Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IS auditor is assessing the capacity management process for a cloud-based enterprise resource planning (ERP) system. The organization has experienced performance degradation during peak periods, and the cloud provider's auto-scaling features are not fully utilized. Which of the following should the auditor recommend FIRST?

⚠ Common exam trap

The trap here is jumping to a technical fix like increasing capacity or configuring auto-scaling without first establishing monitoring, which is necessary to make informed decisions and avoid unnecessary costs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement monitoring tools to track resource utilization and performance metrics.

Effective capacity management begins with understanding current resource utilization and performance. The organization has auto-scaling capabilities but is not using them fully, and performance issues exist. Before making changes, the auditor should recommend implementing monitoring to collect data on resource usage, peak times, and bottlenecks. This data will inform whether to adjust auto-scaling policies, increase baseline capacity, or optimize the application. Monitoring is the essential first step to ensure that subsequent actions are targeted and effective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure auto-scaling policies based on historical peak usage patterns.

    Why it's wrong here

    Configuring auto-scaling policies is important, but without monitoring data, the policies may be based on assumptions rather than actual usage. The auditor should first recommend implementing monitoring to gather accurate data, then use that data to configure effective auto-scaling. Doing auto-scaling without monitoring could lead to over-provisioning or under-provisioning, and it may not address non-capacity-related performance issues.

  • ✗

    Conduct a performance test to simulate peak loads and identify bottlenecks.

    Why it's wrong here

    Performance testing can be valuable, but it is typically used to validate capacity plans or identify bottlenecks in a controlled environment. In this scenario, the system is already experiencing degradation in production, so real-time monitoring is more immediate and relevant. Performance testing might be a subsequent step after monitoring reveals specific areas of concern. The auditor should prioritize monitoring to understand the actual production behavior.

  • ✓

    Implement monitoring tools to track resource utilization and performance metrics.

    Why this is correct

    Before optimizing auto-scaling or adjusting capacity, the organization needs accurate data on resource usage and performance. Monitoring tools provide visibility into when and why degradation occurs, enabling informed decisions. Without this baseline, any capacity changes are guesswork. The auditor should recommend establishing monitoring first as it is foundational to effective capacity management and will inform subsequent actions.

  • ✗

    Increase the baseline capacity of the cloud infrastructure to handle peak loads.

    Why it's wrong here

    Increasing baseline capacity may alleviate symptoms but is not cost-effective and does not address the root cause. The organization already has auto-scaling features that are underutilized. Simply adding more resources without understanding usage patterns could lead to unnecessary costs. The auditor should first ensure that monitoring is in place to determine whether the issue is due to lack of scaling, inefficient application design, or other factors.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.