CISA Domain 4B-1 Practice Test 001

This practice test covers Domain 4 (Information Systems Operations & Business Resilience) Subdomain B-1 (Business Impact Analysis) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 4B-1 Business Impact Analysis Practice Test 001
10 questions • Single best answer
Question 1
During a business continuity audit at a global logistics company, the IS auditor finds the business impact analysis was prepared solely by IT staff without input from business process owners. Recovery time objectives were derived from historical system uptime statistics rather than the criticality of business functions. Which finding is MOST significant?
    Question 2
    A financial services firm's business impact analysis assigns its online payment platform a recovery point objective of four hours, but the IS auditor observes that database backups run only once every 24 hours and no near-real-time transaction log replication is configured for the platform. Which conclusion is MOST appropriate?
      Question 3
      An audit manager reviews the deliverables of a newly completed business impact analysis at a hospital network. The document lists external threats, their likelihood, and recommended safeguards, but does not quantify the operational impact of downtime for each clinical function. Which conclusion is MOST appropriate?
        Question 4
        A manufacturing company is developing its first business continuity program. The steering committee asks the IS auditor which activity should be completed FIRST to establish recovery priorities, noting that several departments have already requested that their own systems be designated as most critical. What should be done FIRST?
          Question 5
          During a business impact analysis review at an insurance provider, the IS auditor finds that each business unit assessed its critical processes independently and set recovery objectives in isolation. Upstream and downstream dependencies between the claims, underwriting, and billing systems were not documented in the consolidated analysis. Which risk is MOST significant?
            Question 6
            A business continuity audit at an e-commerce retailer reveals that the recovery time objective for the order-fulfillment system exceeds the maximum tolerable downtime the business defined for that process. Management states the recovery time objective was set by the IT recovery team. What is the IS auditor's BEST course of action?
              Question 7
              An IS auditor examines the business impact analysis at a regional bank that migrated its core banking platform to a cloud provider 18 months ago. The BIA still reflects the legacy on-premises architecture and its recovery objectives, and it has not been reviewed since the migration. Which finding is MOST significant?
                Question 8
                An IS auditor is assessing whether the recovery time objectives documented in a utility company's business impact analysis are achievable rather than aspirational. Several objectives are shorter than any recovery the organization has previously demonstrated. Which of the following would provide the BEST evidence that the objectives are realistic?
                  Question 9
                  During a business impact analysis at a government benefits agency, impacts of process disruption are recorded only as financial loss estimates. The IS auditor notes that reputational harm, statutory service obligations, and citizen safety impacts were excluded from the criteria used to rank process criticality. Which recommendation is MOST appropriate?
                    Question 10
                    A newly appointed audit committee asks whether the organization's disaster recovery strategy is appropriately prioritized. The IS auditor finds recovery plans were built directly from IT's assessment of system value, with no business impact analysis performed to establish business-driven recovery priorities. Which conclusion is MOST appropriate?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top