Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

A company outsources its IT help desk to a third-party vendor. The service level agreement (SLA) specifies that all P1 incidents must be resolved within 2 hours. During an audit, the auditor finds that the vendor’s average resolution time for P1 incidents is 3 hours. What is the most appropriate recommendation?

⚠ Common exam trap

CISA often tests the boundary between the auditor's advisory role and management's decision-making authority — candidates wrongly pick 'terminate' or 'renegotiate' because those feel decisive, but auditors recommend remediation, not contract actions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Issue a non-compliance notice and require a remediation plan

The vendor is contractually obligated to resolve P1 incidents within 2 hours, and the audit shows an average of 3 hours — a clear SLA breach. The auditor's role is to report the gap and recommend corrective action, not to unilaterally terminate or rewrite the contract. Issuing a non-compliance notice with a required remediation plan is the standard governance response that preserves the business relationship while enforcing accountability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Terminate the contract immediately

    Why it's wrong here

    Termination is a contractual remedy, not an audit recommendation; the auditor's role is to report the SLA breach and recommend remediation, escalation, or a corrective action plan. Immediate termination applies only where the vendor fundamentally fails or breaches material obligations repeatedly.

  • ✗

    Renegotiate the SLA to 3 hours

    Why it's wrong here

    Renegotiating the SLA to 3 hours would legitimise the vendor's underperformance rather than close the 1-hour gap against the contracted 2-hour target, so it fails to address the control weakness the audit identified. It is tempting because SLA renegotiation is valid when targets are genuinely unachievable or business needs have shifted.

  • ✓

    Issue a non-compliance notice and require a remediation plan

    Why this is correct

    The vendor's 3-hour average breaches the SLA's 2-hour P1 resolution target, so the auditor should raise non-compliance and require a remediation plan. This addresses the contractual gap directly rather than accepting or renegotiating the agreed service level.

  • ✗

    Accept the performance as within acceptable variance

    Why it's wrong here

    A one-hour overshoot on a two-hour P1 target is a 50% breach, not acceptable variance; the SLA defines 2 hours as the contractual threshold. Accepting it waives the control the SLA exists to enforce. Variance tolerance would apply to minor, non-material deviations within agreed thresholds.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.