Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IS auditor is reviewing problem management for a payment processor. Recurring incidents share the same root cause, but the problem record has remained open for eight months with no root cause identified because the vendor will not release diagnostic data. Change requests to apply a workaround have been raised and closed repeatedly. Which action should the IS auditor recommend FIRST?

⚠ Common exam trap

The trap here is recommending a technical workaround or record reclassification when the real blocker is an unenforced vendor contractual obligation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Escalate the vendor relationship through contract governance to obtain the diagnostic data needed to determine root cause.

When root cause analysis is blocked by a vendor's refusal to supply diagnostic data, the controlling issue is contractual, not technical. The auditor should first recommend invoking contract governance and escalation to obtain the required information or a permanent fix. Reclassifying as a known error would misstate the record, blind changes without root cause are risky, and improving dashboard visibility does not remove the dependency that prevents resolution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Implement a permanent change to the payment application to bypass the failing component.

    Why it's wrong here

    Applying a permanent change without understanding the root cause risks introducing new defects and may violate the vendor's support terms. Bypassing a component can also mask the underlying fault so that it recurs elsewhere. Because the diagnostic data is unavailable, the organization lacks the evidence needed to design a safe permanent fix, making this premature and potentially harmful.

  • ✓

    Escalate the vendor relationship through contract governance to obtain the diagnostic data needed to determine root cause.

    Why this is correct

    The blocker is a third-party dependency, so the first constructive action is to use contract governance and escalation to compel the vendor to provide diagnostic information or a permanent fix. This addresses the actual constraint preventing root cause analysis rather than merely documenting the symptom. Only after the vendor obligation is enforced can the organization complete problem resolution or, if the vendor fails, pursue remedies under the agreement.

  • ✗

    Reclassify the recurring incidents as known errors and close the problem record to reflect the accepted risk.

    Why it's wrong here

    A known error is a problem with a documented root cause and workaround; here the root cause is unknown, so the classification is inaccurate. Closing the record would also hide an unresolved risk affecting payment processing and remove the accountability that drives resolution. Accepting risk is a management decision requiring formal authorization, not something an auditor should recommend as the first step.

  • ✗

    Increase the priority of the problem record so that it appears on the operations dashboard for management visibility.

    Why it's wrong here

    Raising visibility is useful but does not resolve the vendor dependency blocking root cause analysis. On its own it changes reporting, not the underlying constraint, so it is a supporting action rather than the first substantive recommendation. Management attention without a defined escalation path to the vendor is unlikely to produce the diagnostic data the organization needs.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.