CISA Practice Question: Information Systems Operations and Business Resilience
An IS auditor is examining the job scheduling controls for an organization's nightly batch processing on a mainframe. The auditor finds that operators can modify job schedules, add ad hoc jobs, and override job dependencies without supervisory approval or logging. Which of the following is the MOST appropriate recommendation?
⚠ Common exam trap
The trap here is recommending more monitoring or manual logs instead of fixing the underlying segregation of duties and approval deficiency that allows operators to change schedules without oversight.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restrict scheduling changes to a separate scheduler role and implement automated logging with supervisory approval for exceptions.
The finding shows that operators have excessive privileges over job scheduling without approval or logging, creating a segregation of duties and auditability gap. The most appropriate recommendation restricts scheduling modifications to a controlled role and enforces approval and automated logging for exceptions, which prevents unauthorized changes while preserving an immutable audit trail.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement a job scheduling tool that automatically reschedules failed jobs without operator intervention.
Why it's wrong here
Automated rescheduling of failed jobs improves operational efficiency but does not address unauthorized schedule modification, dependency overrides, or ad hoc job insertion. The finding concerns access control and accountability, not failure recovery. Recommending automation of failure handling would leave the segregation and logging weaknesses intact, failing to remediate the actual risk identified by the auditor.
- ✓
Restrict scheduling changes to a separate scheduler role and implement automated logging with supervisory approval for exceptions.
Why this is correct
Segregating scheduling duties from operations and requiring approval for exceptions addresses both unauthorized modification and lack of accountability. Automated logging ensures an audit trail that cannot be bypassed, and supervisory approval enforces authorization. This combination provides preventive and detective controls appropriate for a critical batch environment, directly remediating the identified weakness in job scheduling access.
- ✗
Require operators to document all schedule changes in a manual log reviewed monthly by the IT manager.
Why it's wrong here
A manual log reviewed monthly is weak because it is retrospective, easily omitted, and does not prevent unauthorized changes in real time. The core issue is the absence of approval and automated logging. Recommending manual logging alone would not establish preventive control or timely detection, and monthly review allows many unauthorized changes to occur before anyone notices.
- ✗
Increase the frequency of batch job monitoring by operations staff to detect unauthorized schedule changes.
Why it's wrong here
Monitoring by the same operations staff who can make unauthorized changes does not provide independent detection and creates a self-review conflict. It also relies on human observation, which is inconsistent and unable to reconstruct historical changes. The recommendation fails to address segregation of duties, approval, and an immutable audit trail, leaving the root control gap unmitigated.
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.