Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IT auditor is reviewing the capacity management process. Which TWO of the following are key activities that should be performed?

⚠ Common exam trap

CISA often tests whether candidates can distinguish capacity management activities (utilization monitoring, threshold alerting) from adjacent disciplines like backup verification, incident management, and disaster recovery testing.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Monitoring resource utilization trends

Capacity management focuses on ensuring IT resources meet current and future demand, so option B (Monitoring resource utilization trends) is correct because tracking CPU, memory, storage, and network usage over time is the foundational activity that reveals whether capacity is adequate and where growth is heading. Option D (Setting threshold alerts for resource usage) is also correct because defining thresholds and alerts (for example, at 80% CPU or disk utilization) enables proactive notification before performance degrades, allowing timely scaling or remediation. Together, B and D represent the core capacity management cycle of measuring trends and acting on predefined limits. Option A (Performing daily backup verification) belongs to backup and recovery management, not capacity management. Option C (Reviewing incident response times) is a service-level or incident management metric, and option E (Conducting annual disaster recovery tests) is a business continuity and disaster recovery activity, neither of which addresses resource capacity planning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Performing daily backup verification

    Why it's wrong here

    Backup verification belongs to availability and data management, not capacity management, which forecasts resource demand against current and future utilisation. It is tempting because both are operational IT processes an auditor reviews, but backup verification would be the correct focus when auditing data restoration or backup controls.

  • ✓

    Monitoring resource utilization trends

    Why this is correct

    Monitoring resource utilisation trends underpins capacity management by revealing consumption patterns before thresholds are breached, satisfying the need to forecast demand and plan procurement. Auditors verify that trend data feeds tuning and scaling decisions, rather than relying on point-in-time snapshots, which would miss gradual saturation across servers, storage and network links.

  • ✗

    Reviewing incident response times

    Why it's wrong here

    Incident response times measure security and service management performance, not capacity management, which analyses resource consumption, thresholds and growth forecasting. It is tempting because both are metrics auditors examine, but incident response times would be the correct focus when auditing incident management or security operations.

  • ✓

    Setting threshold alerts for resource usage

    Why this is correct

    Threshold alerts detect when resource consumption approaches defined limits, enabling proactive intervention before performance degrades. This satisfies capacity management's requirement to monitor current utilisation against baselines and forecast future demand, ensuring infrastructure scales ahead of business growth rather than reacting to outages.

  • ✗

    Conducting annual disaster recovery tests

    Why it's wrong here

    Disaster recovery testing addresses resilience and continuity planning, not capacity management, which monitors resource utilisation, trends and demand forecasting. It is tempting because both are periodic IT governance activities, but DR testing would be the correct answer when auditing business continuity or recovery capability instead.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.