If you’re preparing for the ISC2 Certified in Cybersecurity (CC) exam, ISC2 CC Domain 2 — Business Continuity, Disaster Recovery, and Incident Response is one of the most practical sections you’ll encounter. Accounting for 10% of the 100-question, 120-minute exam (passing score: 700/1000), this domain tests your ability to think like someone responsible for keeping an organization running when things go wrong. From ransomware attacks to natural disasters, the exam wants to know: do you understand how organizations prepare, respond, and recover? Let’s break it down.
What Is Business Continuity Planning (BCP)?
Business Continuity Planning (BCP) is the proactive process of ensuring that critical business functions can continue during and after a disruptive event. Think of it as the organization’s game plan for surviving anything from a power outage to a full-scale cyberattack.
BCP is not just about technology — it covers people, processes, and infrastructure. A well-designed BCP answers questions like: Which functions are absolutely critical to keep running? Who is responsible for each function? What resources are needed to sustain operations at a minimum acceptable level?
Key BCP Concepts the Exam Tests
- Business Impact Analysis (BIA): The foundation of any BCP. A BIA identifies critical business processes, quantifies the impact of their disruption, and establishes recovery priorities.
- Maximum Tolerable Downtime (MTD): The longest period a business function can be unavailable before causing irreparable harm to the organization.
- Succession Planning: A people-focused component of BCP that ensures critical organizational roles can be filled quickly if key personnel become unavailable — whether due to illness, resignation, or a disaster situation. The exam distinguishes this clearly from technology or process planning.
Disaster Recovery Planning (DRP): Getting Back to Normal
While BCP focuses on keeping operations running during a disruption, Disaster Recovery Planning (DRP) focuses specifically on restoring IT systems, data, and infrastructure after an incident. Think of BCP as the broader umbrella and DRP as the technical playbook underneath it.
RPO and RTO — Know These Cold
Two metrics appear consistently on the ISC2 CC exam, and you need to know exactly what they mean and how they differ:
- Recovery Point Objective (RPO): How much data loss is acceptable? RPO defines the maximum age of data that must be recoverable. For example, an RPO of 4 hours means backups must occur at least every 4 hours — because losing more than 4 hours of data is unacceptable to the business.
- Recovery Time Objective (RTO): How quickly must systems be restored? RTO defines the maximum acceptable time to recover a system or process after a failure. An RTO of 2 hours means the business expects systems to be back online within 2 hours of an outage.
A helpful way to remember: RPO looks backward (how much data can we afford to lose?) and RTO looks forward (how fast do we need to recover?). Shorter RPO and RTO values require more investment in backup infrastructure and redundancy.
Backup Strategies
The CC exam expects you to understand different backup approaches and their trade-offs:
- Full Backup: A complete copy of all data. Takes the longest to perform but is the fastest to restore from.
- Incremental Backup: Only backs up data that has changed since the last backup (full or incremental). Faster to perform, but restoration requires the last full backup plus all subsequent incrementals.
- Differential Backup: Backs up all data changed since the last full backup. Restoration only requires the last full backup and the most recent differential.
Incident Response Lifecycle
Incident response is the structured approach an organization uses to handle security incidents. The ISC2 CC exam aligns closely with the NIST incident response framework, which defines four main phases. Understanding which actions belong to which phase is critical — the exam will present real-world scenarios and ask you to identify the correct phase.
The Four Phases of Incident Response
- Preparation: Everything done before an incident occurs. This includes developing policies, training staff, deploying tools, and establishing communication plans. If a team is running tabletop exercises or setting up a SIEM, that’s preparation.
- Detection and Analysis: Identifying that an incident has occurred and understanding its scope. This phase involves log analysis, alert triage, and determining whether an event is actually a security incident.
- Containment, Eradication, and Recovery: Stopping the incident from spreading (containment), removing the threat from the environment (eradication), and restoring systems to normal operation (recovery). These are sometimes listed as separate phases depending on the framework version.
- Post-Incident Activity: Also called the lessons learned phase. After the incident is resolved, the team documents the full timeline, evaluates what the response got right and wrong, and updates procedures to improve future responses.
Test Your Knowledge
Let’s apply what you’ve learned. Try these exam-style questions before checking the answers.
Question 1: A security team discovers ransomware spreading across the network and immediately disconnects the affected servers from all network connections. Which phase of the incident response lifecycle does this action represent?
- A) Preparation
- B) Detection and Analysis
- C) Containment
- D) Post-Incident Activity
Answer: C — Containment. Disconnecting infected systems from the network is a textbook containment action. The goal of containment is to stop the incident from spreading further while the team prepares for eradication and recovery. Detection already identified the ransomware; containment isolates it.
Question 2: After resolving a data breach, the security team holds a formal meeting to review what happened, evaluate the effectiveness of their response, and document improvements for the future. Which incident response phase describes this activity?
- A) Preparation
- B) Eradication
- C) Containment
- D) Post-Incident Activity
Answer: D — Post-Incident Activity. Reviewing the incident after resolution, documenting the timeline, and identifying improvements are all hallmarks of the Post-Incident Activity (lessons learned) phase. This phase is critical for strengthening future responses and updating organizational procedures.
Want more practice? Certcy has 110+ questions like these — download free and start building exam confidence today.
Key Study Tips for Domain 2
- Memorize RPO vs. RTO with a scenario: Don’t just define them — practice applying them. If the exam says “the organization cannot lose more than 1 hour of transactions,” that’s an RPO statement.
- Know your incident response phases by action: The exam presents scenarios, not definitions. Train yourself to read a scenario and instantly identify which phase is described.
- Don’t overlook succession planning: It’s easy to focus on the technical DR components and forget that BCP also covers people. Succession planning is a frequently tested concept that candidates underestimate.
- Practice with timed questions: The CC exam gives you 120 minutes for 100 questions — about 72 seconds per question. Timed practice builds the instinct to identify the right answer efficiently.
Frequently Asked Questions
How much of the ISC2 CC exam does Domain 2 cover?
Domain 2 — Business Continuity, Disaster Recovery, and Incident Response — accounts for 10% of the ISC2 CC exam. While it’s one of the smaller domains by weight, it’s highly scenario-driven, meaning the questions test application of concepts rather than simple recall. A solid understanding of the incident response lifecycle and DR metrics can make a meaningful difference in your final score.
What is the difference between BCP and DRP?
Business Continuity Planning (BCP) is the broader strategy for maintaining critical business functions during any type of disruption — it covers people, processes, and technology. Disaster Recovery Planning (DRP) is a subset of BCP that focuses specifically on restoring IT systems and data after a disaster. In short: BCP keeps the business running; DRP gets the technology back online.
Do I need to memorize specific incident response phases for the CC exam?
Yes — the ISC2 CC exam expects you to identify which incident response phase a described action belongs to. The exam aligns with the NIST framework: Preparation, Detection and Analysis, Containment/Eradication/Recovery, and Post-Incident Activity. Focus on understanding what types of actions occur in each phase rather than just memorizing the names. Scenario-based practice questions are the most effective way to build this skill.
Is the ISC2 CC exam difficult to pass?
The CC exam requires a passing score of 700 out of 1000, across 100 multiple-choice questions in 120 minutes. The exam is designed for entry-level candidates with no mandatory prerequisites, but it does require genuine understanding of cybersecurity concepts across five domains. Consistent practice with scenario-based questions — especially for domains like incident response and access controls — is the most reliable path to passing on your first attempt.
Ready to turn this knowledge into exam-day confidence? Practice ISC2 CC questions free on Certcy — with gamified quizzes, spaced-repetition flashcards, and an AI-personalized study plan that adapts to your weak areas. Download the app, earn XP, and walk into your exam knowing you’re prepared. You’ve got this.
Ready to Pass Your Certification?
Practice with 1,890 expert-written questions across 17 CompTIA, ISC2, AWS, and Cisco exams.
Free to start, no credit card required.