CISA Domain 4B-2 Practice Test 001

This practice test covers Domain 4 (Information Systems Operations & Business Resilience) Subdomain B-2 (System and Operational Resilience) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 4B-2 System and Operational Resilience Practice Test 001
10 questions • Single best answer
Question 1
An IS auditor reviewing the resilient architecture of an online payment processor finds that all transaction services run on a single active data center, with a secondary site kept powered down to reduce costs. Management states that failover to the secondary site has never been tested. Which finding is MOST significant?
    Question 2
    A financial services firm asserts that its core banking platform achieves high availability through active server clustering across multiple nodes in a single data center. Management has not independently confirmed how the cluster behaves when a node is lost. Which control provides the BEST assurance that the cluster will maintain service if an individual node fails?
      Question 3
      During an operational resilience audit of a hospital's electronic health record system, the IS auditor learns that redundant components were added reactively after several unplanned outages disrupted clinical care. Management could not point to any defined resilience requirements or availability targets for the system. What should the IS auditor do FIRST?
        Question 4
        An IS auditor evaluating the operational resilience of a telecommunications provider notes that two redundant network links serving a critical site enter the building through the same underground physical conduit. Both links are also provisioned by the same carrier under a single contract. Which finding is MOST significant?
          Question 5
          A manufacturing company's production control system is designed to continue operating in a degraded mode during partial failures so that output is not lost. The IS auditor finds that documented degraded-mode procedures exist, but operations staff have never been trained on how to invoke or run them. Which risk is of GREATEST concern?
            Question 6
            An IS auditor is assessing whether a retailer's e-commerce platform can withstand the sudden loss of a single cloud availability zone during peak trading. Management believes the platform is resilient because it is hosted across several zones. Which of the following provides the BEST evidence that the platform is genuinely resilient to such a loss?
              Question 7
              During a resilience audit at a government agency, the IS auditor finds that resilience requirements for critical systems are set informally by individual system administrators based on personal judgment. No single function owns operational resilience, and the requirements vary widely between comparable systems. Which recommendation is MOST appropriate?
                Question 8
                An insurance company performs annual failover tests by switching to its secondary site during a scheduled maintenance window when transaction volume is minimal. Each test has passed, and management cites this as proof of resilience. The IS auditor questions whether the results reliably demonstrate resilience. What is the auditor's BEST recommendation?
                  Question 9
                  An IS auditor reviews a bank's resilient design that replicates transactions to a geographically separate secondary site using asynchronous replication. Management asserts that no data whatsoever would be lost during an unplanned failover to the secondary site. Which conclusion is MOST appropriate based on the evidence gathered?
                    Question 10
                    A cloud-native company deliberately injects failures into its live production environment to validate that its systems detect faults and recover automatically without human intervention. An IS auditor evaluating this practice wants assurance that the experiments do not themselves create undue operational risk. Which control provides the BEST assurance?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top