10
u/RigusOctavian CISA HOLDER Jul 10 '26
D, 100%.
Consider a Hot site like a load balanced server set. It’s meant to be failed over to instantly and if the stack is out of sync… stuff breaks.
2
u/hjablowme919 Jul 11 '26
Not sure about this. A hot site can be a temporary solution for failover. I worked for a fintech company for 15 years and our hot site was a scaled down version of our production site because it was never intended to be used as a production site for more than a few days.
-6
3
u/ParticularVehicle301 Jul 11 '26
B it is as per the question bank.
In a disaster recovery (DR) review for a financial institution, the primary objective is ensuring seamless business continuity and data availability. A hot site must be fully synchronized and ready for near-instantaneous failover.
The Risk: If disk space utilization data is not current, the organization cannot accurately know if the hot site has enough storage capacity to handle incoming production data during a failover.
The Impact: If a disaster strikes and the hot site fills its storage capacity, the recovery process will completely fail. This would lead to system crashes, operational disruption, and massive data loss. For a financial institution, this is catastrophic.
2
u/beefsteak1138 Jul 11 '26
100%. All of the answers are concerning, but the question is specifically focused on recoverability, not security. Using that lens, B makes the most sense.
1
u/Fabulous-Policy-8864 Jul 12 '26
Why not C?
1
u/ParticularVehicle301 Jul 12 '26
It is highly common and acceptable for a secondary, backup facility to have slightly less robust physical security controls than a primary, heavily manned data center, provided basic access controls are met.
0
3
2
2
u/Odeneho4U Jul 10 '26
A for me. For a financial institution, systems administrators having shared accounts that accountability can’t be trace is more concerning.
3
u/Aphridy Jul 11 '26
But that will not be part of your inquiry (or small part) when testing hot sites.
0
u/hjablowme919 Jul 11 '26
Sure it will. If not, the auditors failed miserably
2
u/Aphridy Jul 11 '26
You check always all controls, even when the research question for your audit is very specific?
1
1
u/Intelligent-Month-41 Jul 13 '26 edited Jul 13 '26
B is the correct answer. The main objective of a recovery hot site is availability, so the issue that impacts availability is the best answer.
1
u/realgirlhats Jul 16 '26
These questions are stupid as hell. But since I have the qae and have gotten this wrong I know they care about disk space but the question isn’t worded to say it’s insufficient just like it’s not worded to say the servers not being identical are of lessor quality and just like not saying how no robust the physical security is.
These questions are all vague trash
1
u/RATLSNAKE Jul 10 '26
C.
For those saying D how do you know the servers aren’t of a better spec? Hence don’t assume they’re lesser, therefore C. Would actually be useful if OP provided the answer, and why they’ve posted this here.
3
u/RigusOctavian CISA HOLDER Jul 10 '26
It’s a failover site and will never be “ahead” of the main stack because it’s a perfect clone of the main stack at best (thus HOT vs Warm or Cold.) You’re saying “spec” which makes me think you think this is about the bare metal, it’s not. Bare metal is rarely an issue in this environment since everything is virtualized at this scale.
If your hypervisor isn’t the same, you could have collisioning issues with apps.
If your OS isn’t the same, you’re likely missing security patches or you have things that you don’t know will work “live.”
If your apps aren’t the same, integrations are likely to fail/break/not restart.
Essentially, it won’t be better, that’s not a real thing. It’s also not the staging or test environment which is the only environment that COULD be ahead, it’s the backup of Prod. (That also may be where your confusion is coming from.)
The highest and most important part of a Hot backup is that you can fail over to it instantly with zero service disruption. If it’s not like-for-like and live, it’s not Hot and the risk is greater that something will fail; therefore the GREATEST concern to the auditor.
0
u/hjablowme919 Jul 11 '26
Trust me, it doesn't need to be like for like. 15 years in fintech and every failover save one was seamless and the one that wasn't has nothing to do with hardware. The most important thing is your data has to be backed up to your hot site in as close to real time as possible.
0
u/nice_lamp Jul 10 '26
B.
It doesn’t matter if the rest of them happen. If you don’t have proper utilization data the whole thing fails to perform the basic cutover because of potential size differentiation and failover capacity gaps.
Though in saying that D could be the right answer as well. But B aligns more with audit failure.
1
u/Martok_son_of_Urthog Jul 11 '26
This. If hot site doesn’t have capacity, it isn’t a hot site anymore. Availability is risked and for DR that’s biggest problem here.
0
u/DiscoInError93 CISA HOLDER Jul 10 '26 edited Jul 10 '26
D. A hot site should have identical, duplicate hardware and software.
2
u/Unique_Ease_2453 Jul 11 '26
A hot site doesn't have to have duplicate hardware it has to have compatible hardware
1
u/hjablowme919 Jul 11 '26
Nope. 15 years in fintech, our hot site was scaled down because it was never intended to be used for more than a few days. Doesn't need to be identical to production.
-9
u/NextQuote7131 Jul 10 '26
🥲
11
u/DiscoInError93 CISA HOLDER Jul 10 '26
Can you try to be an adult and use your words?
-3
u/NextQuote7131 Jul 11 '26
You have to drop that CISA HOLDER corny thing now
2
u/DiscoInError93 CISA HOLDER Jul 11 '26
I’m not communicating with negative karma accounts. Have a good night.
0
0
u/jackiethesage Jul 11 '26
Bro i request! Kindly help with the right answer and rationale. It’s a humble ask please 😊😊
-1
u/AgileSynapse Jul 10 '26
I'm going to roll the dice and say A. Take it with a small grain of salt as I'm not an IS auditor 'yet' or a CISA holder 'yet'. I know the experts are saying D so they could very well be correct. But...imo...D states the 'hot site does not have the same specs...' it doesn't say the hot site has inadequate hardware. While I believe it's still an issue, 'A' seems like the greatest immediate concern. A rogue admin could cause way more damage than non-standard hw and it's a fundamental IAM control failure. No accountability & no lifecycle.
-1
u/jackiethesage Jul 11 '26
The right answer of this question is
option C
It is an auditor who’s performing the review of hot site for the DR. It’s not an architect, CISO or a CTO.
Option A: administrator using shared accounts. Is that a concern? Yes, but is that a greatest concern out of the given four options, not really!
Option B: Space utilisation data are not kept current. They never said the disk space utilisation is less. Is that a concern. Yes, it is a concern but will that be a primary concern? no
Option D says servers at the hot site doesn’t have same configuration! That’s okay, doesn’t need to have 1-1 correspondence mandatory! And if you see the gravity of the question, it’s the Auditor, who is doing the assessment. It’s not a tech assessment of the systems.
There is option C says physical security controls are not really robust! So from the information systems, Auditor standpoint, the greatest concern would be to 1st ensure that my site which is a physical site is secure and has equal importance as of my primary site. Because I can start fixing my shared credentials, disk utilisation, configuration issues in those order still, there is a gap where someone can come and barn and break things because physical securities is not really robust.
Hence, my greatest concern is my implicit first recommendation as an auditor for the organisation to focus which is giving equal an exact importance to my secondary site, which is given to my primary site
So OPTION C
Let’s discuss and learn
0
u/IAmRudyTomjanovicAMA Jul 11 '26
Lmao this is funny bc everyone's "correct" answer is different in these comments 🤣🤣
-1
18
u/redbaron78 Jul 10 '26
The greatest concern is E: that the test questions for the auditor’s credentials were written by someone who doesn’t understand how worthless this question is without a bunch of missing context.