Ensuring Data Recovery from Backup Media During Disasters | CISA

Business Continuity & Disaster Recovery
Answer Correct answer: C — Periodically restoring backup media for key databases verifies data integrity and proves recovery capability before a disaster strikes.

Which of the following controls is MOST crucial to ensure an organization will be able to recover its data from backup media in the event of a disaster?

  1. Keeping a current inventory of backup media
  2. Encrypting data on backup media
  3. Periodically restoring backup media for key databases Correct Answer
  4. Storing backup media at an offsite facility

Community Votes

D
67%
C
33%

67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether candidates recognize that verifying backup integrity through regular restore tests is the only control that truly ensures successful data recovery during a disaster.

This CISA question tests the critical difference between passive backup storage and active recovery validation. Community consensus and ISACA audit standards prioritize periodic restoration testing over offsite storage alone to guarantee data recoverability.

Candidates frequently select offsite storage (D) because the word 'disaster' implies geographic separation, but this overlooks that untested backups may be corrupted, outdated, or unreadable when needed.

Community Discussion (3 comments)

46080f2 👍 2 Selected: D
I vote for D. While restore tests (option C.) are a general requirement for a backup implementation, this is specifically about disaster case. From my understanding of the ISACA way of thinking, whenever an area is narrowed down in the question, an answer specific to that area is expected. In addition, ISACA also describes the following requirement summarized in the article "How to Develop and Execute a Rigorous Data Backup and Recovery Strategy" from 18.04.2022: The most crucial control to ensure an organization can recover its data from backup media in case of a disaster is to follow the 3-2-1 rule. This rule states that organizations should maintain at least 3 copies or versions of data stored on 2 different pieces of media, with 1 copy being offsite. This approach helps reduce the risk of data disruption and ensures that there are multiple backups available for recovery purposes.
KAP2HURUF 👍 2 Selected: C
However, while storing backup media offsite is crucial, it alone does not guarantee successful data recovery. Without periodically testing the restoration process (option C), there is a risk that the backup media stored offsite may be corrupted, outdated, or incomplete. Regular testing ensures that the backup media is viable and that the organization can recover its data effectively when needed. Therefore, while option D is an essential control, option C (periodically restoring backup media for key databases) is considered more crucial because it directly verifies the integrity and effectiveness of the backup and recovery process.
hermfrancis 👍 2 Selected: D
D , since for a disaster, onsite backup and restoration should not be done. Offsite is the key.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Periodic restoration testing is the only control that actively verifies backup media integrity, file system compatibility, and personnel readiness. Without regular validation, organizations operate on assumptions rather than proven recoverability. ISACA audit standards mandate that testing transforms theoretical backups into actionable disaster recovery capabilities.

Why the Other Options Are Wrong

Maintaining an inventory (A) is an administrative task that tracks assets but does not validate data usability. Encrypting backups (B) enhances security but can actually complicate recovery if key management fails. While offsite storage (D) protects against physical site destruction, it remains a passive measure that cannot guarantee media readability or successful restore execution.

Community Comment Notes

Several candidates selected offsite storage due to the disaster scenario, but comment 2 correctly identifies that geographic separation alone cannot verify data viability. Comment 1 and 3 misinterpret ISACA’s focus on audit assurance by prioritizing location over functional validation. The community split reflects a common trap where situational keywords override core control objectives.

Official Reference

Exam Strategy

When CISA questions pair 'backup' with 'ensure recovery,' always prioritize verification and testing controls over passive protection measures, even when disaster scenarios are mentioned. Audit frameworks demand proof of functionality, not just preparedness.

Frequently Asked Questions

Why isn't offsite storage (D) the best answer for disaster recovery?

Offsite storage protects against physical destruction but does not verify that backups are readable, complete, or compatible with current systems.

How often should backup restoration tests be performed per CISA standards?

At least annually for full restores, with quarterly or monthly partial tests recommended by ISACA to validate ongoing data integrity and procedures.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide