hardMultiple Choice
CISA Practice Question: During an audit, the IS auditor finds that the…
During an audit, the IS auditor finds that the business continuity plan (BCP) was last updated two years ago and does not include new cloud-based applications. The organization has not conducted a BCP test in 18 months. What should the auditor recommend FIRST?
⚠ Common exam trap
The trap here is that candidates often jump to 'update the BCP' or 'test immediately' as the first action, but the CISA exam emphasizes that risk assessment must precede any changes to ensure resources are allocated to the highest-priority gaps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a risk assessment to prioritize changes
Before updating the BCP or scheduling tests, the IS auditor must ensure that a current risk assessment is performed to identify and prioritize the impact of changes—such as the introduction of cloud-based applications—on business continuity. Without a risk assessment, updates or tests may address the wrong threats or miss critical dependencies, violating the principle that BCP updates should be risk-driven. This aligns with ISACA's guidance that risk assessment is the foundation for BCP maintenance and testing frequency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Obtain management approval for BCP updates
Why it's wrong here
Seeking approval to update the BCP addresses documentation before the underlying gap analysis is performed, so the update would lack validated recovery requirements for the cloud applications. It is tempting because management buy-in is genuinely required before BCP changes proceed, making it correct once revised content and test results are ready for sign-off.
- ✓
Perform a risk assessment to prioritize changes
Why this is correct
A risk assessment identifies which cloud applications and business functions carry the greatest exposure from the outdated BCP, letting remediation be sequenced by impact rather than by document age alone. It must precede rewriting or testing, since those activities depend on prioritised findings.
- ✗
Immediately schedule a full-scale test
Why it's wrong here
Scheduling a full-scale test exercises a plan that still omits the cloud applications, so the test cannot validate their recovery and may disrupt operations without approved procedures. It is tempting because the 18-month testing gap is a genuine finding, making a test correct after the BCP has been updated and approved.
- ✗
Update the BCP to include cloud applications
Why it's wrong here
Rewriting the BCP immediately embeds untested assumptions about cloud recovery capabilities, since no business impact analysis or test has validated those applications' requirements. It is tempting because the plan demonstrably omits cloud services, making documentation updates correct once the impact analysis and recovery strategy have been established.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.