[2025] Use Valid New CBCP-002 Test Notes & CBCP-002 Valid Exam Guide [Q18-Q40]

Share

[2025] Use Valid New CBCP-002 Test Notes & CBCP-002 Valid Exam Guide

CBCP-002 Actual Questions Answers PDF 100% Cover Real Exam Questions


GAQM CBCP-002 (Certified Business Continuity Professional (CBCP)) Certification Exam is designed to test the knowledge and skills of individuals who are involved in business continuity planning and management. Certified Business Continuity Professional (CBCP) certification program is recognized globally and is intended for professionals who are responsible for ensuring that their organizations are prepared to survive and recover from disasters, emergencies, and other disruptions. The CBCP certification is an important credential for individuals who want to demonstrate their expertise in business continuity planning and management.

 

NEW QUESTION # 18
Which type of continuity planning will enhance the functioning relationship with the organization's key suppliers, creating stronger assurances of continuous supply of information, material product and services?

  • A. Unilateral
  • B. Bilateral
  • C. Multilateral

Answer: B

Explanation:
Continuity planning with external stakeholders, such as key suppliers, is essential to ensure the uninterrupted flow of information, materials, products, and services during disruptions. The type of continuity planning determines the nature of the relationship and coordination with these suppliers:
* Multilateral: This involves multiple parties (e.g., an organization and several suppliers or partners) working together in a coordinated plan. While multilateral planning can enhance collaboration across a broad network, it is complex and not specifically tailored to strengthening individual supplier relationships, which is the focus of this question.
* Bilateral: This refers to a two-party agreement or plan between the organization and a specific supplier.
Bilateral continuity planning fosters a direct, functioning relationship with key suppliers, enabling mutual understanding, aligned recovery strategies, and stronger assurances of continuous supply. It is the most effective approach for building robust, one-on-one supplier relationships, as it allows for tailored coordination and commitments.
* Unilateral: This is a one-sided plan where the organization develops its continuity strategy without direct supplier involvement. While it may address internal resilience, it does not enhance the functioning relationship with suppliers or provide assurances of their continuity, making it inadequate for this purpose.
The correct answer isB. Bilateral, as it directly enhances the relationship with key suppliers through mutual planning and coordination, ensuring a continuous supply chain. This aligns with Business Continuity Professional practices that emphasize collaboration with critical external dependencies.
References:
* DRI International Professional Practices for Business Continuity Management (2023), Section 4:
Business Impact Analysis and Risk Assessment - Highlights the importance of engaging key suppliers in continuity planning.
* ISO 22301:2019, Clause 8.2.3 - Emphasizes identifying and managing dependencies, including suppliers, through coordinated planning.


NEW QUESTION # 19
Which statement is authorized at an appropriate level and should codify the company's attitude to a particular risk?

  • A. Process Document
  • B. Policy Statement
  • C. QMS Document
  • D. Privacy Statement

Answer: B

Explanation:
Explanation
A policy statement is a statement that is authorized at an appropriate level and should codify the company's attitude to a particular risk. A policy statement is a document that defines the scope, objectives, principles, roles, and responsibilities of a business continuity management program. It should also express the organization's commitment to managing risks and ensuring continuity of its critical functions and processes. A policy statement should be approved by senior management and communicated to all relevant stakeholders.
Verified References:
https://www.iso.org/publication/PUB100442.htmlhttps://phoenixnap.com/blog/what-is-business-continuity-mana


NEW QUESTION # 20
Which of the following are the four T's of risk guidance produced by by the Office of Government Commerce? (choose four)

  • A. Title
  • B. Tolerate
  • C. Technique
  • D. Transfer
  • E. Treat
  • F. Terminate

Answer: B,D,E,F

Explanation:
Explanation
The four T's of risk guidance produced by the Office of Government Commerce are transfer, tolerate, treat, and terminate. They are:
Transfer: This strategy involves transferring or sharing some or all of the responsibility or impact of a risk to another party, such as an insurer, a supplier, or a partner.
Tolerate: This strategy involves accepting or retaining a risk without taking any further action to reduce it, either because the risk level is acceptable or because the cost or effort of reducing it is not justified.
Treat: This strategy involves taking steps to reduce the likelihood or impact of a risk to an acceptable level, such as implementing controls, mitigations, or contingency plans.
Terminate: This strategy involves eliminating or avoiding a risk by discontinuing or changing the activity that causes it. Verified References: https://www.investopedia.com/terms/t/the-four-ts.asp
https://www.thebci.org/training-qualifications/good-practice-guidelines.html


NEW QUESTION # 21
In the event of a disaster, notification shall be given to each employee by either the HR Department Manager or through the firm's emergency notice system.

  • A. True
  • B. False

Answer: A

Explanation:
In the event of a disaster, notification shall be given to each employee by either the HR Department Manager or through the firm's emergency notice system. This is true because communication is a vital component of any disaster recovery and business continuity plan. Employees need to be informed of the situation, their roles and responsibilities, and the actions they need to take to ensure their safety and the continuity of the business.
The HR Department Manager or the emergency notice system are the designated channels for communicating with employees during a disaster. Verified References: https://www.ready.gov/business-continuity- planhttps://www.csoonline.com/article/515730/business-continuity-and-disaster-recovery-planning-the-basics.
html


NEW QUESTION # 22
BIA stands for

  • A. Business Impact Analysis
  • B. Business Information Availability
  • C. Business Importance and Availability
  • D. Business Improvement Activities

Answer: A

Explanation:
Explanation
Business impact analysis (BIA) is the process of identifying and prioritizing the organization's functions and processes based on their importance to the organization's objectives, and assessing the potential impacts of a disruption to those functions and processes over time. The BIA helps to determine the recovery time objectives (RTOs), recovery point objectives (RPOs), and resource requirements for each function and process, as well as the interdependencies and dependencies among them. The BIA provides the basis for developing recovery strategies and plans. Verified References:
https://www.ready.gov/business-impact-analysishttps://drii.org/resources/professionalpractices/EN


NEW QUESTION # 23
Which of the following four are action approach crisis and post-crisis management? (Choose four R's)

  • A. Rustic
  • B. Recovery
  • C. Reduction
  • D. Rss Feed
  • E. Response
  • F. Readiness

Answer: B,C,E,F

Explanation:
Explanation
The four R's are action approaches for crisis and post-crisis management. They are:
Reduction: This approach aims to prevent or mitigate the occurrence or impact of a crisis by identifying and addressing the root causes, vulnerabilities, and risks.
Readiness: This approach aims to prepare for a potential crisis by developing plans, policies, procedures, systems, teams, and resources that can enable a timely and effective response.
Response: This approach aims to manage a crisis by activating the plans, policies, procedures, systems, teams, and resources that can contain, control, and resolve the situation.
Recovery: This approach aims to restore normal operations after a crisis by implementing actions that can repair damages, restore functions and processes, resume services and products, recover losses, and learn lessons. Verified References:
https://www.cisco.com/c/en/us/solutions/hybrid-work/what-is-business-continuity.html
https://phoenixnap.com/blog/what-is-business-continuity-management


NEW QUESTION # 24
Which of the following should NOT be released in a publicly released BCP?

  • A. Process flows
  • B. BIA results
  • C. Contact lists
  • D. All of the above

Answer: C

Explanation:
In Business Continuity Planning (BCP), confidentiality and security of sensitive information are critical considerations when releasing details publicly. According to standard practices outlined in Business Continuity Professional guidelines, such as those from the Disaster Recovery Institute International (DRI) and ISO 22301, certain elements of a BCP should remain confidential to protect the organization and its stakeholders.
* Process flows: These describe how critical processes are maintained or recovered during a disruption.
While detailed process flows may be sensitive internally, a high-level overview can often be shared publicly to demonstrate preparedness without compromising operational security. Thus, they are not inherently prohibited from public release.
* Contact lists: These contain personal and operational details such as names, phone numbers, and roles of key personnel involved in the BCP. Releasing contact lists publicly poses significant risks, including privacy violations, potential targeting by malicious actors, and operational vulnerabilities. Best practices dictate that contact lists should remain confidential and restricted to authorized personnel only.
* BIA results: The Business Impact Analysis (BIA) identifies critical functions, recovery time objectives (RTOs), and potential impacts of disruptions. While detailed BIA results are sensitive, summary-level findings (e.g., critical processes identified without specific vulnerabilities) can sometimes be shared to show due diligence. However, this is not strictly prohibited in public releases if anonymized or generalized.
* All of the above: Since process flows and BIA results can be released in a controlled, summarized form, this option is incorrect. The key element that should unequivocally not be released is the contact list due to its sensitive nature.
Therefore, the correct answer isB. Contact lists, as it aligns with the principle of protecting sensitive personal and operational data in public disclosures.
References:
* DRI International Professional Practices for Business Continuity Management (2023), Section 6:
Business Continuity Plan Development - Emphasizes safeguarding sensitive data like contact details.
* ISO 22301:2019, Clause 8.4 - Highlights confidentiality in BCP documentation and communication.


NEW QUESTION # 25
Which of the following is a low-pressure exercise that uses presentation techniques including videos, slides, and handouts, so that participants fully understand their plans?

  • A. Single team simulation
  • B. Virtualization
  • C. Facilitated discussion
  • D. Plan walkthrough

Answer: D

Explanation:
A plan walkthrough is a low-pressure exercise that uses presentation techniques including videos, slides and handouts, so that participants fully understand their plans1.


NEW QUESTION # 26
Which type of risk is related to human error or achievement?

  • A. Operational
  • B. Commercial
  • C. Technical
  • D. Strategic

Answer: A

Explanation:
Explanation
Operational risk is the type of risk that is related to human error or achievement. Operational risk is the uncertainty or variability of the execution or outcome of an organization's functions or processes. Operational risk can result from factors such as inadequate policies, procedures, systems, controls, skills, training, supervision, or compliance. Operational risk can affect an organization's operational efficiency, quality, safety, security, reputation, or profitability. Verified References:
https://www.investopedia.com/terms/o/operational_risk.asphttps://www.thebci.org/training-qualifications/good-p


NEW QUESTION # 27
There are several reasons why a company would develop and implement a business continuity plan. Which of the following properly describes the best reason?

  • A. Properly react to disasters
  • B. The continuation of a company
  • C. Compliance with regulations
  • D. To increase liability

Answer: B

Explanation:
Explanation
The primary reason for developing and implementing a business continuity plan is to ensure the continuation of a company's critical functions and processes in the face of a disruption that may otherwise cause severe losses or damage to the company's reputation, assets, customers,or stakeholders. A business continuity plan can help a company to resume operations as quickly as possible after a disruption, minimize the impact on its performance and profitability, protect its brand and image, and fulfill its legal and contractual obligations.
Verified References:
https://www.ready.gov/business-continuity-planhttps://drii.org/resources/professionalpractices/EN


NEW QUESTION # 28
Damage assessment includes all but which of the following steps?

  • A. Having the insurance company declare the total extent of the damages.
  • B. Evaluating the time to restore operations and if greater than the MTD, a disaster should be declared and BCP enacted
  • C. Identifying the affected business functions.
  • D. Estimate the time it will take to restore critical business functions.

Answer: A

Explanation:
Damage assessment is the process of evaluating the extent and severity of the damage caused by a disruption to an organization's facilities, equipment, systems, data, records, or personnel. It includes identifying the affected business functions and processes, estimating the time it will take to restore them to normal or acceptable levels of operation, and evaluating whether the recovery time exceeds the maximum tolerable downtime (MTD) for each function or process. If so, a disaster should be declared and the business continuity plan should be activated. Having the insurance company declare the total extent of the damages is not part of the damage assessment process, as it may take longer than the MTD and may not reflect the operational impact of the damage. Verified References: https://www.fema.gov/pdf/emergency/nims/Damage_Assessment.
pdfhttps://drii.org/resources/professionalpractices/EN


NEW QUESTION # 29
Which type of risk occurs due to volatile environments in which businesses operate and the nature of their operations?

  • A. Quality Risk
  • B. Auditing Risk
  • C. Business Risk
  • D. Project Risk

Answer: C

Explanation:
Business risk is the risk of loss or damage to an organization's performance, reputation, assets, or stakeholders due to internal or external factors that affect its ability to achieve its objectives. Business risk can arise from various sources, such as market conditions, customer preferences, competition, technology, regulation, compliance, operations, finance, human resources, or natural disasters. Business risk can have a direct or indirect impact on an organization's profitability, growth, sustainability, or continuity. Verified References: https://www.investopedia.com/terms/b/businessrisk.asphttps://www.thebci.org/training- qualifications/good-practice-guidelines.html


NEW QUESTION # 30
BIA helps you identify

  • A. All of the above
  • B. Critical interdependencies and interested parties
  • C. Tangible and intangible impact of a disruption over period of time
  • D. Critical services and products

Answer: A

Explanation:
BIA helps to identify all of the above aspects of an organization's functions and processes. It helps to identify the critical services and products that the organization delivers to its customers and stakeholders, and the functions and processes that support them. It also helps to identify the critical interdependencies and interested parties that are involved in or affected by the organization's functions and processes, such as suppliers, partners, regulators, or employees. Moreover, it helps to identify the tangible and intangible impacts of a disruption to the organization's functions and processes over a period of time, such as financial losses, reputational damage, legal liabilities, or customer dissatisfaction. Verified References: https://www.ready.gov
/business-impact-analysishttps://drii.org/resources/professionalpractices/EN


NEW QUESTION # 31
Which type of planning requires the commitment of significant financial and human resources for situations that may never even occur?

  • A. Review
  • B. Contingency
  • C. Technical
  • D. Operational

Answer: B

Explanation:
Contingency planning is the type of planning that requires the commitment of significant financial and human resources for situations that may never even occur. Contingency planning is the process of developing alternative courses of action in case the preferred plan fails or an unexpected event occurs. Contingency planning aims to reduce the impact and uncertainty of potential disruptions and ensure the continuity of the organization's functions and processes. Contingency planning can be costly and time-consuming, as it involves identifying risks, analyzing scenarios, developing strategies, testing plans, and maintaining readiness.
Verified References: https://www.iso.org/publication/PUB100442.htmlhttps://phoenixnap.com/blog/what-is- business-continuity-management


NEW QUESTION # 32
Which system in place enables you to balance risk and entrepreneurial energy with appropriate internal control procedures to manage that risk?

  • A. Quality Management System
  • B. Banking System
  • C. Auditing Report
  • D. Corporate Governance

Answer: D

Explanation:
Explanation
Corporate governance is the system of rules, practices, and processes by which an organization is directed and controlled. It involves balancing the interests of various stakeholders, such as shareholders, management, customers, suppliers, regulators, and the community. It also enables an organization to balance risk and entrepreneurial energy with appropriate internal control procedures to manage that risk. Effective corporate governance can enhance performance, accountability, transparency, and trust. Verified References:
https://www.investopedia.com/terms/c/corporategovernance.asphttps://www.thebci.org/training-qualifications/go


NEW QUESTION # 33
Tolerating risk is where no action is taken to mitigate or reduce a risk.

  • A. True
  • B. False

Answer: A

Explanation:
Tolerating risk is where no action is taken to mitigate or reduce a risk. This is true because tolerating risk is one of the possible strategies for managing risk. Tolerating risk means accepting or retaining a risk without taking any further action to reduce it, either because the risk level is acceptable or because the cost or effort of reducing it is not justified. Tolerating risk may be appropriate for low-priority or low-impact risks that do not pose a significant threat to the organization's objectives. Verified References: https://www.investopedia.com
/terms/t/the-four-ts.asphttps://www.thebci.org/training-qualifications/good-practice-guidelines.html


NEW QUESTION # 34
Which of the following can threats be considered? (Choose three)

  • A. Water
  • B. Supply chain failure
  • C. Fire
  • D. Technology failure
  • E. Operational failure

Answer: A,C,D

Explanation:
Explanation
Threats can be considered any events or situations that can cause harm or disruption to an organization's functions or processes. Threats can be natural, human-made, or technological in origin. Some examples of threats are water (such as floods, leaks, or spills), technology failure (such as system crashes, cyberattacks, or power outages), and fire (such as arson, accidents, or explosions). Verified References:
https://www.iso.org/publication/PUB100442.htmlhttps://phoenixnap.com/blog/what-is-business-continuity-mana


NEW QUESTION # 35
Which of the following is a low-pressure exercise that uses presentation techniques including videos, slides, and handouts, so that participants fully understand their plans?

  • A. Single team simulation
  • B. Virtualization
  • C. Facilitated discussion
  • D. Plan walkthrough

Answer: D

Explanation:
Explanation
A plan walkthrough is a low-pressure exercise that uses presentation techniques including videos, slides and handouts, so that participants fully understand their plans1.


NEW QUESTION # 36
Which risk group is associated with risk of physical assets failing/being damaged or enhanced?

  • A. Financial
  • B. Strategic
  • C. Operational
  • D. Technical

Answer: D

Explanation:
Explanation
Technical risk is the type of risk that is associated with risk of physical assets failing/being damaged or enhanced. Technical risk is the uncertainty or variability of the performance or reliability of physical assets, such as equipment, systems, infrastructure, or data. Technical risk can result from factors such as design flaws, manufacturing defects, maintenance issues, obsolescence, human error, natural disasters, or cyberattacks.
Technical risk can affect an organization's operational efficiency, quality, safety, security, or profitability.
Verified References:
https://www.investopedia.com/terms/t/technical-risk.asphttps://www.thebci.org/training-qualifications/good-prac


NEW QUESTION # 37
Which type of planning requires the commitment of significant financial and human resources for situations that may never even occur?

  • A. Review
  • B. Contingency
  • C. Technical
  • D. Operational

Answer: B

Explanation:
Explanation
Contingency planning is the type of planning that requires the commitment of significant financial and human resources for situations that may never even occur. Contingency planning is the process of developing alternative courses of action in case the preferred plan fails or an unexpected event occurs. Contingency planning aims to reduce the impact and uncertainty of potential disruptions and ensure the continuity of the organization's functions and processes. Contingency planning can be costly and time-consuming, as it involves identifying risks, analyzing scenarios, developing strategies, testing plans, and maintaining readiness.
Verified References:
https://www.iso.org/publication/PUB100442.htmlhttps://phoenixnap.com/blog/what-is-business-continuity-mana


NEW QUESTION # 38
Which phase of the project is the time to maximize on the employees' new awareness and management support?

  • A. Benchmark
  • B. Milestones
  • C. Structure
  • D. Timelines

Answer: B

Explanation:
Milestones are important events in a project that mark the completion of a major deliverable or the achievement of a key goal. They are a good time to check in with employees and management to see how they are feeling about the project, and to get their feedback on how things are going. This is also a good time to reinforce the importance of the project and to get everyone re-committed to its success.
The other three options are not as good times to maximize on the employees' new awareness and management support. Timelines are important, but they are not as important as milestones in terms of getting people's attention. Benchmarks are useful for tracking progress, but they are not as good for getting people's buy-in.
Structure is important for organizing a project, but it is not as important as milestones for motivating people.
So, the answer to the question is that the milestones phase of the project is the time to maximize on the employees' new awareness and management support.
Here are some specific things that you can do at the milestones phase to maximize on employee awareness and management support:
* Hold a team meeting to celebrate the milestone and to discuss the next steps.
* Send out a communication to all employees and managers, highlighting the milestone and thanking everyone for their hard work.
* Meet with management to discuss the project's progress and to get their feedback.
* Use the milestone as an opportunity to reinforce the importance of the project and to get everyone re- committed to its success.


NEW QUESTION # 39
A disaster lasting longer than seventy-two (72) hours requires implementation of which of the following:

  • A. Business Continuity and Disaster Recovery Plan
  • B. Short Term Business Continuity Plan

Answer: A

Explanation:
A disaster lasting longer than seventy-two (72) hours requires implementation of a business continuity and disaster recovery plan. A business continuity and disaster recovery plan is a comprehensive document that outlines how an organization will respond to and recover from adisaster that disrupts its normal operations. It covers both the IT aspects (disaster recovery) and the business aspects (business continuity) of restoring the critical functions and processes within an acceptable time frame. A disaster lasting longer than seventy-two (72) hours is likely to have significant impacts on the organization's performance, reputation, assets, and stakeholders, and therefore requires a coordinated and structured approach to ensure its survival and resilience. Verified References: https://www.ready.gov/business-continuity-planhttps://www.csoonline.com
/article/515730/business-continuity-and-disaster-recovery-planning-the-basics.html


NEW QUESTION # 40
......

CBCP-002 Exam questions and answers: https://www.exams-boost.com/CBCP-002-valid-materials.html

Pass CBCP-002 Exam Info and Free Practice Test: https://drive.google.com/open?id=15zby-TpJ422F7nL7jjTTEAb2XlTUMlY6