BCLE 2000 ALL QUESTIONS AND ANSWERS SURE
A+
✔✔Which of the following would be considered an external risk factor?
a. Supply chain for goods and services
b. Disgruntled employees
c. Employee drug screening
d. Clean desk policy procedures - ✔✔A
✔✔Which of the following would be considered a control?
a. Loss of access to facilities
b. A tornado
c. Lack of fire suppression systems
d. UPS/generators - ✔✔D
✔✔Determining cyber threats to the entity is part of the:
a. Business continuity plan
b. Disaster recovery plan
c. Business impact analysis
d. Risk assessment - ✔✔D
, ✔✔Which of the following is an objective of a business impact analysis?
a. To calculate the probability of disruptions to the entity
b. To evaluate the effectiveness of existing controls and safeguards
c. To identify and prioritize the recovery of an entity's functions and processes
d. To develop preparations and procedures for responding to a disaster - ✔✔C
✔✔Which of the following is an example of a qualitative impact? a. Loss of sales
b. Loss of reputation
c. Loss of revenue due to penalties
d. Extra expense - ✔✔B
✔✔Which of the following is an example of a quantitative impact?
a. Lower level of customer service
b. A disruption of quality assurance
c. Loss of sales
d. Lower employee morale - ✔✔C
✔✔Which of the following is NOT a result of conducting a business impact analysis?
a. Identifies all essential entity functions and operations and their critical dependencies
b. Determines when the exposures and impacts begin and how they escalate over time
c. Identifies the technology and workspace needs as well as potential unbudgeted
expenses
d. Identifies threats from sabotage and/or terrorism and how to reduce those threats
using cost-effective controls - ✔✔D
✔✔Data gaps occur:
a. When the system data is current
b. During a data restoration, when the system data has been fully backed up
A+
✔✔Which of the following would be considered an external risk factor?
a. Supply chain for goods and services
b. Disgruntled employees
c. Employee drug screening
d. Clean desk policy procedures - ✔✔A
✔✔Which of the following would be considered a control?
a. Loss of access to facilities
b. A tornado
c. Lack of fire suppression systems
d. UPS/generators - ✔✔D
✔✔Determining cyber threats to the entity is part of the:
a. Business continuity plan
b. Disaster recovery plan
c. Business impact analysis
d. Risk assessment - ✔✔D
, ✔✔Which of the following is an objective of a business impact analysis?
a. To calculate the probability of disruptions to the entity
b. To evaluate the effectiveness of existing controls and safeguards
c. To identify and prioritize the recovery of an entity's functions and processes
d. To develop preparations and procedures for responding to a disaster - ✔✔C
✔✔Which of the following is an example of a qualitative impact? a. Loss of sales
b. Loss of reputation
c. Loss of revenue due to penalties
d. Extra expense - ✔✔B
✔✔Which of the following is an example of a quantitative impact?
a. Lower level of customer service
b. A disruption of quality assurance
c. Loss of sales
d. Lower employee morale - ✔✔C
✔✔Which of the following is NOT a result of conducting a business impact analysis?
a. Identifies all essential entity functions and operations and their critical dependencies
b. Determines when the exposures and impacts begin and how they escalate over time
c. Identifies the technology and workspace needs as well as potential unbudgeted
expenses
d. Identifies threats from sabotage and/or terrorism and how to reduce those threats
using cost-effective controls - ✔✔D
✔✔Data gaps occur:
a. When the system data is current
b. During a data restoration, when the system data has been fully backed up