Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IS auditor is reviewing the problem management process after a series of recurring production outages. The auditor finds that incidents are resolved quickly but the same underlying faults reappear. Which TWO activities should the auditor expect to find in an effective problem management process? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse incident management activities, such as rapid escalation and automatic closure, with problem management, which exists specifically to find and eliminate the underlying cause of recurring incidents.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A known error database that records diagnosed root causes and workarounds for reuse.

Effective problem management identifies the underlying cause of recurring incidents and prevents recurrence. Root cause analysis with corrective actions tracked to closure delivers the permanent fix, while a known error database preserves diagnosed causes and workarounds so recurrences are handled consistently and diagnostic effort is not repeated. Incident escalation, automatic closure, and volume reporting support operations but do not eliminate the root causes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A known error database that records diagnosed root causes and workarounds for reuse.

    Why this is correct

    A known error database captures diagnosed root causes and documented workarounds so that support staff can resolve recurrences faster and avoid duplicating diagnostic effort. It converts problem investigations into organizational knowledge. For an environment where the same faults reappear, this repository directly supports consistent handling and provides evidence that problems are being analyzed rather than merely closed, making it a core problem management activity.

  • ✗

    Weekly reporting of incident volumes by category to the service desk manager.

    Why it's wrong here

    Volume reporting by category is a useful operational metric that can reveal trends and help prioritize problem investigations, but the report itself does not analyze causes or implement fixes. It is an input to problem management rather than a core activity of it. On its own, this reporting leaves the underlying faults in place, which is why it does not satisfy the auditor's expectation in this scenario.

  • ✗

    Escalation of every incident to senior management within one hour of detection.

    Why it's wrong here

    Blanket escalation of all incidents to senior management is an incident management communication practice, not problem management, and applying it universally would overwhelm leadership and dilute attention from genuinely severe events. Escalation thresholds should be risk-based. This activity also does nothing to identify or eliminate the underlying cause of recurring faults, so it cannot address the pattern the auditor found.

  • ✗

    Automatic closure of incidents once the affected service is restored to users.

    Why it's wrong here

    Closing incidents as soon as service is restored is normal incident management behavior, but it is precisely what allows recurring faults to go unaddressed. If closure happens without linking the incident to a problem record, the underlying cause is never investigated. This activity therefore contributes to the pattern the auditor observed rather than correcting it, and it is not a problem management control.

  • ✓

    Root cause analysis performed for recurring incidents, with corrective actions tracked to closure.

    Why this is correct

    Root cause analysis identifies why a fault recurs and produces a corrective action that prevents repetition. Tracking those actions to closure ensures the fix is actually implemented rather than merely documented. Without this activity, the organization remains in a cycle of resolving symptoms while the underlying defect persists, which is exactly the pattern the auditor observed. It is a defining activity of problem management as distinct from incident management.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.