Greatest Concern in Unsuccessful DR Test
Which of the following should be of GREATEST concern to an IS auditor reviewing a report of an unsuccessful disaster recovery test?
Community Votes
57% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the auditor's ability to distinguish between process improvement gaps (root cause analysis) and fundamental control failures (outdated procedures).
When reviewing an unsuccessful disaster recovery test, the greatest concern is whether the procedures were current, as outdated plans render the test invalid and the organization unprotected.
Candidates often choose A because they focus on continuous improvement, but failing to verify procedure currency before analyzing failure causes is a more critical audit finding.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
The correct answer is C. An IS auditor's primary objective is to ensure that the organization can recover from disruptions. If the disaster recovery (DR) procedures are not up to date, the test itself is based on flawed assumptions, meaning the results are invalid and the organization is likely unprepared for a real incident. This is a foundational control failure.Why the Other Options Are Wrong
Option A (lack of root cause analysis) is important for improving the DR program, but it is secondary to ensuring the plan itself is accurate. You cannot effectively analyze the root cause of a failure if the baseline procedures being tested are obsolete. Option B is less critical as steering committee discussion is a governance activity, not a technical control. Option D is irrelevant or even positive, as testing during non-peak hours minimizes business impact and is a best practice.Community Comment Notes
Comments [1] and [2] correctly identify that outdated procedures undermine the entire recovery effort, making them the priority. Comment [4] highlights the common dilemma between A and C, noting that without current procedures, any test validity is questionable. Comments [3], [5], and [6] incorrectly prioritize root cause analysis over the integrity of the plan itself, missing the fundamental audit principle that the plan must be valid before its performance can be critiqued.Official Reference
Exam Strategy
Always check the validity of the asset or plan being tested before evaluating its performance. In IT audit questions, 'up-to-date' or 'current' controls often take precedence over 'process improvements' like root cause analysis when the baseline is compromised.
Frequently Asked Questions
Why is root cause analysis not the greatest concern?
Root cause analysis improves future tests, but if procedures are outdated, the current test is invalid and the organization remains at risk.
Does testing during non-peak hours matter?
No, testing during non-peak hours is a best practice to minimize disruption and is not a concern regarding the test's success or failure.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →