Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 458 discussion

Actual exam question from Isaca's CISA
Question #: 458
Topic #: 1
[All CISA Questions]

Which of the following findings should be of MOST concern to an IS audit or reviewing an organization's business continuity plan (BCP)?

  • A. The plan has not been updated in several years.
  • B. The plan has not been signed by executive management.
  • C. No tabletop exercises have been conducted for the plan.
  • D. End users have not been trained on the latest version of the plan.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
85e8e0b
2 days, 17 hours ago
Selected Answer: A
A BCP that has not been updated in several years presents the greatest risk because the organization's business environment, technology infrastructure, and potential threats (e.g., cyber risks, regulatory changes, or operational processes) likely have evolved since the last update. An outdated plan may no longer be relevant or effective in responding to current risks or disasters. The primary purpose of a BCP is to ensure the organization can continue operating or recover quickly in the event of a disruption, so it is essential that the plan reflects the latest information, resources, and strategies
upvoted 1 times
...
Swallows
5 months, 1 week ago
Selected Answer: A
Regular updates to the BCP are essential to ensure its relevance and effectiveness in mitigating disruptions and maintaining business operations during emergencies. Without updates, the plan may lack critical information, fail to address new threats or vulnerabilities, and be unable to support the organization's recovery efforts effectively. While conducting tabletop exercises (option C) is important for testing the BCP and enhancing preparedness, the absence of updates to the plan represents a fundamental weakness that could undermine its overall effectiveness. Therefore, the finding that the plan has not been updated in several years should be of greater concern during an IS audit or review of a business continuity plan.
upvoted 3 times
...
KAP2HURUF
8 months, 2 weeks ago
Selected Answer: C
Tabletop exercises are critical components of business continuity planning as they simulate various disaster scenarios and test the effectiveness of the BCP in response to those scenarios. Conducting tabletop exercises helps identify weaknesses, gaps, and areas for improvement in the plan, as well as assess the organization's readiness to respond to different types of disruptions. The absence of tabletop exercises suggests that the organization has not tested its BCP in a real-world scenario, leaving it unvalidated and potentially ineffective during an actual disaster or crisis situation. Therefore, this finding should be of the MOST concern to an IS auditor, as it indicates a significant deficiency in the organization's preparedness for business continuity.
upvoted 1 times
...
ItsBananass
1 year, 4 months ago
If the plan is not approved by Mang.do you have a BCP?
upvoted 2 times
...
Mark_1
1 year, 5 months ago
Selected Answer: C
In this scenario there's an existing BCP. That rules out option B, as no such plan would existing without being approved in the first place Option A could be fixed by ensuting that the plan is updated each time a change to operations is implemented such as addressing any new risks or cyber threats etc. Option D can't be considered because only the members of the Business Continuity Management team are privy to the plan (including making sure that the BCP plans align with the company's objectives etc) The option that should be of most concern to the Auditor is Option C. An untested plan is just as bad as having no plan at all. Without testing, there's no guarantee that this approach would enable the company to recover from a disaster
upvoted 4 times
...
MohamedAbdelaal
1 year, 7 months ago
Selected Answer: D
Why Not D
upvoted 1 times
...
David_Hu
1 year, 10 months ago
Selected Answer: B
should be B
upvoted 2 times
...
gomboragchaa
1 year, 11 months ago
Selected Answer: C
I think correct answer is C
upvoted 4 times
...
MunaM
2 years, 2 months ago
Do you think answer is B?
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...