CISA Protection of Information Assets Practice Question
An IS auditor is reviewing the incident response (IR) process. Which of the following is the BEST way to test the effectiveness of the IR plan?
⚠ Common exam trap
CISA often tests the difference between reviewing documentation (policies, procedures) and actually testing a plan — candidates pick 'reviewing IR policies' because it sounds thorough, but the question asks for the BEST way to TEST effectiveness, which requires an exercise like a tabletop.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conducting a tabletop exercise
A tabletop exercise is the best way to test the effectiveness of an incident response plan because it simulates a realistic incident scenario and requires the IR team to walk through their roles, decisions, and communications in a facilitated discussion. This reveals gaps in the plan, unclear responsibilities, and coordination breakdowns without the risk or cost of a live simulation. It directly tests whether the plan works in practice, not just whether it exists on paper.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Checking the availability of forensic tools
Why it's wrong here
Availability of forensic tools shows only that tooling exists, not that the plan works under real incident conditions. It is tempting because forensic readiness genuinely underpins evidence handling, and auditing tool inventories is valid when the question asks about IR capability or preparedness rather than plan effectiveness.
- ✗
Interviewing the IR team
Why it's wrong here
Interviews reveal team members' perceptions and claimed knowledge, not demonstrated performance under incident pressure. It is tempting because interviewing is a core audit evidence-gathering technique, and it would be appropriate if the question asked about awareness, roles and responsibilities, or the adequacy of training coverage.
- ✓
Conducting a tabletop exercise
Why this is correct
A tabletop exercise walks participants through a simulated incident, testing decision-making, roles, communication and plan completeness without production disruption. This validates the IR plan's effectiveness against the stem's requirement, unlike reviewing documentation, which only confirms the plan exists.
- ✗
Reviewing IR policies and procedures
Why it's wrong here
Reviewing documented policies and procedures confirms what is written down, not whether the plan functions during an actual incident. It is tempting because documentation review is a legitimate audit technique, and it would be the correct choice if the question asked whether the IR plan aligns with standards or contains required elements.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.