🇺🇸 Certified Information Systems Auditor (CISA) · flashcards

Certified Information Systems Auditor (CISA) Information Systems Operations and Business Resilience Flashcards

51 question-and-answer cards covering Information Systems Operations and Business Resilience as it is examined in Certified Information Systems Auditor (CISA). 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

51Cards in deck
24Free preview
22Syllabus topics
~240Chars per answer
FreePrice

24 sample cards from the Information Systems Operations and Business Resilience deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. What is a database view and how is it used as a control?

    A view is a logical, virtual table derived from one or more underlying tables. It is used as an access control to restrict users to specific rows/columns, hiding sensitive data and enforcing least-privilege data access.

  2. What are concurrency controls in a DBMS, and what problem do they prevent?

    Concurrency controls (e.g., locking) manage simultaneous access to data by multiple transactions. They prevent problems such as lost updates, dirty reads, and inconsistent data when two transactions update the same record at once.

  3. What are the ACID properties of a database transaction?

    Atomicity (all-or-nothing), Consistency (valid state to valid state), Isolation (concurrent transactions don't interfere), and Durability (committed changes persist even after failure).

  4. What is the role of a data owner versus a data custodian in data governance?

    The data owner (typically a business manager) is accountable for the data—deciding classification, access rights, and usage. The data custodian (typically IT) is responsible for the day-to-day technical safeguarding, storage, backup, and maintenance of the data.

  5. What is the purpose of data classification?

    To categorize data by sensitivity and criticality (e.g., public, internal, confidential, restricted) so that appropriate levels of protection, handling, and access controls are applied based on the value and risk of the data.

  6. Name the commonly cited dimensions of data quality.

    Accuracy, Completeness, Consistency, Timeliness, Validity, and Uniqueness (integrity). High-quality data must be correct, whole, non-contradictory, current, conformant to rules, and free of duplicates.

  7. What are the main phases of the data lifecycle?

    Create/Capture, Store, Use/Process, Share/Transmit, Archive, and Destroy/Dispose. Controls must be applied at each phase to protect data appropriately throughout its life.

  8. What is a data retention policy and what drives retention periods?

    A policy specifying how long different categories of data must be kept and when they are securely destroyed. Retention periods are driven by legal/regulatory requirements, business needs, and litigation/contractual obligations.

  9. What is the difference between a full, incremental, and differential backup?

    Full: copies all selected data. Incremental: copies only data changed since the last backup of any type (fast backup, slower restore, needs the chain). Differential: copies all data changed since the last full backup (larger backup, faster restore needing only full + last differential).

  10. What is the 3-2-1 backup rule?

    Keep at least 3 copies of data, on 2 different types of media, with 1 copy stored off-site. This protects against media failure, site disaster, and single-point-of-failure data loss.

  11. Why is periodic testing of backup restoration essential?

    Because a backup is only valuable if it can be successfully restored. Restore testing verifies media integrity, completeness, recoverability, and that recovery time objectives can actually be met—catching corrupt or unusable backups before a real incident.

  12. What is a Business Impact Analysis (BIA) and what is its primary output?

    A BIA identifies critical business processes and assesses the impact (financial, operational, reputational, legal) of their disruption over time. Its primary outputs are recovery priorities and the recovery time/point objectives (RTO/RPO) for each process.

  13. Define RTO (Recovery Time Objective).

    The maximum acceptable length of time a business process or system can be down after a disruption before causing unacceptable consequences. It drives the speed of recovery solutions required.

  14. Define RPO (Recovery Point Objective).

    The maximum acceptable amount of data loss measured in time—i.e., the point in time to which data must be recovered. It dictates the required frequency of backups or replication.

  15. How do RTO and RPO differ in what they measure?

    RTO measures acceptable downtime (how quickly you must recover); RPO measures acceptable data loss (how much data, in time, you can afford to lose). RTO is about time-to-restore service; RPO is about backup/replication frequency.

  16. What is MTD (Maximum Tolerable Downtime), and how does it relate to RTO?

    MTD (or MAO, Maximum Acceptable Outage) is the total time a process can be unavailable before the organization suffers irreparable harm. RTO must be less than MTD, because MTD also includes the time to restore and verify the recovered process.

  17. What is a Business Continuity Plan (BCP) and how does it relate to a DRP?

    A BCP is the overarching plan to keep critical business functions operating during and after a disruption. A Disaster Recovery Plan (DRP) is a subset focused specifically on recovering IT systems, infrastructure, and data that support those functions.

  18. List the typical steps in developing a BCP.

    1) Project initiation/policy, 2) Risk assessment, 3) Business Impact Analysis, 4) Recovery strategy selection, 5) Plan development/documentation, 6) Training and awareness, 7) Testing, and 8) Maintenance/continual update.

  19. Why must BCP/DRP plans be regularly maintained and updated?

    Because business processes, technology, personnel, and dependencies change over time. Outdated plans (wrong contacts, configurations, or priorities) fail during a real disaster, so plans must be reviewed and updated after changes and on a scheduled basis.

  20. What is the role of crisis management and a crisis communications plan during a disruption?

    Crisis management provides centralized command and decision-making to direct the overall response. The crisis communications plan ensures timely, accurate, consistent information reaches stakeholders—employees, customers, regulators, media—protecting safety, reputation, and coordination.

  21. Compare hot, warm, and cold alternate processing sites.

    Hot site: fully equipped and operational, fastest recovery (hours), highest cost. Warm site: partially equipped (hardware/connectivity but data/software must be loaded), moderate recovery time and cost. Cold site: only facilities/power/space, no equipment, longest recovery (days/weeks), lowest cost.

  22. What is a mirrored (redundant) site and a reciprocal agreement in DR planning?

    A mirrored site is a fully redundant, real-time duplicate of the primary site enabling near-zero downtime (highest cost). A reciprocal agreement is a mutual arrangement between two organizations to host each other's processing during a disaster—low cost but often impractical due to capacity and compatibility issues.

  23. Compare synchronous and asynchronous data replication.

    Synchronous: data is written to primary and remote sites simultaneously; confirmation waits for both, giving near-zero RPO but limited by distance/latency. Asynchronous: data is written to remote site after the primary, allowing greater distance and performance but with some potential data loss (higher RPO).

  24. List the four main types of DR/BCP plan tests in order of increasing rigor and explain the most thorough.

    Checklist (desk) review, Structured walk-through, Simulation, Parallel test, and Full interruption test. Full interruption is the most thorough and risky: actual operations are shut down and moved to the recovery site, fully validating the plan but risking real disruption.

What this deck covers

The Information Systems Operations and Business Resilience deck follows the Certified Information Systems Auditor (CISA) Information Systems Operations and Business Resilience syllabus — 5 chapters and 22 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 10.2 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 240 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Information Systems Operations and Business Resilience flashcards FAQ

How many Information Systems Operations and Business Resilience flashcards are in this Certified Information Systems Auditor (CISA) deck?

51 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these Certified Information Systems Auditor (CISA) flashcards free?

Yes. The preview here is free to read with no signup, and the full 51-card deck is free inside the Examius app.

What do the Information Systems Operations and Business Resilience cards cover?

They follow the Certified Information Systems Auditor (CISA) Information Systems Operations and Business Resilience syllabus — 5 chapters and 22 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.