Medium1 markMultiple Choice
CPA · Question 11 · Area I: Information Systems
An IT auditor is reviewing the 'Recovery Point Objective' (RPO) for a critical transaction database. Management has set the RPO at 1 hour. The current backup strategy involves a full backup every Sunday at midnight and incremental backups every night at midnight. Is this strategy adequate?
An IT auditor is reviewing the 'Recovery Point Objective' (RPO) for a critical transaction database. Management has set the RPO at 1 hour. The current backup strategy involves a full backup every Sunday at midnight and incremental backups every night at midnight. Is this strategy adequate?
Answer options:
A.
Yes, because incremental backups capture daily changes.
B.
Yes, provided the transaction logs are backed up daily.
C.
No, the RPO requires a differential backup strategy.
D.
No, backing up once every 24 hours cannot meet a 1-hour data loss limit.
How to approach this question
Compare the frequency of backups (24 hours) to the RPO (1 hour).
Full Answer
D.No, backing up once every 24 hours cannot meet a 1-hour data loss limit.✓ Correct
RPO (Recovery Point Objective) defines the maximum acceptable data loss measured in time. A 1-hour RPO requires data to be backed up (or replicated) at least every hour. A daily backup schedule implies a potential data loss of up to 24 hours, which fails to meet the objective.
Common mistakes
Confusing RPO (data loss) with RTO (downtime).
Practice the full CPA ISC Practice Exam 3
82 questions · hints · full answers · grading
More questions from this exam
Q01A CPA is advising a client who is migrating their legacy on-premise ERP system to a cloud-based s...MediumQ02During a review of a client's cloud governance structure, an auditor notes that the client uses a...MediumQ03An auditor is evaluating the 'Processing Integrity' principle for a financial institution's loan ...HardQ04A company uses a batch processing system to update inventory records overnight. The 'Grandfather-...HardQ05During a walkthrough of the change management process, an auditor observes that the 'Developer' r...Medium
Expert