How to Master One of the Hardest Parts of the ISC2 CC Exam: Business Continuity, Disaster Recovery, and Incident Response

Business continuity, disaster recovery, and incident response trip up many ISC2 Certified in Cybersecurity (CC) candidates. The terms sound similar, the plans overlap, and many questions hinge on doing the right thing in the right order. On top of that, most newcomers have never lived through a real outage or security incident, so the scenarios can feel abstract.

The good news is that this topic follows clear logic. Once you understand what each plan is for and the sequence of each process, these questions become some of the most predictable on the exam.

We’ll walk you through the core concepts, the common traps, and a couple of worked examples.

Where Does This Topic Appear in the Current ISC2 CC Outline?

Under the previous outline, business continuity, disaster recovery, and incident response formed their own domain. The ISC2 CC Certification Exam Outline effective September 1, 2026 splits them across two domains:

  • Domain 2, Security Governance (17.3%): Objective 2.2, “Understand redundancy,” covers business continuity and disaster recovery.
  • Domain 5, Security Operations and Incident Response (17.3%): Objective 5.3, “Understand Incident Response,” covers data handling policy, implementing an incident response plan (IRP), and IR exercises such as tabletop tests. Objective 5.2 adds logging, monitoring, and security event triage, which is how incidents are detected in the first place.

Together, those two domains make up more than a third of the exam, so you should master this material.

What Is the Difference Between BC, DR, and IR?

Start by separating the three plans. Many exam questions test nothing more than whether you know which plan applies.

  • Business continuity (BC): Keeps critical business functions running during and after a disruption. It’s broad and business-focused, covering people, processes, facilities, suppliers, and technology.
  • Disaster recovery (DR): Restores IT systems, data, and infrastructure after a disaster. DR is a subset of the broader continuity effort and focuses on technology.
  • Incident response (IR): Detects, contains, and recovers from security incidents, such as malware infections, unauthorized access, or data breaches.

A helpful way to remember it: BC asks, “How does the business keep operating?” DR asks, “How do we get the systems back?” IR asks, “How do we stop and clean up this security incident?”

What Core BC and DR Concepts Should You Know?

Business Impact Analysis and Recovery Metrics

A business impact analysis (BIA) identifies critical business functions and what happens if they’re disrupted. It produces the metrics that drive every recovery decision:

  • Maximum tolerable downtime (MTD): The longest a function can be down before the organization suffers unacceptable harm.
  • Recovery time objective (RTO): The target time to restore a system or function. The RTO must be shorter than the MTD.
  • Recovery point objective (RPO): The maximum acceptable amount of data loss, measured in time. An RPO of four hours means you need backups at least every four hours.

Memory trick: RTO is about time to get back up, and RPO is about the point in time your data returns to.

Backup Types

  • Full: Copies all data. Slowest to create, fastest to restore.
  • Incremental: Copies only data changed since the last backup of any type. Fast to create, but a restore needs the last full backup plus every incremental since.
  • Differential: Copies all data changed since the last full backup. A restore needs only the last full backup plus the most recent differential.

Recovery Sites and Redundancy

  • Hot site: Fully equipped with current data. Can be running within minutes to hours. Most expensive.
  • Warm site: Has hardware and connectivity but needs current data restored. Ready in hours to days.
  • Cold site: Space and basic utilities only. Takes the longest to bring online. Least expensive.

Redundancy also shows up at smaller scales: redundant power supplies, uninterruptible power supplies (UPS) and generators, RAID storage, multiple internet providers, and cloud regions. The 2026 outline’s use of the word “redundancy” is a hint that you should connect these controls to the availability part of the CIA triad.

Plan Testing

Plans must be tested to be trusted. From least to most disruptive, common test types are a checklist review, a tabletop exercise (a discussion-based walkthrough of a scenario), a simulation, a parallel test (bringing up the recovery site while production keeps running), and a full interruption test (actually shutting down production). Tabletop exercises are named directly in the new outline, so know that they’re low-cost, discussion-based, and don’t affect live systems.

What Core Incident Response Concepts Should You Know?

First, know your terms. An event is any observable occurrence, such as a login. An incident is an event that actually or potentially threatens confidentiality, integrity, or availability. A breach is an incident in which data is confirmed to have been accessed or disclosed by an unauthorized party.

Most CC study materials teach the four-phase incident response lifecycle from NIST Special Publication 800-61 Revision 2:

  1. Preparation: Build the IR plan, the team, tools, communication paths, and training.
  2. Detection and analysis: Identify potential incidents through logs, alerts, and reports, then triage and confirm them.
  3. Containment, eradication, and recovery: Limit the damage, remove the cause, and restore systems to normal operation.
  4. Post-incident activity: Hold a lessons-learned review and update the plan and controls.

NIST published Revision 3 in 2025, which reorganizes incident response guidance around the NIST Cybersecurity Framework 2.0 functions. The underlying logic is the same, so the four-phase model remains a reliable way to reason through CC questions. Also remember to preserve evidence during an incident and document a chain of custody if it may be used in legal proceedings.

What Are the Most Common Traps?

  • Mixing up BC and DR. If the question is about keeping the business functioning (staff, processes, alternate locations), think BC. If it’s about restoring servers and data, think DR.
  • Swapping RTO and RPO. Questions about backup frequency or data loss are about RPO. Questions about how quickly a service must be back are about RTO.
  • Jumping to eradication or recovery. Containment comes first. Wiping and rebuilding an infected server before isolating it can let the attack spread and destroy evidence.
  • Forgetting life safety. In any disaster scenario involving people, protecting human life is always the top priority, ahead of data or equipment.
  • Skipping lessons learned. The incident isn’t over when systems are restored. The post-incident review is part of the process and a frequent correct answer.
  • Choosing a disruptive test. If a question asks how to test a plan without affecting operations, a full interruption test is almost never the answer.

How Do You Reason Through a Sample Question?

Consider a question where a security analyst sees an alert showing that a workstation in accounting is communicating with a known malicious IP address. The analyst confirms the workstation is infected. What should the analyst do next? The options might include reimaging the workstation, notifying all employees, isolating the workstation from the network, and writing a lessons-learned report.

Walk through the lifecycle. Detection and analysis are done, because the infection is confirmed. The next phase is containment, so the best answer is to isolate the workstation from the network. Reimaging is eradication and recovery, which comes later. The lessons-learned report comes last. Notifying all employees may or may not be needed, and it doesn’t stop the threat.

Now consider a question where a company can tolerate losing no more than one hour of order data, and its database is backed up nightly. What should change? The one-hour limit is the RPO, and nightly backups could lose up to 24 hours of data. The best answer is to back up (or replicate) the data at least hourly. An answer about moving to a hot site would improve RTO, not RPO, so it’s a distractor.

How Does This Topic Connect to the Rest of the Exam?

  • Security Principles: BC and DR protect availability, and IR protects all three parts of the CIA triad. Risk management decides which functions get the most investment.
  • Security Governance: BC and DR plans are governance documents, and metrics such as recovery times and incident counts feed the dashboards and KRIs in objective 2.4.
  • IAM Concepts: Disabling compromised accounts is a common containment step, and promptly deprovisioning departed users helps prevent incidents.
  • Networking and Cloud Security: Segmentation limits how far an incident spreads, and cloud regions and the shared responsibility model shape recovery options.

How Should You Study This Topic?

  1. Write one-sentence definitions of BC, DR, IR, BIA, MTD, RTO, and RPO from memory until they come out cleanly.
  2. Draw the incident response lifecycle and list two actions that belong in each phase.
  3. Practice restore scenarios for full, incremental, and differential backups until you can name the needed backups instantly.
  4. Use Pocket Prep’s Build Your Own Quiz to drill the Security Governance, Security Operations, and Incident Response subjects, then check the explanation on every question, including the ones you get right.
  5. After a few days, mix this topic back in with Level Up or a Timed Quiz, and use the Missed Questions quiz to revisit anything that still trips you up.

Start Preparing for the ISC2 CC Exam With Pocket Prep

Pocket Prep’s ISC2 CC exam prep gives you 800 practice questions with detailed explanations that show why the right answer is right and why the others fall short. When you’re ready, take the full-length mock exam to see how you handle this topic alongside everything else. With steady practice, even the trickiest scenario questions will start to feel familiar.