Certified in Risk and Information Systems Control (CRISC) — Question 312
The best way to test the operational effectiveness of a data backup procedure is to:
Answer options
- A. inspect a selection of audit trails and backup logs
- B. conduct an audit of files stored offsite
- C. demonstrate a successful recovery from backup files
- D. interview employees to compare actual with expected procedures
Correct answer: C
Explanation
The correct answer is C because demonstrating a successful recovery from backup files directly verifies that the backup procedure works as intended. The other options, while useful, do not provide direct evidence of the backup's effectiveness in restoring data.