1. Which of the following activities is MOST important in determining whether a test of a disaster recovery plan has been successful?
A) Evaluating participation by key personnel B) Testing at the backup data center C) Analyzing whether predetermined test objectives were met D) Testing with offsite backup files
2. Which of the following should be the FIRST step when conducting an IT risk assessment?
A) Assess vulnerabilities B) Identify assets to be protected C) Evaluate controls in place D) Identify potential threats
3. To develop a robust data security program, the FIRST course of action should be to:
A) implement monitoring controls B) implement data loss prevention controls C) perform an inventory of assets D) interview IT senior management
4. An IS auditor has been asked to participate in the creation of an organization's formal business continuity program. Which of the following would impair auditor independence?
A) Developing disaster recovery test scenarios B) Determining system criticality C) Facilitating the business impact analysis (BIA) D) Participating on the business continuity committee
5. When is the BEST time to commence continuity planning for a new application system?
A) Immediately after implementation B) Just prior to the handover to the system maintenance group C) During the design phase D) Following successful user testing
Leave a comment