Certified Information Systems Auditor (CISA) — Question 1266

Which of the following is the MOST cost-effective way to determine the effectiveness of a business continuity plan (BCP)?

Answer options

Correct answer: B

Explanation

The correct answer is B, as a tabletop exercise allows for a detailed discussion of the plan's procedures without the high costs associated with full operational tests. Options A and C involve more resources and logistics, making them less cost-effective, while option D is more focused on reviewing outcomes rather than assessing the plan's effectiveness in real-time.