CISA · Question #355
An organization has moved all of its infrastructure to the cloud. Which of the following would be an IS auditor's GREATEST concern related to the organization's ability to continue operations in case
The correct answer is C. The step-by-step recovery process was not updated in the disaster recovery plan (DRP) after the. Option C is correct because a Disaster Recovery Plan is only useful if its recovery procedures reflect the current environment - after migrating to the cloud, the step-by-step processes (IP addresses, instance IDs, cloud-specific recovery commands, vendor contacts, etc.) will dif
Question
An organization has moved all of its infrastructure to the cloud. Which of the following would be an IS auditor’s GREATEST concern related to the organization’s ability to continue operations in case of a disaster?
Options
- AThere is no evidence that disaster recovery plan (DRP) testing was performed after the migration
- BOnly business-critical servers were configured with redundancy services on the cloud service
- CThe step-by-step recovery process was not updated in the disaster recovery plan (DRP) after the
- DThe previous infrastructure was not retained to support business operations in case of a disaster
How the community answered
(41 responses)- A12% (5)
- B5% (2)
- C63% (26)
- D20% (8)
Explanation
Option C is correct because a Disaster Recovery Plan is only useful if its recovery procedures reflect the current environment - after migrating to the cloud, the step-by-step processes (IP addresses, instance IDs, cloud-specific recovery commands, vendor contacts, etc.) will differ fundamentally from on-premises procedures, making an outdated DRP essentially useless during an actual disaster.
Why the distractors are wrong:
- A (no DRP testing evidence) is a serious concern, but a plan that was never tested can still be executed as written - an outdated plan actively misleads responders with wrong instructions, making it more dangerous than an untested but accurate one.
- B (only critical servers have redundancy) is an acceptable and common risk-based decision; prioritizing redundancy for business-critical systems is standard practice and represents a deliberate, defensible trade-off.
- D (old infrastructure not retained) is not a concern - keeping legacy on-premises infrastructure alongside a full cloud migration is costly and unnecessary; cloud environments are designed to be self-sufficient.
Memory tip: Think of a DRP like a GPS - it doesn't matter how often you've practiced the old route (testing) or how good your car is (redundancy); if the map still shows the old roads after construction changed everything, you'll drive into a dead end. After any major infrastructure change, the map (DRP documentation) must be updated first.
Topics
Community Discussion
No community discussion yet for this question.