hardMultiple Choice
CISA Practice Question: Is evaluating its business continuity plan (BCP)…
An organization is evaluating its business continuity plan (BCP) for a critical application with a recovery time objective (RTO) of 4 hours and a recovery point objective (RPO) of 1 hour. The current backup strategy involves daily full backups and hourly transaction log backups. Which of the following is the MOST significant risk?
⚠ Common exam trap
CISA often tests prioritization — candidates pick 'backups not tested' because it sounds like best practice, but the question asks for the MOST significant risk, and co-located backups are a single point of failure that nullifies the entire BCP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The backup media is stored in the same building as the primary system
Storing backup media in the same building as the primary system means a single physical disaster (fire, flood, building loss) can destroy both the production system and its backups, making recovery impossible regardless of RTO/RPO design. This is the most significant risk because it defeats the purpose of the BCP entirely. The other issues are operational weaknesses but do not eliminate the ability to recover.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The backup media is stored in the same building as the primary system
Why this is correct
Housing backups in the same building as production means a single site disaster destroys both systems and backups, so neither the 4-hour RTO nor 1-hour RPO can be met. Off-site replication is required to satisfy continuity.
- ✗
The recovery process requires manual intervention to apply logs
Why it's wrong here
Manual log application affects how long recovery takes, but a four-hour RTO can still accommodate it; the RPO is unaffected. It is tempting because manual steps genuinely slow recovery and introduce human error, and would be the significant risk where the RTO were far tighter.
- ✗
The backups are not tested regularly
Why it's wrong here
Untested backups threaten whether recovery succeeds at all, yet the question asks for the most significant risk to meeting the stated RTO and RPO, which the backup schedule itself determines. It is tempting because untested restores are a classic audit finding and would be the answer where objectives were already met.
- ✗
The hourly logs cover only the last 24 hours
Why it's wrong here
Hourly log backups with 24-hour retention still satisfy a one-hour RPO, so this retention limit does not breach the stated objectives. It is tempting because short log retention genuinely threatens recoverability, and would be the significant risk if the RPO exceeded 24 hours.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.