Inspirational journeys

Follow the stories of academics and their research expeditions

CISA—Certified Information Systems Auditor - Part 150

Mary Smith

Sat, 14 Jun 2025

CISA—Certified Information Systems Auditor - Part 150

1. Which type of major BCP test only requires representatives from each operational area to meet to review the plan?

A) Parallel
B) Preparedness
C) Walk-thorough
D) Paper



2. What influences decisions regarding criticality of assets?

A) The business criticality of the data to be protected
B) Internal corporate politics
C) The business criticality of the data to be protected, and the scope of the impact upon the organization as a whole
D) The business impact analysis



3. Of the three major types of off-site processing facilities, what type is characterized by at least providing for electricity and HVAC?

A) Cold site
B) Alternate site
C) Hot site
D) Warm site



4. With the objective of mitigating the risk and impact of a major business interruption, a disaster recovery plan should endeavor to reduce the length of recovery time necessary, as well as costs associated with recovery. Although DRP results in an increase of pre-and post-incident operational costs, the extra costs are more than offset by reduced recovery and business impact costs. True or false?

A) True
B) False
C)
D)



5. Of the three major types of off-site processing facilities, what type is often an acceptable solution for preparing for recovery of noncritical systems and data?

A) Cold site
B) Hot site
C) Alternate site
D) Warm site



1. Right Answer: C
Explanation: Of the three major types of BCP tests (paper, walk-through, and preparedness), a walk-through test requires only that representatives from each operational area meet to review the plan.

2. Right Answer: C
Explanation: Criticality of assets is often influenced by the business criticality of the data to be protected and by the scope of the impact upon the organization as a whole. For example, the loss of a network backbone creates a much greater impact on the organization as a whole than the loss of data on a typical user's workstation.

3. Right Answer: A
Explanation: Of the three major types of off-site processing facilities (hot, warm, and cold), a cold site is characterized by at least providing for electricity and HVAC. A warm site improves upon this by providing for redundant equipment and software that can be made operational within a short time.

4. Right Answer: A
Explanation: With the objective of mitigating the risk and impact of a major business interruption, a disaster- recovery plan should endeavor to reduce the length of recovery time necessary and the costs associated with recovery. Although DRP results in an increase of pre-and post-incident operational costs, the extra costs are more than offset by reduced recovery and business impact costs.

5. Right Answer: A
Explanation: A cold site is often an acceptable solution for preparing for recovery of noncritical systems and data.

0 Comments

Leave a comment