Information Systems Operations and Business Resilience
Free Certified Information Systems Auditor practice — 6 questions on Information Systems Operations and Business Resilience, with explanations. No sign-up.
Full 12-question mixed test →
Question 1 of 6 · Domain 4: Information Systems Operations and Business Resilience
A database uses a full backup at midnight and transaction log backups every four hours (04:00, 08:00, 12:00, 16:00). A hardware failure occurs at 14:30. The 12:00 log backup completed successfully, but the 16:00 backup had not yet run. What is the maximum data loss exposure the auditor should report for this incident?
The actual data loss exposure is measured from the last successfully completed backup to the point of failure, which is 12:00 to 14:30 (2.5 hours). RPO is achieved only when a backup actually completes; the scheduled interval is not the same as the realized recovery point.
Question 2 of 6 · Domain 4: Information Systems Operations and Business Resilience
During a business continuity audit, the auditor learns that a company has a reciprocal processing agreement with another firm located in the same industrial park. Which risk is MOST significant for the auditor to highlight?
Because both organizations share the same geographic location, a regional disaster (flood, power grid failure, earthquake) is likely to impact both simultaneously, defeating the purpose of the arrangement precisely when it is needed most. This geographic-correlation risk is the most significant concern given the scenario detail.
Question 3 of 6 · Domain 4: Information Systems Operations and Business Resilience
A financial trading firm requires near-zero recovery time (seconds) and cannot tolerate any processing interruption, even during a site-wide outage. Which alternate processing strategy BEST meets this requirement?
A hot site with synchronous, real-time replication and fully mirrored infrastructure is the only option capable of supporting an RTO measured in seconds, since it maintains an active, continuously synchronized standby environment ready for immediate failover.
Question 4 of 6 · Domain 4: Information Systems Operations and Business Resilience
An IS auditor reviewing backup media rotation finds that the organization retains daily (son) tapes for seven days and overwrites weekly (father) tapes every four weeks, but never retains a monthly (grandfather) tape beyond the most recent cycle. Which of the following is the GREATEST concern the auditor should report?
In a standard Grandfather-Father-Son (GFS) scheme, grandfather (monthly) tapes are meant to be retained for extended periods (often a year or more) to support long-term recovery and regulatory/legal retention needs. Failing to keep any monthly tape beyond the current cycle eliminates the organization's ability to restore data from more than one month prior, which is the most significant control gap.
Question 5 of 6 · Domain 4: Information Systems Operations and Business Resilience
Which statement BEST distinguishes problem management from incident management within IT service operations?
Incident management is reactive and focused on rapid restoration of service to minimize business impact. Problem management is proactive/analytical, investigating underlying root causes of one or more incidents to prevent recurrence — a distinction ISACA expects auditors to evaluate when assessing operational maturity.
Question 6 of 6 · Domain 4: Information Systems Operations and Business Resilience
An IS auditor reviewing operations monitoring reports notes that average server CPU utilization during peak business hours has increased steadily from 60% to 92% over the past 12 months, with no corresponding capacity expansion plan on file. What is the MOST significant risk the auditor should report?
Sustained upward utilization trends approaching saturation without a documented capacity plan indicate that management is not proactively managing infrastructure capacity, which creates a real risk of performance degradation or outages as demand continues to grow — a core operations control the auditor must evaluate.
Ready for the real thing?
The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.