which types of businesses should develop a Business Continuity Plan? (Select all that apply.)

A)Public companies
B)Private companies
C)Large companies
D)Small companies
Question
How should the costs associated with a Business Continuity Plan be managed? (Select all that apply.)

A)The BCP should be created and implemented regardless of the costs
B)The BCP should have a budget which is approved by senior management
C)Individual items in the BCP should be financially justified
D)A BCP should be written so that it takes no money to execute
Question
The personnel who are responsible for creating the Business Continuity Plan should _________ that role.

A)volunteer for
B)be assigned to
Question
What is the best definition for "alternate worksite"?

A)A work location that is rarely used
B)A work location to supplement the primary work location when it is full or occupied
C)A work location which can be used when the primary work location is not available
D)A work location which is located in a different state or country than the primary work location
Question
What does BIA stand for?

A)Business Intent Analysis
B)Business Impact Analysis
C)Business Instruction Arguments
D)Beneficial Impact Actions
Question
The crisis contact list should include:

A)All team members and key players
B)All employees
C)Senior management
D)All external vendors
Question
Which of these is not an example of a crisis?

A)A hurricane hits a manufacturing facility
B)A bomb threat is made to a facility next to your company
C)An employee who has worked with the company for six months threatens to quit
D)The company CEO is accused of illegal activities
Question
What is the definition of a critical function?

A)A business function that is so critical, it cannot be disrupted for more than a couple hours without severe business impacts
B)A business function or process that cannot be disabled for more than a couple business days, without it having a negative impact on the organization
C)A function or role within the organization which is irreplaceable
D)A function that is managed by the Crisis Management Team
Question
What are considered "critical records"? (Select all that apply.)

A)Any record that contains confidential, secure company information
B)Any record that contains personal information
C)Any record that would cause considerable inconvenience if lost or destroyed
D)Any record that would be expensive to replace
Question
What is the term used to describe the process of assessing the number of injuries and amount of property destruction?

A)Risk assessment
B)Damage assessment
C)Disaster recovery
D)Mitigation planning
Question
An evacuation must be orderly, phased, and structured.
Question
Which term is best describes the process used to lessen or reduce the impact of a crisis?

A)Risk Assessment
B)Recovery
C)Prevention
D)Mitigation
Question
Assigning accountability for the Business Continuity Plan is part of which step?

A)Recovery
B)Readiness
C)Prevention
D)Evaluation
Question
What is a secondary risk?

A)A risk that is not that important
B)Residual risk
C)Force majeure
D)Risk that is highly unlikely to occur
E)Risk caused by another risk response strategy
Question
Which term is used to describe the process of returning an organization to its normal state after a crisis?

A)Recovery
B)Resumption
C)Readiness
D)Evaluation
Question
An organization has identified that the recovery time objective (RTO) criteria as the most critical criteria for its risk management strategy. The company might consider investing in which of the following?

A)Insurance
B)Hot site
C)Cold site.
D)Warranty
Question
A mitigation plan for which of the following risks is not possible:

A)Terrorist event like 9/11
B)Swine flu pandemic
C)Category 5 Hurricane
D)Death of all board members
E)None of the above
Question
Which of these terms describes the process of securing people in an area where the crisis has occurred?

A)Primary location
B)Offsite storage
C)Alternative worksite
D)Shelter in place
Question
Which of the following exercise types is the closest example to a case study?

A)Simulation
B)Full scale
C)Tabletop
D)Orientation
Question
Mr. Newbie receives a call from the local newspaper asking him details about a recent crisis that occurred at his organization, the Sugarfoot company. What should he do?

A)Answer the media's questions
B)Ignore the media's phone calls
C)Tell the media that he can't discuss the crisis
D)Refer the media to the company spokesperson for the crisis
Question
Risk management should include legal risks as well as other types.
Question
Strategic planning can help __________ the risks to the organization.

A)Mitigate
B)Recover
C)Eliminate
D)Ameliorate
Question
Human resources department is responsible for driving accountability for the Business Continuity Plan.
Question
Jerry was in the midst of assessing risk for his project at a well-known real estate firm, when the stock market collapsed that sent shockwaves through his company and his project. The market crashing can be classified as what type of risk:

A)Foreseeable
B)Internal
C)Technical
D)External
E)Redoubtable
Question
Julie has decided to gather opinions from a group of external consultants, via a short questionnaire, who are experienced with these types of projects within the publishing industry. She'll then show them an aggregated list of the whole group's answers, and ask them if they want to change theirs.
What best describes the technique Julie is utilizing to gather valuable information for her project?

A)Root cause analysis
B)Interviewing
C)Delphi technique
D)Brainstorming
Question
What is Pareto's Law?

A)80% of the effects come from 20% of the causes
B)Work expands so as to fill the time available for its completion.
C)Anything that can go wrong will go wrong.
D)Never attribute to malice that which can be adequately explained by stupidity.
Question
Testing is necessary to keeps teams and employees efficient in their business continuity roles. Which of the following is not a typical role in a BCP exercise?

A)Controller
B)Observer
C)Trainer
D)Simulator
E)Facilitator
Question
A BCP should be regularly reviewed and evaluated. While this should occur on a set schedule, it should also be considered when certain trigger events occur. Which of the following qualify as event triggers?

A)BCP testing results
B)New systems implementation
C)Company reorganization
D)New regulatory requirements
E)All of the above
Question
In which professional practice does a BCP professional identify alternative facility and offsite requirements?

A)Prepare and Present the BIA Report to Management
B)Identify and Review Enterprise Business Continuity Strategy Requirements
C)Identify and Review Existing Enterprise Response Procedures
D)Identify the Process to Support the Plan
E)Design Framework for Plan Development
Question
When developing business continuity unit strategies, you should take into consideration which of the following:

A)Personnel
B)Raw materials
C)Telecom
D)Timeframes
E)All of the above
Question
In which business continuity practice do you train representatives of the organization's major areas as part of a readiness task?

A)Plan and Coordinate Data Gathering and Analysis
B)Obtain Information about the Organization's Risk Tolerance from Management
C)Oversee the Ongoing Effectiveness of the Program
D)Identify Functional Awareness and Training Requirements
E)Identify and Review Enterprise Business Continuity Strategy Requirements
Question
At what point in the business continuity process is it prudent to review any existing leasehold agreements?

A)When developing the actual business continuity plan
B)Prior to developing a business continuity program budget
C)During the business impact analysis
D)During the periodic review of the business continuity plan
E)When performing the risk assessment
Question
Which of the following is a useful strategy for BCP planning?

A)Utilize distributed processing
B)Eliminate any affected product(s)
C)Declare bankruptcy
D)Dump inventory into ocean
Question
At what point in the business continuity planning process do you research regulatory needs and restrictions?

A)During the business impact analysis
B)When recommending business continuity strategies
C)During program initiation
D)As part of the risk assessment
E)When designing the framework for the BCP development
Question
Data collection is an extremely important part of the business planning analysis process. Which of the following are typical methods to acquire data?

A)Workshops
B)Interviews
C)Questionnaires
D)All of the above
E)None of the above
Question
Many of the skills needed to succeed as a business continuity professional are essential project management skills. Which BCP practice sums up this project management component?

A)Identify the process to support the plan
B)Coordinate emergency management with external agencies
C)Coordinate and manage the implementation of the overall program
D)Prepare and present the BIA report to management
E)Establish a business continuity audit process
Question
There are different types of exercises that can be conducted during BCP testing. Which type provides the benefit of evaluating operational capabilities in an interactive manner?

A)Functional
B)Full-Scale
C)Tabletop
D)Orientation
E)Procedural
Question
Protecting assets in the general vicinity in which a crisis occurs is known as:

A)Local asset protection
B)Controlled asset protection
C)Shelter-in-place
D)Normalized asset preservation
E)Shelter nearby
Question
Mutual aid agreements identify resources that may be borrowed from other organizations during a crisis. They also define mutual support that may be shared between different aspects of an organization or between organizations. From a process perspective, mutual aid agreements are considered to be a part of which larger task?

A)Assign accountability
B)Resource management
C)Crisis management and response team development
D)Assess the situation
E)Agree on strategic plans
Question
You are setting the recovery objectives for the BCP. You are now working on the prioritization of business processes. In addition to the order of recovery, what else must you consider?

A)Replacement costs
B)The business impact analysis
C)Interdependencies between business and technology processes
D)Alternative business continuity strategies
E)None of the above
Question
Crisis management is an important aspect of good government functioning. The main purpose of planning for crises is to help people overcome the normalcy bias. What is the normalcy bias?

A)a cognitive bias whereby people refuse to act normal in public during a crisis
B)a cognitive bias against normal or average people when facing a crisis
C)a cognitive bias that makes people refuse to plan for a crisis that has never happened
D)a cognitive bias that makes people refuse to plan for a crisis that has happened
Unlock Deck
Sign up to unlock the cards in this deck!
Unlock Deck
Unlock Deck
1/75
auto play flashcards
Play
simple tutorial
Full screen (f)
exit full mode
Deck 1: Certified Business Continuity Professional
1
Which of the following are required to be a part of the Crisis Management Center? (Select all that apply.)

A)Emergency electrical generator
B)Telephone access
C)State of the art computer systems
D)Access control measures
Emergency electrical generator
Telephone access
Access control measures
2
Mr) Indecisive has been given the task of ensuring that critical papers and records that are required to operate the business are available in the event of a crisis. What advice should you give him to help him determine how to complete this task?

A)Save electronic backup copies of all documents
B)Keep multiple copies of the documents in different areas of the building
C)Set up a fire-proof safe in the building to store the documents
D)Set up an off-site storage to store the documents
Set up an off-site storage to store the documents
3
Damage and Impact Assessment is part of which stage of the Business Continuity Plan?

A)Readiness
B)Prevention
C)Response
D)Recovery and Resumption
Recovery and Resumption
4
How would you explain the purpose of the Recovery and Resumption phase of the Business Continuity Plan to a new hire in your organization, such as Mr. Newbie?

A)It is the process of responding when a crisis happens
B)It is the process of bringing the organization out of the crisis and returning it to normal operations
C)It is the process of cleaning up after a crisis has occurred
D)It is the process of identifying the root cause for the crisis and preventing it from reoccurring
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
5
Which of these should be included in the Damage and Impact Assessment immediately after a crisis? (Select all that apply.)

A)Physical damage to the facility
B)Financial cost of all damages
C)Potential long term reputation damages
D)None of the above
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
6
When planning and implementing recovery/resumption procedures, what is the most important aspect?

A)That work proceed as quickly as possible
B)That business proceed as normal regardless of the cost
C)That each Crisis Team member is contacted prior to work beginning
D)That all decisions are document with justification
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
7
When is a crisis normally declared "over"?

A)When the business is no longer under continued threat from the crisis
B)When the business has a plan to implement to recover from the crisis
C)When the business is able to function with its core processes up and running
D)When the business is able to operate as it was pre-crisis
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
8
Which of these tasks are appropriate tasks for declaring a crisis to be "over"? (Select all that apply.)

A)Holding a press conference
B)Sending communication to employees
C)Documenting the decision
D)None of the above
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
9
Mr) Indecisive wants to return the organization back to its normal, pre-crisis state. However, he is unable to do this as a result of the impact of the crisis. What should he do instead?

A)Continue to try to achieve pre-crisis normal state regardless of the cost
B)Declare the organization failed and file for bankruptcy
C)Declare a "new normal" state for the organization to operate in
D)Continue to react in crisis mode indefinitely
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
10
Which of these best describes the Business Continuity Plan?

A)It should be reviewed on a yearly basis
B)It should be a living document that is constantly updated and renewed
C)Once created, the BCP does not need additional reviews
D)A new BCP needs to be created each time something in the organization changes
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
11
Mr) Indecisive is unsure of who should be trained on the new Business Continuity Plan that was developed. What should you recommend to him?

A)Only Crisis Team members should be trained
B)Only Business Continuity team members should be trained
C)Only those who play a part in the Business Continuity Plan implementation should be trained
D)Every employee should be trained
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
12
How often is it recommended for the Crisis and Response teams to be trained on the Business Continuity Plan?

A)Monthly
B)Annually
C)Every two years
D)Only when a significant change occurs
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
13
Management has set the recovery time objective (RTO) to 24 hours for Joe's process. What does this mean?

A)Joe's people must be in the office performing the process 24 hours after a disaster or disruption.
B)Joe has 24 hours to decide what to do in event of an emergency.
C)No more than 24 hours of data can be lost.
D)All data related to the process must be recovered within 24 hours.
E)Joe's process must be restored after 24 hours.
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
14
Mr) Newbie has recently joined the Crisis Management team as part of his work on the Business Continuity Plan. When should he schedule his training on the current version of the Business Continuity Plan?

A)As soon as possible
B)During the next regularly scheduled training session
C)Official training is not needed
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
15
What documentation is recommended for use when training the Crisis Management and Response teams on the BCP? (Select all that apply.)

A)The Business Continuity Plan itself
B)Checklists of critical actions for the teams
C)Explanation of responsibilities
D)None of the above
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
16
External resources such as Fire and Public Health officials should not be trained in portions of the company's Business Continuity Plan.
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
17
Why should testing be a key component of a successful Business Continuity Plan?

A)Because it is a regulatory mandate
B)Because it will improve the effectiveness of the BCP implementation during a crisis
C)Because senior management requires it
D)Testing is not a key component to BCP success
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
18
What should be the first step in testing the Business Continuity Plan?

A)Assigning responsibility for the testing
B)Schedule testing date and time
C)Establishing test goals and expectations
D)Define the scope of the test
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
19
When developing test scope, which recommendation should be followed?

A)Test the entire BCP immediately to determine outages and then focus on those outages with subsequent tests
B)Pick the most likely aspects of the BCP to fail and test those first
C)Begin the testing with small, simple tests and then based on the results of those tests, increase scope accordingly
D)Testing should be randomized to provide accurate results
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
20
When monitoring the testing of the Business Continuity Plan strategies, which of the following strategies is the ideal method for monitoring the test?

A)No test monitoring is needed
B)Participant feedback at the end of the test
C)Official observers notes about the test
D)Video or audio recording equipment
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
21
BCP testing scenarios should be designed using input from the _______________ .

A)Risk Assessment
B)Damage and Impact Assessment
C)Business Impact Analysis
D)Mitigation Plan
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
22
A risk trigger is what triggers a contingency response.
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
23
Which of these test exercises should be completed first?

A)Functional
B)Tabletop
C)Orientation
D)Full Scale
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
24
Which of these testing types is a practical or simulated exercise and takes approximately 2 - 4 hours to complete?

A)Orientation
B)Full Scale
C)Functional
D)Tabletop
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
25
Which of these testing types will allow the participants to make decisions and respond in real time to learn the consequences of those decisions and its impact on other participants in the test?

A)Full Scale
B)Orientation
C)Functional
D)Tabletop
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
26
Which of these testing types does not require a debriefing period after the test scenario? (Select all that apply.)

A)Orientation
B)Tabletop
C)Functional
D)Full Scale
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
27
Which of these testing types will provide the most feedback and information on whether the Business Continuity Plan will be implemented successfully in the event of an actual crisis?

A)Orientation
B)Functional
C)Tabletop
D)Full Scale
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
28
In testing scenarios, there are different roles. Which of these roles acts to add realism to the scenario?

A)Facilitator
B)Controller
C)Simulator
D)Observer
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
29
Who is responsible for helping to eliminate safety and property damage issues during a testing scenario?

A)Facilitator
B)Controller
C)Simulator
D)Observer
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
30
Which of these testing scenario roles would include the role of Crisis Management team leader during a testing exercise?

A)Participant
B)Controller
C)Simulator
D)Observer
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
31
Which of these roles is intended to evaluate the actions of the participants and the overall effectiveness of the Business Continuity Plan?

A)Facilitator
B)Controller
C)Simulator
D)Observer
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
32
Developing a Business Continuity Plan review schedule is part of which stage of BCP planning?

A)Readiness
B)Prevention
C)Response
D)Evaluation and Maintenance
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
33
Mr) Indecisive is in charge of the testing phase of the Business Continuity Plan. He is debating whether or not he should schedule his test ahead of time with the participants or create a surprise test instead. What advice should you give him?

A)All tests should be previously scheduled with the participants so that they can clear their schedules
B)Depending on the nature of the test, it might make sense to create a surprise test
C)All tests should be surprise tests - this will best simulate a real crisis
D)It does not matter whether the test is a surprise or planned since the results will be the same either way
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
34
The Crisis Management team must consist of members from Human Resources.
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
35
Which types of businesses should develop a Business Continuity Plan? (Select all that apply.)

A)Public companies
B)Private companies
C)Large companies
D)Small companies
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
36
How should the costs associated with a Business Continuity Plan be managed? (Select all that apply.)

A)The BCP should be created and implemented regardless of the costs
B)The BCP should have a budget which is approved by senior management
C)Individual items in the BCP should be financially justified
D)A BCP should be written so that it takes no money to execute
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
37
The personnel who are responsible for creating the Business Continuity Plan should _________ that role.

A)volunteer for
B)be assigned to
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
38
What is the best definition for "alternate worksite"?

A)A work location that is rarely used
B)A work location to supplement the primary work location when it is full or occupied
C)A work location which can be used when the primary work location is not available
D)A work location which is located in a different state or country than the primary work location
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
39
What does BIA stand for?

A)Business Intent Analysis
B)Business Impact Analysis
C)Business Instruction Arguments
D)Beneficial Impact Actions
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
40
The crisis contact list should include:

A)All team members and key players
B)All employees
C)Senior management
D)All external vendors
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
41
Which of these is not an example of a crisis?

A)A hurricane hits a manufacturing facility
B)A bomb threat is made to a facility next to your company
C)An employee who has worked with the company for six months threatens to quit
D)The company CEO is accused of illegal activities
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
42
What is the definition of a critical function?

A)A business function that is so critical, it cannot be disrupted for more than a couple hours without severe business impacts
B)A business function or process that cannot be disabled for more than a couple business days, without it having a negative impact on the organization
C)A function or role within the organization which is irreplaceable
D)A function that is managed by the Crisis Management Team
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
43
What are considered "critical records"? (Select all that apply.)

A)Any record that contains confidential, secure company information
B)Any record that contains personal information
C)Any record that would cause considerable inconvenience if lost or destroyed
D)Any record that would be expensive to replace
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
44
What is the term used to describe the process of assessing the number of injuries and amount of property destruction?

A)Risk assessment
B)Damage assessment
C)Disaster recovery
D)Mitigation planning
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
45
An evacuation must be orderly, phased, and structured.
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
46
Which term is best describes the process used to lessen or reduce the impact of a crisis?

A)Risk Assessment
B)Recovery
C)Prevention
D)Mitigation
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
47
Assigning accountability for the Business Continuity Plan is part of which step?

A)Recovery
B)Readiness
C)Prevention
D)Evaluation
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
48
What is a secondary risk?

A)A risk that is not that important
B)Residual risk
C)Force majeure
D)Risk that is highly unlikely to occur
E)Risk caused by another risk response strategy
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
49
Which term is used to describe the process of returning an organization to its normal state after a crisis?

A)Recovery
B)Resumption
C)Readiness
D)Evaluation
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
50
An organization has identified that the recovery time objective (RTO) criteria as the most critical criteria for its risk management strategy. The company might consider investing in which of the following?

A)Insurance
B)Hot site
C)Cold site.
D)Warranty
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
51
A mitigation plan for which of the following risks is not possible:

A)Terrorist event like 9/11
B)Swine flu pandemic
C)Category 5 Hurricane
D)Death of all board members
E)None of the above
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
52
Which of these terms describes the process of securing people in an area where the crisis has occurred?

A)Primary location
B)Offsite storage
C)Alternative worksite
D)Shelter in place
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
53
Which of the following exercise types is the closest example to a case study?

A)Simulation
B)Full scale
C)Tabletop
D)Orientation
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
54
Mr. Newbie receives a call from the local newspaper asking him details about a recent crisis that occurred at his organization, the Sugarfoot company. What should he do?

A)Answer the media's questions
B)Ignore the media's phone calls
C)Tell the media that he can't discuss the crisis
D)Refer the media to the company spokesperson for the crisis
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
55
Risk management should include legal risks as well as other types.
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
56
Strategic planning can help __________ the risks to the organization.

A)Mitigate
B)Recover
C)Eliminate
D)Ameliorate
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
57
Human resources department is responsible for driving accountability for the Business Continuity Plan.
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
58
Jerry was in the midst of assessing risk for his project at a well-known real estate firm, when the stock market collapsed that sent shockwaves through his company and his project. The market crashing can be classified as what type of risk:

A)Foreseeable
B)Internal
C)Technical
D)External
E)Redoubtable
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
59
Julie has decided to gather opinions from a group of external consultants, via a short questionnaire, who are experienced with these types of projects within the publishing industry. She'll then show them an aggregated list of the whole group's answers, and ask them if they want to change theirs.
What best describes the technique Julie is utilizing to gather valuable information for her project?

A)Root cause analysis
B)Interviewing
C)Delphi technique
D)Brainstorming
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
60
What is Pareto's Law?

A)80% of the effects come from 20% of the causes
B)Work expands so as to fill the time available for its completion.
C)Anything that can go wrong will go wrong.
D)Never attribute to malice that which can be adequately explained by stupidity.
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
61
Testing is necessary to keeps teams and employees efficient in their business continuity roles. Which of the following is not a typical role in a BCP exercise?

A)Controller
B)Observer
C)Trainer
D)Simulator
E)Facilitator
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
62
A BCP should be regularly reviewed and evaluated. While this should occur on a set schedule, it should also be considered when certain trigger events occur. Which of the following qualify as event triggers?

A)BCP testing results
B)New systems implementation
C)Company reorganization
D)New regulatory requirements
E)All of the above
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
63
In which professional practice does a BCP professional identify alternative facility and offsite requirements?

A)Prepare and Present the BIA Report to Management
B)Identify and Review Enterprise Business Continuity Strategy Requirements
C)Identify and Review Existing Enterprise Response Procedures
D)Identify the Process to Support the Plan
E)Design Framework for Plan Development
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
64
When developing business continuity unit strategies, you should take into consideration which of the following:

A)Personnel
B)Raw materials
C)Telecom
D)Timeframes
E)All of the above
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
65
In which business continuity practice do you train representatives of the organization's major areas as part of a readiness task?

A)Plan and Coordinate Data Gathering and Analysis
B)Obtain Information about the Organization's Risk Tolerance from Management
C)Oversee the Ongoing Effectiveness of the Program
D)Identify Functional Awareness and Training Requirements
E)Identify and Review Enterprise Business Continuity Strategy Requirements
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
66
At what point in the business continuity process is it prudent to review any existing leasehold agreements?

A)When developing the actual business continuity plan
B)Prior to developing a business continuity program budget
C)During the business impact analysis
D)During the periodic review of the business continuity plan
E)When performing the risk assessment
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
67
Which of the following is a useful strategy for BCP planning?

A)Utilize distributed processing
B)Eliminate any affected product(s)
C)Declare bankruptcy
D)Dump inventory into ocean
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
68
At what point in the business continuity planning process do you research regulatory needs and restrictions?

A)During the business impact analysis
B)When recommending business continuity strategies
C)During program initiation
D)As part of the risk assessment
E)When designing the framework for the BCP development
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
69
Data collection is an extremely important part of the business planning analysis process. Which of the following are typical methods to acquire data?

A)Workshops
B)Interviews
C)Questionnaires
D)All of the above
E)None of the above
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
70
Many of the skills needed to succeed as a business continuity professional are essential project management skills. Which BCP practice sums up this project management component?

A)Identify the process to support the plan
B)Coordinate emergency management with external agencies
C)Coordinate and manage the implementation of the overall program
D)Prepare and present the BIA report to management
E)Establish a business continuity audit process
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
71
There are different types of exercises that can be conducted during BCP testing. Which type provides the benefit of evaluating operational capabilities in an interactive manner?

A)Functional
B)Full-Scale
C)Tabletop
D)Orientation
E)Procedural
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
72
Protecting assets in the general vicinity in which a crisis occurs is known as:

A)Local asset protection
B)Controlled asset protection
C)Shelter-in-place
D)Normalized asset preservation
E)Shelter nearby
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
73
Mutual aid agreements identify resources that may be borrowed from other organizations during a crisis. They also define mutual support that may be shared between different aspects of an organization or between organizations. From a process perspective, mutual aid agreements are considered to be a part of which larger task?

A)Assign accountability
B)Resource management
C)Crisis management and response team development
D)Assess the situation
E)Agree on strategic plans
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
74
You are setting the recovery objectives for the BCP. You are now working on the prioritization of business processes. In addition to the order of recovery, what else must you consider?

A)Replacement costs
B)The business impact analysis
C)Interdependencies between business and technology processes
D)Alternative business continuity strategies
E)None of the above
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
75
Crisis management is an important aspect of good government functioning. The main purpose of planning for crises is to help people overcome the normalcy bias. What is the normalcy bias?

A)a cognitive bias whereby people refuse to act normal in public during a crisis
B)a cognitive bias against normal or average people when facing a crisis
C)a cognitive bias that makes people refuse to plan for a crisis that has never happened
D)a cognitive bias that makes people refuse to plan for a crisis that has happened
Unlock Deck
Unlock for access to all 75 flashcards in this deck.
Unlock Deck
k this deck
locked card icon
Unlock Deck
Unlock for access to all 75 flashcards in this deck.