Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An organization's business impact analysis shows that a payment processing system has a recovery time objective of two hours and a recovery point objective of fifteen minutes. The current disaster recovery strategy restores the system from nightly tape backups at an alternate site, with an observed restoration time of eight hours and up to twenty-four hours of data loss. Which action should the IS auditor recommend FIRST?

⚠ Common exam trap

The trap here is proposing a tactical tweak, such as more frequent backups or more testing, when the architecture itself cannot satisfy the recovery objectives and requires a different recovery technology.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Report the gap to management and recommend a recovery strategy capable of meeting the objectives, such as replication or continuous data protection.

The recovery strategy must be capable of meeting the stated objectives. Nightly tape restoration fails both the two-hour recovery time objective and the fifteen-minute recovery point objective, so the auditor should report the shortfall and recommend a design such as replication or continuous data protection that can achieve those targets. Changing the objectives or merely testing more often leaves the business exposure intact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Schedule more frequent full interruption tests at the alternate site to validate the current strategy.

    Why it's wrong here

    More frequent testing would only confirm what is already known: the current strategy takes eight hours to restore and loses up to a day of data. Testing validates a strategy but cannot make an inadequate strategy meet the objectives. Recommending additional tests before fixing the design delays remediation and consumes resources without reducing the business risk created by the capability gap.

  • ✗

    Increase the frequency of tape backups to every fifteen minutes.

    Why it's wrong here

    Running tape backups every fifteen minutes might narrow the data loss window, but it does not address the eight-hour restoration time, which alone breaches the two-hour recovery time objective. Frequent tape backups also strain the backup window and media handling without providing near-instant recovery. Because the strategy would still fail the recovery time objective, this action does not close the gap and is not the appropriate first recommendation.

  • ✓

    Report the gap to management and recommend a recovery strategy capable of meeting the objectives, such as replication or continuous data protection.

    Why this is correct

    The current strategy cannot meet either objective, so the auditor's first action is to communicate the gap and recommend a solution whose capabilities match the requirements. Technologies such as synchronous or asynchronous replication and continuous data protection can deliver a fifteen-minute recovery point and support a two-hour recovery time. Recommending a capability-aligned strategy addresses the root problem rather than adjusting targets or marginally improving an inadequate method.

  • ✗

    Revise the recovery time objective and recovery point objective to match current capabilities.

    Why it's wrong here

    Adjusting the objectives to fit existing shortcomings inverts the purpose of a business impact analysis, which derives requirements from business needs. The payment processing system genuinely requires two-hour recovery and fifteen-minute data loss tolerance, so weakening those targets would accept unacceptable business risk. The auditor should recommend a technical solution that meets the requirements, not redefine the requirements to excuse the gap.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.