Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IS auditor is evaluating an organization's backup strategy for a critical database. The database is backed up nightly using a full backup, and transaction logs are backed up every 15 minutes. The auditor discovers that the transaction log backups are written to the same storage array as the database files. Which of the following is the MOST significant risk?

⚠ Common exam trap

The trap here is focusing on backup frequency or encryption instead of the physical separation of backups from primary data, which is essential for disaster recovery.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The transaction log backups may not be usable for point-in-time recovery if the storage array fails.

Storing transaction log backups on the same storage array as the database means a single failure could destroy both the primary data and the logs needed for point-in-time recovery. This creates an unacceptable risk of extended data loss and downtime. The most significant risk is the loss of recoverability, not backup performance, encryption, or RPO frequency, which are either not indicated or less critical in this scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The transaction log backups may not be usable for point-in-time recovery if the storage array fails.

    Why this is correct

    Storing transaction log backups on the same array as the database creates a single point of failure. If the array is lost, both the database and its log backups are destroyed, making point-in-time recovery impossible. This directly undermines the recoverability of the database and violates the principle of separating backups from primary data. The auditor should report this as a critical risk because it can lead to extended data loss and prolonged downtime.

  • ✗

    The recovery point objective (RPO) may not be met because transaction log backups are too infrequent.

    Why it's wrong here

    The transaction logs are backed up every 15 minutes, which likely meets a reasonable RPO. The scenario does not state that the RPO is unmet. The real risk is that these backups are stored on the same array as the database, so a single failure could destroy both. The frequency of backups is adequate; the storage location is the flaw. Therefore, this option misidentifies the root cause of the potential recovery failure.

  • ✗

    The nightly full backup may not complete within the backup window due to contention with transaction log backups.

    Why it's wrong here

    Contention is possible, but the scenario does not indicate that backups are failing or exceeding the window. The more severe risk is the loss of both primary and backup data if the storage array fails. While performance issues could affect backup completion, they are secondary to the catastrophic loss of recoverability. The auditor should prioritize the architectural flaw over potential scheduling conflicts.

  • ✗

    Transaction log backups may not be encrypted, exposing sensitive data if the storage array is compromised.

    Why it's wrong here

    Encryption is important, but the scenario does not mention a lack of encryption or a compromise. The critical issue is the co-location of backups with primary data, which risks total data loss. Even if encryption were missing, it would be a separate finding; here, the immediate risk is the inability to recover the database after a storage failure, making this option less relevant to the described situation.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.