โ† All CISA Flashcard Decks

Business Continuity Planning Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Business Continuity Planning flashcards as text
  1. Which metric defines the maximum amount of data an organization can afford to lose in a disaster, measured in time?

    Answer: Recovery Point Objective (RPO)

    RPO defines the point in time to which data must be recovered, representing the maximum acceptable data loss.

  2. A hot site differs from a warm site primarily because a hot site:

    Answer: Is fully operational with real-time data replication

    A hot site is fully equipped, staffed, and has mirrored data so it can assume operations almost immediately.

  3. During a BCP audit, an IS auditor finds that the organization has not updated its BCP in three years. What is the MOST significant risk?

    Answer: The plan may not reflect current business processes and systems

    An outdated BCP may fail to account for changes in infrastructure, personnel, and critical processes, making it ineffective during a real disaster.

  4. Which of the following BEST describes the purpose of a Business Impact Analysis (BIA)?

    Answer: To quantify the impact of disruptions and prioritize recovery of critical functions

    A BIA quantifies financial and operational impacts of disruptions and prioritizes which functions must be restored first.

  5. An organization's BCP team is conducting an emergency response exercise. Which type of test involves actually moving operations to the recovery site?

    Answer: Full interruption test

    A full interruption test shuts down primary operations and transfers them to the recovery site, providing the most realistic but disruptive test.

  6. Which element is MOST critical to include in a business continuity plan for an organization that relies heavily on third-party vendors?

    Answer: Third-party vendor continuity and resilience requirements

    Organizations must ensure third-party vendors have adequate continuity plans and contractual obligations to support recovery objectives.

  7. When auditing a disaster recovery plan, which finding would be of GREATEST concern to an IS auditor?

    Answer: The DRP is stored only at the primary site

    A DRP stored only at the primary site would be inaccessible in a disaster that destroys or cuts off access to that location.