An auditor we coached reviewed a client's disaster recovery plan. Full backups ran like clockwork every Sunday. Restoration tests passed cleanly. He felt confident. Then a real outage hit on a Thursday. The business's 24-hour Recovery Point Objective (RPO) was useless against a four-day-old backup. The 'successful' plan was a compliance checkbox that failed the business, the exact judgment trap CISA Domain 4 sets for you.
For the CISA exam, Backup and Recovery Strategies require you to judge if an organization's data protection methods meet business-defined resilience targets. Your evaluation must prioritize the ability to satisfy the Recovery Time Objective (RTO) and Recovery Point Objective (RPO) over the specific technology used.
Key facts
- Official body: ISACA (Information Systems Audit and Control Association)
- Relevant domain: Domain 4: Information Systems Operations and Resilience (29% of exam)
- Passing score: 450 on a scale of 200 to 800
- Exam format: 150 multiple-choice questions over 4 hours
- Unofficial pass rate: The CISA exam has a widely cited unofficial pass rate of 50-55%, underscoring the need for targeted study.
- Governing standards: Concepts are often tested against frameworks like COBIT 2019 and NIST SP 800 series.
Why Backup and Recovery is a Critical CISA Domain
Backup and Recovery is the practice of creating and storing copies of data to protect an organization against data loss. On your CISA exam, this isn't a test of your sysadmin skills. It's about applying an auditor's skepticism to determine if the resilience strategy is effective and aligned with business objectives.
This topic sits within Domain 4: Information Systems Operations and Resilience, which accounts for 29% of your total score. You won't just be asked to define a full backup. You'll get scenarios where you must evaluate if a chosen method is appropriate for a bank's transaction system versus a marketing team's development server.
Studying for CISA CISA4? Benchmark your score in 5 minutes.
Get an instant weak-spot assessment and a custom 12-week study plan PDF generated for your exam window.
The biggest mistake candidates make is memorizing technical terms without grasping their business impact. They know what a differential backup is, but can't explain why it's a poor choice for a system with a 15-minute RPO. The exam tests your judgment. It wants to see if you can connect a technical control to a business requirement.
To master this, think like an examiner. Every question is a mini-case study. Identify the business need first, then evaluate the technical options. Try VoraPrep's free CISA practice questions to start building this skill.
What Core Backup Concepts Will Be on the CISA Exam?
You must evaluate if a backup and recovery plan is adequate. This requires a firm grasp of several core concepts ISACA will test you on, from foundational objectives to advanced strategies.
Recovery Objectives: RPO and RTO
These two terms are guaranteed to appear on your exam. They are the non-negotiable business requirements that drive all technical decisions.
- Recovery Point Objective (RPO): The maximum acceptable amount of data loss an organization can tolerate, measured in time. An RPO of 1 hour means the business cannot afford to lose more than one hour's worth of data. This dictates backup frequency.
- Recovery Time Objective (RTO): The maximum acceptable amount of downtime an organization can tolerate. An RTO of 4 hours means a system must be fully restored and operational within four hours of a disruption. This dictates the required recovery speed.
An auditor's job is to find hard evidence that the chosen technology and procedures can meet the RPO and RTO defined in the Business Impact Analysis (BIA).
Backup Types
The exam will expect you to know the trade-offs between the three main backup types.
| Backup Type | Description | Backup Speed | Storage Space | Restoration Complexity |
|---|---|---|---|---|
| Full | Copies all selected data. | Slowest | Most | Easiest (1 media set) |
| Incremental | Copies only data changed since the last backup of any type. | Fastest | Least | Hardest (Full + all increments) |
| Differential | Copies only data changed since the last full backup. | Moderate | Moderate | Moderate (Full + last differential) |
An auditor must assess if the chosen combination (e.g., weekly full, daily differential) aligns with the RPO and RTO. A strategy that takes 6 hours to restore is an automatic failure for a system with a 4-hour RTO.
Advanced Strategies: Replication and Mirroring
For critical systems with near-zero RPO requirements, traditional backups are not enough. The CISA exam will test your knowledge of more advanced, continuous data protection methods.
- Replication: Data is copied from a primary location to a secondary location in real-time or near-real-time. This is essential for meeting very low RPOs (seconds or minutes).
- Mirroring (RAID 1): An exact, real-time copy of data is maintained on one or more separate hard disks. This provides redundancy against disk failure but does not protect against data corruption, which would be mirrored instantly.
Backup Testing
A backup plan that isn't tested is not a plan. The most important evidence an auditor can find is documentation of regular, successful restoration tests.
- Full Restoration Test: The most comprehensive test, where an entire system (OS, applications, data) is restored to a functional state. This is the best way to verify the backup media and procedures are effective.
- Partial/Selective Restoration Test: Restoring specific files or folders. This is less disruptive and can be done more frequently.
From an audit perspective, the absence of recent test results is a significant finding.
Data Lifecycle and Security
Your audit scope covers the entire data lifecycle, from creation to disposal.
- Data Retention Policy: Dictates how long backup data must be kept for legal, regulatory, and business reasons. An auditor checks that backups are retained for the specified period, and not longer.
- Backup Encryption: A critical control. Data must be encrypted both in transit (while being sent to the backup location) and at rest (while stored on tape or disk) to maintain confidentiality.
- Media Sanitization: The process of permanently and irreversibly removing data from storage media. When backups reach their end-of-life, they must be properly sanitized or destroyed according to a standard like NIST SP 800-88, Guidelines for Media Sanitization. Simply deleting files is insufficient.
Worked Example: A CISA Decision-Tree Playbook
Let's apply these concepts to a realistic CISA exam question. This is where you apply judgment, not just memory.
Calculate Your CISA Study Hours by Domain
See the exact domain-by-domain study breakdown reflecting the 2024 ISACA Job Practice weighting shifts.
> 💡 Worked example: > An IS auditor is reviewing the backup strategy for a critical online payment processing system. The Business Impact Analysis (BIA) specifies a Recovery Time Objective (RTO) of 2 hours and a Recovery Point Objective (RPO) of 15 minutes. The current strategy is a full backup performed nightly at midnight to an offsite tape library and differential backups performed every 4 hours. Restoration tests have documented that a full restoration from tape takes approximately 3 hours. Which of the following is the MOST significant concern for the auditor? > > A. The use of a tape library may not be secure for financial data. > B. The differential backup frequency does not meet the RPO. > C. The full backup restoration time exceeds the RTO. > D. The backup media is stored offsite, introducing transport risk.
This question is designed with tempting, but incorrect, distractors. Let's use a decision-tree approach.
Step 1: Identify the Business Thresholds
First, isolate the hard numbers from the BIA. These are the pass/fail criteria.
- Threshold 1 (RTO): Downtime must be ≤ 2 hours.
- Threshold 2 (RPO): Data loss must be ≤ 15 minutes.
Step 2: Evaluate Current Controls Against Thresholds
Next, measure the company's actual performance against those thresholds.
- RTO Check: The tested restoration time is 3 hours. This violates the 2-hour RTO threshold. (FAIL)
- RPO Check: Backups occur every 4 hours. This violates the 15-minute RPO threshold. (FAIL)
We have two clear control failures. The question asks for the MOST significant concern. This requires prioritization.
Step 3: Prioritize the Failures and Select the Answer
This is the core audit judgment. Both B and C are factually correct failures. Which one represents the greater business risk?
- Option A (Tape security): A plausible concern, but the scenario provides no evidence of insecurity. It's a hypothetical risk, whereas we have two documented failures.
- Option B (RPO failure): The 4-hour backup interval cannot meet a 15-minute RPO. This is a definite problem.
- Option C (RTO failure): The 3-hour restore time cannot meet a 2-hour RTO. This is also a definite problem.
- Option D (Offsite risk): Storing media offsite is a best practice for disaster recovery. This is a control, not a weakness.
This is the level of analysis VoraPrep's adaptive engine trains you for. Our platform has over 2,300 questions, each with detailed explanations like this one, to build your critical thinking.