hardMultiple Choice
CISA Practice Question: During a post-implementation review of a new HR…
During a post-implementation review of a new HR system, the auditor finds that the system's disaster recovery plan (DRP) was not tested before go-live. Which of the following is the BEST recommendation?
⚠ Common exam trap
CISA often tests the auditor's role in recommending timely action; candidates may choose to delay testing or focus on backups instead of addressing the untested DRP directly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a DRP test immediately and document results
The best recommendation is to conduct a DRP test immediately and document the results. A DRP that has not been tested poses a significant risk because it may not work as intended. Testing validates the plan, identifies gaps, and ensures that recovery objectives can be met. Accepting the risk is not appropriate, implementing a backup procedure is only part of DRP, and scheduling a test within six months delays mitigation of a critical gap.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the risk because the system is new
Why it's wrong here
Accepting the risk leaves the untested recovery capability unverified, so recovery time and data-loss objectives for the HR system remain unproven. Risk acceptance is legitimate only where the exposure sits within the organisation's stated tolerance and has been formally approved by the accountable owner — not as a substitute for validating a DRP that has never been exercised.
- ✗
Implement a backup procedure for the system
Why it's wrong here
A backup procedure restores data after loss; it does not validate whether the DRP's recovery time and recovery point objectives are achievable, which is the untested element. Backups are the right recommendation when the gap is data protection frequency or retention, not when recovery procedures themselves remain unverified.
- ✓
Conduct a DRP test immediately and document results
Why this is correct
Testing the untested DRP immediately validates recovery capability and produces documented evidence, closing the gap identified at go-live. This is the best recommendation because it directly addresses the missing test and provides assurance that recovery objectives are achievable.
- ✗
Schedule a DRP test within the next six months
Why it's wrong here
Scheduling a test within six months leaves the untested DRP as the live recovery capability for that entire period, so a real outage would expose the gap the review just identified. It is tempting because periodic DRP testing is genuine good practise, and a scheduled future test would suit a system already operating with a validated plan.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.