CompTIA Security+ (SY0-701)Security Program Management and OversightMedium
A company wants to determine which business processes are most critical to resume first after a disruption, along with the maximum acceptable downtime for each. Which activity should the company perform?
- APenetration test
- BBusiness Impact Analysis (BIA)
- CVulnerability assessment
- DTabletop exercise
Show answer & explanationAnswer & explanation
Correct answer: B. Business Impact Analysis (BIA)
A Business Impact Analysis (BIA) identifies critical business functions, their dependencies, and metrics such as Recovery Time Objective (RTO) and Maximum Tolerable Downtime (MTD), enabling prioritization of recovery efforts.
Why the other options are wrong
- A. A penetration test evaluates exploitability of security controls, unrelated to downtime tolerance.
- C. A vulnerability assessment identifies technical weaknesses, not business process priority.
- D. A tabletop exercise tests response plans through discussion, but does not itself determine criticality metrics.
Business Impact Analysis (BIA)
A process that identifies and evaluates the potential effects of disruptions to critical business operations, establishing priorities like RTO and MTD.
- Outputs include Recovery Time Objective (RTO) and Recovery Point Objective (RPO)
- Forms the foundation for business continuity and disaster recovery planning
- Focuses on business processes, not technical vulnerabilities
Memory trick: BIA = 'Before Impact, Analyze' priorities and downtime limits