Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

During a disaster recovery planning audit, the IS auditor notes that the organization's plan includes a hot standby site. However, the plan has not been updated in two years, and the last test was a tabletop exercise 18 months ago. The organization has recently implemented a new ERP system. Which THREE findings should the auditor report as most significant?

⚠ Common exam trap

CISA often tests the importance of DR plan maintenance; candidates may focus on site distance or management approval, but the most critical issues are testing and updating for new systems.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The DR plan has not been tested in over a year.

Option A is correct because the plan's last test was a tabletop exercise 18 months ago, exceeding the commonly expected annual DR testing cadence; tabletop exercises alone also do not validate technical recovery of systems, so the lack of recent, more substantive testing is a significant finding. Option B is correct because the plan has not been updated in two years, meaning it likely no longer reflects the current infrastructure, dependencies, and recovery procedures, which undermines its reliability during an actual disaster. Option E is correct because the recently implemented ERP system is a critical business application whose recovery time objective (RTO) and recovery point objective (RPO), backup integration, and dependencies must be documented in the DR plan; failing to update the plan for it creates a major gap in recoverability. Option C is not marked correct because distance between sites is a design consideration that depends on the organization's risk assessment and is not inherently a deficiency. Option D is not marked correct because the scenario provides no evidence about management review or approval status, so it cannot be reported as a finding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The DR plan has not been tested in over a year.

    Why this is correct

    A tabletop exercise validates discussion, not actual recovery of systems. Eighteen months without a full test leaves the hot standby's real failover capability unproven, so this finding directly challenges whether the stated recovery capability exists.

  • ✓

    The DR plan is outdated; it was last updated two years ago.

    Why this is correct

    An outdated plan cannot reflect the new ERP system's dependencies, recovery sequences or infrastructure requirements, so documented recovery procedures may be unworkable during an actual failover. This directly breaches the audit constraint that the plan must remain current, and it undermines the hot standby site's effectiveness since configuration drift goes undetected.

  • ✗

    The hot standby site is located too far from the primary site.

    Why it's wrong here

    Distance between sites is a design consideration, not a finding arising from the stale plan, untested recovery or new ERP system described. It is tempting because geographic separation protects against regional outages, but the stem's evidence concerns plan currency and testing, so this is unsupported by the audit observations.

  • ✗

    The DR plan has not been reviewed and approved by senior management in the last year.

    Why it's wrong here

    The stem already states the plan has not been updated in two years, so a separate finding about annual review merely restates that fact rather than identifying a distinct significant issue. It is tempting because management approval is genuinely important, but the auditor should report the underlying staleness and untested recovery instead.

  • ✓

    The DR plan has not been updated to reflect the new ERP system.

    Why this is correct

    The new ERP system changes dependencies, recovery sequences and RTOs, none of which the two-year-old plan reflects. This is the most specific gap: recovery procedures would fail or misorder systems because the ERP is absent from the documented plan.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.