Valid IIA-CIA-Part2 Dumps shared by EduDump.com for Helping Passing IIA-CIA-Part2 Exam! EduDump.com now offer the newest IIA-CIA-Part2 exam dumps, the EduDump.com IIA-CIA-Part2 exam questions have been updated and answers have been corrected get the newest EduDump.com IIA-CIA-Part2 dumps with Test Engine here:
While conducting an information security audit, an internal auditor learns that the existing disaster recovery plan is four years old and untested. The auditor also learns that in the four years since the recovery plan was implemented, the information systems have undergone extensive changes. Which of the following actions is most appropriate for the auditor to take?
Correct Answer: D
* A. Inform management and request that the plan be tested immediately:Testing without updating the plan could lead to irrelevant results given the significant changes to the systems. * B. Update the recovery plan for management, as part of the review:The auditor's role is to assess and recommend, not to perform management's responsibilities. * C. Evaluate the recovery plan and report weaknesses to management:Evaluation alone does not address the need for an update and testing of the outdated plan. * D. Recommend that management and users update and test the recovery plan:Correct. This approach addresses the deficiencies in the plan and ensures alignment with current systems. CIA Exam Syllabus Reference: Domain II: Risk Management and Control - Disaster Recovery and Business Continuity Planning.