Greatest Concern in Unsuccessful DR Test

IT Audit Process
Answer Correct answer: C — The disaster recovery procedures are not up to date.

Which of the following should be of GREATEST concern to an IS auditor reviewing a report of an unsuccessful disaster recovery test?

  1. A root cause analysis was not performed.
  2. The report was not discussed with the IT steering committee.
  3. The disaster recovery procedures are not up to date. Correct Answer
  4. The disaster recovery test was conducted during non-peak hours.

Community Votes

C
57%
A
43%

57% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the auditor's ability to distinguish between process improvement gaps (root cause analysis) and fundamental control failures (outdated procedures).

When reviewing an unsuccessful disaster recovery test, the greatest concern is whether the procedures were current, as outdated plans render the test invalid and the organization unprotected.

Candidates often choose A because they focus on continuous improvement, but failing to verify procedure currency before analyzing failure causes is a more critical audit finding.

Community Discussion (6 comments)

PurpleParrot 👍 2 Selected: C
Understanding the cause is important for improvement, but outdated procedures can undermine the entire recovery process.
RS66 👍 2 Selected: C
C. The disaster recovery procedures are not up to date. Not A because the auditor is her to do the analysis so this not a concern.
1e71ed5 👍 1
But if procedures are outdated, the entire disaster recovery plan may be ineffective. This is a foundational issue, as current procedures are critical for a successful recovery and Without current procedures, any test (whether root cause analysis is performed or not) may not be valid. So, which one is the correct one - A or C?
Swallows 👍 2 Selected: A
The absence of a root cause analysis poses a greater risk as it may indicate systemic issues that need to be addressed to improve the effectiveness of the disaster recovery program. Therefore, option A is likely of greatest concern to an IS auditor reviewing a report of an unsuccessful disaster recovery test.
a84n 👍 1 Selected: A
Answer A while the lack of up-to-date disaster recovery procedures (option C) is a concern, addressing the root causes of the unsuccessful test (option A) takes precedence as the GREATEST concern for an IS auditor to ensure that future disaster recovery tests are successful and the organization's resilience to disruptions is strengthened.
MJORGER 👍 1
A. A root cause analysis was not performed. When a disaster recovery test fails, it's crucial to conduct a root cause analysis to understand why the test was unsuccessful.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct answer is C. An IS auditor's primary objective is to ensure that the organization can recover from disruptions. If the disaster recovery (DR) procedures are not up to date, the test itself is based on flawed assumptions, meaning the results are invalid and the organization is likely unprepared for a real incident. This is a foundational control failure.

Why the Other Options Are Wrong

Option A (lack of root cause analysis) is important for improving the DR program, but it is secondary to ensuring the plan itself is accurate. You cannot effectively analyze the root cause of a failure if the baseline procedures being tested are obsolete. Option B is less critical as steering committee discussion is a governance activity, not a technical control. Option D is irrelevant or even positive, as testing during non-peak hours minimizes business impact and is a best practice.

Community Comment Notes

Comments [1] and [2] correctly identify that outdated procedures undermine the entire recovery effort, making them the priority. Comment [4] highlights the common dilemma between A and C, noting that without current procedures, any test validity is questionable. Comments [3], [5], and [6] incorrectly prioritize root cause analysis over the integrity of the plan itself, missing the fundamental audit principle that the plan must be valid before its performance can be critiqued.

Official Reference

ISACA CISA Review Manual, Chapter 12: Business Continuity Planning

Exam Strategy

Always check the validity of the asset or plan being tested before evaluating its performance. In IT audit questions, 'up-to-date' or 'current' controls often take precedence over 'process improvements' like root cause analysis when the baseline is compromised.

Frequently Asked Questions

Why is root cause analysis not the greatest concern?

Root cause analysis improves future tests, but if procedures are outdated, the current test is invalid and the organization remains at risk.

Does testing during non-peak hours matter?

No, testing during non-peak hours is a best practice to minimize disruption and is not a concern regarding the test's success or failure.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide