CISA Practice Question: Information Systems Operations and Business Resilience
An IS auditor is reviewing the IT service continuity plan for a regional bank. The plan identifies a recovery time objective of 6 hours for the core banking system and designates a warm site with pre-installed hardware but no replicated data. The plan states that data will be restored from nightly backups stored in an offsite vault. Which of the following is the MOST critical issue the auditor should raise?
⚠ Common exam trap
The trap here is focusing on backup media security or redefining the RTO, rather than recognizing that a warm site without replicated data cannot realistically restore core banking within six hours.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The warm site lacks replicated data, so restoring from nightly backups may not meet the 6-hour recovery time objective.
The most critical issue is the inconsistency between the recovery strategy and the documented RTO. A warm site without replicated data requires rebuilding from backup media, a process that rarely completes within six hours and may also cause significant data loss. The auditor should raise this capability gap and recommend a strategy such as data replication or a hot site to meet the business requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The recovery time objective of 6 hours should be increased to align with the capabilities of a warm site.
Why it's wrong here
Adjusting the RTO to match site limitations inverts the correct approach: recovery objectives should be derived from business impact analysis, not from infrastructure convenience. Recommending a longer RTO would increase business disruption and potential regulatory exposure for a core banking system. The auditor should instead recommend improving recovery capability to meet the business-defined objective.
- ✓
The warm site lacks replicated data, so restoring from nightly backups may not meet the 6-hour recovery time objective.
Why this is correct
A warm site with pre-installed hardware but no replicated data requires restoring from offsite backups, which involves retrieving media, rebuilding systems, and replaying data. This process typically exceeds six hours and may also lose up to a day of transactions. The mismatch between the recovery strategy and the RTO is the most critical issue because it directly threatens the bank's ability to resume core operations within tolerance.
- ✗
The offsite vault storing nightly backups may not provide adequate physical security for backup media.
Why it's wrong here
Physical security of backup media is important, but the scenario does not indicate any security deficiency. The critical issue is whether the recovery strategy can achieve the stated RTO, not the vault's physical controls. Raising a security concern without evidence would distract from the fundamental capability gap between the warm site design and the six-hour recovery requirement.
- ✗
Nightly backups do not provide a sufficiently low recovery point objective for a core banking system.
Why it's wrong here
The scenario does not state the bank's recovery point objective, so declaring nightly backups inadequate for RPO is speculative. While a core banking system may require low data loss, the explicit and measurable mismatch is between the warm site restore approach and the six-hour RTO. The auditor should focus on the documented objective that the current strategy cannot satisfy.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.