The correct answer is D because the primary purpose of disaster recovery testing is to provide assurance that the organization can recover critical services and continue business operations after a disruptive event. While recovering data within recovery time objectives is important, that is only one measurable component of the broader recovery capability. Testing all critical systems may also be useful, but the real business objective is not merely technical system restoration; it is confidence that business operations can be restored to an acceptable level. Discovering errors in the strategy is a valuable result of testing, but it is not the main objective. From a CISM perspective, recovery planning must support business resilience, risk management, and continuity objectives. A disaster recovery test validates whether people, processes, technology, dependencies, communications, and recovery procedures work together effectively. Therefore, the most important objective is to give the business assurance that it can recover from a disaster.
[Reference: CISM Information Security Incident Management; disaster recovery, business continuity, recovery testing, and resilience principles., , ]
Submit