CISA Domain 4B Practice Test 001

This practice test covers Domain 4 (Information Systems Operations & Business Resilience) Subdomain B (Business Resilience) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA Practice Test — 4B (Business Resilience)
10 questions • Single best answer
Question 1
A business continuity audit at a regional hospital reveals that the business impact analysis was last updated three years ago, before several clinical systems were migrated to a new electronic health record platform. Recovery time objectives still reference the retired legacy applications. Which of the following should be the auditor's MOST significant concern?
    Question 2
    During an audit of a financial services firm's data backup program, the IS auditor wants to confirm that critical databases can actually be recovered within stated objectives. Backup completion logs consistently show successful nightly jobs. Which of the following would provide the BEST evidence that the firm's recovery capabilities are effective?
      Question 3
      An audit of a government agency's disaster recovery plan finds that it documents detailed recovery procedures but has never been tested since it was approved two years ago. During that period, the designated recovery site was substantially reconfigured. Which of the following findings is MOST significant?
        Question 4
        A manufacturing company is developing its business continuity program and has engaged the IS auditor for guidance. Management wants to prioritize recovery investments across dozens of interdependent business processes but lacks a structured basis for doing so. Which of the following should be performed FIRST to support these decisions?
          Question 5
          A cloud migration review at an e-commerce provider identifies that the customer-facing platform runs in a single availability zone with no automated failover. Management states that verified daily backups are sufficient to meet its resilience goals. Which of the following best supports the auditor's conclusion that operational resilience is inadequate?
            Question 6
            During a data backup audit at an insurance company, the IS auditor notes that full backups are performed nightly and verified, but all backup media remain in a fireproof cabinet within the same data center. Management considers this arrangement adequate. Which of the following is the auditor's MOST appropriate recommendation?
              Question 7
              An IS auditor is evaluating the backup strategy for a bank's core transaction processing system. The business has defined a recovery point objective of 15 minutes, but backups of the transaction database are taken only once every 24 hours. Which of the following conclusions is MOST appropriate?
                Question 8
                A business resilience audit at a telecommunications firm reviews the disaster recovery testing approach. The organization has only ever performed checklist and walkthrough reviews of its recovery plan. Management asks which testing method would provide the strongest assurance that recovery will actually succeed. Which of the following should the auditor recommend?
                  Question 9
                  An internal audit team reviewing a logistics company's business continuity plan finds it comprehensive and well-structured. However, the organization has undergone two acquisitions and a major headquarters relocation in the past year, none of which are reflected in the plan. Which of the following findings should the auditor report as MOST significant?
                    Question 10
                    A post-implementation review of a new ERP system at a utility company finds that the disaster recovery plan addresses the ERP application servers but omits the interfaced middleware and database services on which the ERP depends. Which of the following is the auditor's MOST significant concern?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top