Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

A hospital's data centre uses a generator and an uninterruptible power supply (UPS) to protect clinical systems. During a walkthrough, the IS auditor observes that the UPS batteries have never been load-tested and the generator is exercised monthly without transferring the load. Which conclusion is MOST appropriate?

⚠ Common exam trap

The trap here is accepting the existence of redundant power equipment as assurance of effectiveness without evidence that it has been tested under load.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The effectiveness of the power protection controls cannot be confirmed, and load testing of the UPS and generator should be performed.

The presence of a UPS and generator demonstrates design intent but not operating effectiveness. Battery capacity degrades silently, and a generator exercised without load transfer may fail at the automatic transfer switch or under full demand. The auditor should conclude that effectiveness is unconfirmed and recommend documented load testing of both the UPS batteries and the generator with actual load transfer, since these controls protect clinical systems where downtime affects patient safety.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The power protection controls are designed adequately, and monthly generator exercise satisfies the requirement for resilience testing.

    Why it's wrong here

    Monthly no-load generator exercise only proves the engine starts; it does not confirm the generator can carry the critical load or that automatic transfer switches function under demand. Untested UPS batteries may fail within minutes of an outage, so the design cannot be considered adequately verified. Concluding that the controls are adequate ignores the absence of evidence that either component performs when actually needed.

  • ✗

    The controls provide reasonable assurance because two independent power sources exist for the clinical systems.

    Why it's wrong here

    Redundancy in design does not equal effectiveness in operation; a second source that has never been proven under load provides little assurance. Both the UPS and the generator are unverified, so the presumed independence is untested. An auditor cannot accept redundancy as a mitigating control without evidence of periodic functional testing, especially where clinical systems have life-safety implications.

  • ✓

    The effectiveness of the power protection controls cannot be confirmed, and load testing of the UPS and generator should be performed.

    Why this is correct

    Without battery load testing and a generator test that actually transfers the critical load, there is no evidence the protection works during a real outage. The auditor's conclusion should be that control effectiveness is unverified, and the recommendation is periodic load testing with documented results. This directly addresses the gap rather than assuming design adequacy from the presence of equipment.

  • ✗

    The UPS and generator are compensating controls, so the absence of testing is not a reportable condition.

    Why it's wrong here

    Compensating controls still require evidence of operating effectiveness; their role as backup does not exempt them from testing. Because these devices protect life-critical clinical systems, an untested state is a significant reportable condition. Treating them as exempt would leave the organization with no assurance that an outage would not interrupt patient care.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.