Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IS auditor is reviewing the problem management process of a financial services firm. The auditor finds that incidents are frequently resolved by the service desk using documented workarounds, but no problem records are created, and root cause analysis is rarely performed. As a result, the same high-impact incident has recurred 14 times in three months. Which of the following is the MOST significant risk arising from this practice?

⚠ Common exam trap

The trap here is focusing on documentation or reporting side effects of missing problem records, rather than the core business risk that unresolved root causes cause repeated outages and rising operational cost.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Recurring incidents will continue to disrupt critical business services and increase operational cost without permanent resolution.

Problem management exists to identify and eliminate root causes of recurring incidents. When workarounds are used without creating problem records, the organization treats symptoms rather than causes, so high-impact incidents recur and consume resources repeatedly. The most significant risk is therefore continued disruption and cost to critical business services, not secondary issues such as skill loss or data accuracy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Service desk staff may become overly dependent on workarounds and lose technical troubleshooting skills.

    Why it's wrong here

    Skill degradation is a plausible secondary concern, but it is not the most significant risk when high-impact incidents recur repeatedly. The primary risk is operational and financial impact from unresolved root causes. Focusing on staff skills would divert attention from the systemic failure to perform problem management and could result in remediation that does not prevent recurrence or reduce business disruption.

  • ✓

    Recurring incidents will continue to disrupt critical business services and increase operational cost without permanent resolution.

    Why this is correct

    Without problem records and root cause analysis, the underlying defect remains, causing repeated outages that affect availability, customer transactions, and regulatory obligations. Each recurrence consumes support resources, incurs recovery costs, and may breach service level agreements. This is the most significant risk because it directly threatens business operations and resilience, which is the core concern of the audit finding.

  • ✗

    Incident categorization and prioritization data will be unreliable, preventing accurate service level reporting.

    Why it's wrong here

    The scenario does not indicate that incidents are miscategorized or misprioritized; they are being resolved with workarounds and not escalated to problem management. Reporting accuracy could be affected indirectly, but the dominant risk is continued service disruption and escalating cost. Choosing reporting integrity over operational continuity misidentifies the primary control failure and the business impact of recurring incidents.

  • ✗

    The configuration management database will become inaccurate because workarounds are not reflected as changes.

    Why it's wrong here

    Configuration management database accuracy is important, but workarounds are typically temporary and may not require configuration changes. The described deficiency is the absence of problem management, not configuration recordkeeping. While some intersection exists, an inaccurate configuration management database is a narrower and less immediate risk than repeated disruption of critical financial services caused by unresolved root causes.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.