Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 577 discussion

Actual exam question from Isaca's CISA
Question #: 577
Topic #: 1
[All CISA Questions]

An IS auditor is reviewing an organization's business continuity plan (BCP) following a change in organizational structure with significant impact to business processes. Which of the following findings should be the auditor's GREATEST concern?

  • A. Copies of the BCP have not been distributed to new business unit end users since the reorganization
  • B. The most recent business impact analysis (BIA) was performed two years before the reorganization
  • C. A test plan for the BCP has not been completed during the last two years
  • D. Key business process end users did not participate in the business impact analysis (BIA)
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
PurpleParrot
3 months, 2 weeks ago
Selected Answer: B
The greatest risk is ensuring the BIA reflects the current organizational structure and processes. The lack of end-user participation can be addressed through a revised BIA.
upvoted 1 times
...
RS66
4 months, 1 week ago
Selected Answer: B
B is correct
upvoted 2 times
...
Infysenthil
4 months, 2 weeks ago
I choose D. Option B - BCP still be relevant to some extent, Option D - makes the BCP not relevant, adequate and complete which is a greatest risk. Option C - BCP plan may be adequate to some extent.
upvoted 1 times
...
Swallows
6 months ago
Selected Answer: A
During a change in organizational structure with significant impacts on business processes, it's essential to ensure that all relevant personnel have access to the updated BCP. Failure to distribute the plan to new business unit end users could result in a lack of awareness of their roles and responsibilities during disruptions, potentially leading to confusion and inefficiencies during recovery efforts.
upvoted 1 times
...
takuanism
10 months, 1 week ago
I chose B
upvoted 1 times
...
[Removed]
11 months, 2 weeks ago
Selected Answer: C
BCP testing would determine if the current BCP is still relevant, if not then update should be performed on the BCP which will then involve additional BIA within the process
upvoted 1 times
[Removed]
11 months, 2 weeks ago
Ignore above, it says test plan, not actual testing. So the correct answer is B. BIA should be performed after significant change in business process as a result of reorganization to help determine if current critical business processes.
upvoted 1 times
...
...
shiowbah
1 year ago
D. Key business process end users did not participate in the business impact analysis (BIA)
upvoted 1 times
shiowbah
1 year ago
B. The most recent business impact analysis (BIA) was performed two years before the reorganization
upvoted 1 times
...
...
Alizade
1 year, 6 months ago
Selected Answer: B
B. The most recent business impact analysis (BIA) was performed two years before the reorganization.
upvoted 3 times
...
ziutek_
1 year, 11 months ago
I would go with B
upvoted 1 times
...
Deeplaxmi
2 years, 2 months ago
BCP should be reevaluated where significant impact is found (Since significant imapct is found on critical business process, we assume BIA has been done). If test plans are older (before reorg) that means that no testing has been done even after the reorg.. So c could be right
upvoted 4 times
...
MunaM
2 years, 2 months ago
Answer could be A
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...