CISA Practice Question: Information Systems Operations and Business Resilience
An IS auditor is reviewing an organization's problem management process. The auditor finds that problem records are created only after multiple incidents with the same root cause have occurred, and there is no proactive trend analysis. Which TWO of the following are the MOST important improvements the auditor should recommend? (Choose two.)
⚠ Common exam trap
The trap here is recommending operational changes like escalating all incidents or automating closures, which do not address the core weakness of missing proactive analysis and prioritization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establish a formal problem prioritization scheme based on business impact and urgency.
The problem management process is reactive because problems are only created after multiple incidents. The two most important improvements are proactive trend analysis to identify recurring issues and a formal prioritization scheme to ensure business-relevant problems are addressed appropriately. These changes shift the process from reactive to proactive and risk-based, reducing repeat incidents and aligning problem resolution with business impact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require all incidents to be escalated to the problem manager immediately.
Why it's wrong here
Escalating every incident to the problem manager would overwhelm the process and is not practical. Problem management should focus on incidents that indicate underlying problems, not all incidents. Immediate escalation of all incidents would bypass first-line resolution and reduce efficiency, so it is not a recommended improvement.
- ✓
Establish a formal problem prioritization scheme based on business impact and urgency.
Why this is correct
A formal prioritization scheme ensures that problem records are addressed according to business impact and urgency, optimizing resource allocation. Without it, problems may be handled in an ad hoc manner, delaying resolution of critical issues. This improvement complements proactive identification by ensuring that the most significant problems receive appropriate attention and escalation.
- ✗
Outsource the problem management function to a third-party service provider.
Why it's wrong here
Outsourcing problem management does not address the root cause of the finding, which is the lack of proactive analysis and prioritization. It may introduce additional complexity and does not guarantee improvement. The organization can implement trend analysis and prioritization internally or with existing resources. Outsourcing is not a direct or necessary improvement for this specific weakness.
- ✗
Automate the closure of incidents when a problem record is created.
Why it's wrong here
Automatically closing incidents when a problem record is created could prematurely close incidents that are still being worked on or that require user confirmation. Incidents and problems have distinct lifecycles; an incident may be resolved with a workaround even if the root cause is not fixed. This automation could lead to loss of tracking and user dissatisfaction, so it is not appropriate.
- ✓
Implement trend analysis of incident data to identify recurring issues and raise problem records proactively.
Why this is correct
Trend analysis enables the organization to detect patterns and recurring incidents before they escalate, allowing problem records to be raised proactively. This shifts the process from reactive to preventive, reducing the number of repeat incidents and their business impact. It directly addresses the finding that problems are only created after multiple incidents, which indicates a lack of proactive identification.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.