712-50 exam dumps

712-50 practice question 276 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 276

Single answerDisaster Recovery and Business Continuity Planning (5 questions)

A global manufacturing company is updating its disaster recovery (DR) and business continuity plans after a ransomware incident disrupted its ERP platform for 36 hours. The board has now mandated that the company must be able to resume order processing within 8 hours of a major outage and lose no more than 30 minutes of transaction data. The CISO learns that the current DR strategy relies on nightly backups stored offsite and a recovery procedure that has only been tabletop tested. Budget is limited, so the organization cannot fully redesign every system this year. Which action should the CISO prioritize FIRST to align recovery capabilities with business requirements?

  1. A

    Conduct a business impact analysis (BIA) refresh and map the ERP system's recovery time objective (RTO) and recovery point objective (RPO) to technical recovery capabilities, then remediate the highest-risk gap

  2. B

    Increase the frequency of offsite backups from nightly to every four hours and defer broader continuity planning until next year's budget cycle

  3. C

    Schedule a full-scale disaster recovery exercise for the ERP environment immediately, using the current backup and recovery architecture to validate the existing plan

  4. D

    Purchase cyber insurance with business interruption coverage to offset future ERP downtime while maintaining the current recovery design

Show answer and explanation

Correct answer: A

Explanation

The best answer is to begin with a refreshed business impact analysis and capability mapping because DR and BCP must be driven by business requirements, especially RTO and RPO. In this scenario, the current control set clearly cannot meet the stated objectives: nightly backups exceed the allowable data loss threshold, and untested procedures create uncertainty around recovery time. A CISO should first validate critical business processes, dependencies, and impact tolerances, then compare them to current recovery architecture and procedures to identify the highest-risk gaps for targeted remediation.

This approach is consistent with widely accepted continuity and resilience practices, including NIST SP 800-34 Rev. 1 (Contingency Planning Guide for Federal Information Systems), which emphasizes business impact analysis as foundational to recovery strategy selection, and ISO 22301, which requires organizations to determine continuity requirements and implement solutions based on prioritized activities. From a CCISO perspective, the key leadership decision is not merely selecting a technical fix, but ensuring scarce resources are allocated according to business impact and measurable recovery objectives.

  • A. Correct.

    Correct. The scenario shows a clear mismatch between business requirements and current recovery capabilities: an 8-hour RTO and 30-minute RPO cannot be met with nightly backups and unproven recovery procedures. The CISO should first ensure that business requirements are formally validated through an updated BIA and then map those requirements to actual technical capabilities. This establishes the gap between needed and current performance and allows limited budget to be directed to the most critical remediation. In executive leadership roles such as CCISO, prioritization based on business impact is essential before selecting controls or testing approaches.

  • B. Incorrect.

    Incorrect. Increasing backup frequency may help reduce data loss, but it does not by itself address the full requirement. A four-hour backup interval still does not meet a 30-minute RPO, and backups alone do not ensure the organization can restore ERP order processing within 8 hours. This option reflects a common misconception that backup improvements alone equal disaster recovery readiness. DR and BCP require alignment to validated business requirements, not just incremental changes to one control.

  • C. Incorrect.

    Incorrect. Testing is important, and a full-scale exercise can reveal operational issues, but performing it immediately against an architecture already known to be inadequate is not the best first step. Since the current solution likely cannot satisfy the required RTO and RPO, the organization should first confirm priorities and identify capability gaps. Otherwise, the exercise may consume resources without producing a roadmap that aligns investment to business need. Testing should validate a strategy, not substitute for one.

  • D. Incorrect.

    Incorrect. Cyber insurance can provide financial support after an incident, but it does not improve operational resilience, reduce RTO, or reduce RPO. Insurance is a risk transfer mechanism, not a recovery capability. This option may appeal to leaders focused on financial mitigation, but the board's mandate is about restoring business operations within defined tolerances, which requires continuity and recovery planning improvements.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam