CISA Exam Question 491
Which of the following is the PRIMARY advantage of a decentralized database architecture over a centralized architecture?
Correct Answer: A
The primary advantage of a decentralized database architecture over a centralized one is that it reduces the concentration of risk in a single location or single service point. Because data and processing are distributed, the effect of a single outage or denial of service event is generally reduced compared with a centralized architecture, where one core point of failure can disrupt the whole environment.
Option A is therefore the best answer. Decentralization improves resilience by avoiding total dependency on one central database or service node. In audit and risk terms, this lowers the impact of certain availability attacks or failures by distributing exposure.
Option B is incorrect because real-time synchronization over public networks is usually more difficult, not easier, in decentralized environments. Distributed synchronization introduces latency, consistency, and network management challenges.
Option C is incorrect because transaction consistency is generally harder to maintain in decentralized systems.
Distributed databases often trade some degree of simplicity or immediacy of consistency for resilience, scalability, or local autonomy.
Option D is incorrect because uniform security policy enforcement is usually easier in centralized architectures, where governance and administration can be applied from a single control point.
So the correct answer is A, because the main architectural benefit of decentralization in this context is reduced single-point failure risk and reduced impact from centralized service disruption.
References (Official ISACA):
* ISACA Glossary - control and architecture terminology reference.
* ISACA COBIT resources - governance and resilience principles support reducing concentration risk through architectural design choices.
Option A is therefore the best answer. Decentralization improves resilience by avoiding total dependency on one central database or service node. In audit and risk terms, this lowers the impact of certain availability attacks or failures by distributing exposure.
Option B is incorrect because real-time synchronization over public networks is usually more difficult, not easier, in decentralized environments. Distributed synchronization introduces latency, consistency, and network management challenges.
Option C is incorrect because transaction consistency is generally harder to maintain in decentralized systems.
Distributed databases often trade some degree of simplicity or immediacy of consistency for resilience, scalability, or local autonomy.
Option D is incorrect because uniform security policy enforcement is usually easier in centralized architectures, where governance and administration can be applied from a single control point.
So the correct answer is A, because the main architectural benefit of decentralization in this context is reduced single-point failure risk and reduced impact from centralized service disruption.
References (Official ISACA):
* ISACA Glossary - control and architecture terminology reference.
* ISACA COBIT resources - governance and resilience principles support reducing concentration risk through architectural design choices.
CISA Exam Question 492
Which of the following would BEST demonstrate that an effective disaster recovery plan (DRP) is in place?
Correct Answer: D
A disaster recovery plan (DRP) is a set of procedures and resources that enable an organization to restore its critical operations, data, and applications in the event of a disaster1. A DRP should be aligned with the organization's business continuity plan (BCP), which defines the strategies and objectives for maintaining business functions during and after a disaster1.
To ensure that a DRP is effective, it should betested regularly and thoroughly to identify and resolve any issues or gaps that might hinder itsexecution2345. Testing a DRP can help evaluate its feasibility, validity, reliability, and compatibility with the organization's environment and needs4. Testing can also help prepare the staff, stakeholders, and vendors involved in the DRP for their roles and responsibilities during a disaster3.
There are different methods and levels of testing a DRP, depending on the scope, complexity, and objectives of the test4. Some of the common testing methods are:
* Walkthrough testing: This is a step-by-step review of the DRP by the disaster recovery team and relevant stakeholders. It aims to verify the completeness and accuracy of the plan, as well as to clarify any doubts or questions among the participants45.
* Simulation testing: This is a mock exercise of the DRP in a simulated disaster scenario. It aims to assess the readiness and effectiveness of the plan, as well as to identify any challenges or weaknesses that might arise during a real disaster45.
* Checklist testing: This is a verification of the availability and functionality of the resources and equipment required for the DRP. It aims toensure that the backup systems, data, anddocumentation are accessible and up-to-date45.
* Full interruption testing: This is the most realistic and rigorous method of testing a DRP. It involves shutting down the primary site and activating the backup site for a certain period of time. It aims to measure the actual impact andperformance of the DRP under real conditions45.
* Parallel testing: This is a less disruptive method of testing a DRP. It involves running the backup site in parallel with the primary site without affecting the normal operations. It aims to compare and validate the results and outputs of both sites45.
Amongthese methods, full interruption testing would best demonstrate that an effectiveDRP is in place, as it provides the most accurate and comprehensive evaluation ofthe plan's capabilities and limitations4. Full interruption testing can reveal any hidden or unforeseen issues or risks that might affect the recovery process, such as data loss, system failure, compatibility problems, or human errors4. Full interruption testing can also verify that the backup site can support the critical operations and services ofthe organization without compromising its quality or security4.
However, full interruption testing also has some drawbacks, such as being costly, time-consuming, risky, and disruptive to the normaloperations4. Therefore, it should be planned carefullyand conducted periodically with proper coordination and communication among all parties involved4.
The other options are not as effective as full interruption testing in demonstrating that an effective DRP is in place. Frequent testing of backups is only one aspect of checklist testing, which does not cover other components or scenarios of the DRP4. Annual walk-through testing is only atheoretical review of the DRP, which does not test its practical implementation or outcomes4. Periodic risk assessment is only a preparatory step for developing or updating the DRP, which does not test its functionality or performance4.
References: 2: Best Practices For Disaster Recovery Testing | Snyk 3: Disaster Recovery Plan (DR) Testing
- Methods and Must-haves -US Signal 4: Disaster Recovery Testing: What You Need toKnow - Enterprise Storage Forum 5: Disaster Recovery Testing Best Practices - MSP360 1: How to Test a Disaster Recovery Plan - Abacus
To ensure that a DRP is effective, it should betested regularly and thoroughly to identify and resolve any issues or gaps that might hinder itsexecution2345. Testing a DRP can help evaluate its feasibility, validity, reliability, and compatibility with the organization's environment and needs4. Testing can also help prepare the staff, stakeholders, and vendors involved in the DRP for their roles and responsibilities during a disaster3.
There are different methods and levels of testing a DRP, depending on the scope, complexity, and objectives of the test4. Some of the common testing methods are:
* Walkthrough testing: This is a step-by-step review of the DRP by the disaster recovery team and relevant stakeholders. It aims to verify the completeness and accuracy of the plan, as well as to clarify any doubts or questions among the participants45.
* Simulation testing: This is a mock exercise of the DRP in a simulated disaster scenario. It aims to assess the readiness and effectiveness of the plan, as well as to identify any challenges or weaknesses that might arise during a real disaster45.
* Checklist testing: This is a verification of the availability and functionality of the resources and equipment required for the DRP. It aims toensure that the backup systems, data, anddocumentation are accessible and up-to-date45.
* Full interruption testing: This is the most realistic and rigorous method of testing a DRP. It involves shutting down the primary site and activating the backup site for a certain period of time. It aims to measure the actual impact andperformance of the DRP under real conditions45.
* Parallel testing: This is a less disruptive method of testing a DRP. It involves running the backup site in parallel with the primary site without affecting the normal operations. It aims to compare and validate the results and outputs of both sites45.
Amongthese methods, full interruption testing would best demonstrate that an effectiveDRP is in place, as it provides the most accurate and comprehensive evaluation ofthe plan's capabilities and limitations4. Full interruption testing can reveal any hidden or unforeseen issues or risks that might affect the recovery process, such as data loss, system failure, compatibility problems, or human errors4. Full interruption testing can also verify that the backup site can support the critical operations and services ofthe organization without compromising its quality or security4.
However, full interruption testing also has some drawbacks, such as being costly, time-consuming, risky, and disruptive to the normaloperations4. Therefore, it should be planned carefullyand conducted periodically with proper coordination and communication among all parties involved4.
The other options are not as effective as full interruption testing in demonstrating that an effective DRP is in place. Frequent testing of backups is only one aspect of checklist testing, which does not cover other components or scenarios of the DRP4. Annual walk-through testing is only atheoretical review of the DRP, which does not test its practical implementation or outcomes4. Periodic risk assessment is only a preparatory step for developing or updating the DRP, which does not test its functionality or performance4.
References: 2: Best Practices For Disaster Recovery Testing | Snyk 3: Disaster Recovery Plan (DR) Testing
- Methods and Must-haves -US Signal 4: Disaster Recovery Testing: What You Need toKnow - Enterprise Storage Forum 5: Disaster Recovery Testing Best Practices - MSP360 1: How to Test a Disaster Recovery Plan - Abacus
CISA Exam Question 493
An IS auditor is evaluating the progress of a web-based customer service application development project.
Which of the following would be MOST helpful for this evaluation?
Which of the following would be MOST helpful for this evaluation?
Correct Answer: A
A backlog consumption report is a report that shows the amount of work that has been completed and the amount of work that remains to be done in a project. It is a useful tool for measuring the progress and performance of a web-based customer service application development project, as it can indicate whether the project is on track, ahead or behind schedule, and how much effort is required to finish the project. A backlog consumption report can also help identify any issues or risks that may affect the project delivery. Critical path analysis reports, developer status reports and change management logs are also helpful for evaluating a project, but they are not as helpful as a backlog consumption report, as they do not provide a clear picture of the overall project status and completion rate. References:
* : [Backlog Consumption Report Definition]
* : Backlog Consumption Report | ISACA
* : [Backlog Consumption Report Definition]
* : Backlog Consumption Report | ISACA
CISA Exam Question 494
During which process is regression testing MOST commonly used?
Correct Answer: A
CISA Exam Question 495
Which of the following should an organization do FIRST when an employee is terminated for fraudulent activity?
Correct Answer: C
When an employee is terminated for fraudulent activity, the first priority is to immediately prevent further unauthorized or malicious activity. In ISACA guidance, terminated employees' access rights should be removed promptly and effective controls must ensure they lose system access at termination. This makes disabling logical access the most immediate and appropriate first step.
Option C is correct because logical access allows the former employee to continue using systems, data, email, applications, or remote connections. If access is not disabled immediately, the organization remains exposed to sabotage, data theft, fraud continuation, or destruction of evidence. ISACA sources explicitly state that terminated employees should lose all access rights and that access restriction should occur immediately after departure.
Option A may be necessary as part of a fraud investigation, but it is not the first step. Reviewing approved transactions is investigative and retrospective; the organization must first contain the risk by cutting off access. In CISA exam logic, immediate risk containment generally comes before investigation.
Option B may also be appropriate from a physical security and HR perspective, especially if there is concern about confrontation or physical removal. However, from an IT audit and information security perspective, the most urgent action is disabling logical access because damage can occur remotely and instantly if access remains active.
Option D can be relevant for preserving evidence, but it still does not come before access removal. Evidence preservation is important, yet the first control priority is to stop ongoing access and prevent further compromise.
Therefore, the best answer is C because immediate revocation of system access is the first and most critical action when terminating an employee for fraudulent activity.
References (Official ISACA):
ISACA Journal, Mitigating IT Risks for Logical Access - effective controls should ensure terminated employees lose all access rights.
ISACA, Secure Management of Former Employee Data: A Practical Approach - "Immediate Access Restriction" as step 1 after employee departure.
ISACA Journal, What Every CISO Must Know About SSH Keys - access should be terminated when no longer needed.
Option C is correct because logical access allows the former employee to continue using systems, data, email, applications, or remote connections. If access is not disabled immediately, the organization remains exposed to sabotage, data theft, fraud continuation, or destruction of evidence. ISACA sources explicitly state that terminated employees should lose all access rights and that access restriction should occur immediately after departure.
Option A may be necessary as part of a fraud investigation, but it is not the first step. Reviewing approved transactions is investigative and retrospective; the organization must first contain the risk by cutting off access. In CISA exam logic, immediate risk containment generally comes before investigation.
Option B may also be appropriate from a physical security and HR perspective, especially if there is concern about confrontation or physical removal. However, from an IT audit and information security perspective, the most urgent action is disabling logical access because damage can occur remotely and instantly if access remains active.
Option D can be relevant for preserving evidence, but it still does not come before access removal. Evidence preservation is important, yet the first control priority is to stop ongoing access and prevent further compromise.
Therefore, the best answer is C because immediate revocation of system access is the first and most critical action when terminating an employee for fraudulent activity.
References (Official ISACA):
ISACA Journal, Mitigating IT Risks for Logical Access - effective controls should ensure terminated employees lose all access rights.
ISACA, Secure Management of Former Employee Data: A Practical Approach - "Immediate Access Restriction" as step 1 after employee departure.
ISACA Journal, What Every CISO Must Know About SSH Keys - access should be terminated when no longer needed.
- Other Version
- 4787ISACA.CISA.v2025-12-09.q630
- 4911ISACA.CISA.v2025-12-02.q704
- 19447ISACA.CISA.v2025-06-20.q647
- 7826ISACA.CISA.v2025-06-11.q606
- 4884ISACA.CISA.v2023-03-04.q272
- 3775ISACA.CISA.v2022-10-31.q203
- 3580ISACA.CISA.v2022-03-29.q126
- 123ISACA.Examprepaway.CISA.v2022-02-10.by.barret.126q.pdf
- 11227ISACA.CISA.v2021-11-29.q567
- 36ISACA.Actualvce.CISA.v2021-08-31.by.ralap.101q.pdf
- Latest Upload
- 270ServiceNow.CAD.v2026-09-26.q145
- 234GED.GED-Mathematical-Reasoning.v2026-09-26.q133
- 161GAQM.Databricks-Certified-Data-Engineer-Associate.v2026-09-26.q79
- 230CyberAB.CMMC-CCP.v2026-09-26.q110
- 196Salesforce.AP-223.v2026-09-26.q69
- 793ISACA.CISA.v2026-09-25.q633
- 186VMware.250-605.v2026-09-25.q75
- 213Microsoft.AZ-305.v2026-09-25.q198
- 504IIA.IIA-CIA-Part1.v2026-09-25.q362
- 197Huawei.H19-308_V4.0.v2026-09-24.q46
[×]
Download PDF File
Enter your email address to download ISACA.CISA.v2026-09-25.q633 Practice Test
