An auditor reviewing backup controls finds that full backups are performed weekly but no incremental or differential backups are performed between full backups. The primary risk of this configuration is:
Opening subject page...
Loading your content
CPA Isc Quiz
Practice Evaluate Backup And Recovery Controls in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.
Question 1 / 20
0 of 20 answered
An auditor reviewing backup controls finds that full backups are performed weekly but no incremental or differential backups are performed between full backups. The primary risk of this configuration is:
This quiz focuses on Evaluate Backup And Recovery Controls, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.
An auditor reviewing backup controls finds that full backups are performed weekly but no incremental or differential backups are performed between full backups. The primary risk of this configuration is:
Explanation: Without daily incrementals or differentials, any failure between Sunday and the following Saturday could result in up to six days of lost data - a potentially unacceptable RPO for most organizations. Answer D is correct. Storage consumption (A) and restore time (C) are operational concerns. Software compatibility (B) is unrelated.
During a backup controls review, an auditor discovers that the organization performs nightly backup jobs but never monitors the job completion logs. Which control is missing?
Explanation: Unmonitored backup jobs may fail silently - backups that appear scheduled but actually fail create a false sense of security. Monitoring completion logs and escalating failures is an essential detective control. Answer C is correct. A daily backup policy likely exists (A). Encryption (B) addresses confidentiality. A BCP (D) is a separate planning document.
A financial services firm has an RPO of 15 minutes for its trading system. Which backup configuration would best meet this requirement?
Explanation: CDP replicates every write operation continuously, achieving near-zero RPO - appropriate for a 15-minute RPO requirement. Answer A is correct. Hourly incrementals (B) can lose up to 60 minutes of data. Daily differentials (C) could lose a full day. Weekly full backups (D) could lose a week.
Which of the following most directly evaluates whether recovery time objectives (RTOs) are achievable?
Explanation: Only a timed recovery test can confirm whether systems can actually be restored within the RTO - documentation and offsite storage confirm preparedness but do not prove execution capability. Answer D is correct. Plan review (A) and offsite storage (B) are preparedness checks. RPO alignment (C) addresses data loss, not downtime duration.
An organization's disaster recovery plan designates a warm site for system recovery. During an audit, the auditor finds the warm site has not been tested in three years and the hardware at the warm site is significantly outdated compared to production. The most significant risk is:
Explanation: Untested, outdated disaster recovery infrastructure is a critical risk - hardware incompatibilities and untested procedures can result in recovery failures or delays well beyond the RTO. Answer C is correct. Provider fees (A), employee awareness (B), and network speed (D) are minor concerns compared to the risk of recovery failure.
A company's backup policy states that all backups must be encrypted. An auditor tests this control by requesting evidence of encryption for a sample of backup files. The auditor finds that 30% of backup files are unencrypted. This finding should be classified as:
Explanation: A 30% failure rate in an encryption control means a significant portion of backup media is unencrypted - a material control deficiency exposing sensitive data if media is lost or stolen. Answer A is correct. A 30% deviation is not acceptable (B). Many regulations and policies do require backup encryption (C). The root cause may be a configuration issue, but the finding is a control deficiency (D).
A company implements immutable backups using object storage with write-once, read-many (WORM) technology. The primary control objective of immutable backups is:
Explanation: Immutable backups cannot be altered or deleted once written - even by administrators or ransomware - making them a critical control for ransomware resilience and insider threat protection. Answer B is correct. WORM is not primarily a performance technology (A). Immutability does not equal verification (C). Compression is a separate feature (D).
Which of the following is the most significant deficiency in an organization's backup controls if the organization processes financial transactions 24 hours a day, 7 days a week?
Explanation: A 24/7 transaction processor needs continuous or near-continuous backup protection. Weeknight-only backups leave significant gaps on weekends when transactions are still occurring. Answer A is correct. Interface usability (B), notification distribution (C), and storage capacity (D) are operational concerns that do not represent a significant control deficiency for 24/7 operations.
A company's recovery controls documentation specifies that the IT disaster recovery team should be notified of a disaster within 30 minutes and begin recovery activities within 1 hour. During a recovery test, the team is not notified for 2 hours. This finding indicates:
Explanation: A 2-hour notification delay - four times the planned 30-minute target - could push recovery well beyond the RTO. This is a process gap requiring remediation through better communication procedures, automated alerting, or escalation protocols. Answer B is correct. The plan timeframes should not be relaxed without business justification (A). A multi-hour delay is not acceptable (C). Training alone may not address systemic escalation failures (D).
An organization's backup policy requires that critical system backups be tested quarterly. An auditor finds that tests were performed in Q1 but not in Q2 or Q3. The most appropriate audit finding is:
Explanation: Missing two of four required quarterly test cycles means the organization went six months without verifying recovery capability - a material policy non-compliance and control deficiency. Answer D is correct. Policy requirements exist for good reason and should not be relaxed (A). A single passing test does not fulfill ongoing requirements (B). Six months of missed testing is not minor (C).
When reviewing a company's offsite backup storage arrangements, which of the following would be the most significant finding?
Explanation: An offsite facility in the same flood zone as the primary data center could be damaged by the same event, defeating the purpose of offsite storage. Geographic diversity is essential for disaster recovery. Answer C is correct. 25-mile distance (A) is generally acceptable. 24-hour retrieval (B) affects RTO but is manageable. Storage fees (D) are a business arrangement, not a control concern.
An auditor evaluating recovery controls at a cloud-hosted company should verify which of the following in addition to the company's own controls?
Explanation: A SOC 2 Type II report provides independent auditor assurance over the cloud provider's controls over a period of time, including backup and recovery. This is the most reliable third-party evidence of cloud provider control effectiveness. Answer D is correct. Employee counts and financials (A) and marketing materials (B) do not provide control assurance. ISP uptime (C) is unrelated to backup controls.
A company's IT department reports that all critical systems have backup coverage. An auditor compares the list of critical systems in the asset inventory to the list of systems covered by backup jobs and finds 12 critical systems are not backed up. This discrepancy indicates:
Explanation: A direct comparison of asset inventory to backup coverage is an effective audit procedure that reveals gaps. Finding 12 uncovered critical systems contradicts management's assertion and constitutes a significant finding. Answer C is correct. Asset inventories are more comprehensive and should be trusted over informal IT reporting (A). Without evidence, the auditor cannot assume they are non-production systems (B). Compatibility issues may explain the gap but do not change the finding (D).
Which of the following represents the most effective control to ensure that recovery time objectives are met during an actual disaster?
Explanation: Meeting RTOs in a real disaster requires a practiced team with current procedures and demonstrated capability through regular timed exercises - preparation that builds muscle memory and identifies gaps before they matter. Answer B is correct. Documentation alone (A) does not build capability. Insurance (C) covers costs but does not reduce downtime. Consultants on standby (D) introduce delays and lack organizational knowledge.
An auditor is asked to assess whether the organization's backup and recovery controls adequately protect financial reporting data. Which of the following procedures is most relevant to this objective?
Explanation: Protecting financial reporting data requires confirming: the right systems are backed up, backup frequency meets RPO requirements, and restorability has been tested. Answer A directly addresses all three. Capital budgets (B), financial statement testing (C), and prior-year letters (D) do not directly assess current backup control adequacy for financial data.
Which of the following backup control deficiencies poses the greatest risk to an organization's ability to recover from a cyberattack?
Explanation: Network-accessible backups using the same credentials as production are vulnerable to the same ransomware or cyberattack that compromises production - destroying both data and recovery capability. Answer B is correct. Log retention (A), backup timing (C), and report distribution (D) are minor operational issues that do not threaten recovery capability.
Which of the following recovery control test types provides evidence of recoverability with the least operational risk?
Explanation: Parallel testing validates recovery capability by running both environments and comparing results without risking production disruption - a good balance of assurance and operational safety. Answer A is correct. Full cutover (B) risks production disruption if recovery fails. No testing (C) provides no assurance. Destructive testing (D) is high-risk and rarely appropriate.
An auditor evaluating backup controls requests the backup job history for the past 90 days and finds that backup jobs failed on 15 of those days. The IT team has no documentation of these failures being investigated or remediated. This finding indicates:
Explanation: Uninvestigated backup failures mean the organization does not know what data is unprotected. Fifteen days of unexplained failures represents a serious gap in the backup control environment that requires immediate attention. Answer C is correct. Software upgrades (A) may be needed but are not the finding. A 17% failure rate with no remediation is not minor (B) or acceptable (D).
An organization retains backup data for 90 days as per policy. An auditor verifies that backups older than 90 days are automatically deleted. What additional verification should the auditor perform?
Explanation: The auditor must verify that the retention period complies with applicable regulations (SEC, IRS, HIPAA, SOX, etc.) since some financial and health data must be retained for years, not months. Answer C is correct. Vendor support (A) and industry norms (B) are less critical than regulatory compliance. Software flexibility (D) does not confirm current compliance.
When evaluating the adequacy of an organization's backup controls, which of the following is the most important consideration?
Explanation: A backup that has never been tested may be corrupted, incomplete, or technically unrestorable. Restoration testing is the only way to confirm that backups actually work when needed. Answer A is correct. Completion timing (B), vendor certification (C), and software version (D) are operational details that do not confirm recoverability.