Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 727 discussion

Actual exam question from Isaca's CISA
Question #: 727
Topic #: 1
[All CISA Questions]

Which of the following should be of GREATEST concern for an IS auditor reviewing an organization's disaster recovery plan (DRP)?

  • A. The DRP has not been updated since an IT infrastructure upgrade.
  • B. The DRP has not been distributed to end users.
  • C. The DRP has not been formally approved by senior management.
  • D. The DRP contains recovery procedures for critical servers only.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
macksonj
1 month ago
Selected Answer: C
A DRP must be approved by senior management to remain valid. A major concern could be a DRP without necessary approval from management even though its well updated , Approval from designated authorities attests to the validity of the documents and its alignment to the organization objectives, policies and procedures.
upvoted 1 times
...
KAP2HURUF
4 months, 1 week ago
Selected Answer: A
The DRP has not been formally approved by senior management - Formal approval is important for ensuring that the DRP is supported at the highest levels of the organization. However, the lack of approval does not necessarily mean the plan is ineffective, whereas an outdated plan is inherently flawed.
upvoted 3 times
...
Swallows
5 months, 3 weeks ago
Selected Answer: A
While formal approval by senior management (option C) is also important for ensuring organizational support and commitment to the DRP, an outdated plan poses a more immediate risk as it may not accurately reflect the organization's current capabilities and requirements for disaster recovery. Therefore, ensuring that the DRP is updated following infrastructure changes should be of the greatest concern for an IS auditor.
upvoted 3 times
Swallows
4 months, 1 week ago
While the formal approval of the DRP by senior management (option C) is important for governance and accountability, an outdated DRP poses a more immediate risk to the organization's ability to recover effectively from disasters. Senior management approval ensures commitment and support for the DRP, but an outdated plan undermines its operational effectiveness and reliability. Therefore, ensuring that the DRP has been updated since an IT infrastructure upgrade should be of the GREATEST concern for an IS auditor reviewing an organization's disaster recovery plan.
upvoted 2 times
...
...
001Yogesh
10 months, 3 weeks ago
Selected Answer: C
I think, if DRP is not approved then it is not enforceable. So, testing does not matter which is not enforceable.
upvoted 1 times
...
JONESKA
1 year, 4 months ago
I think its D. the GREATEST concern for an IS auditor reviewing an organization's disaster recovery plan is the absence of recovery procedures for critical systems other than just the critical servers. A comprehensive DRP should cover all critical systems and data to ensure effective business continuity and disaster recovery capabilities.
upvoted 3 times
ChaBum
8 months, 1 week ago
D means the DRP was never adapted and has gap in the scope. A means DRP lost relevance over time, because the scope have not been adapted. so D is worst, because it never worked, A worked, but not anymore
upvoted 1 times
...
SuperMax
1 year, 1 month ago
A DRP should cover not only critical servers but also critical business processes, applications, and data. Focusing only on critical servers may leave other important components of the organization vulnerable during a disaster. The adequacy of recovery procedures for critical business functions is crucial for business continuity.
upvoted 1 times
...
...
Pakawat
1 year, 6 months ago
Selected Answer: A
A: It raises concern if plan is outdated.
upvoted 3 times
...
Jag127
1 year, 9 months ago
Selected Answer: C
It should be C as the DRP must be approved by senior management before it can be used to guide during a disaster.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...