Business Continuity, Disaster Recovery & Incident Response Concepts

Worth 10% of the ISC2 Certified in Cybersecurity (CC) exam. CertClue has 40 questions on this objective.

What this objective covers

Incident Response Roles and Communication

A plan only works if people know their part and can reach each other. CC tests who does what and why communication is planned in advance.

Exam tip. Never discuss an incident over channels that may be compromised. That is what out-of-band means.

Evidence Handling and Chain of Custody

If an incident may lead to legal or disciplinary action, how evidence is handled determines whether it can be used at all.

Exam tip. Powering a suspect machine off or on can destroy volatile evidence. Capture memory before considering it.

Business Continuity vs Disaster Recovery

These two disciplines are related but distinct, and the exam tests the boundary. Business continuity is the wider of the two and is not purely an IT concern.

Exam tip. The BIA always comes first. You cannot set a recovery objective before knowing what is critical.

RTO, RPO and Recovery Site Types

Two metrics drive every recovery decision, and each drives a different design choice. Confusing them is one of the most common errors on this exam.

Exam tip. An RPO of four hours means backing up at least every four hours. Match the site type to the RTO.

The Incident Response Lifecycle

The phases are tested in order, and questions frequently place you mid-process and ask what comes next. Only the first phase happens before an incident.

Exam tip. Containment always comes before eradication. You stop the bleeding before removing the cause.

Backup Strategy and the 3-2-1 Rule

Backups are the last line of defence and the primary answer to ransomware. Know the restore requirements of each scheme and why one copy must be unreachable from the network.

Exam tip. Incremental needs the whole chain; differential needs just two sets. This is asked directly.

Redundancy, High Availability and Single Points of Failure

Availability is engineered, not hoped for. These are the mechanisms CC expects you to recognise and the failure they each remove.

Exam tip. RAID is never the answer to accidental deletion or ransomware. Only backups address those.

Recovery Testing and Plan Maintenance

An untested plan is an assumption. CC expects you to know the test types in order of rigour and why plans must be revisited.

Exam tip. Rigour and disruption rise together. Choose the least disruptive test that still answers the question being asked.

Practice questions

Free, with the answer and the reasoning. No account needed.

1. Which phase of the incident response lifecycle involves establishing the team, tools and communication plan before any incident occurs?

  • A. Detection and analysis
  • B. Containment
  • C. Post-incident activity
  • D. Preparationcorrect

Preparation happens in advance and covers building the team, defining procedures, and deploying the tooling and communication channels response will depend on. The remaining phases occur once an incident is under way or concluded.

Work the whole objective

The full ISC2 Certified in Cybersecurity bank, the study notes behind these summaries, and a readiness score that tells you which objective to revise next. Free, no paid tier.

Take the free ISC2 Certified in Cybersecurity practice test

The other ISC2 Certified in Cybersecurity objectives