Courseiva
Governance and Management of ITmediumMultiple ChoiceObjective-mapped

CISA Governance and Management of IT Practice Question

A company's IT governance policy requires that all critical systems have a documented business continuity plan (BCP). During an audit, an IT auditor finds that the BCP for a critical financial system has not been updated in three years. Which of the following is the BEST recommendation?

⚠ Common exam trap

Many exam-takers assume a stable system means the BCP remains valid, but CISA tests the principle that BCPs must be living documents reviewed and tested at regular intervals (typically annually) regardless of system stability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Update the BCP to reflect current processes and conduct a test.

IT governance policies require that BCPs remain current to reflect actual operational processes. An outdated BCP (three years stale) may contain obsolete recovery procedures, contact information, or dependencies, rendering it ineffective during a real incident. Updating the BCP and then testing it validates that the documented steps align with the current system architecture and can be executed successfully, which is a core requirement of the BCP lifecycle per ISACA guidelines.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Archive the outdated BCP and develop a new one from scratch.

    Why it's wrong here

    Archiving does not solve the need for an updated plan.

  • Update the BCP to reflect current processes and conduct a test.

    Why this is correct

    Updating and testing ensures the plan is viable and aligns with governance requirements.

  • Accept the risk because the system has been stable.

    Why it's wrong here

    Risk acceptance is not appropriate; governance requires current plans.

  • Implement a new system with built-in redundancy.

    Why it's wrong here

    Replacing the system is an overreaction and costly.

About these practice questions

This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.