Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An organization has implemented a business continuity plan (BCP) and disaster recovery plan (DRP). During a recent full interruption test, the IT team discovered that the recovery time objective (RTO) for a critical application was not met. What is the MOST likely reason for this failure?

⚠ Common exam trap

A common mix-up: candidates confuse RTO with RPO or assume procedural gaps (like missing a tabletop exercise) are the root cause, when the actual failure is a technical capacity limitation at the alternate site.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The alternate site did not have adequate processing capacity to handle the workload.

The most likely reason the RTO was not met is that the alternate site lacked sufficient processing capacity to handle the workload. RTO measures the time to restore service availability; if the failover site cannot support the required compute, memory, or I/O throughput, restoration will be delayed or fail outright. This is a common capacity planning failure in DR testing, where the alternate site is sized for minimal operations but not for the full production load.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The recovery point objective (RPO) was set too low, causing data loss.

    Why it's wrong here

    RPO governs tolerable data loss, not elapsed recovery duration, so lowering it cannot cause an RTO breach. It is tempting because RPO and RTO are paired recovery objectives, and tightening RPO would be the right action when the requirement is reducing how much data may be lost after an outage.

  • ✗

    The backup data was not encrypted, leading to corruption during restoration.

    Why it's wrong here

    Encryption protects confidentiality; it does not corrupt backups during restoration, so it cannot explain missed RTO. It is tempting because encryption is a standard backup control, and it would be the correct focus when the requirement is protecting backup media against unauthorised disclosure rather than meeting a recovery time target.

  • ✗

    The tabletop exercise was not conducted before the full interruption test.

    Why it's wrong here

    A tabletop exercise validates plans and roles but does not measure actual restoration speed, so skipping it cannot itself cause the RTO miss. It is tempting because tabletops precede full interruption tests, and one would be correct when the requirement is rehearsing decision-making and communication without invoking live recovery.

  • ✓

    The alternate site did not have adequate processing capacity to handle the workload.

    Why this is correct

    Insufficient processing capacity at the alternate site means the workload cannot be recovered within the required window, directly explaining the missed RTO. This satisfies the stem's constraint by identifying a resource shortfall in the recovery environment rather than a procedural or documentation failure.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.