Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IT auditor is evaluating the capacity management process. Which of the following findings would be of MOST concern?

⚠ Common exam trap

CISA often tests the difference between a genuine control gap and a merely suboptimal configuration, so candidates wrongly flag reasonable settings like 80% thresholds or annual reviews instead of the fundamental absence of trend monitoring.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Resource utilization trends are not monitored

The core purpose of capacity management is to ensure that IT resources are sized and timed to meet current and future demand in a cost-effective manner. This is impossible without monitoring resource utilization trends, because trends are the predictive input that drives forecasting, threshold tuning, and procurement decisions. If trends are not monitored, the organization is reactive rather than proactive and will suffer either performance degradation or wasteful over-provisioning. Therefore, the absence of trend monitoring is the most significant control gap among the findings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Alert thresholds are set at 80% utilization

    Why it's wrong here

    An 80% alert threshold is a common, defensible trigger that gives lead time before saturation; it does not by itself indicate a control failure. It is tempting because any fixed percentage can look arbitrary, and would be the correct finding if thresholds were set so high that alerts fire only after capacity is already exhausted.

  • ✓

    Resource utilization trends are not monitored

    Why this is correct

    Without utilisation trend monitoring, capacity planning becomes reactive, so degradation and exhaustion are detected only after service impact. This directly violates the capacity management process's core requirement to anticipate future resource needs, making it the most concerning finding because it removes the early-warning mechanism on which every other capacity control depends.

  • ✗

    Capacity thresholds are reviewed annually

    Why it's wrong here

    Annual review of capacity thresholds can leave them misaligned with current workloads for months, but it is a periodic governance lapse rather than an immediate risk of unmonitored exhaustion. It is tempting because infrequent review sounds negligent, and would be the correct finding when thresholds are absent or never reviewed at all.

  • ✗

    Capacity reports are generated monthly

    Why it's wrong here

    Monthly capacity reporting still provides regular trending data for forecasting; the interval is a reporting cadence, not a monitoring gap. It is tempting because frequent reporting sounds weak, and would be the correct finding if reports were produced so rarely that growth trends could not inform timely procurement or scaling decisions.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.