CISA Practice Question: Information Systems Operations and Business Resilience
An IS auditor is reviewing the IT operations team's use of system-generated alerts. The auditor finds that alerts are configured to notify the operations team via email, but there is no escalation path if an alert is not acknowledged within a specified time. Which of the following is the MOST significant risk?
⚠ Common exam trap
The trap here is assuming that email delivery or alert fatigue is the main issue, when the scenario explicitly points to the lack of an escalation path for unacknowledged alerts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Critical alerts may be overlooked, leading to unplanned downtime or service degradation.
The absence of an escalation path means that if the primary recipient does not acknowledge an alert, no one else is notified. For critical alerts, this can result in delayed response and unplanned downtime. The most significant risk is therefore that critical alerts may be overlooked, leading to service degradation. Other concerns like alert fatigue or email failures are plausible but secondary to the explicit control gap of missing escalation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The alerting system may not be integrated with the incident management system, delaying ticket creation.
Why it's wrong here
Integration with incident management is beneficial, but the scenario does not state that tickets are not being created. The core issue is that unacknowledged alerts are not escalated to another person or team. While integration could improve response, the absence of an escalation path is a more direct risk to timely incident resolution. The auditor should address the escalation gap first, as it can lead to missed critical events even if ticketing works.
- ✗
Email delivery failures may prevent alerts from reaching the operations team.
Why it's wrong here
Email delivery issues are possible, but the scenario does not mention them. The identified weakness is the lack of escalation, which is independent of email reliability. Even if email works perfectly, an unacknowledged alert will not be escalated. Therefore, email delivery is a secondary concern. The auditor should prioritize the missing escalation path, as it is the explicit control gap described in the scenario.
- ✓
Critical alerts may be overlooked, leading to unplanned downtime or service degradation.
Why this is correct
Without an escalation path, an unacknowledged alert may sit in an email inbox indefinitely. If the alert indicates a critical condition, such as a failing disk or high CPU, the lack of escalation means no one else is notified, and the issue may escalate into an outage. This directly threatens availability and service levels, making it the most significant risk. The auditor should recommend a formal escalation procedure with defined timeframes and alternate contacts.
- ✗
The operations team may become desensitized to alerts due to email overload, ignoring them altogether.
Why it's wrong here
Alert fatigue is a real concern, but the scenario specifically highlights the absence of an escalation path, not the volume of alerts. While desensitization could occur, the lack of escalation is a more concrete control gap that can lead to missed critical events. The auditor should focus on the missing escalation mechanism, which is a direct cause of potential downtime, rather than assuming alert fatigue without evidence.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.