Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 854 discussion

Actual exam question from Isaca's CISA
Question #: 854
Topic #: 1
[All CISA Questions]

A disaster recovery plan (DRP) should include steps for:

  • A. negotiating contracts with disaster planning consultants
  • B. identifying application control requirements
  • C. obtaining replacement supplies
  • D. assessing and quantifying risk
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Swallows
4 months ago
Selected Answer: D
I'll correct the answer. While option C (obtaining replacement supplies) might be relevant in certain types of disasters (such as natural disasters that damage physical infrastructure), it is not as fundamental to a disaster recovery plan as assessing and quantifying risk. Risk assessment forms the foundation for determining the scope, priorities, and strategies of the DRP. Therefore, including steps for assessing and quantifying risk (option D) is a critical component of a comprehensive Disaster Recovery Plan (DRP).
upvoted 2 times
...
Swallows
8 months, 1 week ago
Selected Answer: C
Risk assessment and quantification should be done as a BCP, not a DRP; the DRP should plan and train procedures for obtaining replacement supplies for disaster recovery.
upvoted 3 times
...
Rachy
10 months ago
Selected Answer: C
C. Obtaining replacement supplies is a key aspect that should be included in a disaster recovery plan
upvoted 4 times
...
3008
1 year, 3 months ago
Selected Answer: D
One of the key components of a DRP is assessing and quantifying risk. This involves identifying potential threats and vulnerabilities to the organization's critical systems and data, evaluating the likelihood and potential impact of these threats, and determining appropriate risk mitigation strategies. The risk assessment process should involve all relevant stakeholders, including IT staff, business leaders, and other key personnel. The assessment should consider a range of potential threats, including natural disasters, cyber attacks, power outages, and other disruptions. Once the risks have been identified and assessed, the organization can develop appropriate risk mitigation strategies, including backup and recovery procedures, redundant systems and data storage, and other measures to minimize the impact of a disaster
upvoted 4 times
...
ItsBananass
1 year, 4 months ago
I think It's C.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...