CISA Practice Question: Information Systems Operations and Business Resilience
An IS auditor is reviewing the problem management process. The auditor finds that problem tickets are only created after a major incident, and there is no proactive analysis of incident trends to identify underlying problems. Which of the following is the MOST likely consequence of this approach?
⚠ Common exam trap
Many candidates confuse problem management with incident management; problem management is proactive and aims to prevent incidents, while incident management is reactive and aims to restore service quickly.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Recurring incidents will continue because their root causes are not identified and eliminated.
Proactive problem management analyzes incident trends to identify and resolve root causes before they cause major disruptions. Without it, recurring incidents persist because underlying problems are never addressed. The most likely consequence is therefore the continuation of recurring incidents, which can erode service quality and consume operational resources. The other options either describe unrelated impacts or positive outcomes that would not result from this weakness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Recurring incidents will continue because their root causes are not identified and eliminated.
Why this is correct
Without proactive problem management, the organization reacts only to major incidents, leaving chronic issues unresolved. Recurring incidents will persist, consuming resources and potentially causing service disruptions. The auditor should highlight this as the primary consequence because problem management aims to prevent incidents by addressing root causes. The lack of trend analysis means minor incidents that collectively indicate a larger problem are ignored, leading to a cycle of repeated failures.
- ✗
The incident management process will be unable to meet service level agreements for incident resolution.
Why it's wrong here
Incident management focuses on restoring service quickly, while problem management addresses root causes. The scenario does not indicate that incident resolution is failing; it states that problem tickets are only created after major incidents. Recurring incidents may strain resources, but the direct consequence is the persistence of problems, not necessarily SLA breaches for individual incidents. This option misattributes the impact of weak problem management to incident management performance.
- ✗
Known errors will be documented and workarounds will be available for all incidents.
Why it's wrong here
Known errors and workarounds are outputs of problem management. If problem management is reactive, known errors may not be documented, and workarounds may be ad hoc. This option describes a positive outcome that is unlikely given the described process. The auditor would expect the opposite: a lack of documented known errors and inconsistent workarounds. Therefore, this option is not a likely consequence of the weak problem management process.
- ✗
The change management process will be bypassed to implement fixes for recurring incidents.
Why it's wrong here
While urgent fixes might sometimes bypass change management, the scenario does not suggest that this is occurring. The core issue is the absence of proactive problem identification, which leads to unresolved root causes. Bypassing change management would be a separate control failure. The most direct consequence is the continuation of recurring incidents, making this option speculative and less relevant to the described process weakness.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.