ISACA Information Systems Operations and Business Resilience 4 — Questions and Answers
Question 1: An IS auditor reviewing a business continuity plan (BCP) finds that the plan has not been tested in three years. The MOST significant risk is:
- The plan may contain outdated procedures that fail during an actual disaster (Correct answer)
- Staff may be unfamiliar with the document's formatting
- The BCP vendor contract may have expired
- Testing costs have not been budgeted
Correct answer: The plan may contain outdated procedures that fail during an actual disaster
Untested plans may reference decommissioned systems, departed personnel, or obsolete procedures, causing failures precisely when recovery is most critical.
Question 2: Which of the following BEST describes the role of a reciprocal agreement in business continuity?
- Two organizations agree to provide each other computing resources in the event of a disaster (Correct answer)
- An organization contracts with a third-party hot site provider
- An organization maintains a cold site at a secondary location
- Two organizations share a common disaster recovery budget
Correct answer: Two organizations agree to provide each other computing resources in the event of a disaster
A reciprocal agreement is a mutual arrangement between two organizations to host each other's operations during a disaster, though resource conflicts are a known risk.
Question 3: During an IS audit, an auditor discovers that production data is used in the test environment without masking. The PRIMARY concern is:
- Unauthorized exposure of sensitive personal or confidential data (Correct answer)
- Test results may not reflect production performance
- Testing tools may damage production records
- Compliance reporting may be inaccurate
Correct answer: Unauthorized exposure of sensitive personal or confidential data
Using unmasked production data in test environments exposes sensitive information to developers and testers who may not be authorized to view it, creating a privacy and compliance risk.
Question 4: What is the PRIMARY objective of an IT service continuity management (ITSCM) program?
- Ensure IT services can be recovered within agreed timeframes to support business continuity (Correct answer)
- Eliminate all possible IT outages through redundancy
- Reduce the cost of IT infrastructure
- Transfer IT risk to third-party service providers
Correct answer: Ensure IT services can be recovered within agreed timeframes to support business continuity
ITSCM focuses on ensuring that IT services supporting critical business processes can be restored within defined RTO and RPO targets.
Question 5: An IS auditor reviewing problem management should verify that:
- Root cause analyses are completed and permanent fixes are tracked to closure (Correct answer)
- All incidents are escalated to problem management
- Problem management meetings occur daily
- Problem tickets are assigned to senior staff only
Correct answer: Root cause analyses are completed and permanent fixes are tracked to closure
Effective problem management requires identifying root causes and ensuring permanent fixes are implemented and verified, not just documenting the occurrence.
Question 6: Which environmental control is MOST critical for preventing hardware damage in a data center?
- Maintaining temperature and humidity within manufacturer-specified ranges (Correct answer)
- Installing motion-sensor lighting to reduce energy costs
- Using anti-static mats at all workstations
- Painting server racks a light color to reflect heat
Correct answer: Maintaining temperature and humidity within manufacturer-specified ranges
Excessive heat or humidity directly causes hardware failures; maintaining conditions within manufacturer specifications is the primary environmental control.
Question 7: An organization is evaluating its change management process. Which finding indicates an ineffective process?
- Emergency changes are frequently implemented without post-implementation review (Correct answer)
- Standard changes follow a pre-approved template
- All changes require impact assessments
- Change advisory board meetings are held weekly
Correct answer: Emergency changes are frequently implemented without post-implementation review
Emergency changes that consistently bypass post-implementation review create unreviewed risk and suggest the emergency process is being misused to avoid normal controls.
An IS auditor reviewing a business continuity plan (BCP) finds that the plan has not been tested in three years.
The MOST significant risk is: