CISA Practice Question: Information Systems Operations and Business Resilience
An IS auditor is reviewing the problem management process after a series of recurring production outages. The auditor finds that incidents are resolved quickly but the same underlying faults reappear. Which TWO activities should the auditor expect to find in an effective problem management process? (Choose two.)
⚠ Common exam trap
Many exam-takers confuse incident management activities, such as rapid escalation and automatic closure, with problem management, which exists specifically to find and eliminate the underlying cause of recurring incidents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A known error database that records diagnosed root causes and workarounds for reuse.
Effective problem management identifies the underlying cause of recurring incidents and prevents recurrence. Root cause analysis with corrective actions tracked to closure delivers the permanent fix, while a known error database preserves diagnosed causes and workarounds so recurrences are handled consistently and diagnostic effort is not repeated. Incident escalation, automatic closure, and volume reporting support operations but do not eliminate the root causes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A known error database that records diagnosed root causes and workarounds for reuse.
Why this is correct
A known error database captures diagnosed root causes and documented workarounds so that support staff can resolve recurrences faster and avoid duplicating diagnostic effort. It converts problem investigations into organizational knowledge. For an environment where the same faults reappear, this repository directly supports consistent handling and provides evidence that problems are being analyzed rather than merely closed, making it a core problem management activity.
- ✗
Weekly reporting of incident volumes by category to the service desk manager.
Why it's wrong here
Volume reporting by category is a useful operational metric that can reveal trends and help prioritize problem investigations, but the report itself does not analyze causes or implement fixes. It is an input to problem management rather than a core activity of it. On its own, this reporting leaves the underlying faults in place, which is why it does not satisfy the auditor's expectation in this scenario.
- ✗
Escalation of every incident to senior management within one hour of detection.
Why it's wrong here
Blanket escalation of all incidents to senior management is an incident management communication practice, not problem management, and applying it universally would overwhelm leadership and dilute attention from genuinely severe events. Escalation thresholds should be risk-based. This activity also does nothing to identify or eliminate the underlying cause of recurring faults, so it cannot address the pattern the auditor found.
- ✗
Automatic closure of incidents once the affected service is restored to users.
Why it's wrong here
Closing incidents as soon as service is restored is normal incident management behavior, but it is precisely what allows recurring faults to go unaddressed. If closure happens without linking the incident to a problem record, the underlying cause is never investigated. This activity therefore contributes to the pattern the auditor observed rather than correcting it, and it is not a problem management control.
- ✓
Root cause analysis performed for recurring incidents, with corrective actions tracked to closure.
Why this is correct
Root cause analysis identifies why a fault recurs and produces a corrective action that prevents repetition. Tracking those actions to closure ensures the fix is actually implemented rather than merely documented. Without this activity, the organization remains in a cycle of resolving symptoms while the underlying defect persists, which is exactly the pattern the auditor observed. It is a defining activity of problem management as distinct from incident management.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.