CISA Practice Question: Information Systems Operations and Business Resilience
An IS auditor is evaluating the capacity management process. The auditor notices that CPU utilization has been consistently above 90% for the past three months. The IT manager states that no proactive capacity planning has been performed. What is the primary risk?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Potential service degradation or unplanned outages.
Consistently high utilization without planning risks performance degradation and outages. The organization may not be able to handle peak loads.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Potential service degradation or unplanned outages.
Why this is correct
Sustained CPU utilisation above 90% with no proactive capacity planning leaves no headroom for demand spikes, so response times degrade and components may fail. The primary risk is therefore service degradation or unplanned outages affecting dependent business processes.
- ✗
Increased licensing costs for software.
Why it's wrong here
Sustained 90% CPU threatens service levels and processing headroom, not licence entitlements, which are typically tied to user or core counts. Licensing cost is tempting because over-provisioned hardware can trigger tier changes, but that is a procurement concern rather than the operational risk of exhausted capacity.
- ✗
Inability to meet backup windows.
Why it's wrong here
Backup windows may lengthen under CPU contention, but that is one downstream symptom rather than the primary risk. Backup scheduling is tempting because it is a visible batch workload, yet the core exposure is insufficient headroom to meet peak demand and service-level commitments.
- ✗
Increased energy costs for cooling.
Why it's wrong here
Cooling cost is a secondary operating expense, not the primary risk of sustained 90% CPU utilisation. Energy consumption is tempting because high utilisation does raise power draw, but the auditor's concern is service degradation and inability to absorb demand growth, not utility billing.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.