CISA Information System Auditing Process Practice Question
During an audit of an organization's backup and recovery process, the IS auditor finds that full backups are performed weekly and incremental backups are performed nightly. Restoration testing has not been performed in over two years. Which of the following should the auditor do FIRST?
⚠ Common exam trap
The trap here is treating successful backup job logs as proof that recovery will work, when only an actual restoration test demonstrates recoverability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform or observe a restoration test to evaluate the effectiveness of the backups
The key question is whether the backups can actually be restored, and the most persuasive evidence is a restoration test. Performing or observing a test verifies media readability, procedure effectiveness, and recovery objectives. Reporting a finding, changing backup frequency, or reviewing logs address related but different concerns and do not directly demonstrate restoration capability, so they are not the appropriate first action.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Perform or observe a restoration test to evaluate the effectiveness of the backups
Why this is correct
The most persuasive evidence about whether backups can actually be restored is a restoration test. Performing or observing a test allows the auditor to verify that the backup media are readable, that the recovery procedures work, and that recovery time objectives are realistic. This direct evidence supports a reliable conclusion about the control's operating effectiveness, which is exactly what the auditor needs before deciding whether a finding is warranted.
- ✗
Review the backup logs to confirm that nightly jobs completed without error
Why it's wrong here
Backup logs show whether jobs ran and completed, but they do not demonstrate that data can be restored. A job can report success while the media are unreadable or the recovery procedure is flawed. Log review is corroborating evidence, not sufficient on its own. Direct restoration testing is needed to conclude whether the recovery control actually works, making log review a weaker first step.
- ✗
Recommend that management immediately increase the frequency of full backups
Why it's wrong here
Backup frequency is not the identified concern; the concern is whether existing backups can be restored. Recommending more frequent full backups addresses a different risk and may increase cost without resolving the untested recovery capability. The auditor should first determine whether the current backup scheme actually supports restoration before recommending changes to the backup schedule.
- ✗
Report the absence of restoration testing as a high-risk finding in the audit report
Why it's wrong here
Reporting may eventually be appropriate, but the auditor should first gather sufficient evidence about the condition and its impact. Issuing a finding before confirming the actual state of restoration capability and any compensating controls could overstate or misstate the risk. The audit process requires evidence collection and analysis before conclusions are drawn, so jumping directly to a high-risk finding is premature at this stage of fieldwork.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.