CISA Disaster Recovery Testing 3 — Questions and Answers
Question 1: An IS auditor finds that a company's DR plan has never been tested. What is the PRIMARY risk this creates?
- Increased hardware maintenance costs
- Unknown gaps between documented procedures and actual recovery capability (Correct answer)
- Higher insurance premiums
- Regulatory fines for non-testing
Correct answer: Unknown gaps between documented procedures and actual recovery capability
Without testing, the organization cannot know whether recovery procedures will actually work, leaving critical gaps undetected until an actual disaster occurs.
Question 2: Which statement BEST describes the purpose of a hot site in DR testing?
- It stores backup media in a fireproof vault
- It is a fully equipped facility that can take over operations immediately (Correct answer)
- It provides office space without computing equipment
- It is used only for tabletop exercises
Correct answer: It is a fully equipped facility that can take over operations immediately
A hot site is a fully operational facility with hardware, software, and network connectivity pre-configured to assume production operations with minimal delay.
Question 3: During DR test evaluation, an IS auditor should PRIMARILY assess whether:
- The test was conducted without any system errors
- Recovery objectives defined in the BCP were actually achieved (Correct answer)
- All employees participated in the test
- The test budget was not exceeded
Correct answer: Recovery objectives defined in the BCP were actually achieved
The core audit criterion is whether the test demonstrated the organization can meet its defined RTOs and RPOs, validating the effectiveness of the BCP.
Question 4: A company uses a warm site for disaster recovery. Compared to a hot site, what is the PRIMARY trade-off?
- Lower cost but longer recovery time (Correct answer)
- Higher cost but shorter recovery time
- Lower cost but no data backup capability
- Higher security but less redundancy
Correct answer: Lower cost but longer recovery time
Warm sites have some pre-installed equipment and partial configurations, making them less expensive than hot sites but requiring additional setup time before operations can resume.
Question 5: Which DR test metric measures the total time an organization can tolerate being without a critical system before suffering unacceptable business impact?
- Recovery Point Objective
- Recovery Time Objective
- Maximum Tolerable Downtime (Correct answer)
- Mean Time Between Failures
Correct answer: Maximum Tolerable Downtime
Maximum Tolerable Downtime (MTD) is the upper threshold of acceptable downtime; the RTO must always be less than the MTD.
Question 6: An IS auditor recommends that DR test scenarios should include which of the following to be MOST effective?
- Only scenarios that the team has previously rehearsed
- A variety of realistic, risk-based scenarios including partial and full failures (Correct answer)
- Scenarios that guarantee a successful recovery outcome
- Scenarios designed by IT staff without business input
Correct answer: A variety of realistic, risk-based scenarios including partial and full failures
Effective DR tests use diverse, realistic scenarios based on actual risk assessments, including partial outages, to surface a wider range of gaps.
Question 7: After a DR test, which document should be updated FIRST to reflect lessons learned?
- The annual audit report
- The disaster recovery plan (Correct answer)
- The employee handbook
- The network topology diagram
Correct answer: The disaster recovery plan
Lessons learned from DR tests must be incorporated directly into the DR plan to improve future recovery capability before the next incident or test.
An IS auditor finds that a company's DR plan has never been tested.
What is the PRIMARY risk this creates?