Inspirational journeys

Follow the stories of academics and their research expeditions

CISA—Certified Information Systems Auditor - Part 324

Mary Smith

Mon, 20 Apr 2026

CISA—Certified Information Systems Auditor - Part 324

1. Which of the following activities should the business continuity manager perform FIRST after the replacement of hardware at the primary information processing facility?

A) verify compatibility with the hot site.
B) Review the implementation report.
C) Perform a walk-through of the disaster recovery plan.
D) Update the IS assets inventory.



2. Which of the following would contribute MOST to an effective business continuity plan (BCP)?

A) Document is circulated to all interested parties
B) Planning involves all user departments
C) Approval by senior management
D) Audit by an external IS auditor



3. To develop a successful business continuity plan, end user involvement is critical during which of the following phases?

A) Business recovery strategy
B) Detailed plan development
C) Business impact analysis (BIA)
D) Testing and maintenance



4. Which of the following would an IS auditor consider to be the MOST important to review when conducting a business continuity audit?

A) A hot site contracted and available as needed.
B) A business continuity manual is available and current.
C) insurance coverage is adequate and premiums are current.
D) Media backups are performed on a timely basis and stored offsite.



5. The PRIMARY objective of business continuity and disaster recovery plans should be to:

A) safeguard critical IS assets.
B) provide for continuity of operations.
C) minimize the loss to an organization.
D) protect human life.



1. Right Answer: D
Explanation: An IS assets inventory is the basic input for the business continuity/disaster recovery plan, and the plan must be updated to reflect changes in the IS infrastructure.The other choices are procedures required to update the disaster recovery plan after having updated the required assets inventory.

2. Right Answer: B
Explanation: The involvement of user departments in the BCP is crucial for the identification of the business processing priorities. The BCP circulation will ensure that the BCP document is received by all users. Though essential, this does not contribute significantly to the success of the BCP. A BCP approved by senior management would not ensure the quality of the BCP, nor would an audit necessarily improve the quality of the BCP.

3. Right Answer: C
Explanation: End user involvement is critical in the BIA phase. During this phase the current operations of the business needs to be understood and the impact on the business of various disasters must be evaluated. End users are the appropriate persons to provide relevant information for these tasks, inadequate end user involvement in this stage could result in an inadequate understanding of business priorities and the plan not meeting the requirements of the organization.

4. Right Answer: D
Explanation: Without data to process, all other components of the recovery effort are in vain. Even in the absence of a plan, recovery efforts of any type would not be practical without data to process.

5. Right Answer: D
Explanation: Since human life is invaluable, the main priority of any business continuity and disaster recovery plan should be to protect people. All other priorities are important but are secondary objectives of a business continuity and disaster recovery plan.

0 Comments

Leave a comment