CISA Business Continuity Planning 5 — Questions and Answers
Question 1: Which of the following BEST explains why a business continuity plan must be treated as a living document?
- Regulatory requirements mandate annual document versioning
- Business processes, systems, personnel, and risks change over time, making static plans obsolete (Correct answer)
- External auditors require new versions before each engagement
- The plan must be rewritten whenever a new CIO is appointed
Correct answer: Business processes, systems, personnel, and risks change over time, making static plans obsolete
Organizations constantly change, so BCPs must be updated to reflect new systems, staff, processes, and threat landscapes to remain effective.
Question 2: An IS auditor is evaluating the adequacy of an organization's BCP. Which of the following would provide the MOST assurance that the plan is effective?
- A signed attestation from management that the plan is complete
- Documented results from a recent successful full-scale test (Correct answer)
- Certification that the plan was reviewed by a consulting firm
- Evidence that all employees have read and acknowledged the plan
Correct answer: Documented results from a recent successful full-scale test
Actual test results demonstrating that recovery objectives were met provide the strongest evidence of BCP effectiveness.
Question 3: A financial services firm determines that its trading system has an MTD of 30 minutes. Which recovery strategy is MOST appropriate?
- Weekly full backups stored offsite
- Cold site with 24-hour equipment procurement process
- Hot site with synchronous replication and automated failover (Correct answer)
- Warm site with 4-hour restoration time
Correct answer: Hot site with synchronous replication and automated failover
A 30-minute MTD requires near-instant failover capability, only achievable through a hot site with real-time synchronous replication and automated switchover.
Question 4: When performing a BCP audit, an IS auditor discovers that critical recovery procedures are known only to a single IT administrator. This represents a risk of:
- Inadequate system documentation
- Single point of failure in human knowledge—key-person dependency (Correct answer)
- Violation of segregation of duties
- Insufficient access controls over recovery systems
Correct answer: Single point of failure in human knowledge—key-person dependency
If critical recovery knowledge resides with only one person, that person's unavailability during a disaster could prevent successful recovery.
Question 5: Which of the following BEST demonstrates integration between information security and business continuity planning?
- Security policies are listed as a reference document in the BCP appendix
- Recovery procedures include requirements to maintain security controls and access restrictions during restoration (Correct answer)
- The CISO reviews the BCP annually before executive sign-off
- Security awareness training mentions the existence of a BCP
Correct answer: Recovery procedures include requirements to maintain security controls and access restrictions during restoration
True integration means security controls—authentication, encryption, access controls—are actively maintained and enforced throughout the recovery process.
Question 6: An organization wants to reduce its RTO from 8 hours to 1 hour. Which action would MOST directly achieve this goal?
- Increasing the frequency of full system backups
- Upgrading from a cold site to a hot site with pre-configured systems (Correct answer)
- Hiring additional IT staff dedicated to disaster recovery
- Purchasing cyber insurance with a rapid-response clause
Correct answer: Upgrading from a cold site to a hot site with pre-configured systems
Upgrading to a hot site with pre-configured, ready-to-use systems eliminates the time needed to procure, install, and configure equipment, directly reducing RTO.
Question 7: In BCP terminology, which term refers to the minimum level of services that must be maintained for the organization to survive a disaster?
- Recovery Point Objective
- Minimum Business Continuity Objective (MBCO) (Correct answer)
- Maximum Tolerable Downtime
- Service Level Agreement
Correct answer: Minimum Business Continuity Objective (MBCO)
MBCO defines the minimum level of services and/or products acceptable to achieve the business objectives during a disruption.
Which of the following BEST explains why a business continuity plan must be treated as a living document?