ExamGecko
Question list
Search
Search

Related questions

Question 362 - CISA discussion

Report
Export

Which of the following should be of GREATEST concern for an IS auditor reviewing an organization's disaster recovery plan (DRP)?

A.
The DRP has not been formally approved by senior management.
Answers
A.
The DRP has not been formally approved by senior management.
B.
The DRP has not been distributed to end users.
Answers
B.
The DRP has not been distributed to end users.
C.
The DRP has not been updated since an IT infrastructure upgrade.
Answers
C.
The DRP has not been updated since an IT infrastructure upgrade.
D.
The DRP contains recovery procedures for critical servers only.
Answers
D.
The DRP contains recovery procedures for critical servers only.
Suggested answer: C

Explanation:

The greatest concern for an IS auditor reviewing an organization's disaster recovery plan (DRP) is that the DRP has not been updated since an IT infrastructure upgrade. This could render the DRP obsolete or ineffective, as it may not reflect the current configuration, dependencies or recovery requirements of the IT systems. The IS auditor should ensure that the DRP is reviewed and updated regularly to align with any changes in the IT environment. The DRP has not been formally approved by senior management is a concern for an IS auditor reviewing an organization's DRP, but it is not as critical as ensuring that the DRP is up to date and valid. The DRP has not been distributed to end users or the DRP contains recovery procedures for critical servers only are issues that relate to the communication or scope of the DRP, but not to its validity or effectiveness.Reference:ISACA, CISA Review Manual, 27th Edition, 2018, page 389

asked 18/09/2024
Mark Baker
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first