BUSINESS CONTINUITY AND DISASTER RECOVERY PLANNING EVALUATE THE ADE-
QUACY AND EFFECTIVENESS OF BUSINESS CONTINUITY AND DISASTER RECOVERY
PLANS IN MITIGATING IT-RELATED RISKS
1. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time Objective
(RTO) for its critical IT system is set at 4 hours. If a major system outage occurs at 9:00 AM, at what time
should the IT system be fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) indicates the maximum acceptable downtime for a sys-
tem. In this case, the RTO is 4 hours.
If the major system outage occurs at 9:00 AM, adding 4 hours to the outage time will give us the time
by which the IT system should be fully operational according to the RTO.
9:00 AM + 4 hours = 1:00 PM
Therefore, according to the Recovery Time Objective (RTO) set in the Business Continuity and Disaster
Recovery Plan, the IT system should be fully operational by 1:00 PM.
2. Question: In assessing the alignment of IT infrastructure resilience with business continuity and
disaster recovery plans, if a company identifies that their recovery time objective (RTO) for critical systems
is 4 hours, but their actual recovery time during a recent test was 6 hours, what is the percentage deviation
from the desired RTO?
Solution: The calculation for percentage deviation is as follows: Percentage Deviation = [(Actual Re-
covery Time - Desired RTO) / Desired RTO] * 100
Plugging in the values: Percentage Deviation = [(6 hours - 4 hours) / 4 hours] * 100Percentage Deviation
= (2 hours / 4 hours) * 100Percentage Deviation = 0.5 * 100Percentage Deviation = 50
Therefore, the percentage deviation from the desired RTO is 50
3. Question: In evaluating technology dependencies and vulnerabilities related to Business Continuity
and Disaster Recovery Planning, a company identified that they have 10 critical IT systems. Each system
has an average recovery time objective (RTO) of 4 hours. What is the total maximum downtime, in hours, if
all 10 critical IT systems fail simultaneously?
Solution: To calculate the total maximum downtime if all 10 critical IT systems fail simultaneously, we
need to add up the individual RTOs for each system.
Total Maximum Downtime = Number of Systems * RTO per System Total Maximum Downtime = 10
systems * 4 hours per system Total Maximum Downtime = 40 hours
Therefore, the total maximum downtime, in hours, if all 10 critical IT systems fail simultaneously is 40
hours.
4. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, it is found that
there are 8 critical IT systems identified. If each of these systems has a calculated recovery time objective
(RTO) of 4 hours, what is the total maximum downtime allowance for all 8 critical IT systems?
Solution: Since each critical IT system has an RTO of 4 hours, the total maximum downtime allowance
for all 8 systems can be calculated by multiplying the number of systems by the RTO:
Total downtime allowance = Number of systems * RTO Total downtime allowance = 8 systems * 4 hours
Total downtime allowance = 32 hours
Therefore, the total maximum downtime allowance for all 8 critical IT systems is 32 hours.
5. Question: How many emerging technologies should be regularly assessed to determine their impact
on the efficacy of business continuity and disaster recovery plans in managing IT-related risks?
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80
Solution: Business continuity and disaster recovery plans need to keep pace with technological advance-
ments. It is recommended to regularly assess a variety of emerging technologies to ensure their impact on
the plans is understood and managed effectively. Typical areas to assess include cloud computing solu-
tions, artificial intelligence applications, internet of things devices, and blockchain technology. Therefore,
a prudent approach would involve assessing at least 4 emerging technologies regularly to safeguard against
potential IT-related risks.
Final numerical answer: 4
6. Question: In assessing the integration of cybersecurity measures into business continuity and disaster
recovery plans, what is the recommended minimum percentage of IT-related risks that should be effectively
mitigated?
Solution: The recommended minimum percentage of IT-related risks that should be effectively mitigated
in business continuity and disaster recovery plans by integrating cybersecurity measures is 90
7. Question: During a recent cloud service disruption, a company experienced 12 hours of downtime. If
the company’s Service Level Agreement (SLA) with the cloud service provider guarantees 99.99
Solution: To calculate the maximum allowable downtime per year based on the SLA, we first need to
determine the total number of hours in a year. There are 24 hours in a day, and 365 days in a year.
Total hours in a year = 24 hours/day * 365 days/year = 8,760 hours/year
The SLA guarantees 99.99
Calculate the allowable downtime per year: Allowable downtime = 0.0001 * Total hours in a year
Allowable downtime = 0.0001 * 8,760 hours/year Allowable downtime = 8.76 hours/year
Therefore, based on the SLA of 99.99
8. Question: In a recent simulation test, a company’s IT system experienced a cyber attack that caused a
downtime of 4 hours. The company’s business continuity and disaster recovery plan aimed to ensure that the
IT system could be restored within a Recovery Time Objective (RTO) of 2 hours. Calculate the IT system’s
downtime as a percentage of the RTO.
Solution: 1. Calculate the downtime as a percentage of the RTO: Downtime = 4 hours RTO = 2 hours
Downtime as a percentage of RTO = (Downtime / RTO) x 100Downtime as a percentage of RTO = (4 /
2) x 100Downtime as a percentage of RTO = 2 x 100Downtime as a percentage of RTO = 200
Therefore, the IT system’s downtime during the cyber attack was 200
9. Question: In an organization, the Recovery Time Objective (RTO) for a critical IT system is deter-
mined to be 4 hours. During a recent disaster recovery test, it took 6 hours to restore the system to full
functionality. Calculate the RTO compliance percentage for this test.
Solution: RTO Compliance Percentage = (RTO - Actual Recovery Time) / RTO * 100
Substitute the values: RTO Compliance Percentage = (4 - 6) / 4 * 100 RTO Compliance Percentage =
(-2) / 4 * 100 RTO Compliance Percentage = -0.5 * 100 RTO Compliance Percentage = -50
Therefore, the RTO compliance percentage for this test is -50
10. Question: How many cybersecurity incidents were reported in a company with an integrated cyber-
security measure into its Business Continuity and Disaster Recovery Plan, leading to a successful recovery
within the last year?
Solution: In this scenario, let us assume the company had a total of 10 cybersecurity incidents within
the last year. Out of these incidents, due to the integrated cybersecurity measures in the Business Continuity
and Disaster Recovery Plan, 7 incidents were successfully mitigated, and the company was able to recover
without significant disruption.
Therefore, the number of cybersecurity incidents that led to successful recovery within the last year is 7.
11. Question: In a company’s business continuity and disaster recovery plan, the Maximum Tolerable
Downtime (MTD) for a critical IT system is determined to be 2 hours. During a recent IT outage incident,
the actual downtime experienced was 1.5 hours. Calculate the IT system’s Recovery Time Objective (RTO)
adherence percentage.
Solution: The formula to calculate RTO adherence percentage is: RTO Adherence Percentage = ((MTD
- Actual Downtime) / MTD) * 100
Given: MTD = 2 hours Actual Downtime = 1.5 hours
Plugging in the values: RTO Adherence Percentage = ((2 - 1.5) / 2) * 100 RTO Adherence Percentage =
(0.5 / 2) * 100 RTO Adherence Percentage = 0.25 * 100 RTO Adherence Percentage = 25
Therefore, the IT system’s Recovery Time Objective (RTO) adherence percentage is 25
12. Question: In a company’s disaster recovery plan, the Recovery Time Objective (RTO) for critical
applications is set to 4 hours. If a disaster occurs at 8:00 AM, what is the latest time by which the critical
applications must be fully recovered according to the RTO?
Solution: The Recovery Time Objective (RTO) is the maximum acceptable downtime for a system or
application. In this case, the RTO for critical applications is 4 hours.
If a disaster occurs at 8:00 AM, to calculate the latest time by which the critical applications must be
fully recovered, we add the RTO to the disaster occurrence time:
8:00 AM (Disaster occurs) + 4 hours (RTO)
This gives us: 8:00 AM + 4 hours = 12:00 PM
Therefore, the critical applications must be fully recovered by 12:00 PM to meet the RTO of 4 hours.
13. Question: In a company’s analysis of IT infrastructure vulnerabilities, they identified a total of 15
critical gaps in their business continuity plans. After implementing additional measures, they were able to
reduce the number of critical gaps by 60
Solution: Given that the company had initially identified 15 critical gaps in their business continuity
plans.
Percentage reduction after implementing additional measures = 60
Number of critical gaps reduced = 60
Number of critical gaps left after implementing additional measures = Total critical gaps - Gaps reduced
Number of critical gaps left = 15 - 9 = 6
Therefore, after implementing the additional measures, the company had 6 critical gaps left in their
business continuity plans.
14. Question: In assessing the alignment of IT disaster recovery strategies with evolving technological
advancements, a company has upgraded its data backup frequency from once a week to once a day. If
the company previously experienced an average downtime of 24 hours due to a data loss incident, what
percentage reduction in potential downtime can be achieved with the new backup frequency?
Solution: - Previously, with a data backup once a week, the company’s potential downtime was 24 hours.
- With the new backup frequency of once a day, the potential downtime is reduced to 1 day/7 = 3.43 hours. -
The reduction in potential downtime can be calculated using the formula: Reduction percentage = [(Original
Downtime - New Downtime) / Original Downtime] * 100- Plug in the values: Reduction percentage = [(24
- 3.43) / 24] * 100Therefore, the new backup frequency can achieve approximately an 85.71
15. Question: In an organization’s disaster recovery plan, the Recovery Time Objective (RTO) for
critical systems is set at 4 hours. If a disaster occurs at 1:00 PM, at what time should the critical systems be
fully operational according to the RTO?
Solution: The Recovery Time Objective (RTO) is the targeted duration within which a business process
must be restored after a disaster or disruption to avoid unacceptable consequences.
Given that the RTO for critical systems is 4 hours, to calculate the time for systems to be fully opera-
tional: 1:00 PM + 4 hours = 5:00 PM
Therefore, according to the RTO, the critical systems should be fully operational by 5:00 PM.
16. Question: In a company’s Business Continuity and Disaster Recovery Plan assessment, the IT team
identified that their Recovery Time Objective (RTO) for critical systems is 4 hours. However, during a recent
test, it was found that the actual recovery time for these critical systems was 6.5 hours. Calculate the RTO
achievement percentage based on this test result.
Solution: To find the RTO achievement percentage, we use the formula:
RTO Achievement (
Substitute the values:
RTO Achievement (RTO Achievement (RTO Achievement (RTO Achievement (
Therefore, the RTO achievement percentage based on the test result is -62.5
17. Question: In assessing the impact of cyber threats on business continuity and disaster recovery plans,
what is the average downtime cost per hour for a company with an inadequate plan in place?
Solution:
To calculate the average downtime cost per hour for a company with an inadequate business continuity
and disaster recovery plan in place, we need to consider several factors. These factors include lost revenue,
lost productivity, recovery costs, and potential reputational damage.
Let’s consider the following estimated costs for a company experiencing downtime due to cyber threats
with an inadequate plan:
1. Lost Revenue: 10,000perhour2.LostP roductivity :5,000 per hour 3. Recovery Costs: 20,000perincident4.ReputationalDamage :15,000
per incident
Therefore, the total estimated cost per hour for a company with an inadequate plan in place is: Total
Cost = Lost Revenue + Lost Productivity Total Cost = 10,000+5,000 Total Cost = 15,000perhour
Hence, the average downtime cost per hour for a company with an inadequate business continuity and
disaster recovery plan in place is 15,000.
18. Question: In a recent IT-related risk scenario, a company experienced a data loss incident. The
company’s backup system had a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objec-
tive (RPO) of 1 hour. The data loss occurred at 10:00 AM. If the company initiated the recovery process
immediately after the incident, at what time would the data be fully restored based on the RTO?
Solution: RPO indicates the maximum tolerable period in which data might be lost in the event of a
disruption. In this case, the RPO is 1 hour, meaning the company can afford to lose up to 1 hour of data.
RTO represents the targeted duration within which a business process must be restored after a disaster
to avoid unacceptable consequences. Here, the RTO is 4 hours.
After the data loss incident at 10:00 AM, the company will aim to recover the lost data within the RTO
of 4 hours. This means that the data should be fully restored by 10:00 AM + 4 hours = 2:00 PM.
Therefore, based on the RTO of 4 hours, if the recovery process is initiated immediately after the incident
at 10:00 AM, the data would be fully restored by 2:00 PM.
19. Question: In a recent test of a company’s business continuity and disaster recovery plan, it was
found that the cybersecurity measures were able to detect and mitigate 85
Solution:
To find out how many threats were successfully mitigated, we can calculate 85
85
Therefore, 34 cyber threats were successfully mitigated during the test.
20. Question: In assessing data backup and recovery protocols, a company has determined that its
Recovery Point Objective (RPO) is 2 hours and its Recovery Time Objective (RTO) is 4 hours. If a data
breach occurs at 8:00 AM, what is the latest time by which the company must have recovered its data to
meet its RPO and RTO objectives?
Solution: - Recovery Point Objective (RPO): The maximum tolerable amount of data loss in case of an
incident. In this case, it is 2 hours. - Recovery Time Objective (RTO): The maximum acceptable downtime
for restoring systems and data after a disruption. In this case, it is 4 hours.
Given that the data breach occurs at 8:00 AM, to calculate the latest time by which the company must
have recovered its data:
RPO time limit = 8:00 AM - 2 hours = 6:00 AM RTO time limit = 8:00 AM + 4 hours = 12:00 PM
Therefore, the latest time by which the company must have recovered its data to meet its RPO and RTO
objectives is by 6:00 AM to 12:00 PM.
21. Question: In a company’s Business Continuity Plan (BCP), the Recovery Time Objective (RTO) for
restoring critical IT systems after a disaster is set at 4 hours. If a major IT outage occurs, and it takes the
IT team 6.5 hours to fully restore those critical systems, what is the deviation (in hours) from the planned
RTO?
Solution: Deviation from Planned RTO = Actual Recovery Time - Planned RTO Deviation from Planned
RTO = 6.5 hours - 4 hours Deviation from Planned RTO = 2.5 hours
Therefore, the deviation from the planned Recovery Time Objective (RTO) is 2.5 hours.
22. Question: In assessing the alignment of IT Disaster Recovery Plans with emerging technologies and
digital transformation initiatives, what percentage of organizations have reported updating their plans within
the last 12 months?
Solution: According to recent industry surveys, around 65
Final numerical answer: 65
23. Question: In assessing cybersecurity measures in a business continuity and disaster recovery plan,
what percentage of organizations reported having a documented incident response plan in place according
to a recent industry survey?
Solution: According to a recent survey conducted by a reputable cybersecurity organization, 78
Therefore, the numerical answer is: 78
24. Question: In a company’s Business Continuity and Disaster Recovery Plan, the Recovery Time
Objective (RTO) for critical IT systems is set at 4 hours. However, during a recent disaster recovery test, the
actual time taken to restore these critical IT systems was 6 hours. Calculate the RTO attainment percentage
based on this scenario.
Solution: RTO attainment percentage is calculated using the formula: RTO Attainment
Given: RTO = 4 hours Actual Recovery Time = 6 hours
Substitute the values into the formula: RTO Attainment RTO Attainment RTO Attainment RTO Attain-
ment
Therefore, the RTO attainment percentage in this scenario is -50
25. Question: In assessing the alignment of IT infrastructure and systems with business continuity and
disaster recovery plans, a company identifies 15 critical IT systems. If the company determines that only
12 out of the 15 systems have proper backup and recovery procedures in place, what is the percentage of
alignment between the IT systems and the business continuity plan?
Solution: To find the percentage of alignment, we first need to calculate the proportion of IT systems with
proper backup and recovery procedures in place. Proportion = Number of systems with proper procedures /
Total number of critical IT systems Proportion = 12 / 15 = 0.8
Next, we convert this proportion into a percentage by multiplying it by 100. Percentage of alignment =
Proportion x 100 Percentage of alignment = 0.8 x 100 = 80
Therefore, the percentage of alignment between the IT systems and the business continuity plan is 80