CISA · domain
Information Systems Operations and Business Resilience
This domain covers IT operations, service management, backup and recovery, and business resilience for the CISA exam. Questions test whether you can evaluate operational controls, change and incident management, backup strategies, RTO/RPO alignment, and the adequacy of BCP/DRP testing against business requirements.
Focused practice
Practice Information Systems Operations and Business Resilience questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Information Systems Operations and Business Resilience
A candidate must evaluate whether operational and resilience controls actually meet business requirements, not just exist on paper. The single most important thing is correctly distinguishing RTO from RPO and verifying that tested recovery capabilities satisfy both.
Evaluating change management controls, including CAB approval and emergency change handling
Assessing backup strategies: full, incremental, differential, and restoration procedures
Reviewing RTO and RPO alignment with BCP/DRP and business impact analysis
Auditing incident, problem, and service level management processes and metrics
Watch out for
Common Information Systems Operations and Business Resilience exam traps
- ▸Confusing RTO with RPO, or assuming a documented plan guarantees recovery within required timeframes.
- ▸Treating a full interruption test as successful without verifying that critical application RTOs were actually met.
- ▸Assuming CAB approval alone ensures adequate change testing, rollback plans, or post-implementation review.
Question index
All Information Systems Operations and Business Resilience questions (138)
Click any question to see the full explanation, or start a practice session above.
An organization uses automated job scheduling for nightly batch processing. One job fails due to a missing dependency file. What is the most effective control to prevent recurrence?
Easy2During a business impact analysis (BIA), a department manager states that their process can be disrupted for up to 8 hours, but data loss cannot exceed 15 minutes. Which two metrics are defined by these statements?
Hard3An organization's business continuity plan (BCP) includes alternate facilities that can be operational within 24 hours. The maximum tolerable downtime (MTD) for a critical process is 12 hours. What is the most significant gap?
Medium4An organization's backup strategy includes taking full backups weekly and transactional log backups every 15 minutes. The auditor wants to verify that backup encryption is implemented for offsite storage. Which control is most relevant?
Hard5An organization is planning a full interruption test of its disaster recovery plan. Which THREE of the following should the IS auditor recommend as best practices for this type of test? (Select three.)
Hard6An organization uses a standard change model for low-risk, pre-approved changes. Which of the following is an example of a standard change?
Medium7An IT auditor is reviewing the business continuity plan (BCP) testing schedule. The organization conducts a test where participants discuss their roles and responses to a scenario without any actual system activation. Which type of test is this?
Easy8An organization is implementing a change management process. A change that requires approval from the Change Advisory Board (CAB) but is scheduled to be implemented during the next maintenance window is classified as which type of change?
Hard9An IT auditor is reviewing the asset management process for hardware lifecycle. Which two controls should the auditor verify to ensure secure disposition of decommissioned servers?
Medium10An organization is negotiating a contract with a cloud service provider. Which clause is most important for the IS auditor to ensure is included?
Easy11During a change advisory board (CAB) meeting, a proposed change to the database server is discussed. The change involves implementing a security patch that requires a reboot. The change is categorized as 'normal' and has been risk-assessed as low impact. What is the most likely role of the CAB in this scenario?
Medium12An IS auditor is evaluating the capacity management process. The auditor notices that CPU utilization has been consistently above 90% for the past three months. The IT manager states that no proactive capacity planning has been performed. What is the primary risk?
Medium13An organization outsources its data center operations to a third-party provider. Which of the following is the MOST important clause to include in the contract to ensure the organization can verify the provider's controls?
Medium14An organization is selecting a disaster recovery (DR) site. The primary data center is located in a region prone to earthquakes. The DR site should be at a sufficient distance to avoid the same disaster. Which type of alternate site provides the best balance of cost and recovery time for a medium-sized organization?
Hard15In business continuity planning, a company identifies a critical business process with a maximum tolerable downtime (MTD) of 4 hours. What is the primary purpose of this metric?
Easy16An organization uses automated job scheduling for batch processing. A critical job fails due to a dependency on another job that has not completed. Which of the following controls would BEST prevent this issue?
Medium17An organization is developing a business continuity strategy. According to best practices, which THREE of the following should be included in the strategy?
Medium18An IS auditor is evaluating how an organization manages operating system patches on internet-facing web servers. The patch management procedure requires testing in a staging environment, approval by the change manager, and deployment within 30 days of release. The auditor finds that emergency patches for critical vulnerabilities are deployed directly to production within 24 hours without staging tests. Which of the following is the MOST appropriate conclusion?
Hard19An IS auditor is reviewing how a data center schedules preventive maintenance on its uninterruptible power supply (UPS) systems and backup generators. The operations manager states that maintenance is performed monthly by an external vendor and that no formal maintenance window is documented because the work is done during low-usage hours. Which of the following is the MOST significant audit concern?
Medium20An organization is developing a business continuity strategy for its key customer-facing application. The BIA determined an RTO of 2 hours and an RPO of 30 minutes. Which TWO strategies are most appropriate to meet these objectives?
Medium21Which type of disaster recovery test involves actually switching over to the alternate site and processing live transactions, but does not require the primary site to be shut down?
Easy22During a vendor audit, an IS auditor discovers that a cloud service provider uses subcontractors to manage data storage. The contract does not mention subcontracting. Which THREE risks should the auditor highlight to management?
Hard23During a business impact analysis (BIA), the auditor identifies a critical process with a maximum tolerable downtime (MTD) of 4 hours. The IT department proposes a recovery time objective (RTO) of 2 hours and a recovery point objective (RPO) of 1 hour. Which statement is correct?
Medium24During a business impact analysis (BIA), which of the following is the MOST important metric to identify for each critical business process?
Medium25An organization uses a third-party vendor for application support. The vendor has subcontracted some support activities to another firm (fourth party). The contract with the vendor requires the vendor to ensure fourth-party compliance, but there is no direct oversight. What is the IS auditor's primary recommendation?
Hard26An IS auditor is reviewing the problem management process. The auditor finds that problem tickets are often closed without identifying the root cause, and incidents continue to recur. Which of the following is the MOST likely consequence of this practice?
Easy27An IS auditor is reviewing a batch job scheduling environment. A critical nightly job that feeds the general ledger depends on a file transfer from a subsidiary. The scheduler is configured so that if the transfer does not complete by 02:00, the job is cancelled and the ledger is not updated. Operations staff report that they manually rerun the job each morning when this occurs. Which of the following is the MOST important issue for the auditor to raise?
Hard28An IS auditor is reviewing a third-party service provider's controls. Which of the following is the MOST important clause to include in the contract to ensure the auditor can assess the provider's controls?
Medium29An IS auditor is evaluating the backup strategy for a system with a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 2 hours. The current strategy is a full backup nightly to tape with tapes transported offsite weekly. Which finding is MOST significant?
Medium30Which of the following is the PRIMARY purpose of a service desk?
Easy31An IS auditor is reviewing an organization's IT service continuity plan (ITSCP) that supports its business continuity plan (BCP). The auditor finds that the ITSCP includes recovery strategies for critical systems but lacks details on roles and responsibilities during a disaster. Which TWO of the following should the auditor recommend to address this gap? (Choose two.)
Hard32An auditor is reviewing IT asset management processes. The auditor finds that several servers running an older operating system are still in production, even though the vendor has ended support. What is the primary risk associated with this finding?
Medium33Which TWO of the following are key considerations when managing software licenses in an organization? (Select TWO).
Medium34An IS auditor is assessing the capacity management process for a virtualized data center. The auditor finds that CPU and memory utilization on a cluster of hosts regularly exceeds 85 percent during month-end processing, causing performance degradation. Management states that they monitor utilization but have no formal forecasting or trend analysis. Which of the following is the MOST significant risk arising from this situation?
Hard35A company uses a RAID 5 array for its file server. One disk fails, and the system continues to operate. However, during the rebuild process, a second disk fails. What is the likely consequence?
Hard36An IS auditor is reviewing the ITIL incident management process. Which THREE are the correct priority levels and their typical definitions?
Easy37An IS auditor is reviewing capacity management practices. Which TWO indicators suggest that proactive capacity management is being performed effectively?
Medium38During a software asset management (SAM) audit, it is discovered that the organization is using software that has reached end-of-life. Which of the following is the MOST significant risk associated with this situation?
Hard39An IS auditor is evaluating an organization's capacity management process for a critical database server. The auditor observes that CPU utilization averages 85% during peak hours, memory utilization is at 90%, and disk I/O wait times are consistently high. The organization has no formal capacity plan. Which of the following is the MOST significant risk the auditor should report?
Hard40An organization has defined an SLA that requires critical incidents to be resolved within 4 hours. A P1 incident is reported at 10:00 AM. At what time must the incident be resolved to meet the SLA?
Easy41An IS auditor is reviewing the backup process for a critical database. Which TWO of the following are essential controls to ensure data recoverability?
Easy42An IS auditor is reviewing the incident management process. Incidents are categorized as P1 (critical) through P4 (low). The SLA for P1 incidents requires initial response within 15 minutes and resolution within 4 hours. The auditor notes that the average time to respond to P1 incidents is 12 minutes, but the average resolution time is 6 hours. The root cause analysis shows that many P1 incidents are due to known errors documented in the known error database (KEDB). What is the most significant finding?
Hard43An organization's backup strategy includes full backups every Sunday and incremental backups on other days. On Wednesday, a failure occurs. Which backups are needed to restore the data?
Medium44An IS auditor is assessing the capacity management process for a cloud-based enterprise resource planning (ERP) system. The organization has experienced performance degradation during peak periods, and the cloud provider's auto-scaling features are not fully utilized. Which of the following should the auditor recommend FIRST?
Medium45A system has a Mean Time Between Failures (MTBF) of 200 hours and a Mean Time To Repair (MTTR) of 20 hours. What is the availability of the system?
Medium46An IS auditor is reviewing the backup strategy for a financial institution's core transaction processing system. The system processes high volumes of transactions continuously and requires a recovery point objective (RPO) of 5 minutes. The current strategy includes nightly full backups and hourly incremental backups. Which of the following should the auditor recommend as the MOST appropriate improvement?
Medium47An organization has implemented a business continuity plan (BCP) and disaster recovery plan (DRP). During a recent full interruption test, the IT team discovered that the recovery time objective (RTO) for a critical application was not met. What is the MOST likely reason for this failure?
Medium48An IS auditor is reviewing the IT operations of a small company. The auditor finds that scheduled batch jobs are monitored manually by an operator who checks job logs each morning. Which of the following is the MOST significant risk associated with this practice?
Easy49An IS auditor is reviewing the job scheduling environment for an organization's overnight batch processing on a mainframe. The auditor finds that operators have the authority to modify job control statements, restart failed jobs, and manually release jobs held for review, all using the same production operator ID. Which finding should the auditor report as the GREATEST concern?
Medium50An organization is conducting a Business Impact Analysis (BIA). Which of the following metrics defines the maximum acceptable outage time for a critical business process?
Medium51An IS auditor is reviewing the business impact analysis (BIA) for a financial services company. Which THREE metrics are typically defined in a BIA?
Medium52An organization is implementing a software asset management (SAM) program. Which of the following is the PRIMARY benefit of SAM?
Medium53An IS auditor is reviewing an organization's IT operations incident management process. The auditor finds that incidents are categorized and prioritized, but there is no formal escalation procedure. Which TWO of the following are the MOST significant risks of not having an escalation procedure? (Choose two.)
Medium54An IS auditor is reviewing the backup and restoration controls for a hospital's electronic health record (EHR) system, which runs on a relational database with a recovery point objective (RPO) of 15 minutes. The database administrator performs a full backup every Sunday at 01:00, differential backups nightly at 01:00, and transaction log backups every 15 minutes. During testing, the auditor observes that a restore of the database to a point in time at 14:07 on Wednesday completed successfully but took 9 hours, exceeding the stated maximum tolerable downtime (MTD) of 4 hours. Which TWO conclusions should the auditor draw from this observation? (Choose two.)
Hard55During a change management board (CAB) meeting, a proposed change to the network firewall configuration is discussed. The change is considered low risk and pre-approved. Which type of change does this represent?
Easy56Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?
Easy57An IS auditor is reviewing an organization's problem management process. The auditor finds that problem records are created only after multiple incidents with the same root cause have occurred, and there is no proactive trend analysis. Which TWO of the following are the MOST important improvements the auditor should recommend? (Choose two.)
Medium58An IT auditor is reviewing the problem management process. The IT team maintains a repository of known errors with documented workarounds. Which component of problem management is this?
Medium59An IS auditor is reviewing change management for a financial application. Which TWO of the following findings would most likely indicate a control weakness?
Hard60An IS auditor is reviewing an organization's IT operations incident management process. The auditor finds that incidents are logged, but there is no formal problem management process. Which TWO of the following are the MOST likely consequences of this deficiency? (Choose two.)
Hard61An IS auditor is reviewing an organization's disaster recovery plan (DRP) for its primary data center. The DRP specifies a reciprocal arrangement with a partner organization for backup processing. Which of the following is the MOST significant risk associated with this arrangement that the auditor should highlight?
Hard62During a disaster recovery test, the IS auditor observes that the alternate site uses a warm site configuration. Which of the following is a characteristic of a warm site?
Hard63During a software asset management (SAM) audit, the IS auditor discovers that the organization is using software versions that are no longer supported by the vendor. What is the primary risk?
Medium64An IS auditor is evaluating the IT service continuity plan for a hospital's electronic health record (EHR) system. The auditor finds that the plan includes a recovery time objective (RTO) of 4 hours, but the hospital's clinical staff state that they can tolerate only 1 hour of downtime before patient safety is compromised. Which of the following should the auditor recommend FIRST?
Medium65An IS auditor is reviewing the problem management process after a series of recurring production outages. The auditor finds that incidents are resolved quickly but the same underlying faults reappear. Which TWO activities should the auditor expect to find in an effective problem management process? (Choose two.)
Medium66An organization outsources its IT help desk to a third-party vendor. Which clause is MOST important for the IS auditor to verify in the contract to ensure the organization can assess the vendor's controls?
Medium67An IS auditor is reviewing the IT operations function of a mid-sized organization. Management asks which control would BEST ensure that capacity problems are detected before they affect users of critical production systems.
Easy68An organization is developing a business continuity strategy. Which THREE of the following are essential components of a comprehensive BC strategy?
Hard69An IS auditor is reviewing the job scheduling function for a mainframe environment that runs nightly batch processing. The auditor finds that the senior operator has standing access to modify production JCL and job schedules without a second approval. Which control should the auditor recommend to BEST mitigate the associated risk?
Medium70An organization has a disaster recovery plan that includes a hot site. During a full interruption test, the recovery team discovers that the hot site's network configuration is incompatible with the production environment. What is the most likely root cause?
Hard71An IS auditor is reviewing the IT service continuity plan for a regional bank. The plan identifies a recovery time objective of 6 hours for the core banking system and designates a warm site with pre-installed hardware but no replicated data. The plan states that data will be restored from nightly backups stored in an offsite vault. Which of the following is the MOST critical issue the auditor should raise?
Medium72An IS auditor is evaluating how an organization manages its backup and restoration process for a critical financial application. The backup job completes successfully each night and writes to a tape library. Management states that recovery capability has been proven because the backup job reports success. Which audit procedure would BEST test whether the backups are actually restorable?
Hard73An organization is implementing a new release management process. Which TWO activities are essential components of a successful release?
Easy74An IS auditor is assessing an organization's problem management process. The auditor finds that while incidents are logged and resolved, there is no formal problem management procedure. Several recurring incidents have been resolved with workarounds but not investigated for root cause. Which of the following is the MOST significant consequence of this deficiency?
Medium75An IS auditor is reviewing the problem management process of a financial services firm. The auditor finds that incidents are frequently resolved by the service desk using documented workarounds, but no problem records are created, and root cause analysis is rarely performed. As a result, the same high-impact incident has recurred 14 times in three months. Which of the following is the MOST significant risk arising from this practice?
Medium76An organization's IT service desk is the single point of contact for all incidents. The SLA for resolving P2 incidents is 8 hours. The auditor finds that the service desk frequently reassigns P2 incidents to second-level support without updating the incident record, causing delays in resolution. The average resolution time for P2 incidents is 10 hours. What is the primary control weakness?
Hard77An IS auditor is evaluating an organization's backup strategy for a critical database. The database is backed up nightly using a full backup, and transaction logs are backed up every 15 minutes. The auditor discovers that the transaction log backups are written to the same storage array as the database files. Which of the following is the MOST significant risk?
Hard78An organization is disposing of old servers. The IS auditor reviews the asset disposition process and finds that hard drives are being erased using a standard format command. What is the auditor's primary concern?
Hard79An IS auditor is assessing the business impact analysis (BIA) for a critical business function. The BIA identifies a maximum tolerable downtime (MTD) of 8 hours and a recovery time objective (RTO) of 4 hours. The current disaster recovery plan (DRP) states that the recovery of this function will take 6 hours. What should the IS auditor conclude?
Easy80An organization is implementing a disaster recovery plan. The DR team wants to test the plan with minimal risk and without impacting production operations. Which type of test is most appropriate?
Medium81An organization has defined an RTO of 4 hours for its critical financial system. During a disaster recovery test, the system was recovered in 3.5 hours, but data loss was 30 minutes. Which metric is most directly addressed by the recovery time?
Easy82Which of the following is the PRIMARY benefit of conducting a tabletop exercise for disaster recovery?
Easy83An IS auditor is reviewing the backup strategy for a financial institution. The backup administrator states that full backups are taken every Sunday, and incremental backups are taken Monday through Saturday. On Thursday morning, a database server fails, and the administrator needs to restore the server to its state as of Wednesday night. Which backup sets must the administrator use to perform this restoration?
Medium84An organization classifies IT incidents based on severity. A critical financial application is unavailable, impacting all users. According to ITIL best practices, which severity level should this incident be assigned?
Medium85Which type of disaster recovery test involves a full switch-over from the primary site to the alternate site, resulting in actual disruption of normal operations?
Easy86During a change management audit, an IS auditor finds that a critical system change was approved by the change manager without a CAB meeting. The change was categorized as a standard change. Which of the following should the auditor do FIRST?
Medium87An organization is implementing an automated job scheduling system. Which of the following is the PRIMARY benefit of using dependency management in job scheduling?
Medium88An IT auditor is reviewing the capacity management process. Which TWO of the following are key activities that should be performed?
Medium89In ITIL incident management, which severity level typically indicates a critical incident that severely impacts business operations and requires immediate resolution?
Easy90An IS auditor is reviewing an organization's IT operations schedule and job dependency configuration for its overnight batch processing. The auditor discovers that several critical financial reconciliation jobs are scheduled with no predecessor dependencies and no defined restart procedures. The auditor also notes that operators frequently rerun failed jobs without documenting the cause. Which TWO findings should the auditor report as MOST significant operational risks? (Choose two.)
Hard91An organization's business impact analysis shows that a payment processing system has a recovery time objective of two hours and a recovery point objective of fifteen minutes. The current disaster recovery strategy restores the system from nightly tape backups at an alternate site, with an observed restoration time of eight hours and up to twenty-four hours of data loss. Which action should the IS auditor recommend FIRST?
Hard92Which of the following backup types copies only data that has changed since the last full backup?
Easy93An IS auditor is reviewing an organization's problem management process. The auditor wants to verify that the process effectively identifies and resolves root causes of incidents. Which TWO of the following are the MOST important controls to ensure effective problem management? (Choose two.)
Medium94An organization outsources its help desk to a third-party vendor. The contract includes a service level agreement (SLA) with response times. The auditor wants to ensure that the organization can monitor vendor performance. Which clause is most important?
Medium95During a problem management meeting, the team identifies a recurring issue causing multiple incidents. The root cause is known, but a permanent fix is not yet available. Which of the following is the BEST approach to manage this situation until a permanent fix is implemented?
Medium96Which backup method copies all data that has changed since the last full backup, regardless of subsequent incremental backups, and is often used to reduce restore time?
Easy97An IT auditor is reviewing capacity management. The server team monitors CPU utilization and disk space. They receive alerts when thresholds are exceeded. Which practice is most effective for proactive capacity planning?
Easy98An IS auditor is evaluating the disaster recovery plan (DRP) for a organization that relies on a cloud-based ERP system. The DRP states that the recovery time objective (RTO) is 4 hours and the recovery point objective (RPO) is 1 hour. The cloud provider's SLA guarantees 99.9% availability but does not specify RTO or RPO. Which of the following should the auditor recommend FIRST?
Hard99An IS auditor is reviewing the software asset management (SAM) process. The organization uses a mix of commercial off-the-shelf (COTS) and open-source software. The auditor finds that several servers are running end-of-life (EOL) operating systems that are no longer patched. Which TWO risks are most directly associated with this finding?
Medium100An IS auditor is reviewing automated job scheduling controls. A critical batch job failed due to a dependency on a previous job that had not completed. The system did not alert operations staff. Which control weakness is most significant?
Hard101An IS auditor is reviewing the problem management process. The auditor finds that problem tickets are only created after a major incident, and there is no proactive analysis of incident trends to identify underlying problems. Which of the following is the MOST likely consequence of this approach?
Medium102An IS auditor reviewing the backup strategy for a financial application finds that full backups run every Sunday, with daily incremental backups Monday through Saturday. The recovery point objective (RPO) for the application is 4 hours. Which of the following is the MOST significant finding?
Medium103An IS auditor is reviewing the end-of-life (EOL) software policy. Which THREE risks are associated with running unsupported software? (Select THREE).
Hard104An IS auditor is examining the job scheduling controls for an organization's nightly batch processing on a mainframe. The auditor finds that operators can modify job schedules, add ad hoc jobs, and override job dependencies without supervisory approval or logging. Which of the following is the MOST appropriate recommendation?
Easy105An organization's availability management team reports that a critical server has an MTBF of 720 hours and an MTTR of 4 hours. What is the availability percentage for this server?
Medium106An organization uses automated job scheduling with dependency management. A critical nightly batch job failed because a prerequisite job did not complete successfully. The job scheduler automatically attempted to rerun the failed job three times, each time failing due to the same dependency. The operations team was not alerted until the next morning. What control should the auditor recommend to improve this process?
Medium107A system has a Mean Time Between Failures (MTBF) of 500 hours and a Mean Time To Repair (MTTR) of 20 hours. What is the availability of the system?
Hard108An IS auditor is reviewing the IT operations of a small organization. The auditor notes that the operations team performs daily server health checks, but there is no formal capacity management process. The organization recently experienced a slowdown during month-end processing. Which of the following is the MOST likely cause of the slowdown that the auditor should investigate?
Easy109A hospital's data centre uses a generator and an uninterruptible power supply (UPS) to protect clinical systems. During a walkthrough, the IS auditor observes that the UPS batteries have never been load-tested and the generator is exercised monthly without transferring the load. Which conclusion is MOST appropriate?
Easy110An organization is performing software asset management (SAM) to ensure license compliance. Which two activities should the auditor verify?
Medium111An organization uses a hot site as its disaster recovery alternative. Which of the following is the MOST critical consideration when selecting a hot site?
Medium112An IS auditor is reviewing the availability management process. The auditor calculates that the mean time between failures (MTBF) is 200 hours and the mean time to repair (MTTR) is 20 hours. What is the availability percentage?
Medium113An IS auditor is reviewing the capacity management process for a virtualized server environment. The auditor finds that CPU and memory utilization reports are generated monthly, but no formal forecasting is performed, and no thresholds are defined for triggering capacity upgrades. Which of the following is the MOST significant risk arising from this situation?
Medium114An IT auditor is reviewing the release management process. Which of the following is the MOST important control to ensure that new releases do not negatively impact production systems?
Medium115An IS auditor is reviewing the vendor management program for a critical outsourced service. The vendor has recently been acquired by another company. Which TWO factors should the auditor be most concerned about regarding the acquisition?
Medium116An organization uses RAID 5 for its database server. Which of the following is the PRIMARY advantage of RAID 5?
Medium117A company outsources its IT help desk to a third-party vendor. The service level agreement (SLA) specifies that all P1 incidents must be resolved within 2 hours. During an audit, the auditor finds that the vendor’s average resolution time for P1 incidents is 3 hours. What is the most appropriate recommendation?
Medium118During a change management process review, an IS auditor finds that the change advisory board (CAB) approved a change that subsequently caused a major service outage. The change was classified as 'normal' with no emergency. What is the auditor's primary concern?
Medium119During an audit of IT asset management, the IS auditor finds that several servers are running an operating system that has reached end-of-life (EOL). The organization has not deployed any compensating controls. Which of the following is the GREATEST risk?
Hard120An IS auditor is assessing an organization's capacity management process for a virtualized server environment. Management wants to confirm that the process will provide early warning before performance degrades. Which TWO practices are MOST important for the auditor to verify are in place? (Choose two.)
Medium121An IS auditor is assessing the capacity management process for a rapidly growing e-commerce platform. The auditor finds that capacity planning is based solely on historical CPU and memory utilization, with no forecasting of business growth or seasonal peak demand. During the most recent holiday season, the platform experienced severe performance degradation and a two-hour outage. Which of the following should the auditor identify as the PRIMARY weakness in the capacity management process?
Hard122An IT auditor is reviewing backup procedures. The organization performs daily full backups and retains them for 30 days. Additionally, weekly backups are retained for 12 months. Which of the following is the MOST likely risk associated with this backup strategy?
Medium123An IS auditor is reviewing the IT operations of a small organization that runs a critical application on a single physical server. The auditor finds that backups are performed daily to a local tape drive, but the tapes are stored in the same room as the server. Which of the following is the MOST significant risk?
Easy124During a disaster recovery planning audit, the IS auditor notes that the organization's plan includes a hot standby site. However, the plan has not been updated in two years, and the last test was a tabletop exercise 18 months ago. The organization has recently implemented a new ERP system. Which THREE findings should the auditor report as most significant?
Hard125An organization's backup strategy includes daily incremental backups and weekly full backups. During a disaster recovery test, the restoration of a critical server fails because a required incremental backup is corrupt. Which control should the organization implement to verify the integrity of backups?
Hard126An IS auditor is evaluating an organization's job scheduling practices for a critical batch process that updates the general ledger. The process runs nightly and must complete before the start of the business day. The auditor finds that the job scheduler uses a single service account with domain administrator privileges to run all jobs, and there are no alerts for job failures. Which of the following is the MOST significant risk arising from this configuration?
Hard127An IS auditor is reviewing the tape backup process for a mid-sized organization. Backups run nightly and complete successfully, and tapes are stored in a fireproof safe in the same data center as the servers. Which of the following is the MOST significant finding?
Easy128An IS auditor is reviewing the IT operations team's use of system-generated alerts. The auditor finds that alerts are configured to notify the operations team via email, but there is no escalation path if an alert is not acknowledged within a specified time. Which of the following is the MOST significant risk?
Easy129An IS auditor is reviewing problem management for a payment processor. Recurring incidents share the same root cause, but the problem record has remained open for eight months with no root cause identified because the vendor will not release diagnostic data. Change requests to apply a workaround have been raised and closed repeatedly. Which action should the IS auditor recommend FIRST?
Hard130An organization outsources its data center operations to a third-party vendor. The contract includes a right-to-audit clause. During a scheduled audit, the vendor refuses to provide access to logs from a subcontractor managing network security. What is the IS auditor's best course of action?
Medium131During a recent audit, the IT auditor found that the problem management process does not include a known error database (KEDB). Which of the following is the MOST significant risk associated with this finding?
Medium132An IS auditor is reviewing the release management process for a critical application. The release strategy includes a phased rollout to 10% of users initially, then 50%, then 100%. The first phase revealed a data integrity issue that affected a subset of transactions. The release manager decided to continue with the next phase while a patch was being developed. What should the auditor most recommend?
Hard133An IS auditor is reviewing a business continuity plan (BCP). Which TWO of the following are key components of the business continuity strategy? (Select two.)
Medium134An IT auditor is reviewing the change management process for a financial institution. The auditor finds that emergency changes are frequently approved by the change manager without CAB review. Which risk is most associated with this practice?
Medium135An IT auditor is evaluating the capacity management process. Which of the following findings would be of MOST concern?
Hard136An organization is implementing a change management process based on ITIL. Which THREE change types should be included in the policy?
Hard137A company's availability monitoring shows that a critical application has an average MTBF of 720 hours and an average MTTR of 4 hours. What is the availability percentage?
Hard138An IS auditor is reviewing the deployment pipeline for an organization's e-commerce platform. The pipeline automatically deploys every code commit that passes automated unit tests to production without manual approval. The organization argues this accelerates feature delivery. Which of the following is the auditor's GREATEST concern with this approach?
MediumOther domains
All CISA exam domains
Frequently asked questions
- What does the Information Systems Operations and Business Resilience domain cover on the CISA exam?
- A candidate must evaluate whether operational and resilience controls actually meet business requirements, not just exist on paper. The single most important thing is correctly distinguishing RTO from RPO and verifying that tested recovery capabilities satisfy both.
- How many questions are in this domain?
- This page lists all 138 Information Systems Operations and Business Resilience questions in the CISA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Information Systems Operations and Business Resilience questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.