Ensuring Data Recovery from Backup Media During Disasters | CISA
Which of the following controls is MOST crucial to ensure an organization will be able to recover its data from backup media in the event of a disaster?
Community Votes
67% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether candidates recognize that verifying backup integrity through regular restore tests is the only control that truly ensures successful data recovery during a disaster.
This CISA question tests the critical difference between passive backup storage and active recovery validation. Community consensus and ISACA audit standards prioritize periodic restoration testing over offsite storage alone to guarantee data recoverability.
Candidates frequently select offsite storage (D) because the word 'disaster' implies geographic separation, but this overlooks that untested backups may be corrupted, outdated, or unreadable when needed.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Periodic restoration testing is the only control that actively verifies backup media integrity, file system compatibility, and personnel readiness. Without regular validation, organizations operate on assumptions rather than proven recoverability. ISACA audit standards mandate that testing transforms theoretical backups into actionable disaster recovery capabilities.Why the Other Options Are Wrong
Maintaining an inventory (A) is an administrative task that tracks assets but does not validate data usability. Encrypting backups (B) enhances security but can actually complicate recovery if key management fails. While offsite storage (D) protects against physical site destruction, it remains a passive measure that cannot guarantee media readability or successful restore execution.Community Comment Notes
Several candidates selected offsite storage due to the disaster scenario, but comment 2 correctly identifies that geographic separation alone cannot verify data viability. Comment 1 and 3 misinterpret ISACA’s focus on audit assurance by prioritizing location over functional validation. The community split reflects a common trap where situational keywords override core control objectives.Official Reference
Exam Strategy
When CISA questions pair 'backup' with 'ensure recovery,' always prioritize verification and testing controls over passive protection measures, even when disaster scenarios are mentioned. Audit frameworks demand proof of functionality, not just preparedness.
Frequently Asked Questions
Why isn't offsite storage (D) the best answer for disaster recovery?
Offsite storage protects against physical destruction but does not verify that backups are readable, complete, or compatible with current systems.
How often should backup restoration tests be performed per CISA standards?
At least annually for full restores, with quarterly or monthly partial tests recommended by ISACA to validate ongoing data integrity and procedures.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →