CISA Practice Question: Information Systems Operations and Business Resilience
An IS auditor is reviewing the backup strategy for a financial institution's core transaction processing system. The system processes high volumes of transactions continuously and requires a recovery point objective (RPO) of 5 minutes. The current strategy includes nightly full backups and hourly incremental backups. Which of the following should the auditor recommend as the MOST appropriate improvement?
⚠ Common exam trap
The trap here is assuming that more frequent traditional backups (e.g., every 15 minutes) can meet a very low RPO, when in fact only continuous or near-continuous replication technologies can achieve RPOs of 5 minutes or less.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement continuous data protection (CDP) with journaling to capture every transaction.
The core transaction system requires an RPO of 5 minutes, meaning no more than 5 minutes of data can be lost. Nightly full and hourly incremental backups leave up to 60 minutes of data at risk. Continuous data protection captures every change, enabling recovery to within seconds or minutes, thus meeting the RPO. Increasing incremental frequency to 15 minutes still exceeds the RPO, and other options are even less frequent. CDP is the only viable solution among the choices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform full backups twice daily instead of nightly.
Why it's wrong here
Full backups twice daily would still leave a potential data loss window of up to 12 hours, far exceeding the 5-minute RPO. Full backups are resource-intensive and do not provide the granularity needed for continuous transaction processing. This option does not address the core requirement of minimal data loss and is therefore inadequate for the scenario.
- ✗
Increase the frequency of incremental backups to every 15 minutes.
Why it's wrong here
Even with 15-minute incrementals, the RPO would be up to 15 minutes, which exceeds the required 5 minutes. The scenario specifies an RPO of 5 minutes, so this frequency still fails to meet the objective. While it improves on hourly backups, it is not sufficient to satisfy the recovery requirement, making it a less appropriate recommendation than a solution that can achieve sub-5-minute RPO.
- ✗
Implement snapshot-based backups every 30 minutes.
Why it's wrong here
Snapshots every 30 minutes would result in an RPO of up to 30 minutes, which is six times the required 5 minutes. Although snapshots can be taken frequently, the interval specified does not meet the recovery point objective. Additionally, snapshots alone may not provide application-consistent backups for a transaction processing system, so this recommendation is insufficient.
- ✓
Implement continuous data protection (CDP) with journaling to capture every transaction.
Why this is correct
CDP captures changes continuously or near-continuously, enabling recovery to any point in time with minimal data loss. With an RPO of 5 minutes, hourly incrementals are insufficient. CDP can achieve an RPO of seconds or minutes, meeting the requirement. This is the most appropriate recommendation because it directly addresses the gap between the current backup frequency and the required RPO.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.