CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 338


Invoking a business continuity plan (BCP) is demonstrating which type of control?

Show Answer
Correct Answer: B

Invoking a business continuity plan (BCP) demonstrates a corrective control. Corrective controls are designed to minimize the impact of a threat event once it has occurred and help restore business operations to normal. A BCP falls under this category as it outlines procedures to follow and actions to take in response to disruptions, ensuring that the business can continue to function effectively after an incident.

Discussion

5 comments
Sign in to comment
IdkanythingOption: B
Nov 18, 2023

Corrective Controls Corrective controls, as their name suggests, are designed to minimize the impact of a threat event once it has occurred, and help in restoring, or correcting, a business to normal operations. Examples of corrective controls include the following: • Business continuity planning • Disaster recovery planning • Incident response planning • Backup procedures

MohamedAbdelaalOption: A
Apr 16, 2023

As per the CISA manual, the BCP is a preventive and corrective control

[Removed]Option: C
Aug 5, 2023

Answer is c

[Removed]
Aug 5, 2023

Answer is B*

BA27Option: A
Aug 29, 2023

A. Preventive

SwallowsOption: B
Jun 8, 2024

Corrective controls are implemented to mitigate the effects of an identified problem or incident. When a disruptive event occurs, such as a natural disaster or a cyberattack, invoking a BCP is a corrective action aimed at restoring critical business functions and minimizing the impact on operations. Therefore, invoking a BCP is a form of corrective control.