@Broulaye Samake Correct Answer: B. Tabletop the revised plan with the business owners Explanation (CISSP logic): The clues are "rewritten after a cloud migration", "never exercised", and "full production failover as proof". Recovery testing climbs a ladder: read-through, tabletop, walkthrough, simulation, parallel, full interruption, and each rung exists to catch the errors the previous one would turn into an outage. A plan nobody has exercised on paper almost certainly has wrong contacts, wrong dependencies, and recovery objectives the business never agreed to, and the cheapest place to find that out is around a table. Assess before you act: prove the plan is coherent before you bet production on it. Breakdown: A. A full interruption test produces the strongest evidence and the audit clock is real. But running it on an unexercised plan risks a self inflicted outage, and an audit finding for a failed failover is worse than one for an untested plan. B. ✅ Correct. A tabletop costs a few hours, validates roles, sequence, dependencies and recovery targets with the people who own the processes, and produces documented evidence the regulator will accept as the first step of a testing program. Every heavier test builds on it. C. The strong distractor. Restorable backups are the foundation of any recovery and this check belongs early in the testing program. But it validates one technical component in isolation, not whether the plan around it can actually bring the business back, and it is a test the tabletop will schedule anyway. D. Asking for an extension is honest and sometimes necessary. But it is a negotiation, not a control, and 45 days is enough to run the early rungs of the ladder and show the regulator a plan under active testing. Think like a manager: A recovery plan is tested on paper before it is tested on production.