Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IS auditor is reviewing automated job scheduling controls. A critical batch job failed due to a dependency on a previous job that had not completed. The system did not alert operations staff. Which control weakness is most significant?

⚠ Common exam trap

CISA often tests root cause versus symptom — candidates pick the missing alert or rerun procedure because they are visible symptoms, but the question asks for the most significant control weakness, which is the missing dependency management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Missing dependency management in job scheduling.

The job failed because it ran before its prerequisite job completed, which is a classic dependency management failure in job scheduling. The scheduler should have enforced the dependency so the downstream job waits for the upstream job's successful completion. The absence of an alert is a secondary symptom of the same missing control, but the root control weakness is the lack of dependency management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Missing dependency management in job scheduling.

    Why this is correct

    Dependency management prevents a job from starting until its prerequisite completes successfully. Its absence let the batch job run against unmet dependencies and fail silently, which is the root weakness; alerting alone would only report the symptom after the scheduling logic had already misfired.

  • ✗

    Insufficient capacity management to handle job load.

    Why it's wrong here

    Capacity management governs resource availability, whereas the job failed on an unmet predecessor dependency, not resource exhaustion. It is tempting because overloaded schedulers can cause failures, and it would be correct if the stem cited jobs timing out or queue contention under peak load.

  • ✗

    Inadequate rerun procedures for the failed job.

    Why it's wrong here

    Rerun procedures address recovery after failure, not the missing alert that left operations unaware. It is tempting because the job did fail and rerunning is part of remediation, and it would be correct if the stem described repeated failures without documented restart steps.

  • ✗

    Lack of a known error database entry for this issue.

    Why it's wrong here

    A known error database supports diagnosis of recurring incidents; it does not provide the dependency checking or alerting that failed here. It is tempting because documenting known errors aids future resolution, and it would be correct if the stem concerned slow diagnosis of a previously seen fault.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.