CISA Practice Question: Information Systems Operations and Business Resilience
An IT auditor is evaluating the capacity management process. Which of the following findings would be of MOST concern?
⚠ Common exam trap
CISA often tests the difference between a genuine control gap and a merely suboptimal configuration, so candidates wrongly flag reasonable settings like 80% thresholds or annual reviews instead of the fundamental absence of trend monitoring.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Resource utilization trends are not monitored
The core purpose of capacity management is to ensure that IT resources are sized and timed to meet current and future demand in a cost-effective manner. This is impossible without monitoring resource utilization trends, because trends are the predictive input that drives forecasting, threshold tuning, and procurement decisions. If trends are not monitored, the organization is reactive rather than proactive and will suffer either performance degradation or wasteful over-provisioning. Therefore, the absence of trend monitoring is the most significant control gap among the findings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Alert thresholds are set at 80% utilization
Why it's wrong here
An 80% alert threshold is a common, defensible trigger that gives lead time before saturation; it does not by itself indicate a control failure. It is tempting because any fixed percentage can look arbitrary, and would be the correct finding if thresholds were set so high that alerts fire only after capacity is already exhausted.
- ✓
Resource utilization trends are not monitored
Why this is correct
Without utilisation trend monitoring, capacity planning becomes reactive, so degradation and exhaustion are detected only after service impact. This directly violates the capacity management process's core requirement to anticipate future resource needs, making it the most concerning finding because it removes the early-warning mechanism on which every other capacity control depends.
- ✗
Capacity thresholds are reviewed annually
Why it's wrong here
Annual review of capacity thresholds can leave them misaligned with current workloads for months, but it is a periodic governance lapse rather than an immediate risk of unmonitored exhaustion. It is tempting because infrequent review sounds negligent, and would be the correct finding when thresholds are absent or never reviewed at all.
- ✗
Capacity reports are generated monthly
Why it's wrong here
Monthly capacity reporting still provides regular trending data for forecasting; the interval is a reporting cadence, not a monitoring gap. It is tempting because frequent reporting sounds weak, and would be the correct finding if reports were produced so rarely that growth trends could not inform timely procurement or scaling decisions.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.