CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 780


A disaster recovery plan (DRP) should include steps for:

Show Answer
Correct Answer: CD

A disaster recovery plan (DRP) should include steps for obtaining replacement supplies. This is a crucial aspect of ensuring continuity of operations following a disaster. While assessing and quantifying risks is important, it is generally a component of a broader Business Continuity Plan (BCP). The DRP focuses specifically on the logistics and procedures necessary to quickly recover from a disaster, thus obtaining replacement supplies directly addresses the immediate needs following a disruptive event.

Discussion

5 comments
Sign in to comment
ItsBananassOption: C
Jul 19, 2023

I think It's C.

3008Option: D
Aug 13, 2023

One of the key components of a DRP is assessing and quantifying risk. This involves identifying potential threats and vulnerabilities to the organization's critical systems and data, evaluating the likelihood and potential impact of these threats, and determining appropriate risk mitigation strategies. The risk assessment process should involve all relevant stakeholders, including IT staff, business leaders, and other key personnel. The assessment should consider a range of potential threats, including natural disasters, cyber attacks, power outages, and other disruptions. Once the risks have been identified and assessed, the organization can develop appropriate risk mitigation strategies, including backup and recovery procedures, redundant systems and data storage, and other measures to minimize the impact of a disaster

RachyOption: C
Jan 21, 2024

C. Obtaining replacement supplies is a key aspect that should be included in a disaster recovery plan

SwallowsOption: C
Mar 17, 2024

Risk assessment and quantification should be done as a BCP, not a DRP; the DRP should plan and train procedures for obtaining replacement supplies for disaster recovery.

SwallowsOption: D
Jul 21, 2024

I'll correct the answer. While option C (obtaining replacement supplies) might be relevant in certain types of disasters (such as natural disasters that damage physical infrastructure), it is not as fundamental to a disaster recovery plan as assessing and quantifying risk. Risk assessment forms the foundation for determining the scope, priorities, and strategies of the DRP. Therefore, including steps for assessing and quantifying risk (option D) is a critical component of a comprehensive Disaster Recovery Plan (DRP).