CISA Practice Question: Information Systems Operations and Business Resilience
An organization is planning a full interruption test of its disaster recovery plan. Which THREE of the following should the IS auditor recommend as best practices for this type of test? (Select three.)
⚠ Common exam trap
Many exam-takers confuse a full interruption test with a tabletop or simulated test, incorrectly assuming that notifying stakeholders (Option A) reduces realism, when in fact it is a critical safety control for a live failover exercise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Notify all relevant stakeholders in advance
Notifying all relevant stakeholders in advance is a best practice for a full interruption test. This ensures that business units, IT teams, and external vendors are prepared for the planned outage, minimizing confusion and allowing coordinated execution. Without prior notification, the test could cause unnecessary panic or operational disruption, undermining the controlled nature of the exercise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Notify all relevant stakeholders in advance
Why this is correct
Stakeholders need to be aware to coordinate.
- ✗
Conduct the test during peak business hours to simulate real conditions
Why it's wrong here
This could cause unacceptable disruption; tests are often scheduled off-peak.
- ✓
Define clear test objectives and success criteria
Why this is correct
Clear objectives are essential for a meaningful test.
- ✓
Have a rollback plan in case of failure
Why this is correct
A rollback plan is critical to restore normal operations if the test fails.
- ✗
Ensure the test is scheduled after a major system upgrade to validate changes
Why it's wrong here
Tests should be independent of upgrades, but not necessarily after.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.