CISA Domain 4B-4 Practice Test 001

This practice test covers Domain 4 (Information Systems Operations & Business Resilience) Subdomain B-4 (Business Continuity Plan) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 4B-4 Business Continuity Plan Practice Test 001
10 questions • Single best answer
Question 1
An IS auditor is reviewing the business continuity plan of a global manufacturing firm following a recent internal audit request. The plan lists recovery procedures and staff contact lists but was last updated three years ago, before a major corporate reorganization and two business acquisitions were completed. Which finding is MOST significant?
    Question 2
    An IS auditor finds that a commercial bank's business continuity plan assigns recovery priorities to business processes, but these priorities were established by IT staff without reference to any business impact analysis. Senior management approved the plan without independent review. What should the IS auditor recommend FIRST?
      Question 3
      During a business continuity audit at an insurance company, the IS auditor learns that the BCP has been validated only through annual tabletop walkthroughs. Management states the plan is fully reliable because these walkthroughs have consistently passed without any issues. Which conclusion is MOST appropriate?
        Question 4
        An IS auditor begins an engagement to evaluate whether an e-commerce company can continue operations after a significant disruption. Management provides a lengthy BCP document, prior incident logs, and several test result summaries for the auditor to review. What should the IS auditor do FIRST?
          Question 5
          A business continuity audit at a telecommunications provider reveals a comprehensive and up-to-date BCP. However, most operational staff are unaware that the plan exists, and several key recovery roles have never been formally assigned to named individuals across the organization. Which finding represents the GREATEST risk?
            Question 6
            An IS auditor wants to conclude on whether a national retailer's business continuity plan will actually function during a real disruption. The auditor has access to several types of documentation and test artifacts. Which of the following provides the BEST evidence of the plan's effectiveness?
              Question 7
              During an audit, the IS auditor notes that a utility company's business continuity program has no assigned executive owner, and plan updates occur only when individual managers happen to volunteer changes. As a result, the plan is inconsistently maintained over time. Which recommendation is MOST appropriate?
                Question 8
                An IS auditor reviews a financial services firm's recovery documentation and finds a detailed IT disaster recovery plan that restores servers within four hours. However, there is no plan describing how business units will continue to operate during that recovery window. Which finding is MOST significant?
                  Question 9
                  An IS auditor is assessing the reliability of a logistics company's BCP. The plan appears thorough and well organized, but the auditor wants to determine whether it accurately reflects the current operating environment. Which review procedure would provide the BEST assurance that the plan is current?
                    Question 10
                    Following a business continuity audit at a government agency, management agreed to remediate several gaps in its BCP within ninety days. The agreed remediation period has now fully elapsed, and a new reporting cycle has begun. What is the IS auditor's BEST course of action?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top