ISACA Information Systems Operations and Business Resilience 2 — Questions and Answers
Question 1: Which metric best measures the effectiveness of an organization's disaster recovery plan?
- Recovery Time Objective (RTO) achieved (Correct answer)
- Number of backup tapes created
- Frequency of DR plan updates
- Cost of DR infrastructure
Correct answer: Recovery Time Objective (RTO) achieved
Achieving the defined RTO demonstrates that the DR plan can restore operations within the acceptable downtime window.
Question 2: An IS auditor reviewing an organization's job scheduling process should be MOST concerned if:
- Operators can modify production job schedules without change management approval (Correct answer)
- Job scheduling software requires annual license renewal
- Batch jobs run during off-peak hours
- Scheduling logs are retained for 90 days
Correct answer: Operators can modify production job schedules without change management approval
Unauthorized modification of production job schedules bypasses change management controls and can lead to data integrity issues or unauthorized processing.
Question 3: What is the PRIMARY purpose of a business impact analysis (BIA)?
- Identify critical business functions and their recovery priorities (Correct answer)
- Calculate the total cost of a disaster
- Select appropriate backup technology
- Train staff on emergency procedures
Correct answer: Identify critical business functions and their recovery priorities
A BIA identifies critical business processes, their dependencies, and the impact of disruption to establish recovery priorities and objectives.
Question 4: During a data center audit, an IS auditor finds that system logs are stored on the same server being monitored. The MAIN risk is:
- An attacker could alter logs to conceal unauthorized activity (Correct answer)
- Log storage consumes excessive disk space
- Log retrieval performance may be degraded
- Compliance reports may take longer to generate
Correct answer: An attacker could alter logs to conceal unauthorized activity
Storing logs on the monitored system allows an attacker who compromises that system to modify or delete audit trails, eliminating evidence of their actions.
Question 5: Which of the following is the BEST indicator that patch management processes are effective?
- Mean time to patch critical vulnerabilities meets defined SLAs (Correct answer)
- All servers are running the same OS version
- Patches are applied manually by administrators
- Vendor patch notifications are archived
Correct answer: Mean time to patch critical vulnerabilities meets defined SLAs
Measuring mean time to patch against defined SLAs provides a quantifiable indication of whether vulnerabilities are being remediated in a timely manner.
Question 6: A hot site differs from a warm site primarily because a hot site:
- Has fully operational systems with current data ready for immediate failover (Correct answer)
- Is less expensive to maintain on an ongoing basis
- Requires 24–72 hours to become operational
- Is owned by the organization rather than a third party
Correct answer: Has fully operational systems with current data ready for immediate failover
A hot site mirrors the production environment with up-to-date data, enabling near-immediate failover, while a warm site requires additional configuration time.
Question 7: When evaluating an organization's IT operations, an IS auditor should verify that operator procedures are:
- Documented, approved, and reviewed periodically (Correct answer)
- Memorized by all operations staff
- Stored exclusively on the operators' workstations
- Created by individual operators based on experience
Correct answer: Documented, approved, and reviewed periodically
Documented, approved, and periodically reviewed procedures ensure consistency, accountability, and alignment with current operational and security requirements.
Which metric best measures the effectiveness of an organization's disaster recovery plan?