CISA Practice Question: Information Systems Operations and Business Resilience
An IS auditor is reviewing an organization's problem management process. The auditor wants to verify that the process effectively identifies and resolves root causes of incidents. Which TWO of the following are the MOST important controls to ensure effective problem management? (Choose two.)
⚠ Common exam trap
Test-takers frequently confuse problem management with change management or service level management, and selecting controls that belong to those processes instead of focusing on root cause analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incidents are logged with sufficient detail to allow trend analysis and identification of recurring issues.
The two most important controls are detailed incident logging for trend analysis and documentation of known errors linked to incidents. These controls enable the problem management process to identify recurring issues and provide workarounds, ultimately reducing the frequency and impact of incidents. They are fundamental to effective root cause analysis and continuous improvement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incidents are logged with sufficient detail to allow trend analysis and identification of recurring issues.
Why this is correct
Detailed incident logging is essential for problem management because it enables the identification of patterns and recurring incidents. Without adequate data, root cause analysis cannot be performed effectively. This control ensures that problems are detected proactively rather than reactively, reducing downtime and improving service quality.
- ✓
Known errors are documented in a knowledge base and linked to the incidents they may cause.
Why this is correct
Documenting known errors and linking them to incidents helps support staff resolve issues faster and prevents duplicate investigation efforts. It is a key output of problem management and ensures that workarounds are available. This control directly supports the goal of reducing the impact of recurring incidents.
- ✗
Service level agreements (SLAs) specify penalties for missing incident resolution targets.
Why it's wrong here
SLAs and penalties are part of service level management, not problem management. They incentivize timely incident resolution but do not address root cause analysis or the prevention of recurring incidents. The auditor should focus on controls that directly support problem identification and resolution.
- ✗
Problem tickets are automatically closed when the associated incident is resolved.
Why it's wrong here
Automatically closing problem tickets when incidents are resolved can mask underlying root causes that may not be fully addressed. Problem management requires a separate lifecycle to ensure root cause analysis is completed and permanent fixes are implemented. This practice would weaken the process rather than strengthen it.
- ✗
All changes are approved by the change advisory board (CAB) before implementation.
Why it's wrong here
While change management is related, CAB approval is not a core control for problem management. Problem management focuses on root cause analysis and known errors. Change management ensures that changes are assessed and authorized, but it does not directly ensure that problems are identified and resolved.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.