Information Systems Operations and Business Resilience Flashcards
7 cards from real ISACA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Systems Operations and Business Resilience flashcards as text
Which metric best measures the effectiveness of an organization's disaster recovery plan?
Answer: Recovery Time Objective (RTO) achieved
Achieving the defined RTO demonstrates that the DR plan can restore operations within the acceptable downtime window.
An IS auditor reviewing an organization's job scheduling process should be MOST concerned if:
Answer: Operators can modify production job schedules without change management approval
Unauthorized modification of production job schedules bypasses change management controls and can lead to data integrity issues or unauthorized processing.
What is the PRIMARY purpose of a business impact analysis (BIA)?
Answer: Identify critical business functions and their recovery priorities
A BIA identifies critical business processes, their dependencies, and the impact of disruption to establish recovery priorities and objectives.
During a data center audit, an IS auditor finds that system logs are stored on the same server being monitored. The MAIN risk is:
Answer: An attacker could alter logs to conceal unauthorized activity
Storing logs on the monitored system allows an attacker who compromises that system to modify or delete audit trails, eliminating evidence of their actions.
Which of the following is the BEST indicator that patch management processes are effective?
Answer: Mean time to patch critical vulnerabilities meets defined SLAs
Measuring mean time to patch against defined SLAs provides a quantifiable indication of whether vulnerabilities are being remediated in a timely manner.
A hot site differs from a warm site primarily because a hot site:
Answer: Has fully operational systems with current data ready for immediate failover
A hot site mirrors the production environment with up-to-date data, enabling near-immediate failover, while a warm site requires additional configuration time.
When evaluating an organization's IT operations, an IS auditor should verify that operator procedures are:
Answer: Documented, approved, and reviewed periodically
Documented, approved, and periodically reviewed procedures ensure consistency, accountability, and alignment with current operational and security requirements.