CISA Domain 4B-3 Practice Test 001

This practice test covers Domain 4 (Information Systems Operations & Business Resilience) Subdomain B-3 (Data Backup, Storage, and Restoration) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 4B-3 Data Backup, Storage, and Restoration Practice Test 001
10 questions • Single best answer
Question 1
During an audit of a regional hospital's clinical systems backup program, the IS auditor observes that nightly backups complete successfully and monitoring logs show no errors. However, restoration from backup media has never been tested, and no recovery time objective has been formally defined. Which finding is MOST significant?
    Question 2
    A manufacturing firm performs a full backup of its ERP database every Sunday night and takes no additional backups during the week. Management states that the agreed recovery point objective for the ERP system is four hours. The IS auditor is evaluating backup frequency. Which conclusion is MOST appropriate?
      Question 3
      An IS auditor at a financial services company finds that all production backups are stored on the same storage array that hosts the primary data, replicated to a second volume in the same data center. No copies are kept offsite or offline. Which risk is of GREATEST concern?
        Question 4
        During a review of an insurer's backup process, the IS auditor notes that backup tapes containing customer financial records are transported to an offsite vault by a third-party courier. The tapes themselves are not encrypted, though the courier maintains chain-of-custody logs. Which recommendation is MOST appropriate?
          Question 5
          An IS auditor wants assurance that a government agency can actually recover its case-management database from backups following a failure. Management provides successful backup completion reports and a documented restoration procedure signed by the operations manager. Which of the following would provide the BEST evidence of recoverability?
            Question 6
            A retailer's IT department overwrites all backup media on a 30-day rotation to reduce storage costs, and no long-term archival copies are produced. The IS auditor notes that applicable regulations require certain financial transaction records to be retained for seven years. Which finding is MOST significant?
              Question 7
              A SaaS-based HR platform is used to store employee records. During an audit, management assumes the cloud provider automatically backs up all data and can restore it on request, though no contractual terms have been verified. The IS auditor is evaluating backup coverage. What should the auditor do FIRST?
                Question 8
                An IS auditor examines a bank's backup operations and finds that backup jobs are scheduled and generate completion emails, but no one verifies whether the emails indicate success or failure. Several recent jobs failed silently and went unnoticed for weeks. Which control weakness is MOST significant?
                  Question 9
                  A logistics company uses incremental backups every weekday and a full backup each weekend. Following a Thursday failure, restoration required the last full backup plus every intervening incremental, extending recovery well beyond the RTO. The IS auditor is assessing the backup strategy. Which recommendation is MOST appropriate?
                    Question 10
                    After a ransomware incident, an enterprise discovered that its online backups were encrypted by the attacker along with production systems because both were reachable from the same network. The IS auditor is recommending improvements. Which control would BEST protect backup data from a similar attack?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top