nerdexam
Isaca

CRISC · Question #4

Which of the following issues found during the review of a newly created disaster recovery plan (DRP) should be of MOST concern?

The correct answer is A. Some critical business applications are not included in the plan. The most significant concern in a DRP review is the omission of critical business applications, as this directly impedes the organization's ability to restore essential operations after a disaster.

Submitted by khalil_dz· Apr 18, 2026Risk Response and Reporting

Question

Which of the following issues found during the review of a newly created disaster recovery plan (DRP) should be of MOST concern?

Options

  • ASome critical business applications are not included in the plan
  • BSeveral recovery activities will be outsourced
  • CThe plan is not based on an internationally recognized framework
  • DThe chief information security officer (CISO) has not approved the plan

How the community answered

(61 responses)
  • A
    77% (47)
  • B
    5% (3)
  • C
    3% (2)
  • D
    15% (9)

Why each option

The most significant concern in a DRP review is the omission of critical business applications, as this directly impedes the organization's ability to restore essential operations after a disaster.

ASome critical business applications are not included in the planCorrect

If critical business applications are excluded from the disaster recovery plan, the organization will be fundamentally unable to resume its essential functions post-disruption, rendering the DRP ineffective for core business continuity and leading to severe operational and financial consequences.

BSeveral recovery activities will be outsourced

Outsourcing recovery activities is a common and acceptable practice, provided that appropriate service level agreements (SLAs) and oversight are in place to ensure effectiveness.

CThe plan is not based on an internationally recognized framework

While adhering to an internationally recognized framework is beneficial for structuring and comprehensive coverage, a DRP can still be technically sound and effective if it addresses the organization's specific needs, even without strict framework adherence.

DThe chief information security officer (CISO) has not approved the plan

CISO approval is vital for governance and endorsement, but the absence of this approval does not inherently compromise the technical viability or the content of the recovery plan itself as much as missing critical components.

Concept tested: Disaster Recovery Plan (DRP) criticality

Source: https://learn.microsoft.com/en-us/azure/reliability/business-continuity-dr-guidance-recover-applications-data

Topics

#Disaster Recovery Planning (DRP)#Business Continuity#Criticality Analysis#Risk Response Effectiveness

Community Discussion

No community discussion yet for this question.

Full CRISC Practice