Courseiva

CCNA Information Systems Operations and Business Resilience Questions

75 of 138 questions · Page 1/2 · Information Systems Operations and Business Resilience · Answers revealed

1
MCQeasy

An organization uses automated job scheduling for nightly batch processing. One job fails due to a missing dependency file. What is the most effective control to prevent recurrence?

A.Use a different scheduling tool
B.Define dependencies within the job scheduler
C.Increase the frequency of job reruns
D.Assign manual operators to monitor jobs
AnswerB

Defining dependencies within the job scheduler ensures the failing job only starts once its prerequisite files exist, directly addressing the missing dependency file constraint. The scheduler evaluates these conditions before execution, blocking the run rather than allowing failure. This prevents recurrence through automated precondition checking, unlike manual verification or post-failure alerting.

Why this answer

Defining dependencies within the job scheduler is the most effective control to prevent recurrence of a job failure due to a missing dependency file. By explicitly defining dependencies, the scheduler ensures that prerequisite jobs or files are available before the dependent job runs, preventing failures caused by missing inputs.

Exam trap

CISA often tests the difference between preventive controls (defining dependencies) and detective/corrective controls (monitoring, reruns), so candidates must choose the most effective preventive measure.

How to eliminate wrong answers

Option A is wrong because using a different scheduling tool does not address the root cause; the issue is lack of dependency management, not the tool itself. Option C is wrong because increasing the frequency of job reruns is a reactive measure that may waste resources and does not prevent the failure; it only retries after failure. Option D is wrong because assigning manual operators to monitor jobs is not as effective or reliable as automated dependency management; it is prone to human error and does not scale.

2
MCQhard

During a business impact analysis (BIA), a department manager states that their process can be disrupted for up to 8 hours, but data loss cannot exceed 15 minutes. Which two metrics are defined by these statements?

A.Mean time to repair (MTTR) and mean time between failures (MTBF)
B.Recovery time objective (RTO) and recovery point objective (RPO)
C.Service level objective (SLO) and service level agreement (SLA)
D.Maximum tolerable downtime (MTD) and working recovery time (WRT)
AnswerB

The 8-hour disruption tolerance defines the recovery time objective, the maximum acceptable downtime before the process must be restored. The 15-minute data loss limit defines the recovery point objective, the maximum tolerable data loss measured backwards from the incident.

Why this answer

The maximum downtime is the recovery time objective (RTO), and the maximum data loss is the recovery point objective (RPO).

3
MCQmedium

An organization's business continuity plan (BCP) includes alternate facilities that can be operational within 24 hours. The maximum tolerable downtime (MTD) for a critical process is 12 hours. What is the most significant gap?

A.The BCP does not include customer communication procedures.
B.The alternate facility cannot be activated within the required MTD.
C.The BCP does not address data backup procedures.
D.The recovery time objective (RTO) for the process is not defined.
AnswerB

The alternate facility needs 24 hours to become operational, but the critical process tolerates only 12 hours of downtime, so recovery exceeds the MTD by 12 hours. The gap is the mismatch between facility activation time and the required recovery timeframe.

Why this answer

The alternate facility recovery time (24 hours) exceeds the MTD (12 hours), meaning the process would fail its recovery requirement.

4
MCQhard

An organization's backup strategy includes taking full backups weekly and transactional log backups every 15 minutes. The auditor wants to verify that backup encryption is implemented for offsite storage. Which control is most relevant?

A.Backup compression
B.Offsite transport log
C.Backup encryption at rest
D.Backup verification logs
AnswerC

Backup encryption at rest protects the transactional log and full backup files stored offsite, directly satisfying the auditor's verification objective. Because log backups occur every 15 minutes, each resulting file must be encrypted before leaving the environment, ensuring confidentiality of data at the offsite storage location.

Why this answer

Backup encryption at rest ensures that data stored offsite is protected from unauthorized access, which is a key control for offsite backups.

5
Multi-Selecthard

An organization is planning a full interruption test of its disaster recovery plan. Which THREE of the following should the IS auditor recommend as best practices for this type of test? (Select three.)

Select 3 answers
A.Notify all relevant stakeholders in advance
B.Conduct the test during peak business hours to simulate real conditions
C.Define clear test objectives and success criteria
D.Have a rollback plan in case of failure
E.Ensure the test is scheduled after a major system upgrade to validate changes
AnswersA, C, D

Advance notification lets stakeholders prepare for service disruption and staff the test, preventing the interruption from being mistaken for a genuine disaster. This satisfies the stem's full interruption scenario, where unannounced downtime could trigger unnecessary escalation.

Why this answer

Option A is correct because notifying all relevant stakeholders in advance is a best practice for a full interruption test, ensuring that business units, IT staff, and management are aware of the planned outage and can prepare for the disruption, thereby preventing unintended operational impact. Option C is correct because defining clear test objectives and success criteria provides measurable benchmarks for evaluating whether the disaster recovery plan achieves its recovery time objective (RTO) and recovery point objective (RPO), making the test meaningful and auditable. Option D is correct because having a rollback plan in case of failure is essential, as a full interruption test actually shuts down production systems, and if recovery fails, the organization must be able to restore normal operations quickly to avoid extended downtime.

Option B is not recommended because conducting the test during peak business hours unnecessarily magnifies risk to critical operations; such tests are typically scheduled during off-peak or maintenance windows. Option E is not recommended because scheduling the test immediately after a major system upgrade introduces unvalidated changes and instability, which could confound test results and increase the risk of failure unrelated to the DR plan itself.

Exam trap

The trap here is that candidates may confuse a full interruption test with a tabletop or simulated test, incorrectly assuming that notifying stakeholders (Option A) reduces realism, when in fact it is a critical safety control for a live failover exercise.

6
MCQmedium

An organization uses a standard change model for low-risk, pre-approved changes. Which of the following is an example of a standard change?

A.Upgrading the core router to a new model
B.Changing the backup schedule from daily to weekly
C.Applying a routine security patch to the firewall
D.Migrating the entire email system to the cloud
AnswerC

Routine firewall security patching fits the standard change model because it is pre-approved, low-risk, and repeatable, following a documented procedure with no CAB review required. This satisfies the stem's constraint that standard changes are pre-authorised, low-risk, and executed without individual assessment.

Why this answer

Standard changes are pre-approved, low-risk, and follow a defined procedure. Applying a routine security patch that has been tested and approved falls under this category.

7
MCQeasy

An IT auditor is reviewing the business continuity plan (BCP) testing schedule. The organization conducts a test where participants discuss their roles and responses to a scenario without any actual system activation. Which type of test is this?

A.Parallel test
B.Walkthrough
C.Simulation
D.Tabletop exercise
AnswerD

A tabletop exercise gathers participants to walk through roles, decisions and communications against a hypothetical scenario, with no systems activated and no relocation. This discussion-based format contrasts with functional, simulation and full-interruption tests, which involve actual system or site activation.

Why this answer

A tabletop exercise is a discussion-based BCP test where participants verbally walk through their roles and responses to a hypothetical scenario without activating systems or relocating staff. It is the least disruptive and least expensive test type, used to validate plans, clarify roles, and identify gaps before conducting more resource-intensive tests. Because the question specifies 'discuss their roles and responses... without any actual system activation,' this maps directly to a tabletop exercise.

Exam trap

The trap here is confusing discussion-based tests (tabletop, walkthrough) with execution-based tests (simulation, parallel, full interruption); candidates who see 'scenario' and jump to 'simulation' miss the phrase 'without any actual system activation.'

How to eliminate wrong answers

Option A is wrong because a parallel test involves running the recovery site in parallel with the primary site, processing live transactions simultaneously — it requires actual system activation. Option B is wrong because a walkthrough is a structured review of the plan document step by step, often with a checklist, and does not involve scenario-based role discussion; it is more of a documentation review than a response rehearsal. Option C is wrong because a simulation is a more advanced test where participants actually perform recovery activities (e.g., restoring data, activating alternate sites) in a simulated environment, which goes beyond discussion.

8
MCQhard

An organization is implementing a change management process. A change that requires approval from the Change Advisory Board (CAB) but is scheduled to be implemented during the next maintenance window is classified as which type of change?

A.Emergency change
B.Standard change
C.Minor change
D.Normal change
AnswerD

A normal change is defined by its adherence to the full change management process, requiring formal assessment and authorisation. The scenario's explicit mention that the change requires approval from the Change Advisory Board (CAB) directly aligns with this classification. Additionally, scheduling the implementation during a future maintenance window signifies a planned, non-urgent deployment, confirming it follows the structured workflow typical of a normal change, rather than an emergency or pre-approved standard change.

Why this answer

A normal change is any change that is not a standard (pre-approved, low-risk, routine) change and not an emergency change; it must go through the full change management process including CAB review and approval, and is typically scheduled for a maintenance window. Because the change requires CAB approval and is scheduled for the next maintenance window, it fits the definition of a normal change. Standard changes are pre-authorized and do not require CAB review, while emergency changes bypass the normal schedule.

Exam trap

The trap is assuming that any scheduled, low-risk change is a 'standard change'; candidates must remember that standard changes are pre-authorized and do not require CAB approval, whereas normal changes do.

How to eliminate wrong answers

Option A is wrong because an emergency change is one that must be implemented immediately to resolve an incident or restore service, bypassing the normal CAB schedule (often with retroactive approval); this change is scheduled, not urgent. Option B is wrong because a standard change is a pre-approved, low-risk, repeatable change (e.g., password reset, adding a user) that does not require CAB approval at all. Option C is wrong because 'minor change' is not a standard ITIL change category — ITIL 4 defines standard, normal, and emergency changes; minor changes are a colloquial term and not the formal classification tested here.

9
Multi-Selectmedium

An IT auditor is reviewing the asset management process for hardware lifecycle. Which two controls should the auditor verify to ensure secure disposition of decommissioned servers?

Select 2 answers
A.Hardware warranty tracking
B.Performance benchmarking
C.Secure sanitization of storage media
D.Formal disposal policy with authorization
E.Asset tagging during procurement
AnswersC, D

Sanitisation destroys residual data on decommissioned server drives, preventing recovery of sensitive information before the hardware leaves organisational control. Verifying this control confirms the confidentiality constraint in the disposition process is met, since disposal without media cleansing exposes data to unauthorised parties.

Why this answer

Option C (Secure sanitization of storage media) is correct because decommissioned servers often retain sensitive data on HDDs, SSDs, or NVMe drives, and the auditor must verify that media are wiped using approved methods such as NIST SP 800-88 purge/clear or cryptographic erase, or physically destroyed, before the hardware leaves organizational control. Option D (Formal disposal policy with authorization) is correct because secure disposition requires a documented, approved process that defines roles, disposal methods, chain-of-custody, and management sign-off, ensuring decommissioning is authorized and auditable rather than ad hoc. The unmarked options do not belong: A (Hardware warranty tracking) relates to maintenance and support entitlements, not data-bearing disposition; B (Performance benchmarking) measures system capability and has no bearing on secure disposal; and E (Asset tagging during procurement) is an intake/inventory control that supports tracking but does not itself ensure secure sanitization or authorized disposal at end of life.

Exam trap

The trap here is that candidates may confuse operational lifecycle tasks (warranty, tagging, benchmarking) with security-specific disposition controls, overlooking that only sanitization and authorized policy directly address data confidentiality and disposal governance.

10
MCQeasy

An organization is negotiating a contract with a cloud service provider. Which clause is most important for the IS auditor to ensure is included?

A.Data localization requirements.
B.Right-to-audit clause.
C.Automatic renewal terms.
D.Service level agreement (SLA) with penalties.
AnswerB

A right-to-audit clause contractually guarantees the IS auditor independent access to the provider's controls, records and evidence. Without it, the organisation cannot verify that the outsourced service meets its security and compliance obligations, leaving assurance dependent solely on the provider's own reporting.

Why this answer

The right-to-audit clause is the most critical contractual provision for an IS auditor because it grants the organization the legal right to inspect the cloud provider's controls, processes, and records — either directly or via third-party attestations (SOC 2, ISO 27001). Without it, the auditor cannot obtain sufficient evidence to opine on the effectiveness of controls over outsourced data and processing. It is the contractual foundation that makes all other assurance activities possible.

Exam trap

CISA often tests the misconception that an SLA with penalties or data localization clauses provide equivalent assurance to a right-to-audit — candidates must recognize that only the right-to-audit gives the auditor legal standing to obtain control evidence.

How to eliminate wrong answers

Option A is wrong because data localization requirements are jurisdiction-specific and may not be relevant to every organization; they address where data resides, not the auditor's ability to verify controls. Option C is wrong because automatic renewal terms are a commercial convenience and have no bearing on audit assurance or control verification. Option D is wrong because an SLA with penalties addresses service performance and remedies, not the auditor's right to examine the provider's control environment — penalties do not substitute for audit evidence.

11
MCQmedium

During a change advisory board (CAB) meeting, a proposed change to the database server is discussed. The change involves implementing a security patch that requires a reboot. The change is categorized as 'normal' and has been risk-assessed as low impact. What is the most likely role of the CAB in this scenario?

A.Review and approve the change
B.Implement the change directly
C.Reject the change as unnecessary
D.Defer the change to the next release cycle
AnswerA

Normal changes require CAB review and authorisation before implementation. Even though the patch is low impact, the reboot and database scope mean the CAB must review and approve it, satisfying the stem's normal-category constraint rather than auto-approving it as standard.

Why this answer

The CAB's primary role is to review and approve (or reject) proposed changes by assessing risk, impact, and readiness. In this scenario, the change is a normal change that has been risk-assessed as low impact, so the CAB's most likely action is to review and approve it for implementation during the maintenance window. The CAB does not implement changes, nor does it arbitrarily reject or defer changes that are properly justified and assessed.

Exam trap

The trap is confusing the CAB's governance role with operational execution; candidates may pick 'implement the change' because the scenario describes a technical task, but the CAB never implements — it reviews and approves.

How to eliminate wrong answers

Option B is wrong because the CAB is a governance and advisory body; implementation is performed by technical teams (e.g., database administrators, operations staff), not by the CAB itself. Option C is wrong because rejecting the change as unnecessary is not the CAB's default role when a change is properly justified and risk-assessed; rejection would only occur if the change lacked justification or introduced unacceptable risk. Option D is wrong because deferring to the next release cycle is a scheduling decision that may be made if the change is not urgent or if resources are constrained, but it is not the most likely role of the CAB in this scenario — the CAB's core function is review and approval.

12
MCQmedium

An IS auditor is evaluating the capacity management process. The auditor notices that CPU utilization has been consistently above 90% for the past three months. The IT manager states that no proactive capacity planning has been performed. What is the primary risk?

A.Potential service degradation or unplanned outages.
B.Increased licensing costs for software.
C.Inability to meet backup windows.
D.Increased energy costs for cooling.
AnswerA

Sustained CPU utilisation above 90% with no proactive capacity planning leaves no headroom for demand spikes, so response times degrade and components may fail. The primary risk is therefore service degradation or unplanned outages affecting dependent business processes.

Why this answer

Consistently high utilization without planning risks performance degradation and outages. The organization may not be able to handle peak loads.

13
MCQmedium

An organization outsources its data center operations to a third-party provider. Which of the following is the MOST important clause to include in the contract to ensure the organization can verify the provider's controls?

A.Exit strategy
B.Service level agreement (SLA)
C.Vendor concentration risk clause
D.Right-to-audit clause
AnswerD

A right-to-audit clause contractually grants the organisation the ability to inspect the provider's controls, evidence and processes. This directly satisfies the stem's verification constraint, since without it the outsourcer could refuse audits, leaving control effectiveness unconfirmed.

Why this answer

A right-to-audit clause allows the organization or its auditor to review the provider's controls.

14
MCQhard

An organization is selecting a disaster recovery (DR) site. The primary data center is located in a region prone to earthquakes. The DR site should be at a sufficient distance to avoid the same disaster. Which type of alternate site provides the best balance of cost and recovery time for a medium-sized organization?

A.Hot site
B.Warm site
C.Mobile site
D.Cold site
AnswerB

A warm site pre-installs hardware and connectivity but lacks live replicated data, so it restores from backups within hours or days. This sits between cold and hot sites on the cost-versus-recovery-time axis, meeting the medium-sized organisation's need to balance budget against acceptable downtime while sited away from the earthquake zone.

Why this answer

A warm site is partially configured with some hardware, software, and data synchronization, offering a balance between cost and recovery time. For a medium-sized organization, it provides faster recovery than a cold site while being significantly less expensive than a hot site, making it suitable for a region prone to earthquakes where the DR site must be geographically distant.

Exam trap

The trap here is that candidates often confuse 'warm site' with 'hot site' due to the similar terminology, but the key differentiator is the level of data synchronization and hardware readiness, not just the distance from the primary site.

How to eliminate wrong answers

Option A is wrong because a hot site is a fully redundant, real-time mirror of the primary data center, which is excessively costly for a medium-sized organization and typically used only for mission-critical systems requiring near-zero recovery time objectives (RTOs). Option C is wrong because a mobile site is a portable, self-contained unit that is not designed for permanent, geographically distant disaster recovery; it is more suited for temporary or tactical needs, not for avoiding region-wide disasters like earthquakes. Option D is wrong because a cold site has no pre-installed hardware or software, requiring weeks to procure and configure, resulting in a recovery time that is too long for most medium-sized organizations, especially when the primary site is in a high-risk area.

15
MCQeasy

In business continuity planning, a company identifies a critical business process with a maximum tolerable downtime (MTD) of 4 hours. What is the primary purpose of this metric?

A.To define the backup frequency
B.To calculate the mean time between failures (MTBF)
C.To establish service level agreements (SLAs)
D.To determine the recovery time objective (RTO)
AnswerD

MTD defines the maximum time a process can be unavailable, and the RTO must be set at or below it to keep downtime tolerable. Deriving the RTO from the 4-hour MTD ensures recovery capabilities align with business tolerance.

Why this answer

The maximum tolerable downtime (MTD) defines the maximum time a business process can be unavailable before unacceptable consequences occur. The recovery time objective (RTO) is derived from the MTD — it is the target time within which the process must be restored, and it must be less than the MTD to provide a safety margin. Therefore, the primary purpose of the MTD is to determine the RTO for the process.

Exam trap

The trap is confusing MTD with RTO or RPO; candidates must remember that MTD is the business tolerance limit, and RTO is the technical recovery target derived from it — MTD does not define backup frequency (that is RPO).

How to eliminate wrong answers

Option A is wrong because backup frequency is driven by the recovery point objective (RPO), which defines how much data loss is tolerable, not by MTD. Option B is wrong because mean time between failures (MTBF) is a reliability metric for hardware or components, unrelated to business continuity downtime tolerances. Option C is wrong because SLAs are contractual agreements that may reference RTO/RPO, but the MTD itself does not establish SLAs; SLAs are negotiated based on business requirements, of which MTD is one input.

16
MCQmedium

An organization uses automated job scheduling for batch processing. A critical job fails due to a dependency on another job that has not completed. Which of the following controls would BEST prevent this issue?

A.Job failure alerts
B.Manual job scheduling
C.Rerun procedures
D.Dependency management
AnswerD

Dependency management ensures a job only starts once its prerequisite jobs complete successfully, preventing the failure caused by unmet dependencies. It directly addresses the scheduling constraint in the stem, unlike restart or notification controls that react after the job has already failed.

Why this answer

Dependency management is the correct control because it ensures that job scheduling logic explicitly defines and enforces the order of execution based on predecessor/successor relationships. By configuring dependencies (e.g., using job control language (JCL) with COND parameters or scheduling tools like CA Workload Automation ESP), the system will automatically hold a job until all prerequisite jobs have completed successfully, preventing the failure scenario described.

Exam trap

The trap here is that candidates often confuse detective controls (like alerts) with preventive controls, or assume that rerun procedures can prevent the initial failure, when in fact only dependency management addresses the root cause by enforcing execution order.

How to eliminate wrong answers

Option A is wrong because job failure alerts are a detective control that notifies administrators after the failure has already occurred, not a preventive control that stops the issue from happening. Option B is wrong because manual job scheduling introduces human error and inefficiency, and does not inherently enforce dependency sequencing; it would actually increase the risk of similar failures. Option C is wrong because rerun procedures are corrective controls that handle recovery after a failure, not preventive measures that avoid the dependency-related failure in the first place.

17
Multi-Selectmedium

An organization is developing a business continuity strategy. According to best practices, which THREE of the following should be included in the strategy?

Select 3 answers
A.Customer and partner communications plan.
B.Vendor contract renewal dates.
C.Procedures for staff to work remotely.
D.IT asset inventory list.
E.Details of alternate processing facilities.
AnswersA, C, E

A customer and partner communications plan ensures external stakeholders receive timely, accurate notifications during disruption, protecting reputation and contractual obligations. It satisfies the strategy's requirement to address interdependent parties, since continuity depends on coordinated messaging rather than internal recovery alone.

Why this answer

A customer and partner communications plan (A) is a required element of a business continuity strategy because during a disruption the organization must be able to notify external stakeholders about service status, expected recovery times, and alternate contact channels, which protects reputation and contractual relationships. Procedures for staff to work remotely (C) belong in the strategy because personnel are the most critical resource; documented remote-work procedures ensure that essential functions can continue when the primary site is unavailable. Details of alternate processing facilities (E) are essential because the strategy must identify where and how critical systems and operations will be resumed, including recovery site type (hot, warm, or cold), location, and activation criteria.

Vendor contract renewal dates (B) are administrative procurement data rather than continuity planning content, and an IT asset inventory list (D) is an operational input used during business impact analysis and recovery planning, not a strategic continuity element itself.

Exam trap

The trap is confusing BCP strategy elements with BCP inputs or administrative details; candidates may pick 'IT asset inventory' because it sounds important, but it is an input, not a strategic element.

18
MCQhard

An IS auditor is evaluating how an organization manages operating system patches on internet-facing web servers. The patch management procedure requires testing in a staging environment, approval by the change manager, and deployment within 30 days of release. The auditor finds that emergency patches for critical vulnerabilities are deployed directly to production within 24 hours without staging tests. Which of the following is the MOST appropriate conclusion?

A.The staging environment should be eliminated so all patches follow the same emergency path.
B.The emergency process is a control weakness because it bypasses testing entirely.
C.The emergency process is acceptable if it includes documented authorization, a rollback plan, and post-deployment verification.
D.The 30-day deployment window for routine patches is too long and should be shortened to 7 days.
AnswerC

Emergency patching of critical vulnerabilities on internet-facing systems is a legitimate risk response when the exposure window is short. What makes it acceptable is compensating control: a documented approval by an authorized person, a tested rollback plan in case the patch breaks the service, and verification after deployment that the patch applied and the service functions. This balances the security risk of delay against the operational risk of untested change.

Why this answer

Emergency patching is a necessary capability when critical vulnerabilities on internet-facing systems could be exploited before a normal change cycle completes. The control objective is not to prohibit the bypass but to ensure it is governed: authorized by an accountable person, accompanied by a rollback plan, and verified after deployment. If those compensating controls are documented and evidenced, the emergency path is an acceptable risk-based exception to the standard patch procedure.

Exam trap

The trap here is concluding that any deviation from the standard patch process is automatically a finding, rather than evaluating whether the emergency path has its own compensating controls.

19
MCQmedium

An IS auditor is reviewing how a data center schedules preventive maintenance on its uninterruptible power supply (UPS) systems and backup generators. The operations manager states that maintenance is performed monthly by an external vendor and that no formal maintenance window is documented because the work is done during low-usage hours. Which of the following is the MOST significant audit concern?

A.Maintenance is performed monthly instead of quarterly.
B.The vendor performing the maintenance is external rather than internal staff.
C.Maintenance is performed without a formally approved and documented maintenance window.
D.The operations manager, rather than the vendor, owns the maintenance schedule.
AnswerC

Without an approved maintenance window, maintenance activities can overlap with production processing, and any resulting outage cannot be traced to an authorized change. The auditor's primary concern is that maintenance on power infrastructure must be coordinated, approved, and recorded so that availability risk is controlled and accountability is maintained. Undocumented timing removes the audit trail and increases the chance of an unplanned service interruption.

Why this answer

Preventive maintenance on power infrastructure must be planned, authorized, and documented so that availability risks are controlled and any outage can be traced to an approved activity. Performing maintenance during low-usage hours without a formal window means the activity is not governed by change and scheduling controls, leaving the organization exposed to uncoordinated interruptions and no reliable record of what was done to critical equipment.

Exam trap

The trap here is assuming that maintenance performed during low-usage hours is inherently safe and therefore does not need a formal, approved window or documentation.

20
Multi-Selectmedium

An organization is developing a business continuity strategy for its key customer-facing application. The BIA determined an RTO of 2 hours and an RPO of 30 minutes. Which TWO strategies are most appropriate to meet these objectives?

Select 2 answers
A.Implement a hot standby site
B.Adopt a manual workaround process
C.Store backup tape at an offsite location
D.Use synchronous data replication to a secondary site
E.Perform daily full backups to tape
AnswersA, D

A hot standby site maintains continuously synchronised infrastructure with near-zero data loss, comfortably satisfying the 30-minute RPO and 2-hour RTO. Because systems run live and replicate in real time, failover completes within minutes, unlike warm or cold alternatives requiring rebuild time that would breach both objectives.

Why this answer

Option A (hot standby site) is correct because a hot standby keeps a fully operational, continuously synchronized environment ready to take over immediately, so the 2-hour RTO can be met with minimal failover time. Option D (synchronous data replication to a secondary site) is correct because synchronous replication commits writes to the secondary site before acknowledging them, giving an RPO of effectively zero, which is well within the required 30-minute RPO. Option B (manual workaround process) is not appropriate because manual procedures typically introduce delays and human error that cannot reliably satisfy a 2-hour RTO.

Option C (offsite tape storage) does not belong because retrieving and restoring tapes takes far longer than 2 hours and cannot meet a 30-minute RPO. Option E (daily full backups to tape) is unsuitable because a 24-hour backup interval yields an RPO of up to 24 hours, far exceeding the 30-minute requirement.

21
MCQeasy

Which type of disaster recovery test involves actually switching over to the alternate site and processing live transactions, but does not require the primary site to be shut down?

A.Simulation test
B.Full interruption test
C.Tabletop test
D.Parallel test
AnswerD

A parallel test processes live transactions at the alternate site while the primary site continues running, satisfying the stem's requirement that the primary is not shut down. Unlike full failover, both sites operate simultaneously, validating recovery capability without disrupting production.

Why this answer

Parallel testing is the correct answer because it involves processing live transactions at the alternate site while the primary site remains fully operational. This allows validation of the disaster recovery (DR) systems without risking a service outage, as both sites run concurrently and results are compared for consistency. Unlike a full interruption test, the primary site is not shut down, ensuring business continuity during the test.

Exam trap

The trap here is that candidates often confuse parallel testing with a full interruption test, mistakenly thinking that any test involving live transactions must require shutting down the primary site, but parallel testing explicitly avoids that by running both sites concurrently.

How to eliminate wrong answers

Option A is wrong because a simulation test involves a simulated disaster scenario where team members practice their roles, but it does not involve actual failover or processing of live transactions at the alternate site. Option B is wrong because a full interruption test requires the primary site to be shut down and all processing to be moved to the alternate site, which contradicts the condition that the primary site remains operational. Option C is wrong because a tabletop test is a discussion-based exercise where participants walk through disaster scenarios without any actual system failover or live transaction processing.

22
Multi-Selecthard

During a vendor audit, an IS auditor discovers that a cloud service provider uses subcontractors to manage data storage. The contract does not mention subcontracting. Which THREE risks should the auditor highlight to management?

Select 3 answers
A.Vendor concentration risk from subcontractor dependency
B.Exit strategy complications if subcontractor fails
C.Improved service level performance
D.Increased licensing costs
E.Fourth-party risk due to lack of contractual oversight
AnswersA, B, E

Subcontractors managing storage introduce vendor concentration risk: the provider's reliance on a single subcontractor means an outage, insolvency or service failure at that third party cascades directly to the organisation, yet the contract grants no visibility, audit rights or service-level guarantees over that dependency.

Why this answer

Option A is correct because undisclosed subcontracting creates vendor concentration risk: the organization becomes dependent not only on the primary provider but also on subcontractors it did not evaluate or approve, so a subcontractor failure or change can disrupt critical data storage services. Option B is correct because the absence of subcontracting clauses complicates the exit strategy — the organization may lack contractual rights to require transition assistance, data return, or cooperation from subcontractors during termination or migration. Option E is correct because unmanaged subcontractors are fourth parties, and without contractual flow-down requirements (e.g., security, privacy, audit rights, SLAs), the provider's oversight of them is unverified, exposing the organization to compliance and data protection failures.

Option C is not a risk but a potential benefit, and it is not guaranteed by subcontracting. Option D is not a relevant risk here, since the scenario concerns undisclosed data storage subcontracting, not licensing cost increases.

Exam trap

CISA often tests third-party and fourth-party risk concepts, and candidates may overlook the lack of contractual oversight as a distinct risk, focusing only on concentration and exit strategy, but the question asks for THREE risks, and fourth-party risk is a key one.

23
MCQmedium

During a business impact analysis (BIA), the auditor identifies a critical process with a maximum tolerable downtime (MTD) of 4 hours. The IT department proposes a recovery time objective (RTO) of 2 hours and a recovery point objective (RPO) of 1 hour. Which statement is correct?

A.The MTD should be reduced to match the RTO
B.The RPO is too high because it exceeds the MTD
C.The RTO is acceptable as it is less than the MTD
D.The RTO should be equal to the MTD
AnswerC

The proposed Recovery Time Objective (RTO) of 2 hours is acceptable because it directly satisfies the critical business continuity constraint established by the Maximum Tolerable Downtime (MTD) of 4 hours. For any recovery strategy to be effective, the RTO, representing the target time to restore operations, must always be less than or equal to the MTD. This ensures that the process can resume before the organisation incurs unacceptable losses, which is met in this scenario.

Why this answer

The RTO must be less than or equal to the MTD. Here, RTO (2 hours) is less than MTD (4 hours), so the recovery target is acceptable.

24
MCQmedium

During a business impact analysis (BIA), which of the following is the MOST important metric to identify for each critical business process?

A.Recovery Point Objective (RPO)
B.Work Recovery Time (WRT)
C.Maximum Tolerable Downtime (MTD)
D.Recovery Time Objective (RTO)
AnswerC

MTD defines the longest a process can be unavailable before unacceptable business impact occurs, directly setting the recovery time objective and driving continuity strategy. During a BIA, it is the primary metric quantifying tolerable outage per critical process, making it the most important figure to establish.

Why this answer

Maximum Tolerable Downtime (MTD) is the most important metric because it defines the maximum time a business process can be unavailable before causing unacceptable consequences. It sets the upper bound for recovery objectives like RTO and WRT. Without knowing MTD, other metrics lack context.

Exam trap

The trap is selecting RTO or RPO as the most important, but MTD is the business-driven metric that sets the stage for all others.

How to eliminate wrong answers

Option A is wrong because RPO defines acceptable data loss, which is important but secondary to MTD; MTD determines how long the business can survive without the process. Option B is wrong because WRT is the time to verify and resume operations after recovery, a component of MTD but not the overarching metric. Option D is wrong because RTO is the target time to restore, which must be less than MTD; it is derived from MTD, not the most important metric itself.

25
MCQhard

An organization uses a third-party vendor for application support. The vendor has subcontracted some support activities to another firm (fourth party). The contract with the vendor requires the vendor to ensure fourth-party compliance, but there is no direct oversight. What is the IS auditor's primary recommendation?

A.Perform a vulnerability assessment on the fourth party.
B.Include a right-to-audit clause for all subcontractors in the contract.
C.Terminate the contract with the vendor.
D.Require the vendor to provide evidence of fourth-party compliance.
AnswerB

A right-to-audit clause extending to subcontractors gives the organisation contractual authority to examine fourth-party controls directly, closing the oversight gap created by reliance on vendor-managed compliance. Without it, assurance depends entirely on vendor reporting. This satisfies the stem's constraint: no direct oversight of the fourth party exists, so enforceable audit access must be established contractually.

Why this answer

The primary recommendation is to include a right-to-audit clause for all subcontractors in the contract. This ensures the organization retains direct oversight and contractual leverage over fourth-party risks, as relying solely on the vendor's assurance without audit rights creates a blind spot in the supply chain. Without such a clause, the organization cannot independently verify the fourth party's compliance with security controls, which is critical for maintaining business resilience.

Exam trap

The trap here is that candidates confuse operational verification (Option D) with contractual governance, failing to recognize that without a right-to-audit clause, the organization has no enforceable mechanism to independently validate fourth-party compliance.

How to eliminate wrong answers

Option A is wrong because performing a vulnerability assessment on the fourth party without contractual authority or direct access is impractical and may violate legal boundaries; it also addresses technical vulnerabilities but not the root governance gap. Option C is wrong because terminating the contract is a drastic, business-disruptive step that should only be considered after less severe remediation options (like renegotiating contract terms) have failed. Option D is wrong because requiring evidence from the vendor is insufficient without a contractual right to audit; the vendor could provide incomplete or falsified evidence, and the organization has no means to verify its accuracy or scope.

26
MCQeasy

An IS auditor is reviewing the problem management process. The auditor finds that problem tickets are often closed without identifying the root cause, and incidents continue to recur. Which of the following is the MOST likely consequence of this practice?

A.Higher change management costs due to emergency changes.
B.Decreased effectiveness of the service desk due to increased workload.
C.Noncompliance with regulatory requirements for incident reporting.
D.Increased number of incidents and reduced service availability.
AnswerD

If problems are not resolved by addressing root causes, the underlying issues persist and generate recurring incidents. This leads to increased incident volume and reduced service availability, as the same problems disrupt services repeatedly. The auditor should recognize that effective problem management is essential to prevent incident recurrence and improve overall stability. This is the most direct consequence.

Why this answer

Problem management aims to identify and resolve root causes to prevent incident recurrence. When problems are closed without root cause analysis, the underlying issues remain, causing the same incidents to happen again. This directly increases the number of incidents and reduces service availability.

Other consequences, such as higher change costs or service desk workload, are secondary effects. The auditor should recognize that ineffective problem management leads to chronic operational instability.

Exam trap

The trap here is selecting a secondary effect like increased service desk workload or change costs, instead of recognizing that the fundamental consequence of unresolved problems is the persistent recurrence of incidents and degraded availability.

27
MCQhard

An IS auditor is reviewing a batch job scheduling environment. A critical nightly job that feeds the general ledger depends on a file transfer from a subsidiary. The scheduler is configured so that if the transfer does not complete by 02:00, the job is cancelled and the ledger is not updated. Operations staff report that they manually rerun the job each morning when this occurs. Which of the following is the MOST important issue for the auditor to raise?

A.The manual morning reruns are not documented, approved, or monitored as operational procedures.
B.The scheduler cancels the job instead of retrying the file transfer automatically.
C.The subsidiary file transfer uses a protocol that is not encrypted.
D.The 02:00 cutoff time is too early for the subsidiary to complete its transfer.
AnswerA

Undocumented manual reruns mean the ledger update depends on informal operator knowledge rather than a controlled procedure. If the operator is absent or the rerun is performed incorrectly, financial data may be incomplete or posted late without detection. The auditor's key concern is that a recurring failure has been normalized into an uncontrolled workaround, bypassing scheduling, approval, and monitoring controls over a financially significant batch process.

Why this answer

A recurring batch failure that is silently corrected by manual reruns represents an uncontrolled operational workaround. Because the ledger update depends on informal operator action, there is no assurance that the rerun is performed consistently, authorized, or evidenced. The auditor should require that the dependency failure be detected and alerted, that the recovery procedure be documented and approved, and that reruns be logged and reviewed so completeness of financial processing is demonstrable.

Exam trap

The trap here is focusing on the technical scheduling configuration instead of recognizing that the real weakness is an undocumented manual workaround supporting a financially significant process.

28
MCQmedium

An IS auditor is reviewing a third-party service provider's controls. Which of the following is the MOST important clause to include in the contract to ensure the auditor can assess the provider's controls?

A.Right-to-audit clause
B.Service level agreement (SLA) with penalties
C.Exit strategy clause
D.Confidentiality clause
AnswerA

A right-to-audit clause contractually grants the organisation and its IS auditors the authority to examine the provider's controls, evidence and processes. Without it, the provider can lawfully refuse access, so this clause directly satisfies the requirement to assess third-party controls.

Why this answer

A right-to-audit clause (A) is the most important contractual provision because it grants the organization (and its auditors or regulators) the legal right to examine the service provider's controls, records, and facilities. Without it, the auditor has no contractual basis to assess the provider's control environment, making third-party risk assurance impossible. SLAs, exit strategies, and confidentiality clauses address performance, transition, and data protection respectively, but none of them enable control assessment.

Exam trap

The trap is selecting a clause that sounds protective (SLA penalties, confidentiality) when the question specifically asks about enabling the auditor to assess controls, which only a right-to-audit clause provides.

How to eliminate wrong answers

Option B is wrong because an SLA with penalties governs service performance and remedies for failure; it does not grant the auditor access to evaluate the provider's internal controls. Option C is wrong because an exit strategy clause addresses how the relationship terminates and how data/assets are returned or destroyed; it is a continuity control, not an audit-enablement control. Option D is wrong because a confidentiality clause protects the provider's and the organization's sensitive information; it actually can restrict information sharing and does not by itself authorize audit access.

29
MCQmedium

An IS auditor is evaluating the backup strategy for a system with a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 2 hours. The current strategy is a full backup nightly to tape with tapes transported offsite weekly. Which finding is MOST significant?

A.Weekly offsite transport is unnecessary because the data centre already has fire suppression and redundant power.
B.The backup window may overlap with online transaction processing, degrading system performance for users.
C.The nightly full backup exceeds the 15-minute RPO, and weekly offsite transport increases the potential data loss window.
D.Tape media is less durable than disk, so the backup may be unreadable when restoration is attempted.
AnswerC

A nightly full backup means up to 24 hours of data could be lost, far exceeding the 15-minute RPO, and weekly offsite shipment means recovery after a site loss could depend on tapes that are days old. This is the most significant finding because the strategy cannot meet the defined recovery objectives at all, leaving the business exposed to substantial data loss and extended outage.

Why this answer

The strategy must be evaluated against the stated RPO and RTO. A nightly full backup permits up to a day of data loss against a fifteen-minute RPO, and weekly offsite shipment means a site loss could force recovery from tapes several days old, also jeopardizing the two-hour RTO. The dominant finding is therefore the fundamental inability of the current approach to meet the defined recovery objectives, which requires a redesign such as more frequent incremental or continuous replication.

Exam trap

The trap here is focusing on tape durability or backup window performance instead of measuring the backup frequency and offsite cadence against the stated RPO and RTO.

30
MCQeasy

Which of the following is the PRIMARY purpose of a service desk?

A.To monitor network performance
B.To manage IT assets
C.To perform root cause analysis
D.To provide a single point of contact for incidents and service requests
AnswerD

A service desk exists to give users one consistent entry point for logging incidents and service requests, ensuring nothing is lost across multiple channels. This single-point-of-contact function is its defining purpose, distinct from resolution, which second-level and specialist teams perform.

Why this answer

The service desk acts as a single point of contact for IT support.

31
Multi-Selecthard

An IS auditor is reviewing an organization's IT service continuity plan (ITSCP) that supports its business continuity plan (BCP). The auditor finds that the ITSCP includes recovery strategies for critical systems but lacks details on roles and responsibilities during a disaster. Which TWO of the following should the auditor recommend to address this gap? (Choose two.)

Select 2 answers
A.Align the ITSCP with the BCP by mapping IT recovery times to business process RTOs.
B.Conduct regular testing of the ITSCP through tabletop exercises.
C.Document detailed recovery procedures for each critical system.
D.Define a crisis management team with clear roles and decision-making authority.
E.Establish an emergency operations center (EOC) with assigned staff and contact information.
AnswersD, E

A crisis management team with defined roles ensures that during a disaster, there is clear leadership and decision-making. This addresses the gap in roles and responsibilities. The team should include representatives from IT, business units, and communications. Clear authority helps avoid confusion and delays. This is a key recommendation to improve the ITSCP's effectiveness and alignment with the BCP.

Why this answer

The ITSCP lacks details on roles and responsibilities during a disaster. To address this, the auditor should recommend defining a crisis management team with clear roles and establishing an emergency operations center with assigned staff and contact information. These actions directly provide the missing structure for decision-making and coordination.

Documenting recovery procedures, testing, and aligning with BCP are important but do not specifically fill the gap of roles and responsibilities.

Exam trap

The trap here is selecting testing or procedure documentation as the primary fix, when the specific deficiency is the absence of defined roles and responsibilities, which are best addressed by establishing a crisis management team and an emergency operations center.

32
MCQmedium

An auditor is reviewing IT asset management processes. The auditor finds that several servers running an older operating system are still in production, even though the vendor has ended support. What is the primary risk associated with this finding?

A.Lack of vendor support and security patches
B.Non-compliance with software licensing
C.Incompatibility with new hardware
D.Increased licensing costs
AnswerA

Once a vendor ends support, no further security patches or vulnerability fixes are released, leaving known exploits permanently unpatched on production servers. This exposes the organisation to compromise and non-compliance, since compensating controls cannot fully substitute for vendor-supplied remediation.

Why this answer

Unsupported software no longer receives security patches, making the systems vulnerable to exploitation.

33
Multi-Selectmedium

Which TWO of the following are key considerations when managing software licenses in an organization? (Select TWO).

Select 2 answers
A.Implementing automated license optimization tools
B.Conducting regular license compliance audits
C.Storing all software installation media in a secure location
D.Maintaining a hardware inventory for asset tracking
E.Ensuring all software is patched to the latest version
AnswersA, B

Automated licence optimisation tools continuously reconcile installed software against entitlements, reclaiming unused seats and flagging over-deployment before true-up audits. This directly satisfies the stem's consideration of ongoing licence management, since manual tracking cannot scale across large estates and typically causes compliance breaches or unnecessary spend.

Why this answer

Option A is correct because automated license optimization tools (e.g., Software Asset Management/SAM platforms that reconcile entitlements against discovered installations) continuously track usage, identify unused or over-deployed licenses, and help reclaim or reassign seats, which directly reduces cost and compliance risk. Option B is correct because regular license compliance audits compare purchased entitlements against actual deployments and usage, producing the evidence needed to true-up agreements, avoid vendor penalties, and satisfy software audits. Option C is not a key license-management consideration; storing installation media securely is a media-handling/backup practice, not license entitlement management.

Option D is not correct because a hardware inventory supports asset tracking and configuration management, but it does not by itself address license entitlements, usage rights, or compliance. Option E is not correct because patching to the latest version is vulnerability and configuration management, unrelated to tracking or optimizing software licenses.

34
MCQhard

An IS auditor is assessing the capacity management process for a virtualized data center. The auditor finds that CPU and memory utilization on a cluster of hosts regularly exceeds 85 percent during month-end processing, causing performance degradation. Management states that they monitor utilization but have no formal forecasting or trend analysis. Which of the following is the MOST significant risk arising from this situation?

A.Inaccurate chargeback to business units for IT resource consumption.
B.Noncompliance with software licensing agreements due to overutilization.
C.Inability to recover from a disaster within the recovery time objective.
D.Unplanned outages and service degradation during peak business periods.
AnswerD

Without forecasting or trend analysis, capacity shortfalls during predictable peaks such as month-end can lead to resource exhaustion, causing outages or severe performance degradation. This directly threatens service availability and business operations. The risk is significant because the organization already experiences high utilization and has no forward-looking process to anticipate and remediate capacity constraints before they impact users.

Why this answer

The absence of forecasting and trend analysis in a capacity management process means the organization cannot anticipate resource demands. With utilization already exceeding 85 percent during month-end, the most significant risk is that peak loads will exhaust resources, causing outages or severe performance issues. This directly impacts business operations and service availability.

Other concerns like chargeback or licensing are less immediate and not indicated by the scenario.

Exam trap

The trap here is focusing on secondary IT management concerns like chargeback or licensing when the scenario's core issue is the lack of predictive capacity planning leading to operational disruption.

35
MCQhard

A company uses a RAID 5 array for its file server. One disk fails, and the system continues to operate. However, during the rebuild process, a second disk fails. What is the likely consequence?

A.Performance degrades but data remains intact
B.Data is still available from parity
C.The system automatically switches to a hot spare
D.Data loss occurs
AnswerD

RAID 5 tolerates only one simultaneous disk failure, storing parity across all member disks. With one disk already failed, the array runs in degraded mode with no redundancy; a second failure during rebuild leaves insufficient parity to reconstruct missing data, so the volume is lost. This satisfies the stem's double-failure constraint.

Why this answer

RAID 5 tolerates exactly one disk failure by storing distributed parity across all member disks. When one disk fails, the array enters degraded mode and can still serve data by reconstructing missing blocks from parity. However, if a second disk fails before the first is rebuilt, the parity information is insufficient to reconstruct two missing data sets, resulting in complete data loss for the array.

Exam trap

The trap is assuming RAID 5 can survive any single failure plus a rebuild — candidates forget that the rebuild window is a period of zero redundancy, so a second failure during rebuild is catastrophic.

How to eliminate wrong answers

Option A is wrong because performance degradation without data loss describes a single-disk failure scenario, not a double failure — with two failed disks, RAID 5 cannot maintain data integrity. Option B is wrong because parity can only reconstruct one missing disk's worth of data; with two disks down, the parity equations are underdetermined and data cannot be recovered. Option C is wrong because hot spare activation is a configuration feature that may or may not exist, and even if a hot spare is present, it only helps if it kicks in before the second failure — the question states the second failure occurs during rebuild, so the spare (if any) is already being rebuilt and cannot save the array.

36
Multi-Selecteasy

An IS auditor is reviewing the ITIL incident management process. Which THREE are the correct priority levels and their typical definitions?

Select 3 answers
A.P1: Critical impact, immediate response required.
B.P4: Critical impact, requires escalation to senior management.
C.P2: Low impact, can be resolved within normal service hours.
D.P2: High impact, requires urgent response.
E.P3: Moderate impact, standard response time.
AnswersA, D, E

P1 denotes the highest priority, reserved for incidents causing critical business impact or major service outage, demanding immediate response and continuous effort until resolution. This matches the ITIL priority matrix, where priority derives from impact and urgency, so P1 definitions must reflect severe disruption requiring escalation.

Why this answer

Option A is correct because P1 is the highest priority level in ITIL incident management, reserved for critical impact incidents (e.g., major outages affecting the whole organization) that demand immediate response and often major incident procedures. Option D is correct because P2 represents high-impact incidents requiring an urgent response, typically affecting a significant user group or critical business function but not as catastrophically as P1. Option E is correct because P3 denotes moderate impact incidents handled with a standard response time under normal service desk workflows.

Option B is incorrect because P4 is the lowest priority (low impact, minor issue), not a critical-impact level requiring senior management escalation. Option C is incorrect because P2 is not defined as low impact resolved within normal service hours; that description better fits P4 or P3, whereas P2 requires urgent attention.

Exam trap

The trap here is that candidates often confuse P2 with low impact or normal service hours, but ITIL defines P2 as high impact requiring urgent response, not low impact, and P4 is never critical impact.

37
Multi-Selectmedium

An IS auditor is reviewing capacity management practices. Which TWO indicators suggest that proactive capacity management is being performed effectively?

Select 2 answers
A.Conducting business impact analysis (BIA) annually.
B.Reviewing backup logs for errors.
C.Monitoring resource utilization trends over time.
D.Setting threshold alerts for CPU, memory, and disk usage.
E.Analyzing historical cost data for IT infrastructure.
AnswersC, D

Tracking utilisation trends over time reveals gradual growth before thresholds are breached, enabling forecasting and timely scaling. This satisfies the stem's requirement for proactive capacity management, since trend analysis anticipates future demand rather than reacting to incidents. Point-in-time monitoring alone would be reactive, whereas historical baselines support informed planning decisions.

Why this answer

Option C is correct because proactive capacity management depends on continuously collecting and analyzing resource utilization metrics (CPU, memory, disk, network, I/O) over time to identify growth trends and forecast future demand before performance degrades. Option D is correct because configuring threshold alerts for CPU, memory, and disk usage enables early detection of approaching capacity limits, allowing remediation actions to be taken before service levels are impacted. Together, trend monitoring and threshold alerting are the hallmarks of a proactive, forecast-driven capacity management process.

Option A is not correct because a BIA is a business continuity/disaster recovery activity that identifies critical processes and recovery requirements, not a capacity management indicator. Option B is not correct because reviewing backup logs addresses backup integrity and recoverability, which is unrelated to capacity planning. Option E is not correct because analyzing historical cost data supports IT financial management and budgeting, not the technical forecasting of resource capacity needs.

Exam trap

CISA often tests the distinction between proactive and reactive activities, and candidates may confuse business continuity or cost analysis tasks with capacity management indicators.

38
MCQhard

During a software asset management (SAM) audit, it is discovered that the organization is using software that has reached end-of-life. Which of the following is the MOST significant risk associated with this situation?

A.Incompatibility with new hardware
B.Lack of security patches
C.Increased maintenance costs
D.License compliance issues
AnswerB

End-of-life software no longer receives vendor security patches, so known vulnerabilities remain unmitigated and exploitable. This is the most significant risk because it directly exposes the organisation to compromise, outweighing the lesser concerns of reduced support or licence compliance.

Why this answer

End-of-life software no longer receives security patches from the vendor, meaning any newly discovered vulnerabilities will remain unaddressed. This creates a direct and exploitable attack surface, making lack of security patches the most significant risk because it can lead to data breaches, system compromise, and regulatory non-compliance.

Exam trap

The trap here is that candidates often focus on immediate operational or financial impacts like cost or compatibility, but the CISA exam prioritizes security risks, especially unpatched vulnerabilities, as the most critical consequence of end-of-life software.

How to eliminate wrong answers

Option A is wrong because incompatibility with new hardware, while operationally inconvenient, is typically manageable through virtualization, compatibility layers, or hardware refreshes and does not introduce active security threats. Option C is wrong because increased maintenance costs, though a financial concern, are a secondary business impact rather than a primary security or compliance risk; the organization could choose to absorb the cost without immediate harm. Option D is wrong because license compliance issues are a legal and contractual risk, but end-of-life software often has no active license requirement, and the greater danger is the absence of security updates that protect the organization from exploitation.

39
MCQhard

An IS auditor is evaluating an organization's capacity management process for a critical database server. The auditor observes that CPU utilization averages 85% during peak hours, memory utilization is at 90%, and disk I/O wait times are consistently high. The organization has no formal capacity plan. Which of the following is the MOST significant risk the auditor should report?

A.The lack of a formal capacity plan may lead to unplanned outages and inability to meet service level agreements.
B.The high CPU and memory utilization may indicate a need for additional hardware, which should be procured immediately.
C.The disk I/O wait times suggest that the storage area network (SAN) is misconfigured and requires tuning.
D.The organization is not complying with industry best practices for capacity management, which could result in regulatory penalties.
AnswerA

This is the most significant risk because without a capacity plan, the organization cannot proactively address resource constraints. High utilization and I/O wait times indicate the server is near its limits, and any further growth or unexpected demand could cause performance degradation or outages, directly impacting SLAs.

Why this answer

The absence of a formal capacity plan is the most critical risk because it leaves the organization unable to predict and prevent performance issues. High utilization metrics indicate the server is already stressed, and without a plan, the organization cannot ensure it will meet current and future demands, leading to potential outages and SLA breaches. Other issues like hardware needs or SAN tuning are symptoms that should be addressed within a capacity management framework.

Exam trap

The trap here is focusing on the immediate technical symptoms (high utilization) rather than the underlying governance failure of not having a capacity plan, which is the root cause of the risk.

40
MCQeasy

An organization has defined an SLA that requires critical incidents to be resolved within 4 hours. A P1 incident is reported at 10:00 AM. At what time must the incident be resolved to meet the SLA?

A.2:00 PM
B.4:00 PM
C.6:00 PM
D.12:00 PM
AnswerA

Resolving by 2:00 PM satisfies the four-hour SLA window starting at 10:00 AM, giving the critical incident team the full mandated response period. Any later resolution breaches the defined service commitment, triggering escalation and SLA penalty provisions under the organisation's incident management process.

Why this answer

The SLA requires critical incidents to be resolved within 4 hours. A P1 incident reported at 10:00 AM must therefore be resolved by 2:00 PM, which is exactly 4 hours later. This is a straightforward time calculation based on the SLA definition.

Exam trap

CISA often tests basic SLA calculations, and the trap is misreading the start time or adding the wrong number of hours, or confusing the deadline with an earlier resolution time.

How to eliminate wrong answers

Option B is wrong because 4:00 PM would be 6 hours after 10:00 AM, exceeding the 4-hour SLA. Option C is wrong because 6:00 PM would be 8 hours later, far beyond the SLA. Option D is wrong because 12:00 PM is only 2 hours after 10:00 AM, which is earlier than the SLA deadline but not the required resolution time; the question asks when it must be resolved to meet the SLA, which is the deadline, not an earlier time.

41
Multi-Selecteasy

An IS auditor is reviewing the backup process for a critical database. Which TWO of the following are essential controls to ensure data recoverability?

Select 2 answers
A.Automated job scheduling for backups.
B.Offsite storage of backup media.
C.Regular restore testing of backups.
D.Encryption of backup data.
E.Backup retention period of at least one year.
AnswersB, C

Offsite storage places backup media beyond the reach of site-specific events such as fire, flood or theft that could destroy both production systems and locally held copies. This satisfies the recoverability requirement by ensuring a surviving copy exists after a site-wide disaster.

Why this answer

Option B (offsite storage of backup media) is essential because it ensures that a viable copy of the data survives a site-level disaster such as fire, flood, or theft that destroys the primary data center, which is a core requirement for recoverability. Option C (regular restore testing of backups) is essential because backups are only proven recoverable when restores are actually performed and validated; untested backups may fail due to media errors, corrupted files, or incomplete jobs, so periodic restore drills confirm the recovery capability and RTO/RPO assumptions. Option A (automated job scheduling) improves reliability and consistency but is a convenience/efficiency control, not a guarantee of recoverability, since scheduled jobs can still fail silently.

Option D (encryption of backup data) is a confidentiality control that protects data at rest or in transit but does nothing to ensure the data can be restored. Option E (a one-year retention period) is an arbitrary retention choice driven by business, legal, and regulatory requirements rather than a universal essential control for recoverability.

Exam trap

The trap here is that candidates often confuse operational controls (like scheduling or encryption) with recoverability controls, forgetting that a backup is only as good as its ability to be restored from a separate location.

42
MCQhard

An IS auditor is reviewing the incident management process. Incidents are categorized as P1 (critical) through P4 (low). The SLA for P1 incidents requires initial response within 15 minutes and resolution within 4 hours. The auditor notes that the average time to respond to P1 incidents is 12 minutes, but the average resolution time is 6 hours. The root cause analysis shows that many P1 incidents are due to known errors documented in the known error database (KEDB). What is the most significant finding?

A.Problem management is not effectively utilizing the KEDB to prevent recurring incidents.
B.The average resolution time for P1 incidents exceeds SLA.
C.The average response time for P1 incidents is within SLA.
D.Incident management is not escalating P1 incidents properly.
AnswerA

Known errors in the KEDB should drive permanent fixes through problem management, eliminating recurrence. Resolution averaging six hours against a four-hour SLA, with recurring known errors, shows problem management is not converting KEDB entries into root-cause resolutions.

Why this answer

If known errors are causing P1 incidents, problem management should have identified workarounds or permanent fixes. The fact that these incidents recur indicates a weakness in the problem management process, which should reduce incidents from known errors.

43
MCQmedium

An organization's backup strategy includes full backups every Sunday and incremental backups on other days. On Wednesday, a failure occurs. Which backups are needed to restore the data?

A.Sunday's full backup only
B.Sunday's full backup and Wednesday's incremental backup
C.Wednesday's incremental backup only
D.Sunday's full backup and Monday through Wednesday incremental backups
AnswerD

Incremental backups capture only changes since the previous backup, so restoration requires the last full backup plus every incremental in sequence. Sunday's full plus Monday, Tuesday and Wednesday incrementals satisfies the stem's Wednesday failure scenario.

Why this answer

To restore from incremental backups, you need the last full backup (Sunday) and all incremental backups from Monday through Wednesday.

44
MCQmedium

An IS auditor is assessing the capacity management process for a cloud-based enterprise resource planning (ERP) system. The organization has experienced performance degradation during peak periods, and the cloud provider's auto-scaling features are not fully utilized. Which of the following should the auditor recommend FIRST?

A.Configure auto-scaling policies based on historical peak usage patterns.
B.Conduct a performance test to simulate peak loads and identify bottlenecks.
C.Implement monitoring tools to track resource utilization and performance metrics.
D.Increase the baseline capacity of the cloud infrastructure to handle peak loads.
AnswerC

Before optimizing auto-scaling or adjusting capacity, the organization needs accurate data on resource usage and performance. Monitoring tools provide visibility into when and why degradation occurs, enabling informed decisions. Without this baseline, any capacity changes are guesswork. The auditor should recommend establishing monitoring first as it is foundational to effective capacity management and will inform subsequent actions.

Why this answer

Effective capacity management begins with understanding current resource utilization and performance. The organization has auto-scaling capabilities but is not using them fully, and performance issues exist. Before making changes, the auditor should recommend implementing monitoring to collect data on resource usage, peak times, and bottlenecks.

This data will inform whether to adjust auto-scaling policies, increase baseline capacity, or optimize the application. Monitoring is the essential first step to ensure that subsequent actions are targeted and effective.

Exam trap

The trap here is jumping to a technical fix like increasing capacity or configuring auto-scaling without first establishing monitoring, which is necessary to make informed decisions and avoid unnecessary costs.

45
MCQmedium

A system has a Mean Time Between Failures (MTBF) of 200 hours and a Mean Time To Repair (MTTR) of 20 hours. What is the availability of the system?

A.95.0%
B.91.0%
C.90.0%
D.90.9%
AnswerD

Availability equals MTBF divided by the sum of MTBF and MTTR: 200 / (200 + 20) = 200/220 = 0.909, giving 90.9%. The 20-hour repair window is the only downtime component, so the system is available for 200 of every 220 hours.

Why this answer

Availability is calculated as MTBF / (MTBF + MTTR). With MTBF = 200 hours and MTTR = 20 hours, availability = 200 / (200 + 20) = 200/220 = 0.90909..., which rounds to 90.9%. This formula reflects the proportion of total time the system is operational versus the total time including repair.

Exam trap

CISA often tests the availability formula, and candidates frequently confuse MTBF and MTTR or incorrectly use MTTR/MTBF instead of MTBF/(MTBF+MTTR).

How to eliminate wrong answers

Option A (95.0%) is wrong because it would require MTTR of approximately 10.5 hours (200/210 ≈ 95.2%), not 20 hours. Option B (91.0%) is wrong because it does not match the precise calculation; 200/220 = 90.909%, which rounds to 90.9%, not 91.0%. Option C (90.0%) is wrong because it incorrectly uses a simple subtraction or misapplies the formula; 200/220 is not 90.0%.

46
MCQmedium

An IS auditor is reviewing the backup strategy for a financial institution's core transaction processing system. The system processes high volumes of transactions continuously and requires a recovery point objective (RPO) of 5 minutes. The current strategy includes nightly full backups and hourly incremental backups. Which of the following should the auditor recommend as the MOST appropriate improvement?

A.Perform full backups twice daily instead of nightly.
B.Increase the frequency of incremental backups to every 15 minutes.
C.Implement snapshot-based backups every 30 minutes.
D.Implement continuous data protection (CDP) with journaling to capture every transaction.
AnswerD

CDP captures changes continuously or near-continuously, enabling recovery to any point in time with minimal data loss. With an RPO of 5 minutes, hourly incrementals are insufficient. CDP can achieve an RPO of seconds or minutes, meeting the requirement. This is the most appropriate recommendation because it directly addresses the gap between the current backup frequency and the required RPO.

Why this answer

The core transaction system requires an RPO of 5 minutes, meaning no more than 5 minutes of data can be lost. Nightly full and hourly incremental backups leave up to 60 minutes of data at risk. Continuous data protection captures every change, enabling recovery to within seconds or minutes, thus meeting the RPO.

Increasing incremental frequency to 15 minutes still exceeds the RPO, and other options are even less frequent. CDP is the only viable solution among the choices.

Exam trap

The trap here is assuming that more frequent traditional backups (e.g., every 15 minutes) can meet a very low RPO, when in fact only continuous or near-continuous replication technologies can achieve RPOs of 5 minutes or less.

47
MCQmedium

An organization has implemented a business continuity plan (BCP) and disaster recovery plan (DRP). During a recent full interruption test, the IT team discovered that the recovery time objective (RTO) for a critical application was not met. What is the MOST likely reason for this failure?

A.The recovery point objective (RPO) was set too low, causing data loss.
B.The backup data was not encrypted, leading to corruption during restoration.
C.The tabletop exercise was not conducted before the full interruption test.
D.The alternate site did not have adequate processing capacity to handle the workload.
AnswerD

Insufficient processing capacity at the alternate site means the workload cannot be recovered within the required window, directly explaining the missed RTO. This satisfies the stem's constraint by identifying a resource shortfall in the recovery environment rather than a procedural or documentation failure.

Why this answer

The most likely reason the RTO was not met is that the alternate site lacked sufficient processing capacity to handle the workload. RTO measures the time to restore service availability; if the failover site cannot support the required compute, memory, or I/O throughput, restoration will be delayed or fail outright. This is a common capacity planning failure in DR testing, where the alternate site is sized for minimal operations but not for the full production load.

Exam trap

The trap here is that candidates confuse RTO with RPO or assume procedural gaps (like missing a tabletop exercise) are the root cause, when the actual failure is a technical capacity limitation at the alternate site.

How to eliminate wrong answers

Option A is wrong because RPO being set too low (i.e., very frequent backups) reduces potential data loss, not causes RTO failure; RPO and RTO are independent metrics. Option B is wrong because backup encryption does not cause corruption; encryption protects data at rest, and corruption typically results from media errors or improper backup/restore processes, not the encryption itself. Option C is wrong because while tabletop exercises validate plans, skipping one does not directly cause a capacity shortfall at the alternate site; the RTO failure here is a technical infrastructure issue, not a procedural gap.

48
MCQeasy

An IS auditor is reviewing the IT operations of a small company. The auditor finds that scheduled batch jobs are monitored manually by an operator who checks job logs each morning. Which of the following is the MOST significant risk associated with this practice?

A.Job failures may not be detected until the next morning, delaying critical business processes.
B.Batch jobs may run longer than expected, causing resource contention during peak hours.
C.The operator may lack the technical skills to restart failed jobs, leading to prolonged outages.
D.Manual monitoring increases the risk of unauthorized access to job logs containing sensitive data.
AnswerA

With only a daily manual check, a failed batch job could go unnoticed for up to 24 hours. This delay can disrupt dependent business processes, such as financial reporting or payroll, causing operational and financial impact. Automated monitoring with alerts would enable immediate detection and response. This is the most significant risk because it directly affects timeliness and availability of critical processing.

Why this answer

Manual monitoring once per day means that any failure occurring after the check will not be detected until the next day, potentially delaying critical business processes. Automated monitoring with real-time alerts is essential for timely detection and response. Resource contention, operator skill, and log access are relevant but are not the primary risk introduced by this practice.

Exam trap

The trap here is focusing on secondary operational issues like performance or security instead of the core weakness: delayed detection of job failures due to infrequent manual monitoring.

49
MCQmedium

An IS auditor is reviewing the job scheduling environment for an organization's overnight batch processing on a mainframe. The auditor finds that operators have the authority to modify job control statements, restart failed jobs, and manually release jobs held for review, all using the same production operator ID. Which finding should the auditor report as the GREATEST concern?

A.Operators can restart failed jobs without notifying the application owner.
B.Operators can manually release jobs held for review using the same production operator ID.
C.Execution, modification, and review of batch jobs are performed under a single shared operator ID.
D.Operators can modify job control statements without a second approver.
AnswerC

The greatest concern is the collapse of segregation of duties: one shared production operator ID performs execution, modification of job control statements, restart, and release of held jobs. Because the same credential spans all these functions, no independent review or approval can be enforced, and actions cannot be attributed to an individual. This defeats the detective and preventive controls that a batch environment depends on.

Why this answer

Batch integrity depends on separating who prepares and modifies jobs from who executes, restarts, and releases them, and on unique IDs so every action is attributable. When one shared operator ID carries modification, restart, and release rights, a single operator can alter processing logic and then release the altered job without any independent check. That combination of powers, not any single right, is the reportable control failure.

Exam trap

The trap here is focusing on one sensitive permission, such as job control statement modification, instead of recognizing that the combination of modification, restart, and release rights under a single shared ID is what eliminates independent review.

50
MCQmedium

An organization is conducting a Business Impact Analysis (BIA). Which of the following metrics defines the maximum acceptable outage time for a critical business process?

A.Recovery Point Objective (RPO)
B.Maximum Tolerable Downtime (MTD)
C.Recovery Time Objective (RTO)
D.Work Recovery Time (WRT)
AnswerB

Maximum Tolerable Downtime directly expresses the longest period a critical process may remain unavailable before unacceptable business impact occurs, which is precisely the outage limit a BIA must document. Recovery Time Objectives for individual systems are then derived to sit within this business-defined threshold, satisfying the stem's requirement for the maximum acceptable outage.

Why this answer

Maximum Tolerable Downtime (MTD) defines the maximum acceptable outage time for a critical business process. It represents the total time a business can tolerate the unavailability of a process before unacceptable consequences occur. MTD is a key output of the BIA and sets the upper limit for recovery objectives.

Exam trap

CISA often tests the distinction between MTD, RTO, RPO, and WRT; candidates may incorrectly select RTO as the maximum acceptable outage, but RTO is the target recovery time, not the maximum tolerable downtime.

How to eliminate wrong answers

Option A (RPO) is wrong because RPO defines the maximum acceptable data loss measured in time, not outage duration. Option C (RTO) is wrong because RTO is the target time to restore a system or process after a disruption, which must be less than MTD. Option D (WRT) is wrong because Work Recovery Time is the time needed to verify data integrity and resume normal operations after systems are restored, which is part of the overall recovery but not the maximum acceptable outage.

51
Multi-Selectmedium

An IS auditor is reviewing the business impact analysis (BIA) for a financial services company. Which THREE metrics are typically defined in a BIA?

Select 3 answers
A.Mean time to repair (MTTR).
B.Mean time between failures (MTBF).
C.Recovery point objective (RPO).
D.Maximum tolerable downtime (MTD).
E.Recovery time objective (RTO).
AnswersC, D, E

RPO defines the maximum tolerable data loss, expressed as time, and directly drives backup frequency. A BIA must record it so recovery strategies align with the financial services company's tolerance for lost transactions, making it one of the three core metrics alongside RTO and MTD.

Why this answer

The BIA defines the recovery objectives that drive continuity and DR planning: C (Recovery point objective, RPO) specifies the maximum acceptable data loss measured in time before the disruption, determining backup frequency; D (Maximum tolerable downtime, MTD) is the total time a business process can be unavailable before unacceptable impact occurs, and it bounds the recovery strategy; and E (Recovery time objective, RTO) is the target time to restore the process or system after disruption, which must be less than the MTD. These three are business-driven metrics derived from process criticality and impact over time. By contrast, A (MTTR) and B (MTBF) are operational reliability and maintainability metrics of components or systems, not business impact metrics defined in a BIA.

Exam trap

The trap here is that candidates confuse operational metrics like MTBF and MTTR (which are used in IT service management and availability calculations) with the business-focused recovery metrics (RTO, RPO, MTD) that are defined in a BIA, leading them to select options A or B instead of the correct trio.

52
MCQmedium

An organization is implementing a software asset management (SAM) program. Which of the following is the PRIMARY benefit of SAM?

A.Ensuring compliance with software licensing agreements
B.Reducing hardware costs
C.Automating patch management
D.Improving network performance
AnswerA

SAM maintains an accurate inventory of installed software against entitlements, so licensing compliance is the primary benefit. It directly satisfies the stem's constraint by reconciling deployed licences with purchased rights, preventing legal exposure and unbudgeted true-up costs.

Why this answer

The primary benefit of a software asset management (SAM) program is ensuring compliance with software licensing agreements, which mitigates legal, financial, and reputational risk from unlicensed or over-deployed software. SAM provides visibility into what software is installed, where, and under what license terms, enabling accurate reconciliation of entitlements versus deployments. While SAM can yield cost savings, compliance is the primary driver because non-compliance carries legal penalties and audit exposure.

Exam trap

CISA often tests the distinction between primary and secondary benefits — candidates pick cost reduction (a common outcome) instead of compliance, which is the stated primary purpose of SAM.

How to eliminate wrong answers

Option B is wrong because reducing hardware costs is a potential secondary outcome of better asset visibility, not the primary benefit of SAM, which focuses on software. Option C is wrong because patch management is a separate IT operations discipline; SAM may inform patch decisions by identifying installed software, but automating patching is not its purpose. Option D is wrong because network performance is unrelated to software asset management — SAM does not monitor or optimize network traffic.

53
Multi-Selectmedium

An IS auditor is reviewing an organization's IT operations incident management process. The auditor finds that incidents are categorized and prioritized, but there is no formal escalation procedure. Which TWO of the following are the MOST significant risks of not having an escalation procedure? (Choose two.)

Select 2 answers
A.Critical incidents may not be escalated to senior management in a timely manner, delaying decision-making.
B.Support staff may not have clear guidance on when to involve higher-tier support, causing delays in resolution.
C.The organization may incur unnecessary costs by over-escalating minor incidents to senior management.
D.Incidents may be resolved without proper documentation, leading to incomplete records.
E.Incidents may be incorrectly prioritized, leading to a focus on low-impact issues.
AnswersA, B

This is a significant risk because without a defined escalation path, critical incidents may remain at lower support tiers, preventing senior management from being informed and making timely decisions. This can prolong outages and increase business impact. Escalation procedures ensure that the right people are engaged at the right time, especially for high-severity incidents that require executive attention or cross-functional coordination.

Why this answer

A formal escalation procedure defines when and how incidents should be escalated to higher tiers of support or management. Without it, critical incidents may not receive timely attention from senior management, and support staff may lack clear criteria for involving higher-level resources. These two risks can lead to extended outages, poor decision-making, and increased business impact.

The other options describe issues related to documentation, prioritization, or over-escalation, which are less directly caused by the absence of an escalation procedure.

Exam trap

The trap here is selecting documentation or prioritization issues as primary risks, when the core risks are delayed escalation of critical incidents and unclear guidance for support staff on when to escalate.

54
Multi-Selecthard

An IS auditor is reviewing the backup and restoration controls for a hospital's electronic health record (EHR) system, which runs on a relational database with a recovery point objective (RPO) of 15 minutes. The database administrator performs a full backup every Sunday at 01:00, differential backups nightly at 01:00, and transaction log backups every 15 minutes. During testing, the auditor observes that a restore of the database to a point in time at 14:07 on Wednesday completed successfully but took 9 hours, exceeding the stated maximum tolerable downtime (MTD) of 4 hours. Which TWO conclusions should the auditor draw from this observation? (Choose two.)

Select 2 answers
A.The recovery process should be re-engineered or supplemented so that restoration can be completed within the MTD.
B.The transaction log backups should be replaced with hourly full backups to reduce the total restore time.
C.The differential backup strategy is the root cause of the lengthy restore because differential backups must be applied in sequence.
D.The restore should be considered a failure of the backup integrity controls because the elapsed time exceeded the MTD.
E.The backup schedule satisfies the RPO but the restoration time indicates the MTD cannot be met with the current recovery strategy.
AnswersA, E

Because the restore succeeded but exceeded the 4-hour MTD, the recovery capability does not support the business requirement. The auditor should conclude that the recovery process needs redesign, such as using snapshot or replication technologies, faster storage, or parallel recovery, to bring restoration time within the MTD. This is the actionable control conclusion from the test.

Why this answer

The backup frequency meets the RPO, but the restore duration violates the MTD, revealing a gap between backup adequacy and actual recoverability. The auditor must recognize that a successful restore is not sufficient if it cannot be completed within the business tolerance. The appropriate conclusions are that the RPO is satisfied and that the recovery process must be improved to meet the MTD.

Exam trap

The trap here is assuming that a successful restore proves the recovery strategy is adequate, when recovery time objectives and maximum tolerable downtime are separate requirements that a slow restore can violate.

55
MCQeasy

During a change management board (CAB) meeting, a proposed change to the network firewall configuration is discussed. The change is considered low risk and pre-approved. Which type of change does this represent?

A.Emergency change
B.Major change
C.Standard change
D.Normal change
AnswerC

A standard change is a pre-authorised, low-risk change with a documented procedure, requiring no further CAB approval before implementation. This directly satisfies the stem's constraints: the firewall change is low risk and pre-approved, so it follows an established path rather than requiring individual authorisation.

Why this answer

A standard change is a pre-approved, low-risk change that follows a documented procedure and does not require additional review or approval from the change management board (CAB). Since the firewall change is described as low risk and pre-approved, it fits the definition of a standard change. Standard changes are routine and repeatable, allowing them to bypass the full CAB review process, which is reserved for normal or major changes.

Exam trap

CISA often tests the distinction between standard and normal changes, where candidates may incorrectly assume that any low-risk change is a normal change requiring CAB approval, forgetting that standard changes are pre-approved and do not need CAB review.

How to eliminate wrong answers

Option A is wrong because an emergency change is an unplanned change that must be implemented immediately to resolve a critical incident or restore service, and it typically requires expedited approval, not pre-approval. Option B is wrong because a major change is a high-risk change that significantly impacts the organization and requires extensive review, testing, and approval by the CAB, not a low-risk pre-approved change. Option D is wrong because a normal change is a change that is not an emergency or standard change; it requires review and approval by the CAB, even if it is low risk, whereas standard changes are pre-approved and do not require such review.

56
MCQeasy

Which of the following is the PRIMARY purpose of a business impact analysis (BIA)?

A.To establish service level agreements (SLAs)
B.To identify critical business processes and their recovery requirements
C.To test the effectiveness of backup procedures
D.To develop the disaster recovery plan
AnswerB

The BIA determines which business processes are critical and quantifies their recovery time objectives and recovery point objectives. These outputs drive the continuity strategy, so identifying critical processes and their recovery requirements is its primary purpose rather than risk ranking alone.

Why this answer

A business impact analysis (BIA) is the foundational step in business continuity planning that identifies which business processes are critical and quantifies the impact of their disruption over time. It determines recovery time objectives (RTOs) and recovery point objectives (RPOs) for each process, which then drive the recovery strategies and resource requirements documented in the BCP and DRP. Without a BIA, recovery priorities cannot be rationally established.

Exam trap

The trap here is confusing the BIA with the BCP or DRP — candidates often pick 'develop the disaster recovery plan' because they conflate the analysis phase with the planning phase that follows it.

How to eliminate wrong answers

Option A is wrong because SLAs are contractual agreements between a service provider and customer defining expected service levels; they are informed by, but not the purpose of, a BIA. Option C is wrong because testing backup procedures is a validation activity within the BCP maintenance lifecycle, not the purpose of the BIA itself — the BIA identifies what needs to be recovered, not whether backups work. Option D is wrong because developing the disaster recovery plan is a downstream activity that uses BIA output; the BIA is an input to the DRP, not the DRP itself, and conflating the two reverses the dependency.

57
Multi-Selectmedium

An IS auditor is reviewing an organization's problem management process. The auditor finds that problem records are created only after multiple incidents with the same root cause have occurred, and there is no proactive trend analysis. Which TWO of the following are the MOST important improvements the auditor should recommend? (Choose two.)

Select 2 answers
A.Require all incidents to be escalated to the problem manager immediately.
B.Establish a formal problem prioritization scheme based on business impact and urgency.
C.Outsource the problem management function to a third-party service provider.
D.Automate the closure of incidents when a problem record is created.
E.Implement trend analysis of incident data to identify recurring issues and raise problem records proactively.
AnswersB, E

A formal prioritization scheme ensures that problem records are addressed according to business impact and urgency, optimizing resource allocation. Without it, problems may be handled in an ad hoc manner, delaying resolution of critical issues. This improvement complements proactive identification by ensuring that the most significant problems receive appropriate attention and escalation.

Why this answer

The problem management process is reactive because problems are only created after multiple incidents. The two most important improvements are proactive trend analysis to identify recurring issues and a formal prioritization scheme to ensure business-relevant problems are addressed appropriately. These changes shift the process from reactive to proactive and risk-based, reducing repeat incidents and aligning problem resolution with business impact.

Exam trap

The trap here is recommending operational changes like escalating all incidents or automating closures, which do not address the core weakness of missing proactive analysis and prioritization.

58
MCQmedium

An IT auditor is reviewing the problem management process. The IT team maintains a repository of known errors with documented workarounds. Which component of problem management is this?

A.Service request
B.Root cause analysis
C.Known error database
D.Problem record
AnswerC

The known error database records previously diagnosed problems and their documented workarounds, letting service desk staff resolve recurring incidents quickly without re-diagnosing root cause. It is a core problem management artefact, distinct from the incident record itself.

Why this answer

A known error database (KED) is the ITIL problem management repository that stores known errors and their documented workarounds. When the IT team maintains a repository of known errors with workarounds, that is by definition the KED.

Exam trap

CISA often tests the confusion between the problem record (single problem lifecycle) and the known error database (aggregated repository of known errors and workarounds).

How to eliminate wrong answers

Option A is wrong because a service request is a user request for something (e.g., password reset), handled by request fulfillment, not problem management. Option B is wrong because root cause analysis is the investigative activity that identifies the underlying cause of a problem, not the repository itself. Option D is wrong because a problem record documents a single problem's lifecycle; the KED is the aggregated repository of known errors and workarounds.

59
Multi-Selecthard

An IS auditor is reviewing change management for a financial application. Which TWO of the following findings would most likely indicate a control weakness?

Select 2 answers
A.Regression testing is not performed for minor changes.
B.Emergency changes are authorized by the change manager only.
C.Normal changes are tested in a development environment before production.
D.The change advisory board meets weekly to review all changes.
E.All changes are documented in a change log.
AnswersA, B

Regression testing verifies that existing functionality still works after a change. Skipping it for minor changes allows unintended side effects to reach production undetected, directly weakening change control in a financial application where data integrity and transaction accuracy are critical.

Why this answer

Option A is a control weakness because regression testing verifies that a change has not broken existing functionality; skipping it even for minor changes to a financial application risks undetected defects or integrity failures in production. Option B is a control weakness because emergency changes should be authorized by an appropriate business or IT authority (and later reviewed by the change advisory board), not by the change manager alone, which creates an improper segregation-of-duties conflict since the same person manages and approves the change. Option C is not a weakness because testing normal changes in a development environment before production is a sound change management control.

Option D is not a weakness because a weekly change advisory board reviewing all changes provides proper oversight and authorization. Option E is not a weakness because documenting all changes in a change log supports traceability and auditability.

Exam trap

The trap here is that candidates may incorrectly consider emergency changes authorized only by the change manager as acceptable, but it is a control weakness because it bypasses proper segregation of duties and approval hierarchy. Even emergency changes should require authorization from a higher authority or be subject to post-implementation review.

60
Multi-Selecthard

An IS auditor is reviewing an organization's IT operations incident management process. The auditor finds that incidents are logged, but there is no formal problem management process. Which TWO of the following are the MOST likely consequences of this deficiency? (Choose two.)

Select 2 answers
A.Major incidents will automatically be escalated to the problem manager for resolution.
B.Incident resolution times will increase because support staff lack a knowledge base of known errors.
C.Recurring incidents will not be analyzed to identify and eliminate their root causes.
D.The service desk will be unable to log incidents due to the absence of problem records.
E.Change management will be unable to assess the impact of changes without problem tickets.
AnswersB, C

Problem management maintains a known error database and workarounds. Without it, support staff cannot quickly reference previously identified issues and solutions, so they may spend more time diagnosing the same problems. This leads to longer resolution times and reduced service quality, making it a correct consequence.

Why this answer

Problem management focuses on identifying the root causes of incidents and preventing recurrence. Without it, organizations suffer from repeated incidents and lack a known error database, which slows resolution. Incident logging and change management are separate processes that do not depend on problem management.

Escalation of major incidents is an incident management activity, not a consequence of missing problem management.

Exam trap

The trap here is assuming that incident management depends on problem management for basic functions like logging or escalation, when in fact problem management is an improvement layer that addresses root causes.

61
MCQhard

An IS auditor is reviewing an organization's disaster recovery plan (DRP) for its primary data center. The DRP specifies a reciprocal arrangement with a partner organization for backup processing. Which of the following is the MOST significant risk associated with this arrangement that the auditor should highlight?

A.The partner may not have adequate security controls to protect the organization's data.
B.The partner may not have sufficient capacity to handle the organization's workload during a simultaneous disaster.
C.The partner may not have compatible hardware and software configurations.
D.The arrangement may not be legally enforceable without a formal contract.
AnswerB

Reciprocal agreements rely on the assumption that the partner's facility will be available and have spare capacity. However, if both organizations are affected by the same disaster (e.g., regional event), the partner may be unable to accommodate the additional load. This is a critical risk because it can render the DRP ineffective precisely when needed. The auditor should emphasize this as the most significant concern.

Why this answer

A reciprocal disaster recovery arrangement depends on the partner's ability to provide processing capacity when needed. The most significant risk is that the partner may also be affected by the same disaster or may not have enough spare capacity to handle both organizations' workloads simultaneously. This can lead to failure of the DRP.

Compatibility, legal enforceability, and security are important but secondary to the fundamental availability risk. The auditor should prioritize highlighting the capacity risk.

Exam trap

The trap here is focusing on technical compatibility or legal issues as the primary risk, when the most critical weakness of reciprocal agreements is the unguaranteed availability of the partner's resources during a widespread disaster.

62
MCQhard

During a disaster recovery test, the IS auditor observes that the alternate site uses a warm site configuration. Which of the following is a characteristic of a warm site?

A.It is a mobile recovery unit
B.It has infrastructure but no processing equipment
C.It has equipment but requires data restoration
D.It is a fully operational duplicate of the primary site
AnswerC

A warm site is partially equipped: hardware, peripherals and network connectivity are installed, but current production data is absent and must be restored from backups before operations resume. This distinguishes it from a hot site, which holds mirrored live data, and a cold site, which lacks installed equipment.

Why this answer

A warm site is a partially equipped recovery facility that contains the hardware, network infrastructure, and peripherals needed to run operations, but it does not have current production data pre-loaded. After a disaster is declared, the organization must restore data from backups and apply recent transaction logs before the site can process live workloads. This makes warm sites a middle-ground option between a cold site (empty facility) and a hot site (fully mirrored, near-instant failover).

Exam trap

CISA often tests the distinction between cold, warm, and hot sites by swapping their defining characteristics — candidates frequently confuse 'has equipment but needs data' (warm) with 'has infrastructure but no equipment' (cold) or 'fully operational duplicate' (hot).

How to eliminate wrong answers

Option A is wrong because a mobile recovery unit is a self-contained trailer or portable facility that can be transported to a location — that is a distinct recovery strategy, not the definition of a warm site. Option B is wrong because a facility with infrastructure but no processing equipment describes a cold site, which lacks the servers and hardware needed to run applications. Option D is wrong because a fully operational duplicate of the primary site describes a hot site, which maintains synchronized data and can take over almost immediately.

63
MCQmedium

During a software asset management (SAM) audit, the IS auditor discovers that the organization is using software versions that are no longer supported by the vendor. What is the primary risk?

A.Exposure to security vulnerabilities without patches.
B.Inability to recover data from backups.
C.Increased licensing costs due to non-compliance.
D.Difficulty in migrating to new versions.
AnswerA

Unsupported software no longer receives vendor security patches, so known vulnerabilities remain permanently exploitable. This directly satisfies the stem's primary risk: unmitigated exposure, since no remediation path exists until the version is upgraded or replaced.

Why this answer

The primary risk of using unsupported software versions is the absence of vendor-provided security patches. Without these patches, known vulnerabilities remain unaddressed, exposing the organization to exploitation, data breaches, and system compromise. This directly impacts the confidentiality, integrity, and availability of information assets.

Exam trap

The trap here is that candidates may focus on operational inconveniences like migration difficulty or licensing costs, overlooking the fact that the most critical and immediate risk from unsupported software is the lack of security patches, which directly enables exploitation.

How to eliminate wrong answers

Option B is wrong because data recovery from backups depends on backup integrity and restoration procedures, not on vendor support status; unsupported software can still be backed up and restored. Option C is wrong because unsupported software typically has no licensing costs (support contracts end), and non-compliance usually involves over-licensing or unlicensed use, not the use of unsupported versions. Option D is wrong while migration difficulty is a potential operational challenge, it is not the primary risk; the immediate and most severe risk is the security exposure from unpatched vulnerabilities.

64
MCQmedium

An IS auditor is evaluating the IT service continuity plan for a hospital's electronic health record (EHR) system. The auditor finds that the plan includes a recovery time objective (RTO) of 4 hours, but the hospital's clinical staff state that they can tolerate only 1 hour of downtime before patient safety is compromised. Which of the following should the auditor recommend FIRST?

A.Conduct a full interruption test to validate the current recovery capabilities.
B.Revise the RTO to align with the clinical requirement and reassess the recovery strategy.
C.Implement a redundant server cluster at the primary site to improve availability.
D.Increase the frequency of data backups to reduce potential data loss.
AnswerB

The RTO in the plan does not match the business requirement identified by clinical staff. The auditor should first recommend that the RTO be corrected to reflect the actual tolerable downtime, and then the recovery strategy must be reassessed to ensure it can meet the new RTO. Aligning the RTO with business needs is the foundation for an effective continuity plan.

Why this answer

The RTO in the plan is 4 hours, but clinical staff require no more than 1 hour of downtime. The auditor should first recommend revising the RTO to reflect the true business requirement, then reassess whether the recovery strategy can meet that RTO. Without this alignment, any subsequent technical improvements may be misdirected.

The RTO is a business-driven metric and must be accurate before designing recovery solutions.

Exam trap

The trap here is jumping to technical solutions like backups or clustering without first correcting the misaligned RTO, which is the root cause of the mismatch between the plan and business needs.

65
Multi-Selectmedium

An IS auditor is reviewing the problem management process after a series of recurring production outages. The auditor finds that incidents are resolved quickly but the same underlying faults reappear. Which TWO activities should the auditor expect to find in an effective problem management process? (Choose two.)

Select 2 answers
A.A known error database that records diagnosed root causes and workarounds for reuse.
B.Weekly reporting of incident volumes by category to the service desk manager.
C.Escalation of every incident to senior management within one hour of detection.
D.Automatic closure of incidents once the affected service is restored to users.
E.Root cause analysis performed for recurring incidents, with corrective actions tracked to closure.
AnswersA, E

A known error database captures diagnosed root causes and documented workarounds so that support staff can resolve recurrences faster and avoid duplicating diagnostic effort. It converts problem investigations into organizational knowledge. For an environment where the same faults reappear, this repository directly supports consistent handling and provides evidence that problems are being analyzed rather than merely closed, making it a core problem management activity.

Why this answer

Effective problem management identifies the underlying cause of recurring incidents and prevents recurrence. Root cause analysis with corrective actions tracked to closure delivers the permanent fix, while a known error database preserves diagnosed causes and workarounds so recurrences are handled consistently and diagnostic effort is not repeated. Incident escalation, automatic closure, and volume reporting support operations but do not eliminate the root causes.

Exam trap

The trap here is confusing incident management activities, such as rapid escalation and automatic closure, with problem management, which exists specifically to find and eliminate the underlying cause of recurring incidents.

66
MCQmedium

An organization outsources its IT help desk to a third-party vendor. Which clause is MOST important for the IS auditor to verify in the contract to ensure the organization can assess the vendor's controls?

A.Service level agreement (SLA) metrics
B.Subcontracting restrictions
C.Exit strategy provisions
D.Right-to-audit clause
AnswerD

A right-to-audit clause contractually grants the organisation access to assess the vendor's controls, processes and evidence. Without it, the auditor cannot independently verify the outsourced help desk's control environment, directly satisfying the stem's assessment objective.

Why this answer

A right-to-audit clause in the contract explicitly grants the organization the right to audit the vendor's controls, processes, and compliance, which is essential for the IS auditor to assess the vendor's security posture. Without this clause, the organization may have no contractual authority to conduct audits or obtain audit reports, making it impossible to verify the effectiveness of controls.

Exam trap

The trap is confusing SLA metrics or exit strategies with audit rights; candidates must recognize that only a right-to-audit clause gives the organization the contractual authority to assess the vendor's controls.

How to eliminate wrong answers

Option A is wrong because SLA metrics define performance expectations but do not grant the right to audit the vendor's controls; SLAs are about service levels, not audit access. Option B is wrong because subcontracting restrictions limit the vendor's ability to outsource work but do not provide audit rights. Option C is wrong because exit strategy provisions address how to terminate the relationship and migrate services, not how to audit the vendor's controls during the contract term.

67
MCQeasy

An IS auditor is reviewing the IT operations function of a mid-sized organization. Management asks which control would BEST ensure that capacity problems are detected before they affect users of critical production systems.

A.Annual benchmarking of server performance against vendor specifications.
B.Automated resource utilization monitoring with defined thresholds and alerting.
C.Periodic review of historical performance reports by the operations manager.
D.A help desk procedure that logs user complaints about slow response times.
AnswerB

Automated monitoring of CPU, memory, storage, and network utilization against defined thresholds generates alerts when consumption approaches capacity limits, allowing staff to act before users are affected. It is continuous, objective, and repeatable, unlike manual review. Defining thresholds converts raw metrics into actionable triggers, which is exactly the proactive detection the scenario requires for critical production systems.

Why this answer

Early detection of capacity problems requires continuous, automated measurement of resource consumption against thresholds that trigger alerts, enabling staff to act before service levels degrade. Historical reports, annual benchmarking, and user complaints all detect problems after the fact or only intermittently. Automated threshold-based monitoring is the only option that operates proactively and consistently across critical production systems.

Exam trap

The trap here is choosing a manual review or user feedback activity because it sounds like oversight, when the requirement to detect problems before users are affected demands automated, threshold-driven monitoring.

68
Multi-Selecthard

An organization is developing a business continuity strategy. Which THREE of the following are essential components of a comprehensive BC strategy?

Select 3 answers
A.Alternate facilities
B.Data backup and technology recovery
C.Software licensing compliance
D.Vendor audit reports
E.People procedures and communication
AnswersA, B, E

Alternate facilities provide the recoverable processing environment when the primary site is unavailable, satisfying the continuity strategy's requirement for restoring critical operations within the maximum tolerable downtime. Without a prearranged site, recovery depends on ad hoc arrangements that rarely meet required timeframes.

Why this answer

A comprehensive business continuity strategy must include alternate facilities (A), because if the primary site is unavailable, the organization needs a prearranged recovery site such as a hot, warm, or cold site to resume critical operations within the recovery time objective. Data backup and technology recovery (B) are essential because restoring systems, applications, and data from backups (with defined RPO/RTO) is the technical foundation for resuming business functions after disruption. People procedures and communication (E) are equally essential, since BC plans require defined roles, call trees, escalation paths, and communication methods to coordinate staff, customers, and stakeholders during and after an incident.

Software licensing compliance (C) is a legal/audit concern rather than a core BC component, and vendor audit reports (D) support third-party risk management but are not themselves essential elements of a BC strategy.

Exam trap

CISA often tests the boundary between BC strategy components and adjacent governance areas — candidates who pick software licensing or vendor audits confuse IT compliance activities with continuity planning.

69
MCQmedium

An IS auditor is reviewing the job scheduling function for a mainframe environment that runs nightly batch processing. The auditor finds that the senior operator has standing access to modify production JCL and job schedules without a second approval. Which control should the auditor recommend to BEST mitigate the associated risk?

A.Implement dual control over scheduling changes that affect production jobs.
B.Enable logging of all JCL modifications and review the logs monthly.
C.Require the senior operator to document all schedule changes in a change log.
D.Restrict the senior operator's access to read-only for all production JCL.
AnswerA

Dual control requires two authorized individuals to approve and apply scheduling changes, preventing a single operator from unilaterally altering production processing. This directly addresses the segregation-of-duties weakness where one person can modify JCL and schedules. It is the most effective preventive control because it introduces independent verification before the change executes, reducing the risk of unauthorized or erroneous job modifications affecting financial or operational data.

Why this answer

The core issue is a segregation-of-duties gap: one senior operator can modify production JCL and schedules without independent approval. The most effective mitigation is a preventive control that requires two people to authorize and apply changes. Dual control ensures no single individual can alter critical batch processing, reducing the risk of both errors and fraud.

Detective controls like logging are useful but do not stop the change from occurring.

Exam trap

The trap here is assuming that logging or documentation provides sufficient control when the real risk is the lack of a preventive segregation-of-duties mechanism.

70
MCQhard

An organization has a disaster recovery plan that includes a hot site. During a full interruption test, the recovery team discovers that the hot site's network configuration is incompatible with the production environment. What is the most likely root cause?

A.The backup data was not encrypted.
B.The test was not conducted during business hours.
C.The DR plan was not updated to reflect production changes.
D.The hot site is too far from the primary site.
AnswerC

Production changes to network addressing, routing or topology were not reflected in the DR documentation, so the hot site was configured against an outdated baseline. Configuration drift between production and the plan causes such incompatibility during full interruption testing.

Why this answer

The incompatibility suggests that the hot site was not properly configured to mirror production, possibly due to lack of change synchronization or testing.

71
MCQmedium

An IS auditor is reviewing the IT service continuity plan for a regional bank. The plan identifies a recovery time objective of 6 hours for the core banking system and designates a warm site with pre-installed hardware but no replicated data. The plan states that data will be restored from nightly backups stored in an offsite vault. Which of the following is the MOST critical issue the auditor should raise?

A.The recovery time objective of 6 hours should be increased to align with the capabilities of a warm site.
B.The warm site lacks replicated data, so restoring from nightly backups may not meet the 6-hour recovery time objective.
C.The offsite vault storing nightly backups may not provide adequate physical security for backup media.
D.Nightly backups do not provide a sufficiently low recovery point objective for a core banking system.
AnswerB

A warm site with pre-installed hardware but no replicated data requires restoring from offsite backups, which involves retrieving media, rebuilding systems, and replaying data. This process typically exceeds six hours and may also lose up to a day of transactions. The mismatch between the recovery strategy and the RTO is the most critical issue because it directly threatens the bank's ability to resume core operations within tolerance.

Why this answer

The most critical issue is the inconsistency between the recovery strategy and the documented RTO. A warm site without replicated data requires rebuilding from backup media, a process that rarely completes within six hours and may also cause significant data loss. The auditor should raise this capability gap and recommend a strategy such as data replication or a hot site to meet the business requirement.

Exam trap

The trap here is focusing on backup media security or redefining the RTO, rather than recognizing that a warm site without replicated data cannot realistically restore core banking within six hours.

72
MCQhard

An IS auditor is evaluating how an organization manages its backup and restoration process for a critical financial application. The backup job completes successfully each night and writes to a tape library. Management states that recovery capability has been proven because the backup job reports success. Which audit procedure would BEST test whether the backups are actually restorable?

A.Confirm that the backup window and retention schedule align with the recovery point objective.
B.Perform a periodic test restoration of selected data to a separate environment and reconcile the results.
C.Review the backup job logs to confirm that all scheduled jobs completed without errors.
D.Verify that backup tapes are stored in a secure offsite location with environmental controls.
AnswerB

A test restoration is the only procedure that directly demonstrates the backups can be read and used to rebuild data or the application. Restoring selected files or a full instance to an isolated environment and reconciling record counts or control totals validates both media readability and data integrity. This evidence-based approach also exercises the documented recovery procedures, revealing gaps in instructions or dependencies before a real outage occurs.

Why this answer

Only an actual restoration test demonstrates that backup data can be read and used to recover the application. Job success logs, offsite storage, and schedule alignment all address supporting conditions but none proves recoverability. Periodic test restorations with reconciliation of results provide direct evidence and also validate the recovery procedures and dependencies that a real recovery would require.

Exam trap

The trap here is accepting a successful backup job status as proof of recoverability, when a successful write does not guarantee that the media can be read or the application rebuilt.

73
Multi-Selecteasy

An organization is implementing a new release management process. Which TWO activities are essential components of a successful release?

Select 2 answers
A.Service desk operations
B.Release planning
C.Capacity management
D.Incident management
E.Testing
AnswersB, E

Release planning defines scope, schedule, dependencies and acceptance criteria before build begins, giving the release process its controlled baseline. Without this upfront activity, subsequent build, test and deployment stages lack agreed entry criteria, so the release cannot be managed or authorised against defined expectations.

Why this answer

Release planning (B) is essential because it defines the scope, schedule, resources, and coordination of the release, ensuring that the release package and its deployment are agreed upon and aligned with business needs. Testing (E) is essential because the release must be validated against defined acceptance criteria and quality requirements before deployment, reducing the risk of defects or failed changes reaching production. The other options are not core release activities: service desk operations (A) handle day-to-day user support and incident intake, capacity management (C) ensures sufficient resource capacity for services, and incident management (D) restores normal service operation after disruptions, all of which are separate ITIL practices rather than essential components of a release itself.

Exam trap

CISA often tests the boundary between release management and adjacent ITIL processes; the trap is selecting operational processes like incident or capacity management that support but are not components of a release.

74
MCQmedium

An IS auditor is assessing an organization's problem management process. The auditor finds that while incidents are logged and resolved, there is no formal problem management procedure. Several recurring incidents have been resolved with workarounds but not investigated for root cause. Which of the following is the MOST significant consequence of this deficiency?

A.Incident records will be incomplete, making it difficult to track service level agreement (SLA) compliance.
B.Knowledge articles will not be created, resulting in longer resolution times for new incidents.
C.The IT team will be unable to prioritize incidents effectively, leading to delays in resolving critical issues.
D.The organization will continue to experience recurring incidents, leading to increased downtime and resource drain.
AnswerD

This is the most significant consequence because without problem management, root causes of recurring incidents are not identified and eliminated. Workarounds only provide temporary relief, so the same incidents will recur, causing repeated disruptions, wasted effort, and potential impact on service levels. This creates a cycle of firefighting that can erode user confidence and increase operational costs. The auditor should recommend implementing a formal problem management process.

Why this answer

Problem management aims to identify and eliminate the root causes of incidents to prevent recurrence. Without it, recurring incidents are only temporarily resolved with workarounds, leading to repeated disruptions, increased downtime, and inefficient use of IT resources. This can also affect service quality and user satisfaction.

The other options are potential side effects, but the most significant consequence is the persistent recurrence of incidents and the associated operational impact.

Exam trap

The trap here is focusing on documentation or prioritization issues, when the core impact of missing problem management is the continued recurrence of incidents and the resulting operational drain.

75
MCQmedium

An IS auditor is reviewing the problem management process of a financial services firm. The auditor finds that incidents are frequently resolved by the service desk using documented workarounds, but no problem records are created, and root cause analysis is rarely performed. As a result, the same high-impact incident has recurred 14 times in three months. Which of the following is the MOST significant risk arising from this practice?

A.Service desk staff may become overly dependent on workarounds and lose technical troubleshooting skills.
B.Recurring incidents will continue to disrupt critical business services and increase operational cost without permanent resolution.
C.Incident categorization and prioritization data will be unreliable, preventing accurate service level reporting.
D.The configuration management database will become inaccurate because workarounds are not reflected as changes.
AnswerB

Without problem records and root cause analysis, the underlying defect remains, causing repeated outages that affect availability, customer transactions, and regulatory obligations. Each recurrence consumes support resources, incurs recovery costs, and may breach service level agreements. This is the most significant risk because it directly threatens business operations and resilience, which is the core concern of the audit finding.

Why this answer

Problem management exists to identify and eliminate root causes of recurring incidents. When workarounds are used without creating problem records, the organization treats symptoms rather than causes, so high-impact incidents recur and consume resources repeatedly. The most significant risk is therefore continued disruption and cost to critical business services, not secondary issues such as skill loss or data accuracy.

Exam trap

The trap here is focusing on documentation or reporting side effects of missing problem records, rather than the core business risk that unresolved root causes cause repeated outages and rising operational cost.

Page 1 of 2 · 138 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Information Systems Operations and Business Resilience questions.