Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IS auditor is evaluating the IT service continuity plan for a hospital's electronic health record (EHR) system. The auditor finds that the plan includes a recovery time objective (RTO) of 4 hours, but the hospital's clinical staff state that they can tolerate only 1 hour of downtime before patient safety is compromised. Which of the following should the auditor recommend FIRST?

⚠ Common exam trap

The trap here is jumping to technical solutions like backups or clustering without first correcting the misaligned RTO, which is the root cause of the mismatch between the plan and business needs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Revise the RTO to align with the clinical requirement and reassess the recovery strategy.

The RTO in the plan is 4 hours, but clinical staff require no more than 1 hour of downtime. The auditor should first recommend revising the RTO to reflect the true business requirement, then reassess whether the recovery strategy can meet that RTO. Without this alignment, any subsequent technical improvements may be misdirected. The RTO is a business-driven metric and must be accurate before designing recovery solutions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conduct a full interruption test to validate the current recovery capabilities.

    Why it's wrong here

    Testing is important, but the scenario already reveals a mismatch between the documented RTO and the business requirement. Testing the current plan would only confirm it cannot meet the 1-hour requirement. The first step is to correct the RTO and reassess the strategy, not to test a plan that is already known to be inadequate.

  • ✓

    Revise the RTO to align with the clinical requirement and reassess the recovery strategy.

    Why this is correct

    The RTO in the plan does not match the business requirement identified by clinical staff. The auditor should first recommend that the RTO be corrected to reflect the actual tolerable downtime, and then the recovery strategy must be reassessed to ensure it can meet the new RTO. Aligning the RTO with business needs is the foundation for an effective continuity plan.

  • ✗

    Implement a redundant server cluster at the primary site to improve availability.

    Why it's wrong here

    A redundant cluster at the primary site improves local availability but does not address a site-wide disaster or major outage that requires recovery at an alternate site. The RTO of 1 hour likely requires a more robust solution such as a hot site or active-active configuration. Redundancy alone may not meet the RTO if the entire primary site is affected.

  • ✗

    Increase the frequency of data backups to reduce potential data loss.

    Why it's wrong here

    Increasing backup frequency addresses the recovery point objective (RPO), not the RTO. While data loss is important, the issue here is the time to restore service. Even with frequent backups, if restoration takes longer than 1 hour, patient safety is still at risk. The primary need is to align the RTO and ensure the recovery strategy can achieve it.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.