ISACA Information Systems Operations and Business Resilience 5 — Questions and Answers
Question 1: Which of the following BEST describes a tabletop exercise in the context of business continuity?
- A discussion-based walkthrough of a disaster scenario without activating recovery systems (Correct answer)
- A full live failover to the alternate processing site
- A technical test of backup media restoration
- An annual review of the BCP document by management
Correct answer: A discussion-based walkthrough of a disaster scenario without activating recovery systems
A tabletop exercise engages key personnel in a scenario discussion to identify gaps and clarify roles without the cost and disruption of a full operational test.
Question 2: An IS auditor finds that system administrators have the ability to modify audit logs. This PRIMARILY represents a failure of:
- Segregation of duties and audit trail integrity controls (Correct answer)
- Physical access controls to the data center
- Password complexity requirements
- Network segmentation policies
Correct answer: Segregation of duties and audit trail integrity controls
Allowing those being monitored to modify the records of their activity undermines the integrity of the audit trail and violates segregation of duties.
Question 3: When auditing an outsourced data center, an IS auditor should rely PRIMARILY on:
- SSAE 18 SOC 2 Type II reports and contractual audit rights clauses (Correct answer)
- Verbal assurances from the vendor's account manager
- The vendor's marketing materials and certifications list
- Annual financial statements of the vendor
Correct answer: SSAE 18 SOC 2 Type II reports and contractual audit rights clauses
SOC 2 Type II reports provide an independent, structured assessment of controls over a period of time, and audit rights clauses allow the organization to verify controls directly.
Question 4: Which metric is MOST useful for evaluating the effectiveness of an incident response program?
- Mean time to detect (MTTD) and mean time to respond (MTTR) to security incidents (Correct answer)
- Total number of security tools deployed
- Annual security training completion rate
- Number of security policies documented
Correct answer: Mean time to detect (MTTD) and mean time to respond (MTTR) to security incidents
MTTD and MTTR directly measure how quickly threats are identified and contained, reflecting the operational performance of the incident response process.
Question 5: An organization's IT operations team performs all system administration, change management, and security monitoring. The GREATEST risk from this arrangement is:
- Lack of segregation of duties allows unauthorized changes to go undetected (Correct answer)
- Operations staff may become overwhelmed with multiple responsibilities
- Training costs increase when staff perform multiple roles
- Security monitoring may not be performed during change windows
Correct answer: Lack of segregation of duties allows unauthorized changes to go undetected
When the same team administers systems, approves changes, and monitors security, there is no independent check on their activities, enabling concealment of unauthorized actions.
Question 6: Which of the following is a key characteristic of a resilient IT architecture?
- Elimination of single points of failure through redundancy and failover capabilities (Correct answer)
- Use of the latest technology regardless of stability
- Centralization of all processing at a single location for easier management
- Minimization of redundant components to reduce cost
Correct answer: Elimination of single points of failure through redundancy and failover capabilities
Resilience depends on redundancy and automated failover so that the failure of any single component does not cause a system-wide outage.
Question 7: During a review of IS operations, an IS auditor should verify that service level agreements (SLAs) with IT vendors:
- Include measurable performance targets, reporting requirements, and remedies for non-compliance (Correct answer)
- Are reviewed only when a performance issue occurs
- Are negotiated exclusively by the IT department without legal review
- Focus solely on cost benchmarks
Correct answer: Include measurable performance targets, reporting requirements, and remedies for non-compliance
Effective SLAs must define measurable targets and consequences for non-compliance to be enforceable and to provide a basis for vendor performance evaluation.
Which of the following BEST describes a tabletop exercise in the context of business continuity?