
CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Information Systems Operations and Business Resilience.
Question
An IS auditor reviews backup practices for a critical transactional application. Daily encrypted backups are retained offsite for 30 days. The vendor provides monthly test reports showing successful file-level restores, but there is no evidence of full system restores or validation of recovery objectives. Which control most effectively demonstrates that the organization can meet its recovery time and recovery point objectives for this application?
Show the answer and explanation
Correct answer: B. Perform periodic full-system restores into a production-like environment and validate recovery time and recovery point objectives.
Periodic full-system restores into a production-like environment are the best control because they exercise the complete recovery process, including application dependencies, configurations, and data consistency, and allow measurement against RTOs and RPOs. Extending retention (option A) increases historical availability but does not prove that systems and applications can be successfully restored within required timeframes. Immutable storage and integrity checks (option C) protect against tampering and corruption but do not validate the end-to-end recovery procedure or timing. Automated monitoring and alerts (option D) help detect backup failures but do not demonstrate that a full restore will succeed or meet recovery objectives.
Want more practice?
Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.
