Information Systems Operations and Business Resilience Flashcards
7 cards from real ISACA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Systems Operations and Business Resilience flashcards as text
Which of the following BEST describes a tabletop exercise in the context of business continuity?
Answer: A discussion-based walkthrough of a disaster scenario without activating recovery systems
A tabletop exercise engages key personnel in a scenario discussion to identify gaps and clarify roles without the cost and disruption of a full operational test.
An IS auditor finds that system administrators have the ability to modify audit logs. This PRIMARILY represents a failure of:
Answer: Segregation of duties and audit trail integrity controls
Allowing those being monitored to modify the records of their activity undermines the integrity of the audit trail and violates segregation of duties.
When auditing an outsourced data center, an IS auditor should rely PRIMARILY on:
Answer: SSAE 18 SOC 2 Type II reports and contractual audit rights clauses
SOC 2 Type II reports provide an independent, structured assessment of controls over a period of time, and audit rights clauses allow the organization to verify controls directly.
Which metric is MOST useful for evaluating the effectiveness of an incident response program?
Answer: Mean time to detect (MTTD) and mean time to respond (MTTR) to security incidents
MTTD and MTTR directly measure how quickly threats are identified and contained, reflecting the operational performance of the incident response process.
An organization's IT operations team performs all system administration, change management, and security monitoring. The GREATEST risk from this arrangement is:
Answer: Lack of segregation of duties allows unauthorized changes to go undetected
When the same team administers systems, approves changes, and monitors security, there is no independent check on their activities, enabling concealment of unauthorized actions.
Which of the following is a key characteristic of a resilient IT architecture?
Answer: Elimination of single points of failure through redundancy and failover capabilities
Resilience depends on redundancy and automated failover so that the failure of any single component does not cause a system-wide outage.
During a review of IS operations, an IS auditor should verify that service level agreements (SLAs) with IT vendors:
Answer: Include measurable performance targets, reporting requirements, and remedies for non-compliance
Effective SLAs must define measurable targets and consequences for non-compliance to be enforceable and to provide a basis for vendor performance evaluation.