Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which of the following statements about an Activity Business Impact Analysis (BIA) is correct?
An Activity Business Impact Analysis (BIA) is a crucial component of the Business Continuity Management System (BCMS) that focuses on identifying and prioritizing the activities within the organization that contribute to delivering critical products and services. According to the CBCI 7.0 course, the Activity BIA maps out which activities are most urgent and vital, and it determines the necessary resources and interdependencies required to maintain or restore these activities following a disruption. This detailed understanding enables the organization to allocate resources effectively and design recovery strategies tailored to priority activities. Unlike a broad process or product BIA, the Activity BIA provides granular insights into operational components, ensuring continuity plans address practical recovery needs and dependencies.
Recovery solutions that support an alternate location strategy for physical infrastructure that can be made available within hours include:
An alternate location strategy for physical infrastructure focuses on providing usable workspace quickly when a primary site is unavailable. Solutions that can be available within hours typically rely on options the organization already controls---such as repurposing internal space (often described in continuity guidance as ''displacement/budge-up,'' using other facilities, or relocating teams into existing sites). This is the most realistic ''hours-scale'' approach because it avoids procurement lead times and complex engineering dependencies.
Option B fits that model precisely: repurposing other work areas and facilities can be activated rapidly with basic logistics (access, seating, connectivity, and prioritization of critical teams).
Option A (working from home) can be a valid continuity strategy, but the question specifies physical infrastructure and an alternate location approach; remote working is not a physical alternate site solution in the same sense. Options C and D typically take longer than hours: ordering/installing equipment and rebuilding/reconnecting utilities involve supply chains, specialist work, and external dependencies. Therefore, B is the best answer.
Which of the following is NOT a reason why it is important for organizations to have effective internal and external communications in place during a crisis?
Effective crisis communications exist to protect people, operations, trust, and reputation by ensuring stakeholders receive timely, accurate, and consistent information. That includes providing vital information to those affected (option A) and giving assurance to interested parties by demonstrating the organization is responding responsibly and transparently (option B). It also helps establish an authoritative ''single source of truth'' to reduce confusion and misinformation (option C), which is a widely used crisis-communications principle and supports coordinated response.
Option D is NOT a valid reason in BC good practice terms. A crisis is not an ethical marketing opportunity; attempting to leverage public attention for new business can damage trust, distract from response priorities, and conflict with the purpose of crisis communication (safety, clarity, confidence, and stakeholder care). Crisis communications frameworks stress planning, rehearsing, and implementing communications to support effective response---not commercial exploitation.
Important note on ''100% verified from CBCI 7.0 course documents'': the official CBCI 7.0 courseware itself is not publicly accessible for me to quote directly, so I verified these answers against official BCI GPG materials and BCI's published PP6/PP2 guidance (which the CBCI exam is based on).
The organization's requirements for information and data resources should be considered as part of the Activity Business Impact Analysis (BIA). Which of the following is correct in relation to the Recovery Point Objective (RPO)?
Recovery Point Objective (RPO) defines the maximum acceptable age of data to be recovered following a disruption, effectively setting the point in time to which information must be restored. The CBCI 7.0 course explains that RPOs vary depending on the priority and criticality of activities, requiring consultation with data users to ensure continuity needs are met accurately. RPOs are crucial for developing backup and data recovery strategies and directly influence the selection of technical solutions. While data protection compliance is necessary, it is not the primary function of RPO. Additionally, RPO focuses on data restoration points, not on the duration IT services can be disrupted---that relates to Recovery Time Objective (RTO).
Which of the following should be included in a post-incident review of a Business Continuity Management System (BCMS)?
In GPG 7.0's Validation practice (PP6), a post-incident review is emphasised as a way to evaluate response and recovery efforts and determine the extent to which ''plans, capabilities, and competencies met the business continuity requirements.'' To do that credibly, the review must capture factual, first-hand evidence from the people who experienced the incident and those who executed the response and recovery---what happened, what decisions were made, what worked, what didn't, and why. That is exactly what option A provides.
Option B shifts the review into blame allocation, which undermines the constructive learning mindset that validation aims to build (identify strengths and improvements positively). Option C contains a desirable outcome (an improvement plan), but the question asks what should be included in the post-incident review itself; without structured input from participants, improvement actions become speculative. Option D (audit reports) can be a useful reference, but it is not the defining content of a post-incident review of actual response/recovery performance.
176 questions covering all exam domains, starting from $20
Exam domains verified against: Official BCI CBCI exam guide, last checked August 2026.
This section lays the groundwork for newcomers to business continuity by clarifying what business continuity is, why it matters in organizational resilience, and how its fundamental practices interconnect under the Good Practice Guidelines (GPG) framework.
This part guides users through establishing a Business Continuity Management System (BCMS), including how to craft governance, define a policy, and embed these elements into the fabric of an organization for long-term sustainability.
This module dives into the analytical stage, focusing on tools such as Business Impact Analysis (BIA) and risk assessment to identify critical functions and vulnerabilities.
Here, learners explore how to translate analysis into strategic plans by developing continuity designs that mitigate identified risks.
Sample question from this domain above: Q2
This section covers putting the designed continuity strategies into action, including creating and deploying incident response and business continuity plans.
Sample question from this domain above: Q3
This final module emphasizes testing and verifying the effectiveness of implemented plans through exercises and reviews, ensuring that what was designed and implemented actually performs as intended under real-world conditions.
Sample question from this domain above: Q5
Common questions about the exam itself