CISA Practice Question: Information Systems Operations and Business Resilience
An IS auditor is reviewing an organization's disaster recovery plan (DRP) for its primary data center. The DRP specifies a reciprocal arrangement with a partner organization for backup processing. Which of the following is the MOST significant risk associated with this arrangement that the auditor should highlight?
⚠ Common exam trap
The trap here is focusing on technical compatibility or legal issues as the primary risk, when the most critical weakness of reciprocal agreements is the unguaranteed availability of the partner's resources during a widespread disaster.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The partner may not have sufficient capacity to handle the organization's workload during a simultaneous disaster.
A reciprocal disaster recovery arrangement depends on the partner's ability to provide processing capacity when needed. The most significant risk is that the partner may also be affected by the same disaster or may not have enough spare capacity to handle both organizations' workloads simultaneously. This can lead to failure of the DRP. Compatibility, legal enforceability, and security are important but secondary to the fundamental availability risk. The auditor should prioritize highlighting the capacity risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The partner may not have adequate security controls to protect the organization's data.
Why it's wrong here
Security is a critical consideration, but in a reciprocal arrangement, the partner is typically a trusted entity with similar security requirements. The auditor would still need to assess security, but the most significant risk is the availability of resources during a disaster. Security breaches can be mitigated through confidentiality agreements and audits, whereas capacity limitations during a disaster directly impact recovery capability.
- ✓
The partner may not have sufficient capacity to handle the organization's workload during a simultaneous disaster.
Why this is correct
Reciprocal agreements rely on the assumption that the partner's facility will be available and have spare capacity. However, if both organizations are affected by the same disaster (e.g., regional event), the partner may be unable to accommodate the additional load. This is a critical risk because it can render the DRP ineffective precisely when needed. The auditor should emphasize this as the most significant concern.
- ✗
The partner may not have compatible hardware and software configurations.
Why it's wrong here
While compatibility is a valid concern, it can be addressed through contractual requirements and periodic testing. It is typically less severe than the risk of capacity shortage during a simultaneous disaster. In a reciprocal arrangement, the primary risk is that the partner's resources are not guaranteed, especially under concurrent stress. Compatibility issues are usually mitigated through detailed planning and testing, making them less significant.
- ✗
The arrangement may not be legally enforceable without a formal contract.
Why it's wrong here
Legal enforceability is important, but a reciprocal arrangement is often informal. However, even with a contract, the partner may be unable to perform during a disaster. The auditor's primary concern should be operational feasibility, not just legal enforceability. While the lack of a formal contract increases risk, it is not the most significant risk compared to the potential inability to provide services during a disaster.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.