CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 1207


Which of the following should be of GREATEST concern to an IS auditor reviewing a report of an unsuccessful disaster recovery test?

Show Answer
Correct Answer: C

The disaster recovery procedures not being up to date should be of greatest concern to an IS auditor. Updated procedures are fundamental as they ensure the plan aligns with current business processes, technologies, and threat landscapes. Without up-to-date procedures, even a well-executed recovery test could fail due to steps or information being obsolete, leading to an ineffective response in the event of an actual disaster.

Discussion

3 comments
Sign in to comment
MJORGEROption: A
Mar 3, 2024

A. A root cause analysis was not performed. When a disaster recovery test fails, it's crucial to conduct a root cause analysis to understand why the test was unsuccessful.

MJORGER
Apr 26, 2024

C is right.

a84nOption: A
May 6, 2024

Answer A while the lack of up-to-date disaster recovery procedures (option C) is a concern, addressing the root causes of the unsuccessful test (option A) takes precedence as the GREATEST concern for an IS auditor to ensure that future disaster recovery tests are successful and the organization's resilience to disruptions is strengthened.

SwallowsOption: A
May 28, 2024

The absence of a root cause analysis poses a greater risk as it may indicate systemic issues that need to be addressed to improve the effectiveness of the disaster recovery program. Therefore, option A is likely of greatest concern to an IS auditor reviewing a report of an unsuccessful disaster recovery test.