Inspirational journeys

Follow the stories of academics and their research expeditions

CISA—Certified Information Systems Auditor - Part 325

Mary Smith

Thu, 16 Apr 2026

CISA—Certified Information Systems Auditor - Part 325

1. After a full operational contingency test, an IS auditor performs a review of the recovery steps. The auditor concludes that the time it took for the technological environment and systems to return to full-functioning exceeded the required critical recovery time. Which of the following should the auditor recommend?

A) Perform an integral review of the recovery tasks.
B) Broaden the processing capacity to gain recovery time.
C) Make improvements in the facility's circulation structure.
D) increase the amount of human resources involved in the recovery.



2. While designing the business continuity plan (BCP) for an airline reservation system, the MOST appropriate method of data transfer/backup at an offsite location would be:

A) shadow file processing.
B) electronic vaulting.
C) hard-disk mirroring.
D) hot-site provisioning.



3. Depending on the complexity of an organization's business continuity plan (BCP), the plan may be developed as a set of more than one plan to address various aspects of business continuity and disaster recovery, in such an environment, it is essential that:

A) each plan is consistent with one another.
B) all plans are integrated into a single plan.
C) each plan is dependent on one another.
D) the sequence for implementation of all plans is defined.



4. Which of the following insurance types provide for a loss arising from fraudulent acts by employees?

A) Business interruption
B) Fidelity coverage
C) Errors and omissions
D) Extra expense



5. The BEST method for assessing the effectiveness of a business continuity plan is to review the:

A) plans and compare them to appropriate standards.
B) results from previous tests.
C) emergency procedures and employee training.
D) offsite storage and environmental controls.



1. Right Answer: A
Explanation: Performing an exhaustive review of the recovery tasks would be appropriate to identify the way these tasks were performed, identify the time allocated to each of the steps required to accomplish recovery, and determine where adjustments can be made. Choices B, C and D could be actions after the described review has been completed.

2. Right Answer: A
Explanation: In shadow file processing, exact duplicates of the files are maintained at the same site or at a remote site. The two files are processed concurrently. This is used for critical data files, such as airline booking systems. Electronic vaulting electronically transmits data either to direct access storage, an optical disc or another storage medium; this is a method used by banks. Hard-disk mirroring provides redundancy in case the primary hard disk fails. All transactions and operations occur on two hard disks in the same server. A hot site is an alternate site ready to take over business operations within a few hours of any business interruption and is not a method for backing up data.

3. Right Answer: A
Explanation: Depending on the complexity of an organization, there could be more than one plan to address various aspects of business continuity and disaster recovery.These do not necessarily have to be integrated into one single plan. However, each plan has to be consistent with other plans to have a viable business continuity planning strategy. It may not be possible to define a sequence in which plans have to be implemented, as it may be dependent on the nature of disaster, criticality, recovery time, etc.

4. Right Answer: B
Explanation: Fidelity insurance covers the loss arising from dishonest or fraudulent acts by employees. Business interruption insurance covers the loss of profit due to the disruption in the operations of an organization. Errors and omissions insurance provides legal liability protection in the event that the professional practitioner commits an act that results in financial loss to a client. Extra expense insurance is designed to cover the extra costs of continuing operations following a disaster/ disruption within an organization.

5. Right Answer: B
Explanation: Previous test results will provide evidence of the effectiveness of the business continuity plan. Comparisons to standards will give some assurance that the plan addresses the critical aspects of a business continuity plan but will not reveal anything about its effectiveness. Reviewing emergency procedures, offsite storage and environmental controls would provide insight into some aspects of the plan but would fall short of providing assurance of the plan's overall effectiveness.

0 Comments

Leave a comment