EDRP logo
Focused certification exam prep
Start practice

EDRP Exam Domains 2026: Complete Guide to All 10 Content Areas

TL;DR
  • EDRP v4 (exam 312-76) has 150 multiple-choice questions, 4 hours, and a 70% passing score across 10 domains.
  • Risk Assessment, Business Impact Analysis and Disaster Recovery Planning each carry 12%, or 18 questions apiece.
  • Domains 1, 9 and 10 carry 8% each, so they are lighter but still worth about 12 questions each.
  • The v4 blueprint adds AI, governance and organizational resilience; older v3 topic lists should not guide your study.

How the EDRP v4 Blueprint Is Built

The EC-Council Disaster Recovery Professional (EDRP) exam is organized around a ten-domain blueprint that follows the natural lifecycle of a resilience program: establish the foundations, understand the organization's risk and impact exposure, write the plans, build the technical recovery capability, then activate and rehearse everything. If you read the domains in order, you are essentially reading the story of how an organization goes from "we have no plan" to "we have a tested, trained, living recovery capability."

The official scope document is the EC-Council Disaster Recovery Professional Version 4 Exam Blueprint, currently linked from EC-Council's EDRP certification page. Treat that PDF as the authority. This article explains each domain, how it tends to show up on the test, and where candidates commonly lose points. If you are still orienting yourself to the credential, start with What Is EDRP Certification? and come back here once the basics are clear.

One point worth stating up front: the current v4 blueprint includes AI, governance and organizational resilience themes. Older v3 topic lists and domain weights are version-specific and should not be mixed with v4 preparation. If a third-party outline does not mention governance, resilience or the v4 structure, verify it against the official blueprint before trusting it.

Domain Weights at a Glance

The exam delivers 150 multiple-choice questions, so each percentage translates directly into a question count. The table below shows the official weights and the approximate number of questions each domain contributes.

DomainNameWeightApprox. Questions
1Foundations of Business Continuity and Disaster Recovery8%12
2Business Continuity Management10%15
3Risk Assessment12%18
4Business Impact Analysis12%18
5Business Continuity Plan10%15
6Disaster Recovery Planning12%18
7Data Backup and System Recovery10%15
8Disaster Recovery Plan Development10%15
9Business Continuity and Disaster Recovery Plan Activation8%12
10Business Continuity and Disaster Recovery Plan Activation Test, Training, and Exercise8%12
Where the points concentrate: Domains 3, 4 and 6 together account for 36% of the exam, or 54 questions. They are also tightly linked: the risk assessment feeds the business impact analysis, and both feed disaster recovery planning. Mastering how these three connect pays off far beyond the individual domain boundaries.

Notice that no single domain dominates. The spread is deliberately even, which means you cannot compensate for a weak domain by over-studying a strong one. With a 70% passing score, you need broad competence rather than narrow expertise. For deeper analysis of how the cut score plays out in practice, see EDRP Passing Score 2026: Exactly What You Need to Pass.

Domains 1-2: Foundations and Business Continuity Management

Domain 1: Foundations of Business Continuity and Disaster Recovery (8%)

This domain sets the vocabulary the rest of the exam assumes. Expect questions that test whether you can distinguish closely related terms and place each in its proper context.

  • The difference between business continuity (keeping critical functions running) and disaster recovery (restoring technology and data after a disruption)
  • Types of disruptions and disasters: natural, human-caused, technological and pandemic-style events
  • Core recovery concepts such as recovery time objective (RTO), recovery point objective (RPO) and maximum tolerable downtime
  • The role of standards, frameworks and regulatory drivers in shaping a continuity program

Although it is among the lighter domains, Domain 1 is the one candidates are most tempted to skim, and that is a mistake. The exam writes scenario questions in later domains using these terms precisely. If you blur the line between an RTO and an RPO here, you will misread questions in Domains 4, 6 and 7.

Domain 2: Business Continuity Management (10%)

Where Domain 1 defines the concepts, Domain 2 is about running continuity as a managed, ongoing program. This is where v4's governance and organizational resilience emphasis becomes visible.

  • Establishing program governance: executive sponsorship, policy, roles, responsibilities and steering structures
  • Defining program scope, objectives and how continuity aligns with business strategy
  • The program lifecycle and continual improvement, including how lessons learned feed back into the program
  • Organizational resilience as a broader goal than recovering from any single incident

Questions here often present a governance gap, such as a program without executive backing or unclear ownership, and ask for the most appropriate corrective action. Think like a program manager, not just a technician.

Domains 3-4: Risk Assessment and Business Impact Analysis

Domain 3: Risk Assessment (12%)

This is one of the three heaviest domains at 18 questions. It covers how an organization identifies, analyzes and treats the threats that could trigger a disaster.

  • Identifying assets, threats and vulnerabilities, and understanding how they combine into risk
  • Qualitative versus quantitative analysis and when each is appropriate
  • Risk treatment options: accept, avoid, transfer and mitigate
  • Documenting results in a risk register and communicating them to decision-makers

A reliable pattern on this exam is the "best next step" question: a scenario describes a partially completed assessment and asks what should happen next. Knowing the sequence of the risk process is worth more than memorizing definitions in isolation.

Domain 4: Business Impact Analysis (12%)

The BIA is the analytical backbone of the whole exam. It determines which business functions matter most, how quickly they must be restored, and what dependencies they rely on.

  • Identifying critical business functions and the processes, people, applications and facilities that support them
  • Estimating financial and operational impact over time as an outage continues
  • Setting recovery priorities and deriving RTOs and RPOs from impact findings
  • Mapping interdependencies, including third-party and supply-chain dependencies
Risk assessment versus BIA: A frequent point of confusion is that risk assessment asks "what could go wrong and how likely is it?" while the BIA asks "if it does go wrong, what do we lose and how fast?" Likelihood belongs to the former; impact over time and recovery priority belong to the latter. Exam distractors often swap the two.

Because these two domains total 36 questions, they deserve more study time than their individual weights suggest. If you want a realistic sense of how demanding this material feels, How Hard Is the EDRP Exam? Complete Difficulty Guide 2026 covers where candidates typically struggle.

Domains 5-6: Business Continuity Plan and Disaster Recovery Planning

Domain 5: Business Continuity Plan (10%)

With the BIA complete, the organization writes the business continuity plan (BCP): the document that keeps critical functions operating during a disruption.

  • BCP structure and contents: purpose, scope, assumptions, roles, communication procedures and recovery strategies
  • Continuity strategies such as alternate work sites, work-from-home provisions, manual workarounds and supplier alternatives
  • Crisis management and communication planning, including internal and external stakeholder messaging
  • Emergency response and the protection of people as the first priority

Domain 6: Disaster Recovery Planning (12%)

At 18 questions, this is the third of the heaviest domains. It concentrates on the technology side: how IT services and infrastructure are recovered in line with the priorities the BIA established.

  • Recovery strategies for infrastructure, applications, networks and data
  • Recovery site models: hot, warm, cold and mobile sites, and the cost-versus-speed trade-offs between them
  • Cloud and hybrid recovery approaches, which the current EC-Council preparation program explicitly addresses
  • Aligning recovery architecture to RTO and RPO targets

Candidates frequently mix up the BCP and the disaster recovery plan. A useful mental model: the BCP is organized around business functions and people; the DRP is organized around systems and infrastructure. Both are driven by the same BIA, and the exam rewards you for knowing which document answers which question.

Domains 7-8: Data Backup, System Recovery and DR Plan Development

Domain 7: Data Backup and System Recovery (10%)

This is the most hands-on technical domain, though the exam tests understanding of principles rather than vendor-specific commands.

  • Backup types: full, incremental and differential, and how each affects backup windows and restoration speed
  • Backup media, storage locations, offsite and cloud storage, and replication concepts
  • Retention policies, backup verification and restoration testing
  • System recovery approaches, from rebuilding systems to restoring from images and failing over to standby environments
A classic trap: Many candidates remember that incremental backups are small and fast but forget the consequence at restore time: you need the last full backup plus every incremental since. Differential backups need only the last full backup plus the latest differential. Expect scenario questions that make you reason through restore sequences.

Domain 8: Disaster Recovery Plan Development (10%)

Domain 6 covers planning concepts; Domain 8 covers turning them into a working, documented plan.

  • Plan structure: scope, objectives, recovery team roles, contact lists, escalation paths and recovery procedures
  • Documenting step-by-step recovery runbooks that someone unfamiliar with the system could follow under stress
  • Plan approval, version control and distribution, including keeping copies accessible if primary systems are down
  • Maintenance: updating the plan after infrastructure, personnel or business changes

The emphasis here is practical. A plan that exists but cannot be found, understood or executed during a crisis is a plan that fails. Questions often hinge on small but realistic details, such as where the plan is stored or who is authorized to declare a disaster.

Domains 9-10: Activation, Testing, Training and Exercises

Domain 9: Business Continuity and Disaster Recovery Plan Activation (8%)

This domain covers the moment of truth: deciding to invoke the plans and carrying out the response.

  • Activation criteria and who has the authority to declare an incident or disaster
  • Notification and escalation procedures, and activating the crisis and recovery teams
  • Managing the response, coordinating communications and tracking recovery progress
  • Stand-down, return to normal operations and post-incident review

Domain 10: Business Continuity and Disaster Recovery Plan Activation Test, Training, and Exercise (8%)

The final domain closes the loop: a plan is only credible if it has been tested and the people who must execute it have been trained.

  • Exercise types, from document reviews and walkthroughs to tabletop exercises, simulations and full-scale tests
  • Designing test objectives, scenarios and success criteria
  • Awareness and role-based training for staff and recovery teams
  • Capturing results, tracking corrective actions and feeding findings back into plan maintenance

Know the progression of exercise types and what each one validates. A tabletop discusses decisions; a full-scale exercise stresses actual recovery capability. Questions often describe an exercise and ask you to identify its type or to recommend the right level of exercise for a given maturity stage.

Sequencing the Domains Across Your Prep

Rather than studying the domains in a flat list, sequence them to match how the content builds on itself. The framework below is a suggested ordering tied to the blueprint's dependencies, not a prescription. Adjust it to the time you have. The official preparation program is a 5-day live course, which is separate from exam time, so your self-paced schedule should be sized to your own pace and background.

Phase 1

Vocabulary and governance

  • Domains 1 and 2: lock down the terminology and program governance concepts
  • Write out RTO, RPO and maximum tolerable downtime in your own words
Phase 2

The analytical core

  • Domains 3 and 4: risk process sequence and BIA workflow
  • Practice distinguishing likelihood questions from impact questions
Phase 3

Plans and technical recovery

  • Domains 5 through 8: BCP, DR planning, backup and recovery, plan development
  • Work through backup-restore sequences and recovery site trade-offs by hand
Phase 4

Execution and validation

  • Domains 9 and 10: activation procedures and exercise types
  • Take mixed-domain practice sets and review every miss against the blueprint

For a fuller preparation plan, the EDRP Study Guide 2026: How to Pass on Your First Attempt goes deeper on resources and pacing, and the EDRP Cheat Sheet 2026: One-Page Review of Must-Know Facts is useful for final-week consolidation. To test your recall under realistic conditions, use the EDRP practice tests.

Exam Mechanics That Shape Domain Strategy

Understanding the delivery format helps you decide how to prepare. The EDRP v4 exam (312-76) consists of 150 multiple-choice questions to be completed in 4 hours, with a passing score of 70%. That works out to a little over 1.5 minutes per question on average, which is generous for recall questions but tighter for long scenario items, so plan to move quickly through definitions and bank time for scenarios.

The exam is delivered through the ECC Exam Center and ECC Exam Portal with remote proctoring by the RPS team. Under RPS conditions, the exam is closed book. Calculators, reference notes and assistance websites or software are prohibited. You need a webcam and a single monitor, and you may use one pen or pencil and two scratch sheets, which are destroyed after the exam. Because you cannot consult notes, the domains that involve sequences and frameworks, such as the risk process, the BIA steps and the backup restore chain, are worth committing to memory and rehearsing on paper.

Key Takeaway

Use your scratch sheets deliberately. Before answering anything, you can jot down the frameworks you tend to forget, such as the sequence of risk assessment steps or the restore requirements for each backup type, then reference them throughout the exam. Practice this habit in your timed practice sessions so it is automatic on exam day.

On eligibility and cost, the picture depends on your route. Official EC-Council training or an official courseware bundle is a qualifying route. Independent self-study applicants need 2 years of information-security experience, a supervisor or department-lead verifier, a USD 100 nonrefundable eligibility application and EC-Council approval, and approved applicants must purchase their voucher within 3 months. The RPS voucher is USD 450, nontransferable and valid for one year from release, and an approved retake voucher is USD 249, subject to EC-Council retake approval and policy. EC-Council states the application fee is included in official training fees, and the separately listed e-courseware price is study material rather than the exam fee. For the full breakdown, see EDRP Certification Cost 2026: Complete Pricing Breakdown and EDRP Requirements 2026: Eligibility, Prerequisites & How to Qualify.

After you pass, the credential is maintained through 120 Continuing Professional Education credits within a 3-year cycle plus USD 80 in annual continuing education fees. If you are weighing the long-term value of that commitment, Is the EDRP Certification Worth It? Complete ROI Analysis 2026 lays out the considerations.

Frequently Asked Questions

How many domains are on the EDRP v4 exam?

There are 10 official content domains, running from Foundations of Business Continuity and Disaster Recovery through Business Continuity and Disaster Recovery Plan Activation Test, Training, and Exercise. Together they cover 150 multiple-choice questions.

Which EDRP domains carry the most weight?

Risk Assessment, Business Impact Analysis and Disaster Recovery Planning each carry 12%, or 18 questions. The lightest domains are Foundations, Plan Activation, and Test, Training and Exercise at 8% each.

Do older EDRP v3 study materials still apply to the v4 exam?

Only partially. The v4 blueprint includes AI, governance and organizational resilience content, and older v3 topic lists and weights are version-specific. Always check any outline against the official v4 blueprint published by EC-Council before relying on it.

What score do I need to pass, and can I bring notes?

The passing score is 70%. The exam is closed book under remote proctoring: calculators, reference notes and assistance websites or software are prohibited, though one pen or pencil and two scratch sheets are allowed and destroyed afterward.

Where can I learn more about the credential and the careers it supports?

For background, see What Is EDRP?, and for the employment side, EDRP Jobs and the EDRP Salary Guide 2026: Complete Earnings Analysis. When you are ready to test your knowledge across all ten domains, try the practice exams at EDRP Exam Prep.

Ready to pass your EDRP exam?

Put this into practice with free EDRP questions across every exam domain.