CISA Question of the Day: Tabletop Exercises and Third-Party Dependencies

CISA exam practice question — CISA Question of the Day: Tabletop Exercises and Third-Party Dependencies

CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Information Systems Operations and Business Resilience.

Question

As an IS auditor reviewing the organization's annual tabletop testing of its incident response plan, you discover the exercises exclude critical cloud service providers and no formal lessons-learned reports are produced. Which action best enhances the effectiveness of the incident response testing program?

  • A. Increase the frequency of tabletop exercises from annual to quarterly to improve readiness
  • B. Replace tabletop exercises with desktop reviews conducted by internal managers to reduce disruption
  • C. Expand tabletop exercises to include critical third-party dependencies and document lessons learned to update plans
  • D. Continue annual exercises but require IT management to sign off on plan accuracy without additional testing
Show the answer and explanation

Correct answer: C. Expand tabletop exercises to include critical third-party dependencies and document lessons learned to update plans

The best action is to expand tabletop exercises to include critical third-party dependencies and document lessons learned to update plans. Effective testing must validate real dependencies (including cloud providers) and capture actionable findings so plans and relationships can be improved. Increasing frequency alone (option 1) may improve familiarity but does not address missing scope or lack of feedback. Replacing exercises with desktop reviews (option 2) reduces realism and the ability to uncover coordination or dependency issues. Requiring sign-off without further testing (option 3) produces declarative assurance but does not validate the plan in practice or correct weaknesses revealed by tests.

Want more practice?

Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.