EC-Council · EDRP
Validates the ability to develop and implement business continuity and disaster recovery plans, covering business impact analysis, risk assessment, recovery strategy development, emergency response procedures, recovery site management, and disaster recovery plan testing and maintenance.
Practice Questions
623
≈ 4 practice exams
Duration
240 minutes
Passing Score
70%
Difficulty
ProfessionalLast Updated
Oct 2026
EC-Council's Disaster Recovery Professional course covers business continuity and disaster recovery in ten modules: foundations, business continuity management, risk assessment, business impact analysis, the business continuity plan, disaster recovery planning, data backup and system recovery, disaster recovery plan development, plan activation, and plan testing, training, and exercises. EC-Council does not publish percentage weights for these modules, so treat any site quoting exact weights with caution.
The exam has 150 multiple-choice questions and four hours. A voucher costs $450, and self-study candidates need two years of information-security experience plus a $100 non-refundable eligibility application; a retake voucher is $249. EC-Council sets cut scores per exam form and does not publish a score for this exam, so a fixed 70% is unconfirmed - the exact score appears in the exam portal. EC-Council currently lists v4 courseware while a v3 retake voucher is still sold, and the code 312-76 appears mostly on third-party sites, so confirm the version when you book.
Use these 623 questions to practise the order of the recovery lifecycle: assess risk, run a business impact analysis, set recovery objectives, choose strategies, write and activate the plan, then test it. Pay attention to how backup, replication, and recovery-site choices follow from the recovery objectives rather than the other way around.
The EC-Council Disaster Recovery Professional (EDRP) course teaches business continuity and disaster recovery across ten modules: foundations, business continuity management, risk assessment, business impact analysis, the business continuity plan, disaster recovery planning, data backup and system recovery, disaster recovery plan development, plan activation, and plan testing, training, and exercises.
The emphasis is on building and exercising a recovery capability from risk analysis through activation, not on a single vendor's tooling. EC-Council currently lists EDRP v4 courseware.
The EDRP is designed for IT and information security professionals who are responsible for—or transitioning into—business continuity and disaster recovery roles. Ideal candidates include network and systems administrators, firewall and security administrators, risk assessment professionals, IT infrastructure managers, and cybersecurity analysts who need to formalize their BC/DR knowledge with a vendor-neutral, globally recognized credential.
The certification is also well-suited for IT managers and project managers who oversee organizational resilience programs, as well as professionals in regulated industries such as financial services, healthcare, and government who must demonstrate compliance with continuity standards. Candidates with at least a foundational understanding of IT infrastructure and information security will benefit most, though no strict prior certification is required.
There are no mandatory formal prerequisites to sit for the EDRP exam. However, EC-Council recommends that candidates have some practical experience in the IT BC/DR domain before attempting the certification. A working knowledge of IT infrastructure, basic information security concepts, and familiarity with organizational processes is strongly advised.
Candidates who have completed an official EC-Council course at an Accredited Training Center (ATC), an Academia Partner institution, or through the EC-Council iClass platform are automatically eligible to sit for the exam. Those who have not completed an official EC-Council course must submit an Exam Eligibility Application along with a non-refundable $100 USD fee and demonstrate a minimum of two years of work experience in the information security domain before being approved to test.
EC-Council lists 150 multiple-choice questions and four hours. An exam voucher costs $450; self-study candidates need two years of information-security experience and a $100 non-refundable eligibility application, and a retake voucher is $249. EC-Council sets cut scores per exam form and does not publish a score for EDRP, so a fixed 70% is unconfirmed. The exam code 312-76 appears mostly on third-party sites, so confirm the version and code at booking.
EDRP is aimed at business continuity and disaster recovery staff, system administrators, IT risk managers and consultants, and IT directors who own recovery planning. It is most useful where you must show a documented, tested recovery process. Holders renew through EC-Council's continuing-education cycle.
5 sample questions with answers and explanations. The full bank has 623 questions, enough for 4 full-length practice exams.
Preview — answers shown1. A storage array uses block-level striping with distributed parity across three disks, providing fault tolerance for one disk failure while optimizing storage capacity. Which RAID level is implemented? (Select one!)
Explanation
RAID 5 uses striping with distributed parity across a minimum of three disks, providing single disk fault tolerance while maximizing usable storage capacity through parity calculations. RAID 0 uses striping without any redundancy or fault tolerance. RAID 1 uses mirroring between two disks without striping or parity. RAID 10 combines mirroring and striping with a minimum of four disks, providing higher fault tolerance but at greater cost than RAID 5.
2. An organization subject to SOX Section 404 requirements must implement technical controls to protect financial data and maintain audit trails. For how many years must business records be retained to meet SOX compliance? (Select one!)
Explanation
Sarbanes-Oxley Act requires organizations to save all business records including financial data, audit trails, and supporting documentation for at least 5 years. This retention period ensures financial transparency and accountability for publicly traded companies. Destruction or alteration of records can result in penalties up to 5 million dollars in fines and 20 years imprisonment. The 5-year requirement applies to electronic records, backup systems, and disaster recovery archives. Organizations must ensure DR and backup solutions maintain record accessibility throughout the retention period. Three years is insufficient for SOX. Seven years represents IRS tax record retention. Ten years exceeds SOX requirements though some organizations adopt longer retention for other regulatory or business reasons.
3. An organization chooses to acknowledge a low-probability, low-impact risk of workstation theft without implementing additional controls beyond existing physical security. Which risk treatment option is selected? (Select one!)
Explanation
Risk acceptance acknowledges risk and chooses not to avoid, mitigate, or transfer it, typically for low-probability or low-impact scenarios where mitigation costs exceed potential losses. This should be an informed decision, not a default position. Risk avoidance would eliminate the risk entirely by removing workstations. Risk mitigation would reduce likelihood or impact through additional controls like cable locks or enhanced monitoring. Risk transfer would shift the risk through insurance or contractual agreements.
4. A mission-critical application has RTO of 2 hours and requires 1.5 hours for data validation, testing critical functions, and manual data entry after systems are restored. What is the maximum time allowed for actual system restoration? (Select one!)
Explanation
Using the formula MTD equals RTO plus WRT, if RTO is 2 hours total and WRT is 1.5 hours for post-restoration activities, then actual system restoration time cannot exceed 30 minutes. The relationship is RTO equals restoration time plus WRT, therefore 2 hours equals 0.5 hours plus 1.5 hours. Selecting 1.5 hours would leave no time for WRT activities. Selecting 2 hours ignores WRT entirely. Selecting 3.5 hours exceeds the RTO constraint.
5. A forensic investigator uses Helix Windows Live tools to examine a compromised system and needs to reveal the database password of a password-protected MDB file created with Microsoft Access. Which tool should the investigator use? (Select one!)
Explanation
Access Pass View is the Helix Windows Live tool specifically designed to reveal database passwords for password-protected MDB files created using Microsoft Access or Jet Database Engine. This is a commonly tested tool-specific question on the EDRP exam. Asterisk Logger is a password recovery tool for revealing passwords hidden behind asterisks in dialog boxes, not for database files. Galleta is a cookie analysis tool used for examining browser cookies during forensic investigations. FAU is a Forensic Analysis Utility for general forensic tasks, not specifically for Access database password recovery.
EC-Council lists 150 multiple-choice questions and four hours.
EC-Council sets cut scores per exam form and does not publish one for EDRP. Its programs cite ranges of roughly 60% to 85%, and the exact score is shown in the exam portal.
An exam voucher is $450. Self-study candidates also pay a $100 non-refundable eligibility fee, and a retake voucher is $249.
Yes. You need two years of information-security experience and an approved eligibility application.
EC-Council now lists v4 courseware, while a v3 retake voucher is still sold. Confirm the version in your booking, and note that the code 312-76 appears mostly on third-party sites.
EC-Council certifications run on a three-year cycle renewed with 120 EC-Council Education credits and an annual membership fee. Check the live ECE policy page for the current fee.
EC-Council Certified Incident Handler (ECIH)
ECIH · 590 questions
Certified Network Defender (CND)
CND · 562 questions
Computer Hacking Forensic Investigator (CHFI)
CHFI · 589 questions
Certified Cybersecurity Technician (CCT)
212-82 · 630 questions
EC-Council Certified DevSecOps Engineer (ECDE) v2
ECDE · 609 questions
Digital Forensics Essentials (DFE)
DFE · 626 questions
$17.99
One-time access to this exam