Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing the incident response (IR) process. Which of the following is the BEST way to test the effectiveness of the IR plan?

⚠ Common exam trap

CISA often tests the difference between reviewing documentation (policies, procedures) and actually testing a plan — candidates pick 'reviewing IR policies' because it sounds thorough, but the question asks for the BEST way to TEST effectiveness, which requires an exercise like a tabletop.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conducting a tabletop exercise

A tabletop exercise is the best way to test the effectiveness of an incident response plan because it simulates a realistic incident scenario and requires the IR team to walk through their roles, decisions, and communications in a facilitated discussion. This reveals gaps in the plan, unclear responsibilities, and coordination breakdowns without the risk or cost of a live simulation. It directly tests whether the plan works in practice, not just whether it exists on paper.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Checking the availability of forensic tools

    Why it's wrong here

    Availability of forensic tools shows only that tooling exists, not that the plan works under real incident conditions. It is tempting because forensic readiness genuinely underpins evidence handling, and auditing tool inventories is valid when the question asks about IR capability or preparedness rather than plan effectiveness.

  • ✗

    Interviewing the IR team

    Why it's wrong here

    Interviews reveal team members' perceptions and claimed knowledge, not demonstrated performance under incident pressure. It is tempting because interviewing is a core audit evidence-gathering technique, and it would be appropriate if the question asked about awareness, roles and responsibilities, or the adequacy of training coverage.

  • ✓

    Conducting a tabletop exercise

    Why this is correct

    A tabletop exercise walks participants through a simulated incident, testing decision-making, roles, communication and plan completeness without production disruption. This validates the IR plan's effectiveness against the stem's requirement, unlike reviewing documentation, which only confirms the plan exists.

  • ✗

    Reviewing IR policies and procedures

    Why it's wrong here

    Reviewing documented policies and procedures confirms what is written down, not whether the plan functions during an actual incident. It is tempting because documentation review is a legitimate audit technique, and it would be the correct choice if the question asked whether the IR plan aligns with standards or contains required elements.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.