Home

Tutoring

Subjects

Live Classes

Study Coach

Essay Review

On-Demand Courses

Colleges

Games


Sign up

Log in

Opening subject page...

Loading your content

Practice

  • All Subjects
  • Algebra Flashcards
  • SAT Math Practice Tests
  • Math Question of the Day
  • Live Classes
  • On-Demand Courses

Varsity Tutors

  • Find a Tutor
  • Test Prep
  • Online Classes
  • K-12 Learning
  • College Search
  • VarsityTutors.com

© 2026 Varsity Tutors. All rights reserved.

← Back to quizzes

CPA Isc Quiz

CPA Isc Quiz: Evaluate Backup And Recovery Controls

Practice Evaluate Backup And Recovery Controls in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.

Question 1 / 20

0 of 20 answered

An auditor reviewing backup controls finds that full backups are performed weekly but no incremental or differential backups are performed between full backups. The primary risk of this configuration is:

Select an answer to continue

What this quiz covers

This quiz focuses on Evaluate Backup And Recovery Controls, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.

How to use this quiz

Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.

All questions

Question 1

An auditor reviewing backup controls finds that full backups are performed weekly but no incremental or differential backups are performed between full backups. The primary risk of this configuration is:

  1. Full backups consume too much storage space compared to incrementals.
  2. The backup software may become incompatible with the operating system.
  3. Full backups take longer to restore than differential backups.
  4. A system failure between full backups could result in up to one week of data loss, potentially exceeding the organization's RPO. (correct answer)

Explanation: Without daily incrementals or differentials, any failure between Sunday and the following Saturday could result in up to six days of lost data - a potentially unacceptable RPO for most organizations. Answer D is correct. Storage consumption (A) and restore time (C) are operational concerns. Software compatibility (B) is unrelated.

Question 2

During a backup controls review, an auditor discovers that the organization performs nightly backup jobs but never monitors the job completion logs. Which control is missing?

  1. A policy requiring daily backups.
  2. Encryption of backup data before transmission.
  3. A monitoring control that reviews backup job results and escalates failures for prompt remediation. (correct answer)
  4. A business continuity plan addressing recovery procedures.

Explanation: Unmonitored backup jobs may fail silently - backups that appear scheduled but actually fail create a false sense of security. Monitoring completion logs and escalating failures is an essential detective control. Answer C is correct. A daily backup policy likely exists (A). Encryption (B) addresses confidentiality. A BCP (D) is a separate planning document.

Question 3

A financial services firm has an RPO of 15 minutes for its trading system. Which backup configuration would best meet this requirement?

  1. Continuous data protection (CDP) that captures every write operation to a secondary system in real time or near real time. (correct answer)
  2. Hourly incremental backups to a disk-based backup system.
  3. Daily differential backups to an offsite tape facility.
  4. Weekly full backups with a hot standby server.

Explanation: CDP replicates every write operation continuously, achieving near-zero RPO - appropriate for a 15-minute RPO requirement. Answer A is correct. Hourly incrementals (B) can lose up to 60 minutes of data. Daily differentials (C) could lose a full day. Weekly full backups (D) could lose a week.

Question 4

Which of the following most directly evaluates whether recovery time objectives (RTOs) are achievable?

  1. Reviewing the disaster recovery plan documentation for defined RTO targets.
  2. Confirming that backup media is stored at an offsite facility.
  3. Verifying that the backup schedule aligns with the stated RPO.
  4. Conducting a timed recovery exercise that measures how long it actually takes to restore systems from backup. (correct answer)

Explanation: Only a timed recovery test can confirm whether systems can actually be restored within the RTO - documentation and offsite storage confirm preparedness but do not prove execution capability. Answer D is correct. Plan review (A) and offsite storage (B) are preparedness checks. RPO alignment (C) addresses data loss, not downtime duration.

Question 5

An organization's disaster recovery plan designates a warm site for system recovery. During an audit, the auditor finds the warm site has not been tested in three years and the hardware at the warm site is significantly outdated compared to production. The most significant risk is:

  1. The warm site provider may increase fees if the site is not used regularly.
  2. Employees may not know the location of the warm site.
  3. In a real disaster, recovery may fail or significantly exceed the RTO because untested, outdated hardware may be incompatible with current production configurations. (correct answer)
  4. The warm site's network connection may be slower than production.

Explanation: Untested, outdated disaster recovery infrastructure is a critical risk - hardware incompatibilities and untested procedures can result in recovery failures or delays well beyond the RTO. Answer C is correct. Provider fees (A), employee awareness (B), and network speed (D) are minor concerns compared to the risk of recovery failure.

Question 6

A company's backup policy states that all backups must be encrypted. An auditor tests this control by requesting evidence of encryption for a sample of backup files. The auditor finds that 30% of backup files are unencrypted. This finding should be classified as:

  1. A control deficiency - the backup encryption control is not operating effectively, and unencrypted backups expose sensitive data to potential loss or theft. (correct answer)
  2. An acceptable deviation - occasional unencrypted backups are normal.
  3. An informational finding - encryption of backups is not required by law.
  4. A configuration issue - the IT team should update the backup software settings.

Explanation: A 30% failure rate in an encryption control means a significant portion of backup media is unencrypted - a material control deficiency exposing sensitive data if media is lost or stolen. Answer A is correct. A 30% deviation is not acceptable (B). Many regulations and policies do require backup encryption (C). The root cause may be a configuration issue, but the finding is a control deficiency (D).

Question 7

A company implements immutable backups using object storage with write-once, read-many (WORM) technology. The primary control objective of immutable backups is:

  1. Improving backup speed by writing data only once.
  2. Preventing backup data from being modified or deleted by ransomware or malicious insiders during the retention period. (correct answer)
  3. Ensuring backups are automatically verified after each write operation.
  4. Compressing backup data to reduce storage costs.

Explanation: Immutable backups cannot be altered or deleted once written - even by administrators or ransomware - making them a critical control for ransomware resilience and insider threat protection. Answer B is correct. WORM is not primarily a performance technology (A). Immutability does not equal verification (C). Compression is a separate feature (D).

Question 8

Which of the following is the most significant deficiency in an organization's backup controls if the organization processes financial transactions 24 hours a day, 7 days a week?

  1. Backups are performed only on weekday nights, leaving weekend transactions unprotected and potentially creating multi-day data loss exposure. (correct answer)
  2. The backup software interface is not user-friendly for IT staff.
  3. Backup job notifications are sent to a distribution list rather than individual staff members.
  4. The backup storage capacity exceeds current requirements.

Explanation: A 24/7 transaction processor needs continuous or near-continuous backup protection. Weeknight-only backups leave significant gaps on weekends when transactions are still occurring. Answer A is correct. Interface usability (B), notification distribution (C), and storage capacity (D) are operational concerns that do not represent a significant control deficiency for 24/7 operations.

Question 9

A company's recovery controls documentation specifies that the IT disaster recovery team should be notified of a disaster within 30 minutes and begin recovery activities within 1 hour. During a recovery test, the team is not notified for 2 hours. This finding indicates:

  1. The notification timeframes in the plan are too aggressive and should be extended.
  2. A gap in the disaster notification and escalation process that could delay recovery and jeopardize the RTO. (correct answer)
  3. An acceptable deviation since recovery still began within 3 hours.
  4. A training issue that can be resolved with a brief reminder email to the team.

Explanation: A 2-hour notification delay - four times the planned 30-minute target - could push recovery well beyond the RTO. This is a process gap requiring remediation through better communication procedures, automated alerting, or escalation protocols. Answer B is correct. The plan timeframes should not be relaxed without business justification (A). A multi-hour delay is not acceptable (C). Training alone may not address systemic escalation failures (D).

Question 10

An organization's backup policy requires that critical system backups be tested quarterly. An auditor finds that tests were performed in Q1 but not in Q2 or Q3. The most appropriate audit finding is:

  1. The policy is too stringent; annual testing would be sufficient.
  2. No finding is necessary since Q1 testing was documented.
  3. A minor deviation that should be noted but requires no corrective action.
  4. A control deficiency - the required backup restoration testing was not performed as specified in policy, creating unknown recovery capability gaps for six months. (correct answer)

Explanation: Missing two of four required quarterly test cycles means the organization went six months without verifying recovery capability - a material policy non-compliance and control deficiency. Answer D is correct. Policy requirements exist for good reason and should not be relaxed (A). A single passing test does not fulfill ongoing requirements (B). Six months of missed testing is not minor (C).

Question 11

When reviewing a company's offsite backup storage arrangements, which of the following would be the most significant finding?

  1. The offsite facility is located 25 miles from the primary data center.
  2. The offsite facility requires 24-hour advance notice for media retrieval.
  3. The offsite facility is located in the same geographic flood zone as the primary data center. (correct answer)
  4. The offsite facility charges monthly storage fees based on volume.

Explanation: An offsite facility in the same flood zone as the primary data center could be damaged by the same event, defeating the purpose of offsite storage. Geographic diversity is essential for disaster recovery. Answer C is correct. 25-mile distance (A) is generally acceptable. 24-hour retrieval (B) affects RTO but is manageable. Storage fees (D) are a business arrangement, not a control concern.

Question 12

An auditor evaluating recovery controls at a cloud-hosted company should verify which of the following in addition to the company's own controls?

  1. The cloud provider's employee headcount and financial stability.
  2. The cloud provider's marketing materials describing their backup capabilities.
  3. The company's internet service provider's uptime statistics.
  4. The cloud provider's SOC 2 Type II report, which provides independent assurance over the provider's backup and recovery controls. (correct answer)

Explanation: A SOC 2 Type II report provides independent auditor assurance over the cloud provider's controls over a period of time, including backup and recovery. This is the most reliable third-party evidence of cloud provider control effectiveness. Answer D is correct. Employee counts and financials (A) and marketing materials (B) do not provide control assurance. ISP uptime (C) is unrelated to backup controls.

Question 13

A company's IT department reports that all critical systems have backup coverage. An auditor compares the list of critical systems in the asset inventory to the list of systems covered by backup jobs and finds 12 critical systems are not backed up. This discrepancy indicates:

  1. The asset inventory is incorrect and the backup list should be trusted.
  2. The 12 systems are likely test or development systems with no production data.
  3. A backup coverage gap - 12 critical systems are unprotected, and management's assertion of complete backup coverage was incorrect. (correct answer)
  4. The backup software does not support the operating systems used by those 12 systems.

Explanation: A direct comparison of asset inventory to backup coverage is an effective audit procedure that reveals gaps. Finding 12 uncovered critical systems contradicts management's assertion and constitutes a significant finding. Answer C is correct. Asset inventories are more comprehensive and should be trusted over informal IT reporting (A). Without evidence, the auditor cannot assume they are non-production systems (B). Compatibility issues may explain the gap but do not change the finding (D).

Question 14

Which of the following represents the most effective control to ensure that recovery time objectives are met during an actual disaster?

  1. Documenting RTO targets in the disaster recovery plan.
  2. Regularly training the recovery team, maintaining updated recovery runbooks, and conducting realistic timed recovery exercises. (correct answer)
  3. Purchasing cyber insurance to cover losses from extended downtime.
  4. Retaining a disaster recovery consultant on standby.

Explanation: Meeting RTOs in a real disaster requires a practiced team with current procedures and demonstrated capability through regular timed exercises - preparation that builds muscle memory and identifies gaps before they matter. Answer B is correct. Documentation alone (A) does not build capability. Insurance (C) covers costs but does not reduce downtime. Consultants on standby (D) introduce delays and lack organizational knowledge.

Question 15

An auditor is asked to assess whether the organization's backup and recovery controls adequately protect financial reporting data. Which of the following procedures is most relevant to this objective?

  1. Identifying all systems that process or store financial reporting data, verifying they are included in backup coverage, confirming backup frequency meets the RPO, and reviewing restoration test results. (correct answer)
  2. Reviewing the IT department's capital budget for backup infrastructure investments.
  3. Testing the mathematical accuracy of financial statements.
  4. Reviewing the external auditor's management letter for prior-year IT findings.

Explanation: Protecting financial reporting data requires confirming: the right systems are backed up, backup frequency meets RPO requirements, and restorability has been tested. Answer A directly addresses all three. Capital budgets (B), financial statement testing (C), and prior-year letters (D) do not directly assess current backup control adequacy for financial data.

Question 16

Which of the following backup control deficiencies poses the greatest risk to an organization's ability to recover from a cyberattack?

  1. Backup logs are retained for only 30 days.
  2. Backup files are stored on the same network as production systems and are accessible to the same user accounts. (correct answer)
  3. Backups are performed at 2 AM instead of midnight as the policy specifies.
  4. The backup job completion report is sent to only one IT staff member.

Explanation: Network-accessible backups using the same credentials as production are vulnerable to the same ransomware or cyberattack that compromises production - destroying both data and recovery capability. Answer B is correct. Log retention (A), backup timing (C), and report distribution (D) are minor operational issues that do not threaten recovery capability.

Question 17

Which of the following recovery control test types provides evidence of recoverability with the least operational risk?

  1. Parallel testing - running both primary and recovery systems simultaneously and comparing outputs, without switching production traffic to the recovery environment. (correct answer)
  2. Full cutover testing - redirecting all production traffic to the recovery environment.
  3. No testing - relying on documentation and vendor guarantees.
  4. Destructive testing - intentionally disabling production systems to force a real recovery.

Explanation: Parallel testing validates recovery capability by running both environments and comparing results without risking production disruption - a good balance of assurance and operational safety. Answer A is correct. Full cutover (B) risks production disruption if recovery fails. No testing (C) provides no assurance. Destructive testing (D) is high-risk and rarely appropriate.

Question 18

An auditor evaluating backup controls requests the backup job history for the past 90 days and finds that backup jobs failed on 15 of those days. The IT team has no documentation of these failures being investigated or remediated. This finding indicates:

  1. The backup software needs to be upgraded to improve reliability.
  2. A minor issue that can be addressed in the next IT project cycle.
  3. A significant control deficiency - backup failures were not detected and remediated, creating unknown data loss exposure for those 15 days. (correct answer)
  4. An acceptable failure rate since 75 of 90 days had successful backups.

Explanation: Uninvestigated backup failures mean the organization does not know what data is unprotected. Fifteen days of unexplained failures represents a serious gap in the backup control environment that requires immediate attention. Answer C is correct. Software upgrades (A) may be needed but are not the finding. A 17% failure rate with no remediation is not minor (B) or acceptable (D).

Question 19

An organization retains backup data for 90 days as per policy. An auditor verifies that backups older than 90 days are automatically deleted. What additional verification should the auditor perform?

  1. Confirm that the backup storage vendor supports 90-day retention.
  2. Verify that 90-day retention is the industry standard for the organization's sector.
  3. Confirm that the 90-day retention period meets all applicable regulatory and legal requirements for the types of data being backed up. (correct answer)
  4. Verify that the backup software can be configured to retain data for longer periods if needed.

Explanation: The auditor must verify that the retention period complies with applicable regulations (SEC, IRS, HIPAA, SOX, etc.) since some financial and health data must be retained for years, not months. Answer C is correct. Vendor support (A) and industry norms (B) are less critical than regulatory compliance. Software flexibility (D) does not confirm current compliance.

Question 20

When evaluating the adequacy of an organization's backup controls, which of the following is the most important consideration?

  1. Whether the organization has tested its backups by performing actual restoration exercises to confirm data is recoverable. (correct answer)
  2. Whether backup jobs complete within the allocated nightly maintenance window.
  3. Whether backup media is purchased from a certified vendor.
  4. Whether the backup software version is the most current available.

Explanation: A backup that has never been tested may be corrupted, incomplete, or technically unrestorable. Restoration testing is the only way to confirm that backups actually work when needed. Answer A is correct. Completion timing (B), vendor certification (C), and software version (D) are operational details that do not confirm recoverability.