Courseiva
hardMultiple ChoiceObjective-mapped

CISA Practice Question: During an audit, the IS auditor finds that the…

During an audit, the IS auditor finds that the business continuity plan (BCP) was last updated two years ago and does not include new cloud-based applications. The organization has not conducted a BCP test in 18 months. What should the auditor recommend FIRST?

⚠ Common exam trap

The trap here is that candidates often jump to 'update the BCP' or 'test immediately' as the first action, but the CISA exam emphasizes that risk assessment must precede any changes to ensure resources are allocated to the highest-priority gaps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Perform a risk assessment to prioritize changes

Before updating the BCP or scheduling tests, the IS auditor must ensure that a current risk assessment is performed to identify and prioritize the impact of changes—such as the introduction of cloud-based applications—on business continuity. Without a risk assessment, updates or tests may address the wrong threats or miss critical dependencies, violating the principle that BCP updates should be risk-driven. This aligns with ISACA's guidance that risk assessment is the foundation for BCP maintenance and testing frequency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Obtain management approval for BCP updates

    Why it's wrong here

    Approval is necessary but should come after identifying what needs to be updated.

  • Perform a risk assessment to prioritize changes

    Why this is correct

    A risk assessment identifies the most critical gaps, enabling efficient allocation of resources.

  • Immediately schedule a full-scale test

    Why it's wrong here

    Testing without an updated BCP and risk assessment could be ineffective and risky.

  • Update the BCP to include cloud applications

    Why it's wrong here

    Updating without prioritizing could lead to overlooking other critical areas.

About these practice questions

One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.