Information Systems Operations and Business Resilience
Drill 20 practice questions focused entirely on Information Systems Operations and Business Resilience for the ISACA CISA exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.
During an audit of a company's disaster recovery arrangements, the IS auditor confirms that full backups are performed nightly and encrypted copies are shipped to an offsite vault daily. Backup completion logs show no failures for the past 12 months. Which of the following should be the auditor's GREATEST concern?
During a review of nightly batch operations, an IS auditor notes that the overnight processing window has begun to overrun into online business hours, delaying transaction availability for morning users. Data volumes have grown 40% over the past year, but the job schedule and hardware have not changed. What should the auditor recommend as the MOST appropriate first action?
An IS auditor is reviewing the results of a recently completed business impact analysis (BIA) for a financial services firm. The BIA identifies several business processes but does not rank them or specify the maximum tolerable downtime for each. Management wants to proceed directly to selecting recovery technologies based on the BIA. What should the auditor recommend as the MOST important missing element before recovery solutions are chosen?
During an audit of IT operations, an IS auditor notes that the organization only investigates system performance after users report slowdowns, and no forecasting of future resource demand is performed. Which weakness should the auditor identify as the MOST significant concern?
During a review of the change management process, an IS auditor finds that emergency changes are deployed directly to production by on-call engineers using elevated access, and that the process relies on a documented step to formally record and approve the change after deployment. Which control MOST effectively ensures that these emergency changes do not become a means to bypass normal change governance?
An IS auditor reviews a company's backup strategy for a critical transactional database. The organization performs a full backup every Sunday and synthetic full backups are not used; instead, transaction log backups are taken every 15 minutes throughout the week. During a test, the DBA restores the database to the state it was in on Wednesday at 2:00 p.m. Which of the following is the MOST important factor determining whether this point-in-time recovery will succeed?
During a review of IT operations, an IS auditor finds that the configuration management database (CMDB) is used to support incident, problem, and change management processes. However, several recent outages were traced to changes made on servers that were not reflected in the CMDB. What should the auditor recommend as the MOST effective control to address this issue?
During an audit of a production database, an IS auditor finds that database administrators (DBAs) use a shared privileged account to perform maintenance, and native database audit logging of privileged activity is disabled to improve performance. Which of the following findings should the auditor identify as the MOST significant concern?
A production database server crashes suddenly during peak processing. When the DBA restarts the database management system, the recovery process must determine which transactions to redo and which to roll back. Which database mechanism primarily enables the DBMS to restore the database to a consistent state without replaying every transaction since the last full backup?
During a review of a high-volume transaction processing system, an IS auditor notes that users frequently report intermittent transaction timeouts during peak business hours. The DBA team confirms that database CPU and memory utilization remain well within thresholds during these periods. Which of the following is the MOST likely cause the auditor should recommend investigating first?
During a review of a production order-processing database, an IS auditor notes that query response times have gradually worsened over the past several months, though transaction volumes have remained stable and hardware utilization is well within normal ranges. The DBA confirms that no schema or application changes have occurred. Which condition is the auditor MOST likely to identify as the cause?
During a review of a newly deployed customer relationship management database, an IS auditor notes that a single 'Orders' table stores customer name, address, and phone number repeated on every order row, and that deleting a customer record leaves orphaned order rows referencing a non-existent customer. Which control weakness is the auditor MOST likely to report as the primary concern?
A financial services firm requires that its transaction database be continuously replicated to a geographically distant site so that, in the event of a primary data center failure, the alternate site holds an identical, up-to-the-second copy of the data. Which technique BEST meets this requirement?
A data center performs a full backup every Sunday and uses a supplementary daily backup scheme Monday through Saturday. Management wants to minimize the time required to restore a server if it fails on a Friday, while accepting that daily backups will take somewhat longer to complete each night. Which supplementary backup approach best meets this restore-time objective?
A financial services firm has determined that its core trading platform has a recovery time objective (RTO) of 30 minutes. During a disaster recovery review, the IS auditor finds the organization currently relies on a warm site that requires several hours to load recent data backups and configure applications before the platform can resume. Which recommendation should the auditor make to best address this gap?
During a disaster recovery plan review, an IS auditor finds that the plan document is technically comprehensive but the emergency contact list, vendor phone numbers, and named recovery team members have not been updated in over two years, and several listed staff have left the organization. Which of the following is the auditor's GREATEST concern?
An IS auditor is evaluating an organization's disaster recovery program. The DR plan has been documented and updated after a recent infrastructure refresh, but the organization has never executed a live failover to the alternate site because operations staff fear disrupting production services. Which testing approach should the auditor recommend as the MOST effective next step to validate recovery capability while minimizing operational risk?
An IS auditor is reviewing an automated nightly interface that transfers a consolidated transaction file from a branch banking application to the central core system. The auditor wants assurance that the file received by the core system is complete and has not been altered in transit. Which control would BEST provide this assurance?
A financial services firm requires that transaction data be recoverable with minimal data loss after a disaster, but its current tape backups are physically couriered to an offsite location once each night. During an IS audit, which recommendation would BEST reduce the amount of data that could be lost between the last backup and a disaster event?
An IS auditor is reviewing a bank's data protection strategy for its core transaction database. The bank transmits only the database transaction logs to an offsite facility continuously as they are generated, rather than sending full copies of the database files at scheduled intervals. Which technique is the bank using?
More CISA practice
Keep going with the other ISACA CISA — Certified Information Systems Auditor domains, or take a full timed mock exam.
← Back to CISA overview