CISA Practice Question: Information Systems Operations and Business Resilience
An organization is planning a full interruption test of its disaster recovery plan. Which THREE of the following should the IS auditor recommend as best practices for this type of test? (Select three.)
⚠ Common exam trap
Many exam-takers confuse a full interruption test with a tabletop or simulated test, incorrectly assuming that notifying stakeholders (Option A) reduces realism, when in fact it is a critical safety control for a live failover exercise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Notify all relevant stakeholders in advance
Option A is correct because notifying all relevant stakeholders in advance is a best practice for a full interruption test, ensuring that business units, IT staff, and management are aware of the planned outage and can prepare for the disruption, thereby preventing unintended operational impact. Option C is correct because defining clear test objectives and success criteria provides measurable benchmarks for evaluating whether the disaster recovery plan achieves its recovery time objective (RTO) and recovery point objective (RPO), making the test meaningful and auditable. Option D is correct because having a rollback plan in case of failure is essential, as a full interruption test actually shuts down production systems, and if recovery fails, the organization must be able to restore normal operations quickly to avoid extended downtime. Option B is not recommended because conducting the test during peak business hours unnecessarily magnifies risk to critical operations; such tests are typically scheduled during off-peak or maintenance windows. Option E is not recommended because scheduling the test immediately after a major system upgrade introduces unvalidated changes and instability, which could confound test results and increase the risk of failure unrelated to the DR plan itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Notify all relevant stakeholders in advance
Why this is correct
Advance notification lets stakeholders prepare for service disruption and staff the test, preventing the interruption from being mistaken for a genuine disaster. This satisfies the stem's full interruption scenario, where unannounced downtime could trigger unnecessary escalation.
- ✗
Conduct the test during peak business hours to simulate real conditions
Why it's wrong here
Running a full interruption test during peak hours risks disrupting live production transactions and customers, contradicting the controlled, off-peak scheduling a DR test requires. Peak-hour testing suits load or stress testing, where realistic concurrent demand is the objective rather than recovery validation.
- ✓
Define clear test objectives and success criteria
Why this is correct
Clearly defined objectives and success criteria let the organisation measure whether recovery time and recovery point targets were actually met. This satisfies the stem's full interruption test, which otherwise produces no objective evidence of the plan's effectiveness.
- ✓
Have a rollback plan in case of failure
Why this is correct
A rollback plan allows production to be restored if the full interruption test fails or exceeds its window. This satisfies the stem's scenario, where a failed cutover could leave critical systems unavailable with no defined path back.
- ✗
Ensure the test is scheduled after a major system upgrade to validate changes
Why it's wrong here
Scheduling immediately after a major upgrade conflates two change variables, so any failure cannot be attributed to the DR plan or the upgrade. Post-upgrade validation suits a targeted regression or change-verification test, not a full interruption exercise.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.