Information Systems Operations and Business Resilience Flashcards
7 cards from real ISACA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Systems Operations and Business Resilience flashcards as text
An IS auditor reviewing a business continuity plan (BCP) finds that the plan has not been tested in three years. The MOST significant risk is:
Answer: The plan may contain outdated procedures that fail during an actual disaster
Untested plans may reference decommissioned systems, departed personnel, or obsolete procedures, causing failures precisely when recovery is most critical.
Which of the following BEST describes the role of a reciprocal agreement in business continuity?
Answer: Two organizations agree to provide each other computing resources in the event of a disaster
A reciprocal agreement is a mutual arrangement between two organizations to host each other's operations during a disaster, though resource conflicts are a known risk.
During an IS audit, an auditor discovers that production data is used in the test environment without masking. The PRIMARY concern is:
Answer: Unauthorized exposure of sensitive personal or confidential data
Using unmasked production data in test environments exposes sensitive information to developers and testers who may not be authorized to view it, creating a privacy and compliance risk.
What is the PRIMARY objective of an IT service continuity management (ITSCM) program?
Answer: Ensure IT services can be recovered within agreed timeframes to support business continuity
ITSCM focuses on ensuring that IT services supporting critical business processes can be restored within defined RTO and RPO targets.
An IS auditor reviewing problem management should verify that:
Answer: Root cause analyses are completed and permanent fixes are tracked to closure
Effective problem management requires identifying root causes and ensuring permanent fixes are implemented and verified, not just documenting the occurrence.
Which environmental control is MOST critical for preventing hardware damage in a data center?
Answer: Maintaining temperature and humidity within manufacturer-specified ranges
Excessive heat or humidity directly causes hardware failures; maintaining conditions within manufacturer specifications is the primary environmental control.
An organization is evaluating its change management process. Which finding indicates an ineffective process?
Answer: Emergency changes are frequently implemented without post-implementation review
Emergency changes that consistently bypass post-implementation review create unreviewed risk and suggest the emergency process is being misused to avoid normal controls.