CISA Domain 4B-5 Practice Test 001

This practice test covers Domain 4 (Information Systems Operations & Business Resilience) Subdomain B-5 (Disaster Recovery Plans) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 4B-5 Disaster Recovery Plans Practice Test 001
10 questions • Single best answer
Question 1
During a disaster recovery test at a regional bank, the IS auditor observes that critical applications were restored at the alternate site within the recovery time objective, but transaction data was recovered only up to the previous night's backup. Business units require near-zero data loss. Which finding is MOST significant?
    Question 2
    A government agency is selecting an alternate processing facility for its disaster recovery strategy. The agency must resume mission-critical citizen services within two hours of a disruption, and management wants to minimize recovery delay while controlling ongoing costs. Which type of recovery site BEST supports the two-hour recovery requirement?
      Question 3
      An IS auditor reviewing a hospital's disaster recovery plan finds that the document identifies recovery teams and procedures but does not specify the sequence in which systems should be restored. Several interdependent clinical applications exist, and restoring them out of order could corrupt data. What is the auditor's BEST recommendation?
        Question 4
        An organization wants to validate its disaster recovery plan without disrupting live production systems. Management seeks reasonable assurance that recovery procedures work and that the alternate site can actually process transactions, while avoiding any impact on ongoing operations. Which disaster recovery testing approach BEST meets this objective?
          Question 5
          During a review of a company's disaster recovery plan, the IS auditor notes that recovery time objectives were defined by the IT department without input from business process owners. Some critical business functions may have shorter tolerances than the current RTOs. Which finding is MOST significant?
            Question 6
            An IS auditor finds that an organization's disaster recovery plan is comprehensive and well documented but has never been tested since it was written two years ago. The IT environment has changed considerably since then. What should the IS auditor be MOST concerned about regarding the plan?
              Question 7
              During a regulatory examination, an IS auditor wants to determine whether a payment processor can actually recover its critical systems within the stated recovery time objective following a major disruption. Which of the following would provide the BEST evidence that the recovery time objective can be met?
                Question 8
                An IS auditor reviewing a disaster recovery arrangement finds that the organization's alternate processing site is located in the same industrial park as the primary data center, approximately two kilometers away. Both facilities draw power from the same regional substation. Which finding is MOST significant?
                  Question 9
                  A recent disaster recovery test at an insurance company failed because several server configurations at the recovery site did not match those in production, preventing critical applications from starting. Management attributed this to recent unlogged production changes. What is the auditor's BEST recommendation to prevent recurrence?
                    Question 10
                    An IS auditor is evaluating the data recovery component of a disaster recovery plan. Backups are performed nightly and stored on-site, with copies shipped to an offsite vault weekly. The organization's recovery point objective is four hours, but backups run only once daily. Which conclusion is MOST appropriate?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top