EC-Council · EDRP
Validates the ability to develop and implement business continuity and disaster recovery plans, covering business impact analysis, risk assessment, recovery strategy development, emergency response procedures, recovery site management, and disaster recovery plan testing and maintenance.
Practice Questions
623
≈ 4 practice exams
Duration
240 minutes
Passing Score
70%
Difficulty
ProfessionalLast Updated
Feb 2026
Use this EDRP practice exam to prepare for EC-Council Certified Disaster Recovery Professional (EDRP) with realistic questions, detailed explanations, and focused study modes. The practice bank includes 623 questions for EC-Council EDRP, so you can review the exam steadily instead of relying on one long cram session.
As you practice, pay extra attention to patterns in your missed answers. Start with short sessions to identify weak areas, then move into timed quizzes once your accuracy is consistent.
The explanations are especially useful when you want to connect exam wording to the responsibilities and scenarios described in the official certification guidance. Use the free preview first, then unlock the full question bank when you are ready to build a complete study routine.
The EC-Council Certified Disaster Recovery Professional (EDRP), exam code 312-76, is a professional-level certification that validates a candidate's ability to plan, strategize, implement, and maintain comprehensive business continuity and disaster recovery (BC/DR) programs. The credential covers the full lifecycle of disaster preparedness: from conducting business impact analyses and risk assessments to designing recovery strategies, managing recovery sites, and testing and maintaining disaster recovery plans. It addresses data backup and recovery, virtualization-based recovery, centralized and decentralized system restoration, and telecommunications continuity.
The EDRP v3 curriculum aligns with major industry compliance frameworks including ISO 22301, ISO 22313, ISO 27001, ISO/IEC 27005, ISO 31000, ISO 31010, NFPA 1600, INCITS 483-2012, and the NIST NICE Framework. The program includes cloud-based virtual labs that allow candidates to practice BC/DR techniques in simulated enterprise environments. Recognized under DoD 8570/8140, the EDRP is accepted by U.S. government and military employers as a qualifying credential for information assurance and continuity roles.
The EDRP is designed for IT and information security professionals who are responsible for—or transitioning into—business continuity and disaster recovery roles. Ideal candidates include network and systems administrators, firewall and security administrators, risk assessment professionals, IT infrastructure managers, and cybersecurity analysts who need to formalize their BC/DR knowledge with a vendor-neutral, globally recognized credential.
The certification is also well-suited for IT managers and project managers who oversee organizational resilience programs, as well as professionals in regulated industries such as financial services, healthcare, and government who must demonstrate compliance with continuity standards. Candidates with at least a foundational understanding of IT infrastructure and information security will benefit most, though no strict prior certification is required.
There are no mandatory formal prerequisites to sit for the EDRP exam. However, EC-Council recommends that candidates have some practical experience in the IT BC/DR domain before attempting the certification. A working knowledge of IT infrastructure, basic information security concepts, and familiarity with organizational processes is strongly advised.
Candidates who have completed an official EC-Council course at an Accredited Training Center (ATC), an Academia Partner institution, or through the EC-Council iClass platform are automatically eligible to sit for the exam. Those who have not completed an official EC-Council course must submit an Exam Eligibility Application along with a non-refundable $100 USD fee and demonstrate a minimum of two years of work experience in the information security domain before being approved to test.
The EDRP exam (code 312-76) consists of 150 multiple-choice questions and must be completed within 4 hours. The passing score is 70%. The exam is delivered at authorized ECC Exam Centers and is also available at Pearson VUE testing centers worldwide. The certification is valid for three years, after which recertification is required through EC-Council Continuing Education (ECE) credits.
The exam tests knowledge across all core BC/DR domains rather than being divided into weighted sections with published percentages. Candidates are assessed on practical understanding of disaster recovery planning methodologies, risk and business impact analysis techniques, recovery strategies, and emergency response procedures. No unscored or survey questions have been officially disclosed by EC-Council.
EDRP-certified professionals are positioned for roles such as Disaster Recovery Specialist, Business Continuity Planner, IT Risk Manager, IT Infrastructure Manager, and Cybersecurity Analyst. Salaries for disaster recovery professionals in the United States typically range from approximately $75,000 to $125,000 annually, with median figures around $95,000 depending on experience, organization size, and location. The certification is recognized under DoD 8570/8140, making it particularly valuable for professionals seeking federal government, defense contractor, or military positions.
The global disaster recovery solutions market was valued at $10.93 billion in 2024 and is projected to reach $24.56 billion by 2029—a CAGR of roughly 17.5%—reflecting strong and growing employer demand for credentialed BC/DR professionals. Compared to alternatives such as the DRII CBCP (Certified Business Continuity Professional) or ISACA's CRISC, the EDRP is distinguished by its technical depth in IT systems recovery, its virtual lab component, and its alignment with EC-Council's broader cybersecurity certification ecosystem, making it a strong complement to credentials like CEH or CISSP for security-focused professionals.
5 sample questions with answers and explanations. The full bank has 623 questions, enough for 4 full-length practice exams.
Preview — answers shown1. A disaster recovery administrator is implementing Hyper-V Replica for a critical business application running on virtual machines. The organization requires the ability to recover to multiple points in time over the past day to protect against data corruption scenarios. The administrator needs to configure the maximum number of recovery points supported by Hyper-V Replica for point-in-time recovery. What is the maximum number of hourly recovery points that can be configured for a Hyper-V Replica? (Select one!)
Explanation
Hyper-V Replica supports up to 24 hourly recovery points for point-in-time recovery, enabling administrators to revert a virtual machine to any hourly snapshot within the past day. This capability was increased from earlier versions to provide a full 24-hour recovery window. Each recovery point is stored as a Hyper-V checkpoint on the replica server. The 12-hour option was the limit in earlier Windows Server versions before the enhancement. The 16-hour and 48-hour options are not valid configurations for Hyper-V Replica recovery points. Recovery points work in conjunction with VSS integration to provide application-consistent snapshots for applications like SQL Server and Exchange.
2. An organization performs weekly full backups on Saturday evenings and differential backups Monday through Friday. On Friday afternoon at 3 PM, the primary storage array fails catastrophically. The backup team begins restoration procedures. Which backup sets must be restored to achieve complete data recovery? (Select one!)
Explanation
Differential backups archive all files changed since the last full backup and do not clear archive bits. Each successive differential backup contains all changes since the Saturday full backup, making each differential cumulative. For restoration, only the most recent differential backup must be restored alongside the full backup. Friday's differential already contains all changes from Monday, Tuesday, Wednesday, and Thursday because differential backups do not reset the archive bit. This contrasts with incremental backups, which would require restoring the full backup plus each incremental in chronological sequence.
3. A data center manager implements tape backup rotation using Grandfather-Father-Son methodology. The daily incremental backups are rotated on a first-in-first-out basis, weekly full backups are promoted and retained for 8 weeks, and monthly full backups are stored off-site for 12 months. A user requests recovery of a file created on Monday of the second week of June and deleted on Tuesday of the same week. What is the likely outcome? (Select one!)
Explanation
GFS backup retention has a notable limitation where older backups become less granular. A file created and deleted between daily backup cycles within the same week will be lost irretrievably because daily backups may have already rotated out, the weekly backup may not capture that specific day, and monthly backups only capture month-end state. Monday's daily backup would only exist if still within the daily retention window. Weekly and monthly backups typically occur at week-end and month-end, missing mid-week files.
4. A BCP development team categorizes business functions by criticality to determine recovery priorities. The customer-facing e-commerce platform is categorized as mission-critical with a 2-hour MTD. The internal HR benefits portal is categorized as necessary with a 5-day MTD. The corporate blog is categorized as desirable with a 2-week MTD. Which statement correctly describes the relationship between criticality and MTD? (Select one!)
Explanation
Higher criticality business functions require shorter Maximum Tolerable Downtime values because critical processes cause severe harm to the organization when unavailable, necessitating rapid recovery. Mission-critical functions like the e-commerce platform generate revenue and serve customers directly, making extended downtime financially catastrophic. Necessary functions like HR portals support operations but can tolerate moderate delays without severe consequences. Desirable functions like corporate blogs provide value but are non-essential during crisis recovery. The inverse relationship between criticality and MTD drives resource allocation; mission-critical systems receive hot site protection with hours of MTD, while desirable systems may use cold site recovery with days or weeks of MTD. Criticality and MTD are directly related rather than independent, as criticality assessment informs MTD determination during BIA. Mission-critical functions may have different MTD values based on specific business impacts rather than requiring identical values.
5. A disaster recovery team conducts incident damage assessment following a tornado that severely damaged the primary datacenter facility. The team must perform different assessment types at various stages of the incident response. Which damage assessment type should be conducted during the initial hours immediately following the disaster? (Select one!)
Explanation
Rapid Needs Assessment is conducted during the initial hours immediately following a disaster and focuses on life-safety concerns, immediate critical needs, and whether emergency services are required. This assessment prioritizes human safety and urgent stabilization over detailed damage documentation. Initial Damage Assessment is conducted in the days following the incident after immediate life-safety concerns are addressed, documenting the extent of damage to facilities and infrastructure. Detailed Assessment occurs later in the timeline and provides comprehensive analysis for recovery planning including cost estimation and detailed repair requirements. Financial Impact Assessment is an ongoing process that may take weeks or months to complete accurately as full business interruption costs become known.
Certified Cybersecurity Technician (CCT)
CCT · 630 questions
Certified DevSecOps Engineer (ECDE)
ECDE · 609 questions
Digital Forensics Essentials (DFE)
DFE · 626 questions
Certified Application Security Engineer .NET (CASE-.NET)
CASE-.NET · 625 questions
EC-Council Certified Incident Handler (ECIH)
ECIH · 590 questions
EC-Council Certified Encryption Specialist (ECES)
ECES · 627 questions
$17.99
One-time access to this exam