โ† All CISA Flashcard Decks

Disaster Recovery Testing Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Disaster Recovery Testing flashcards as text
  1. An organization's DR plan calls for restoring systems from tape, but the most recent tape is three days old. The BEST control to address this gap is:

    Answer: Implementing real-time or near-real-time replication to the recovery site

    Real-time or near-real-time replication eliminates the data-age problem by continuously mirroring production data to the recovery site.

  2. Which of the following BEST describes a structured walkthrough in the context of DR testing?

    Answer: A review where team members individually verify their portions of the DR plan for accuracy

    A structured walkthrough has each team member review their section of the DR plan and confirm it is accurate and feasible, without activating any systems.

  3. An IS auditor is evaluating DR test documentation. Which finding would be MOST concerning?

    Answer: Test results are undated and lack signatures from responsible parties

    Undated and unsigned test records lack the basic governance controls needed to demonstrate accountability and cannot serve as reliable audit evidence.

  4. Which of the following scenarios would MOST likely require an immediate, unplanned update to the DR plan?

    Answer: A major application is migrated to a new cloud platform

    Migrating a critical application to a new platform fundamentally changes recovery dependencies, procedures, and RTO/RPO assumptions, requiring immediate DR plan updates.

  5. During a DR test, a member of the recovery team cannot locate the call tree and is unable to notify key stakeholders. This BEST highlights a gap in:

    Answer: DR plan accessibility and communication procedures

    Recovery team members must be able to access communication tools and call trees immediately; failure to do so indicates the plan is not accessible or communication procedures are inadequate.

  6. An IS auditor recommends that DR tests should include which of the following to address supply chain risk?

    Answer: Testing recovery of systems that depend on third-party vendors and cloud providers

    Modern IT environments depend heavily on third-party vendors and cloud providers; DR tests must validate that these dependencies can be recovered or worked around.

  7. After completing a DR test, management decides the results do not need to be shared with the board. An IS auditor should flag this because:

    Answer: Board-level oversight of DR program effectiveness is a governance best practice

    Governance frameworks such as COBIT and ISO 22301 require that DR program results be reported to senior leadership and the board to ensure appropriate oversight of organizational resilience.