Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing the backup strategy for a transactional database that processes customer orders. The database is backed up nightly with full backups, and transaction log backups occur every 15 minutes. The recovery point objective (RPO) for the system is 5 minutes. Which of the following is the MOST significant finding the auditor should report?

⚠ Common exam trap

The trap here is comparing the nightly full backup to the RPO and overlooking that the transaction log interval, not the full backup frequency, governs how much data can be lost.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The backup schedule cannot meet the stated recovery point objective.

The RPO defines the maximum tolerable data loss, and the transaction log interval determines how much committed data could be lost in a failure. With log backups every 15 minutes, the system can lose up to 15 minutes of transactions, which exceeds the 5-minute objective. The auditor should report this mismatch between configured backup frequency and the stated business requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The backup schedule cannot meet the stated recovery point objective.

    Why this is correct

    The transaction log backups run every 15 minutes, but the RPO requires no more than 5 minutes of data loss. In a failure between log backups, up to 15 minutes of committed transactions could be lost, exceeding the objective. This is a direct mismatch between the configured backup frequency and the business requirement, making it the most significant finding.

  • ✗

    Nightly full backups consume excessive storage capacity.

    Why it's wrong here

    Storage consumption is an operational efficiency concern, not a failure to meet a stated recovery requirement. The scenario provides no evidence that capacity is constrained or that retention is problematic. Raising this as the most significant finding would distract from the clear gap between the 15-minute log interval and the 5-minute recovery point objective.

  • ✗

    Transaction log backups are not encrypted at rest.

    Why it's wrong here

    Encryption of backups is a legitimate control consideration, but the scenario does not state that encryption is absent or required, nor does it relate to the RPO gap. The auditor's most significant finding should address the demonstrated inability to meet the recovery requirement. This option introduces an unrelated control concern that is not supported by the facts provided.

  • ✗

    Full backups should be performed weekly instead of nightly.

    Why it's wrong here

    Reducing full backup frequency would lengthen recovery time and increase dependency on log replay, which does not help meet a 5-minute RPO. The problem is the interval between log backups, not the frequency of full backups. This recommendation addresses the wrong variable and would likely worsen recovery performance if implemented.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.