Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IS auditor is reviewing the backup and restoration controls for a hospital's electronic health record (EHR) system, which runs on a relational database with a recovery point objective (RPO) of 15 minutes. The database administrator performs a full backup every Sunday at 01:00, differential backups nightly at 01:00, and transaction log backups every 15 minutes. During testing, the auditor observes that a restore of the database to a point in time at 14:07 on Wednesday completed successfully but took 9 hours, exceeding the stated maximum tolerable downtime (MTD) of 4 hours. Which TWO conclusions should the auditor draw from this observation? (Choose two.)

⚠ Common exam trap

The trap here is assuming that a successful restore proves the recovery strategy is adequate, when recovery time objectives and maximum tolerable downtime are separate requirements that a slow restore can violate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The recovery process should be re-engineered or supplemented so that restoration can be completed within the MTD.

The backup frequency meets the RPO, but the restore duration violates the MTD, revealing a gap between backup adequacy and actual recoverability. The auditor must recognize that a successful restore is not sufficient if it cannot be completed within the business tolerance. The appropriate conclusions are that the RPO is satisfied and that the recovery process must be improved to meet the MTD.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The recovery process should be re-engineered or supplemented so that restoration can be completed within the MTD.

    Why this is correct

    Because the restore succeeded but exceeded the 4-hour MTD, the recovery capability does not support the business requirement. The auditor should conclude that the recovery process needs redesign, such as using snapshot or replication technologies, faster storage, or parallel recovery, to bring restoration time within the MTD. This is the actionable control conclusion from the test.

  • ✗

    The transaction log backups should be replaced with hourly full backups to reduce the total restore time.

    Why it's wrong here

    Replacing transaction log backups with hourly full backups would increase the backup window, storage consumption, and restore complexity without necessarily reducing recovery time. Full backups are larger and do not provide point-in-time recovery granularity. The observed problem is restore duration, not backup type; the auditor should not recommend a change that worsens RPO granularity and resource usage.

  • ✗

    The differential backup strategy is the root cause of the lengthy restore because differential backups must be applied in sequence.

    Why it's wrong here

    Differential backups capture all changes since the last full backup and require only the latest differential plus the full backup to restore, unlike incremental backups which must be applied in sequence. Therefore, differentials are not the cause of a 9-hour restore. Misidentifying the backup type as the root cause would direct remediation incorrectly and leave the actual restore performance issue unresolved.

  • ✗

    The restore should be considered a failure of the backup integrity controls because the elapsed time exceeded the MTD.

    Why it's wrong here

    Restore duration is a performance and recovery capability issue, not a backup integrity failure. Integrity controls verify that backup data is complete, uncorrupted, and restorable, which this test actually demonstrated by completing successfully. Equating slow recovery with integrity failure misclassifies the finding and could lead to inappropriate corrective actions focused on media verification rather than recovery time improvement.

  • ✓

    The backup schedule satisfies the RPO but the restoration time indicates the MTD cannot be met with the current recovery strategy.

    Why this is correct

    The 15-minute transaction log backups align with the 15-minute RPO, so data loss exposure is acceptable. However, a 9-hour restore exceeds the 4-hour MTD, meaning the recovery strategy fails to meet business resilience requirements. The auditor should conclude the restore process, not the backup frequency, is the control gap requiring remediation such as faster media, parallel restore, or database replication.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.