CISA Disaster Recovery Testing 4 โ Questions and Answers
Question 1: A company's DR test reveals that the recovery site network bandwidth is insufficient for peak transaction volumes. This finding MOST likely indicates a gap in:
- Employee training
- Capacity planning for the recovery environment (Correct answer)
- Backup media labeling
- Change management procedures
Correct answer: Capacity planning for the recovery environment
Insufficient bandwidth at the recovery site is a capacity planning failure; the recovery environment must be sized to handle actual production workloads.
Question 2: Which party should APPROVE the final DR test plan before testing begins?
- The external auditor
- Senior management or the steering committee (Correct answer)
- The IT operations manager only
- The recovery site vendor
Correct answer: Senior management or the steering committee
Senior management or the steering committee must approve DR test plans to ensure organizational alignment, resource commitment, and accountability.
Question 3: During a DR test, the team successfully restores data but discovers the restored database is missing two hours of transactions. Which control failure does this MOST directly indicate?
- Inadequate physical security at the recovery site
- Replication or backup frequency not meeting the RPO (Correct answer)
- Failure to encrypt backup data
- Insufficient staffing at the recovery site
Correct answer: Replication or backup frequency not meeting the RPO
Missing two hours of transactions means the backup or replication interval was too long, causing the RPO to be exceeded.
Question 4: An IS auditor notes that DR tests are only conducted by the IT department without business unit participation. The GREATEST risk of this approach is:
- Increased cost of testing
- Failure to validate recovery of business processes, not just technical systems (Correct answer)
- Violation of change management policies
- Excessive system downtime during tests
Correct answer: Failure to validate recovery of business processes, not just technical systems
Without business unit involvement, DR tests may confirm technical recovery but miss whether business processes, workflows, and outputs are actually restored correctly.
Question 5: Which of the following is the BEST evidence that a DR test was successful from an IS audit perspective?
- No complaints were received from users during the test
- Recovery objectives were met and results were documented and signed off by management (Correct answer)
- The test was completed on schedule
- The recovery site vendor confirmed system availability
Correct answer: Recovery objectives were met and results were documented and signed off by management
Documented results showing that RTOs and RPOs were achieved, with formal management sign-off, provide the most auditable evidence of test success.
Question 6: A cold site differs from a warm or hot site in that it:
- Has fully mirrored live data at all times
- Provides only physical space and basic utilities, requiring equipment to be installed before use (Correct answer)
- Is used exclusively for tabletop exercises
- Automatically fails over without human intervention
Correct answer: Provides only physical space and basic utilities, requiring equipment to be installed before use
A cold site provides the physical facility but no pre-installed hardware or software, requiring the organization to procure and configure equipment after declaring a disaster.
Question 7: When an IS auditor reviews the frequency of DR tests, the MOST appropriate benchmark is that tests should be conducted:
- Every five years regardless of risk
- Based on the criticality of systems and regulatory or contractual requirements (Correct answer)
- Only after a real disaster has occurred
- Whenever IT staff have available time
Correct answer: Based on the criticality of systems and regulatory or contractual requirements
DR test frequency should be driven by business criticality, regulatory mandates (e.g., SOX, HIPAA), and the rate of change in the IT environment.
A company's DR test reveals that the recovery site network bandwidth is insufficient for peak transaction volumes.
This finding MOST likely indicates a gap in: