Courseiva
hardMultiple Choice

CISA Practice Question: During a post-implementation review of a new HR…

During a post-implementation review of a new HR system, the auditor finds that the system's disaster recovery plan (DRP) was not tested before go-live. Which of the following is the BEST recommendation?

⚠ Common exam trap

CISA often tests the auditor's role in recommending timely action; candidates may choose to delay testing or focus on backups instead of addressing the untested DRP directly.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a DRP test immediately and document results

The best recommendation is to conduct a DRP test immediately and document the results. A DRP that has not been tested poses a significant risk because it may not work as intended. Testing validates the plan, identifies gaps, and ensures that recovery objectives can be met. Accepting the risk is not appropriate, implementing a backup procedure is only part of DRP, and scheduling a test within six months delays mitigation of a critical gap.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Accept the risk because the system is new

    Why it's wrong here

    Accepting the risk leaves the untested recovery capability unverified, so recovery time and data-loss objectives for the HR system remain unproven. Risk acceptance is legitimate only where the exposure sits within the organisation's stated tolerance and has been formally approved by the accountable owner — not as a substitute for validating a DRP that has never been exercised.

  • ✗

    Implement a backup procedure for the system

    Why it's wrong here

    A backup procedure restores data after loss; it does not validate whether the DRP's recovery time and recovery point objectives are achievable, which is the untested element. Backups are the right recommendation when the gap is data protection frequency or retention, not when recovery procedures themselves remain unverified.

  • ✓

    Conduct a DRP test immediately and document results

    Why this is correct

    Testing the untested DRP immediately validates recovery capability and produces documented evidence, closing the gap identified at go-live. This is the best recommendation because it directly addresses the missing test and provides assurance that recovery objectives are achievable.

  • ✗

    Schedule a DRP test within the next six months

    Why it's wrong here

    Scheduling a test within six months leaves the untested DRP as the live recovery capability for that entire period, so a real outage would expose the gap the review just identified. It is tempting because periodic DRP testing is genuine good practise, and a scheduled future test would suit a system already operating with a validated plan.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.