Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IT auditor is reviewing backup procedures. The organization performs daily full backups and retains them for 30 days. Additionally, weekly backups are retained for 12 months. Which of the following is the MOST likely risk associated with this backup strategy?

⚠ Common exam trap

The trap is focusing on recovery or encryption issues when the most evident risk of frequent full backups is resource consumption; candidates may overlook the operational impact of storage and backup windows.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Excessive storage consumption and longer backup windows

The backup strategy performs daily full backups retained for 30 days and weekly backups retained for 12 months. This means that for each day, a full backup is stored, and additionally, weekly full backups are kept for a year. The most likely risk is excessive storage consumption because full backups are large and numerous, and longer backup windows because full backups take time to complete. This can strain storage capacity and backup infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Backup data may not be recoverable

    Why it's wrong here

    Recoverability depends on tested restores, media integrity and verification, none of which the stem describes; the schedule alone does not make data unrecoverable. This is the right concern when backups are never test-restored or verified.

  • ✗

    Inability to meet recovery point objectives

    Why it's wrong here

    Daily full backups give a recovery point of at most 24 hours, so the schedule itself satisfies typical RPOs; the stem names no tighter target. RPO shortfalls arise when backup frequency is longer than the tolerated data-loss window.

  • ✗

    Backup encryption may be weak

    Why it's wrong here

    Encryption strength is independent of the full-versus-weekly schedule and retention periods; nothing in the stem addresses cipher or key management. Encryption is the correct audit concern when backups traverse untrusted media or offsite storage without protection.

  • ✓

    Excessive storage consumption and longer backup windows

    Why this is correct

    Daily full backups retained 30 days, plus weekly fulls retained 12 months, duplicate data heavily. The dominant risk is storage exhaustion and lengthened backup windows, which can cause jobs to overrun their slots and threaten subsequent backup completion.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.