Skillset can help you prepare! Sign up for your free Skillset account and take the first steps towards your certification.
In the course of an assessment of the disaster recovery plan for an international organization, it is discovered that some remote offices have a limited number of local IT resources. Which observation is the most critical to the IT auditor?
testing has not been performed to ensure that tape backups from the remote offices are usable.
A test has not been made to ensure that remote resources could maintain security and quality standards when recovering from a disaster or incident.
The corporate business continuity plan (BCP) does not accurately capture the systems that exist at remote offices.
The test plan fails to verify the corporate security measures.
Regardless of the capability of local IT resources, the most critical risk would be the lack of testing, which would identify quality issues in the recovery process. The other choices could affect the reliability of the plan in terms of assessing ability to recover and run in the event of an emergency, but the more critical issue would be whether the plan had not been tested at remote offices. EDIT: Why should I not assume the testing was complete at the remote offices and that was what uncovered the lack of IT resources? Question never explains that the testing was unfulfilled, just that it was noted that IT was understaffed. if the corporate business continuity plan (BCP) does not accurately capture the systems that exist at remote offices, then how can anything be considered reliable. Horrible question that does not help with preparing for the exam.
Train with Skillset and pass your certification exam. Faster. Guaranteed.
Study thousands of practice questions that organized by skills and ranked by difficulty.
Create a tailored training plan based on the knowledge you already possess.
Know when you’re ready for the high-stakes exam. Have the confidence that you will pass on your first attempt.