Courseiva

CISA · topic practice

Information Systems Operations and Business Resilience practice questions

This domain covers IT operations, service management, backup and recovery, and business resilience for the CISA exam. Questions test whether you can evaluate operational controls, change and incident management, backup strategies, RTO/RPO alignment, and the adequacy of BCP/DRP testing against business requirements.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Information Systems Operations and Business Resilience

What the exam tests

What to know about Information Systems Operations and Business Resilience

A candidate must evaluate whether operational and resilience controls actually meet business requirements, not just exist on paper. The single most important thing is correctly distinguishing RTO from RPO and verifying that tested recovery capabilities satisfy both.

Evaluating change management controls, including CAB approval and emergency change handling

Assessing backup strategies: full, incremental, differential, and restoration procedures

Reviewing RTO and RPO alignment with BCP/DRP and business impact analysis

Auditing incident, problem, and service level management processes and metrics

Watch out for

Common Information Systems Operations and Business Resilience exam traps

  • ▸Confusing RTO with RPO, or assuming a documented plan guarantees recovery within required timeframes.
  • ▸Treating a full interruption test as successful without verifying that critical application RTOs were actually met.
  • ▸Assuming CAB approval alone ensures adequate change testing, rollback plans, or post-implementation review.

Practice set

Information Systems Operations and Business Resilience questions

20 questions · select your answer, then reveal the explanation

An organization is implementing a new incident management process aligned with ITIL. The IT team discovers a critical system is down, affecting all users. According to ITIL, what severity level should be assigned to this incident?

An IS auditor is reviewing the change management process and notices that several emergency changes were implemented without post-implementation review. What is the PRIMARY concern?

Which TWO of the following are important controls for managing cloud resources to prevent cost overruns? (Select TWO).

An organization uses automated job scheduling for batch processing. A critical payroll job fails due to a dependency on a prior job that did not complete. The job scheduler is configured to handle dependencies. What should the auditor verify regarding rerun procedures?

A company performs daily full backups of its database and weekly incremental backups. The backup retention policy requires keeping full backups for 30 days and incremental backups for 7 days. An auditor reviews the backup schedule. Which backup type provides the fastest restore?

An organization is implementing a cloud resource management strategy to optimize costs and prevent waste. Which three practices should the auditor recommend?

During a change management review, an IS auditor discovers that a recent database upgrade was implemented without prior approval from the Change Advisory Board (CAB) because it was classified as a 'standard change.' However, the change involved migrating to a new database version that required application code modifications. What should concern the auditor most?

During a business impact analysis (BIA), the IS auditor identifies that the maximum tolerable downtime (MTD) for an online payment system is 2 hours, and the recovery point objective (RPO) is 15 minutes. The current disaster recovery solution uses nightly backups (12-hour RPO) and can restore the system in 4 hours. Which risk is most critical?

An organization uses a cloud-based CRM system. The asset management team has implemented tagging to track resource costs by department. During an audit, the IS auditor finds that several orphaned resources (e.g., virtual machines, storage volumes) exist that are not tagged and have been running for months. The cloud service provider's cost allocation report shows these resources under a default account. What is the most significant risk associated with this finding?

An IS auditor is reviewing the capacity management process for a server hosting a critical application. The server's CPU utilization has been consistently above 90% for the past three months, and memory usage is at 85%. There are no threshold alerts configured. The capacity plan shows that additional resources are scheduled to be added in six months. What should the auditor most recommend?

An organization's IT service desk categorizes incidents based on severity levels. A P1 incident is defined as a critical system outage affecting all users. Which of the following is the MOST appropriate target for the initial response time for a P1 incident?

An organization is selecting an alternate site for disaster recovery. The site must have sufficient equipment to resume operations within a few hours, and the organization is willing to share the site with another business. Which type of alternate site is MOST appropriate?

Which of the following disaster recovery test types involves a full switch-over to the alternate site, resulting in actual disruption to normal operations?

An organization is implementing a new incident management process based on ITIL. An incident classified as P1 (Priority 1) occurs. According to ITIL best practices, what is the most appropriate initial action?

An organization performs daily full backups of its critical database. The recovery time objective (RTO) is 4 hours. During a disaster, it takes 6 hours to restore the database. What is the most likely cause?

An IS auditor is reviewing a backup strategy that includes daily full backups and weekly offsite storage. The recovery time objective (RTO) for a critical application is 4 hours. Which of the following findings would be of GREATEST concern?

An organization has an availability requirement of 99.99% for its online transaction processing system. The system's MTBF is 720 hours. What is the maximum allowable MTTR to meet this requirement?

An IS auditor is reviewing problem management processes. Which TWO of the following are key outputs of effective problem management? (Select two.)

An IS auditor is reviewing backup procedures for a critical database. Which THREE are key considerations for ensuring backup reliability and recoverability?

An IS auditor is assessing the vendor management process. Which TWO are key controls for managing third-party risk?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Information Systems Operations and Business Resilience sessions

Start a Information Systems Operations and Business Resilience only practice session

Every question in these sessions is drawn from the Information Systems Operations and Business Resilience domain — nothing else.

Related practice questions

Related CISA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CISA exam test about Information Systems Operations and Business Resilience?
A candidate must evaluate whether operational and resilience controls actually meet business requirements, not just exist on paper. The single most important thing is correctly distinguishing RTO from RPO and verifying that tested recovery capabilities satisfy both.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Information Systems Operations and Business Resilience questions in a focused session?
Yes — the session launcher on this page draws every question from the Information Systems Operations and Business Resilience domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CISA topics?
Use the topic links above to move to related areas, or go back to the CISA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CISA exam covers. They are not copied from any real exam or dump site.