View Full Isaca CISA Exam Dumps and Practice Test Dumps
Question 121. What is the primary purpose of a disaster recovery plan?
1) To define procedures for restoring critical IT services after a disruption
2) To eliminate all business risks
3) To replace the organization’s security policy
4) To document employee performance reviews
Answer: 1) To define procedures for restoring critical IT services after a disruption
Explanation:
A disaster recovery plan provides documented procedures for restoring IT systems, applications, infrastructure, and supporting resources following a disruptive event. It typically identifies recovery priorities, responsibilities, dependencies, communication procedures, recovery strategies, and escalation processes. An IS auditor should determine whether the plan is aligned with business requirements and whether critical systems and dependencies are adequately addressed. The plan should also be maintained as the organization’s technology and business processes change. A disaster recovery plan does not eliminate risk or replace other governance and security documents. Its purpose is to provide an organized framework for recovering important technology services within established recovery objectives.
Question 122. Which activity provides the strongest assurance that a disaster recovery plan will work as intended?
1) Reviewing the plan’s formatting
2) Conducting periodic recovery exercises
3) Increasing the number of plan copies
4) Asking employees whether they have seen the plan
Answer: 2) Conducting periodic recovery exercises
Explanation:
Recovery exercises provide practical evidence that documented disaster recovery procedures can be executed effectively. Testing can reveal missing dependencies, unclear responsibilities, outdated contact information, technical failures, insufficient resources, or unrealistic recovery assumptions. Depending on organizational requirements, exercises may range from walkthroughs and simulations to more comprehensive technical recovery tests. An IS auditor should evaluate whether tests are performed at appropriate intervals, cover critical services, document results, and lead to corrective actions. Simply distributing or reviewing a plan does not demonstrate that recovery procedures will function during an actual disruption. Test results should be reviewed by responsible management and used to improve recovery capabilities.
Question 123. What should an IS auditor verify first when evaluating an organization’s recovery priorities?
1) The number of employees in the IT department
2) The age of the organization’s servers
3) The criticality of business processes and supporting systems
4) The amount of office furniture available
Answer: 3) The criticality of business processes and supporting systems
Explanation:
Recovery priorities should be based on the business impact of service disruption rather than solely on technical characteristics. An IS auditor should determine whether critical business processes have been identified and whether their supporting applications, infrastructure, data, and dependencies are understood. Business impact analysis results can help establish recovery priorities, acceptable downtime, and required recovery resources. This information allows technology recovery efforts to focus first on services whose disruption would have the greatest business consequences. Server age, IT staffing levels, and office furniture may be relevant to other assessments but do not independently establish business recovery priorities. Recovery planning should ultimately reflect documented business requirements.
Question 124. Which metric defines the maximum acceptable amount of data loss measured in time?
1) Recovery Time Objective
2) Mean Time Between Failures
3) Service Level Agreement
4) Recovery Point Objective
Answer: 4) Recovery Point Objective
Explanation:
The Recovery Point Objective, or RPO, defines the maximum acceptable period of data loss measured backward from the point of disruption. For example, an organization with an RPO of one hour should have recovery capabilities that limit potential data loss to approximately one hour of transactions or changes, subject to the organization’s specific implementation. RPO influences backup frequency, replication requirements, and recovery architecture. The Recovery Time Objective, or RTO, instead addresses how quickly a service should be restored. An IS auditor should verify that recovery strategies and technical controls are consistent with documented RPO requirements for critical systems and data.
Question 125. Which control best helps ensure that recovery procedures remain aligned with changes to an organization’s IT environment?
1) Integrating recovery-plan updates with change management
2) Limiting plan reviews to once every ten years
3) Preventing all system changes
4) Removing technical dependencies from recovery documentation
Answer: 1) Integrating recovery-plan updates with change management
Explanation:
IT environments change frequently as applications, infrastructure, vendors, configurations, and business processes are modified. If recovery documentation is not updated accordingly, procedures may become inaccurate or incomplete. Integrating disaster recovery maintenance with change management helps ensure that significant changes trigger an evaluation of recovery requirements and documentation. An IS auditor should determine whether recovery plans identify critical dependencies and whether changes to those dependencies are reflected in recovery procedures. Periodic reviews remain useful, but relying only on scheduled reviews can allow plans to become outdated between review dates. Effective maintenance should therefore combine periodic review with change-driven updates.
Question 126. What is the primary purpose of a business impact analysis (BIA)?
1) To identify employee training preferences
2) To determine the business consequences of disruptions to important processes
3) To select antivirus software
4) To calculate annual IT staffing costs
Answer: 2) To determine the business consequences of disruptions to important processes
Explanation:
A business impact analysis identifies the potential consequences of interruptions to critical business processes and helps establish recovery priorities. It may examine financial effects, operational impacts, legal or regulatory consequences, customer effects, dependencies, and reputational considerations. BIA results can support the definition of recovery requirements such as RTOs and RPOs. An IS auditor should assess whether the analysis includes relevant business functions, supporting technology, dependencies, and appropriate management participation. The BIA should provide a business-based foundation for continuity and recovery planning rather than simply focusing on technical infrastructure. Its findings should be periodically reviewed as business operations and dependencies change.
Question 127. Which recovery strategy generally provides the shortest restoration time for a critical system?
1) A facility with no installed equipment
2) Manual reconstruction from paper records
3) A fully prepared environment with current systems and data
4) Rebuilding infrastructure only after a disaster occurs
Answer: 3) A fully prepared environment with current systems and data
Explanation:
A fully prepared recovery environment can significantly reduce restoration time because required infrastructure, systems, configurations, and data are already available. Such an arrangement generally requires greater investment and ongoing maintenance than less-prepared recovery alternatives. An IS auditor should evaluate whether the selected recovery strategy is consistent with the business’s recovery objectives and risk tolerance. The auditor should also consider whether the recovery environment is maintained, synchronized appropriately, and tested. The fastest possible strategy is not automatically appropriate for every system because cost, criticality, dependencies, and recovery requirements must be considered. Recovery capabilities should therefore be aligned with documented business priorities.
Question 128. Which document should define the sequence and responsibilities for restoring technology services following a major disruption?
1) Marketing plan
2) Disaster recovery procedures
3) Employee attendance policy
4) Procurement catalog
Answer: 2) Disaster recovery procedures
Explanation:
Disaster recovery procedures provide operational instructions for restoring technology services after a disruption. They may identify recovery steps, system dependencies, responsible personnel, escalation paths, communication requirements, validation activities, and criteria for returning services to normal operations. Detailed procedures are particularly important for complex environments where recovery activities must occur in a specific order. An IS auditor should determine whether procedures are sufficiently detailed for responsible personnel to execute them under stressful conditions and whether they have been tested. Recovery documentation should also reflect current infrastructure and applications. General business documents such as marketing plans or procurement catalogs do not provide the technical recovery instructions required during a disruption.
Question 129. What is the main purpose of a recovery site assessment?
1) To determine whether the alternate site can support required recovery capabilities
2) To calculate employee salaries
3) To identify customer preferences
4) To replace the business impact analysis
Answer: 1) To determine whether the alternate site can support required recovery capabilities
Explanation:
A recovery site assessment evaluates whether an alternate facility or recovery environment has the resources necessary to support business recovery requirements. Depending on the strategy, the assessment may consider power, connectivity, computing capacity, physical security, environmental controls, access, equipment, data availability, and provider capabilities. An IS auditor should evaluate whether site characteristics are consistent with the criticality and recovery objectives of supported systems. The assessment should also consider dependencies and capacity requirements. An alternate location is only useful if it can provide sufficient resources when needed. Evaluating the site helps identify gaps before a real disruption occurs and supports informed recovery planning.
Question 130. Which factor should most influence the frequency of disaster recovery testing?
1) The number of pages in the recovery plan
2) The size of the organization’s headquarters
3) The number of employees in the audit department
4) Business criticality, risk, and changes to the recovery environment
Answer: 4) Business criticality, risk, and changes to the recovery environment
Explanation:
Recovery testing frequency should reflect the importance of the systems involved, the risks facing the organization, and changes that could affect recovery capability. Critical systems generally require more rigorous and appropriately frequent testing than low-impact services. Significant changes to infrastructure, applications, vendors, recovery procedures, or business processes may also trigger additional testing. An IS auditor should assess whether testing frequency is defined by risk and business requirements rather than arbitrary administrative factors. Test results should be documented, exceptions tracked, and corrective actions monitored. A risk-based approach helps ensure that recovery capabilities remain reliable without requiring identical testing arrangements for every system.
Question 131. What is the primary purpose of an IT asset inventory?
1) To identify and maintain information about technology assets owned or managed by the organization
2) To replace financial statements
3) To eliminate software licensing requirements
4) To prevent all unauthorized changes automatically
Answer: 1) To identify and maintain information about technology assets owned or managed by the organization
Explanation:
An IT asset inventory provides an organized record of hardware, software, systems, network devices, and other technology resources within the organization’s environment. Accurate inventory information supports security, configuration management, licensing, maintenance, vulnerability management, incident response, and lifecycle planning. An IS auditor should assess whether the inventory is complete, accurate, appropriately maintained, and reconciled with other relevant records. Important information may include ownership, location, configuration, business purpose, and lifecycle status. An inventory does not automatically prevent unauthorized changes, but accurate asset information helps the organization understand what must be protected and monitored and provides a foundation for other IT control processes.
Question 132. Which control is most effective for detecting unauthorized hardware connected to an organization’s network?
1) Increasing printer capacity
2) Network access control and asset discovery mechanisms
3) Reducing employee training
4) Removing network monitoring
Answer: 2) Network access control and asset discovery mechanisms
Explanation:
Network access control and asset discovery mechanisms can help identify devices attempting to connect to organizational networks and determine whether those devices are authorized. Depending on implementation, controls may validate device identity, enforce security requirements, place unknown devices into restricted network segments, or generate alerts for investigation. An IS auditor should assess whether network-connected assets are identified and whether appropriate procedures exist for handling unauthorized devices. Maintaining an asset inventory alone may not immediately detect a newly connected device. Automated discovery and access controls can therefore provide additional assurance. These controls should be integrated with broader network security and asset management processes.
Question 133. What is the primary purpose of software license management?
1) To ensure software use complies with licensing terms and organizational requirements
2) To increase network bandwidth
3) To replace application testing
4) To prevent hardware theft
Answer: 1) To ensure software use complies with licensing terms and organizational requirements
Explanation:
Software license management helps organizations understand which software products are installed, how they are being used, and whether usage complies with contractual licensing terms. Effective management can reduce the risk of unauthorized software use, unexpected licensing costs, and noncompliance. An IS auditor should evaluate whether software inventories are accurate, licenses are tracked, installations are monitored, and renewal requirements are managed. License management may also identify unused or unnecessary software that can be removed. It does not replace application testing, network management, or physical security controls. A well-maintained software inventory is an important component of effective license management and technology asset governance.
Question 134. Which control best supports accountability for changes made to a critical application?
1) Allowing shared administrator accounts
2) Disabling all system logs
3) Requiring individually identifiable accounts and maintaining change records
4) Allowing undocumented emergency changes
Answer: 3) Requiring individually identifiable accounts and maintaining change records
Explanation:
Individual accounts allow changes to be associated with specific users, which supports accountability and investigation. Maintaining change records can provide additional information about what was changed, when it was changed, who performed the activity, and whether the change was authorized. Shared administrative accounts make attribution more difficult and can weaken accountability. An IS auditor should determine whether access to critical applications is individually assigned, privileged activities are appropriately controlled, and significant changes are documented. Emergency changes may be necessary, but they should still be subject to retrospective review and documentation. Strong accountability controls help management investigate unauthorized or inappropriate modifications to critical systems.
Question 135. Which condition represents the greatest concern when an organization has no formal process for managing emergency changes?
1) Increased office supply costs
2) Unauthorized or insufficiently tested changes could be introduced into production
3) Reduced meeting frequency
4) Increased employee vacation requests
Answer: 2) Unauthorized or insufficiently tested changes could be introduced into production
Explanation:
Emergency changes may be necessary to address critical incidents, security vulnerabilities, or operational failures, but bypassing normal change controls can introduce significant risks. Without a formal emergency change process, changes may not receive appropriate authorization, testing, documentation, or retrospective review. This can result in system instability, security weaknesses, or unauthorized modifications. An IS auditor should verify that emergency changes have clearly defined approval criteria and that appropriate technical safeguards remain in place. Even when normal procedures cannot be followed in advance, organizations should maintain evidence of the change and conduct a timely post-implementation review. Emergency procedures should provide flexibility without eliminating accountability.
Question 136. Which activity is most appropriate after implementing a major system change?
1) Immediately remove all system documentation
2) Disable monitoring temporarily
3) Conduct a post-implementation review
4) Delete the original change request
Answer: 3) Conduct a post-implementation review
Explanation:
A post-implementation review evaluates whether a significant change achieved its intended objectives and whether unexpected issues or control weaknesses emerged. The review may consider system performance, business requirements, user acceptance, security controls, project objectives, costs, and unresolved problems. It can also identify lessons that should improve future change initiatives. An IS auditor should determine whether major changes are subject to appropriate post-implementation review and whether findings are documented and addressed. Removing documentation or disabling monitoring would reduce visibility into the change. A structured review provides management with evidence about whether the change delivered the expected result and whether additional corrective actions are necessary.
Question 137. Which control helps ensure that only approved software versions are deployed into production?
1) Configuration and release management controls
2) Increasing office access hours
3) Removing version information
4) Allowing developers unrestricted production access
Answer: 1) Configuration and release management controls
Explanation:
Configuration and release management controls help ensure that software deployed into production has been properly authorized, tested, and identified by an approved version. These controls can include version repositories, approval workflows, deployment procedures, segregation of development and production environments, and controlled release processes. An IS auditor should evaluate whether production deployments can be traced to approved changes and whether unauthorized versions can be detected or prevented. Allowing developers unrestricted production access can weaken segregation and accountability. Effective release management reduces the likelihood that untested or unauthorized software will be introduced into critical environments and helps organizations maintain reliable and controlled application configurations.
Question 138. What is the primary purpose of segregating development, testing, and production environments?
1) To increase the number of software defects
2) To prevent developers from creating documentation
3) To reduce the risk that untested or unauthorized changes affect production
4) To eliminate the need for access management
Answer: 3) To reduce the risk that untested or unauthorized changes affect production
Explanation:
Separating development, testing, and production environments reduces the likelihood that experimental or insufficiently tested changes will directly affect operational systems. Developers can build and modify applications in controlled environments, while testing personnel can validate functionality and security before approved releases reach production. An IS auditor should assess whether access to each environment is appropriately restricted and whether movement between environments follows formal release procedures. Segregation does not eliminate the need for access management because each environment still requires appropriate authorization. Proper separation also supports accountability and reduces conflicts of interest by limiting the ability of individuals to independently develop, approve, and deploy changes.
Question 139. Which control is most appropriate for ensuring that obsolete IT equipment is disposed of securely?
1) Removing equipment labels only
2) Selling all equipment without inspection
3) Storing obsolete devices indefinitely
4) Using documented disposal procedures that include secure data destruction**
Answer: 4) Using documented disposal procedures that include secure data destruction
Explanation:
Obsolete IT equipment may contain sensitive information even when the equipment is no longer actively used. Secure disposal procedures should address data destruction, equipment handling, authorization, environmental requirements where applicable, and evidence of disposal. Depending on the technology and sensitivity of the information, appropriate methods may include secure wiping, cryptographic erasure, or physical destruction. An IS auditor should verify that disposal procedures are documented and consistently followed and that evidence exists to demonstrate completion. Simply removing labels or selling equipment without ensuring data has been securely removed can expose organizational information. Disposal should therefore be treated as part of the asset lifecycle rather than an informal end-of-use activity.
Question 140. Which measure provides useful evidence that an IT service is meeting its agreed availability requirement?
1) Number of employee meetings
2) Percentage of time the service is available compared with the agreed availability target
3) Number of documents stored in the service
4) Amount of office space used by the IT department
Answer: 2) Percentage of time the service is available compared with the agreed availability target
Explanation:
Availability measurement should compare actual service availability with defined business or service-level requirements. Measuring the percentage of time a service remains available provides management with an objective basis for determining whether agreed availability targets are being achieved. An IS auditor should verify that availability measurements use reliable monitoring data, appropriate measurement periods, and clearly defined service-level criteria. The auditor should also consider how planned maintenance, outages, and exceptions are treated under the relevant agreement. Metrics such as office space or document volume do not directly demonstrate service availability. Meaningful availability reporting helps management identify performance gaps and evaluate whether service providers or internal IT teams are meeting established commitments.