Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IS auditor is evaluating an organization's capacity management process for a critical database server. The auditor observes that CPU utilization averages 85% during peak hours, memory utilization is at 90%, and disk I/O wait times are consistently high. The organization has no formal capacity plan. Which of the following is the MOST significant risk the auditor should report?

⚠ Common exam trap

The trap here is focusing on the immediate technical symptoms (high utilization) rather than the underlying governance failure of not having a capacity plan, which is the root cause of the risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The lack of a formal capacity plan may lead to unplanned outages and inability to meet service level agreements.

The absence of a formal capacity plan is the most critical risk because it leaves the organization unable to predict and prevent performance issues. High utilization metrics indicate the server is already stressed, and without a plan, the organization cannot ensure it will meet current and future demands, leading to potential outages and SLA breaches. Other issues like hardware needs or SAN tuning are symptoms that should be addressed within a capacity management framework.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The lack of a formal capacity plan may lead to unplanned outages and inability to meet service level agreements.

    Why this is correct

    This is the most significant risk because without a capacity plan, the organization cannot proactively address resource constraints. High utilization and I/O wait times indicate the server is near its limits, and any further growth or unexpected demand could cause performance degradation or outages, directly impacting SLAs.

  • ✗

    The high CPU and memory utilization may indicate a need for additional hardware, which should be procured immediately.

    Why it's wrong here

    While additional hardware might be needed, the absence of a capacity plan is a more fundamental governance issue. Procuring hardware without a plan may not align with long-term needs and could be a reactive measure that fails to address the root cause of the lack of planning.

  • ✗

    The disk I/O wait times suggest that the storage area network (SAN) is misconfigured and requires tuning.

    Why it's wrong here

    High I/O wait times could have multiple causes, and assuming a SAN misconfiguration is premature. The auditor's primary concern should be the lack of a capacity management process, which would include monitoring and analyzing I/O trends to determine the root cause.

  • ✗

    The organization is not complying with industry best practices for capacity management, which could result in regulatory penalties.

    Why it's wrong here

    While best practices recommend capacity planning, regulatory penalties are not typically directly associated with the absence of a capacity plan unless specific regulations mandate it. The more direct and significant risk is operational disruption due to resource exhaustion, not regulatory penalties.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.