hardMultiple ChoiceObjective-mapped
CISA Practice Question: During an audit, the IS auditor finds that the…
During an audit, the IS auditor finds that the business continuity plan (BCP) was last updated two years ago and does not include new cloud-based applications. The organization has not conducted a BCP test in 18 months. What should the auditor recommend FIRST?
⚠ Common exam trap
The trap here is that candidates often jump to 'update the BCP' or 'test immediately' as the first action, but the CISA exam emphasizes that risk assessment must precede any changes to ensure resources are allocated to the highest-priority gaps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform a risk assessment to prioritize changes
Before updating the BCP or scheduling tests, the IS auditor must ensure that a current risk assessment is performed to identify and prioritize the impact of changes—such as the introduction of cloud-based applications—on business continuity. Without a risk assessment, updates or tests may address the wrong threats or miss critical dependencies, violating the principle that BCP updates should be risk-driven. This aligns with ISACA's guidance that risk assessment is the foundation for BCP maintenance and testing frequency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Obtain management approval for BCP updates
Why it's wrong here
Approval is necessary but should come after identifying what needs to be updated.
- ✓
Perform a risk assessment to prioritize changes
Why this is correct
A risk assessment identifies the most critical gaps, enabling efficient allocation of resources.
- ✗
Immediately schedule a full-scale test
Why it's wrong here
Testing without an updated BCP and risk assessment could be ineffective and risky.
- ✗
Update the BCP to include cloud applications
Why it's wrong here
Updating without prioritizing could lead to overlooking other critical areas.
Go deeper
Related to this question
About these practice questions
One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.