CISA Practice Question: Information Systems Operations and Business Resilience
An IS auditor is reviewing an organization's IT operations incident management process. The auditor finds that incidents are logged, but there is no formal problem management process. Which TWO of the following are the MOST likely consequences of this deficiency? (Choose two.)
⚠ Common exam trap
The trap here is assuming that incident management depends on problem management for basic functions like logging or escalation, when in fact problem management is an improvement layer that addresses root causes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incident resolution times will increase because support staff lack a knowledge base of known errors.
Problem management focuses on identifying the root causes of incidents and preventing recurrence. Without it, organizations suffer from repeated incidents and lack a known error database, which slows resolution. Incident logging and change management are separate processes that do not depend on problem management. Escalation of major incidents is an incident management activity, not a consequence of missing problem management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Major incidents will automatically be escalated to the problem manager for resolution.
Why it's wrong here
Major incident escalation is typically defined in incident management procedures and does not require a problem management process to function. In fact, without a problem manager role, such escalation may not occur at all. This option describes a process that would not exist, rather than a consequence of its absence, so it is incorrect.
- ✓
Incident resolution times will increase because support staff lack a knowledge base of known errors.
Why this is correct
Problem management maintains a known error database and workarounds. Without it, support staff cannot quickly reference previously identified issues and solutions, so they may spend more time diagnosing the same problems. This leads to longer resolution times and reduced service quality, making it a correct consequence.
- ✓
Recurring incidents will not be analyzed to identify and eliminate their root causes.
Why this is correct
Problem management is responsible for root cause analysis and implementing permanent fixes. Without it, incidents that share an underlying cause will continue to recur, leading to repeated disruptions and wasted resources. This is a direct and significant consequence of the missing process, making it a correct choice.
- ✗
The service desk will be unable to log incidents due to the absence of problem records.
Why it's wrong here
Incident logging is part of incident management and does not depend on problem management. The scenario states that incidents are already logged. Problem records are created from incident trends, but their absence does not prevent incident logging. This option misstates the relationship between the two processes and is therefore incorrect.
- ✗
Change management will be unable to assess the impact of changes without problem tickets.
Why it's wrong here
Change management assesses risk and impact based on change requests, configuration items, and business needs, not on problem tickets. While problem records can inform changes, they are not a prerequisite for change assessment. This option incorrectly links change management to problem management and is not a likely consequence of the missing process.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.