CISA Practice Question: Information Systems Operations and Business Resilience
An IT auditor is reviewing the release management process. Which of the following is the MOST important control to ensure that new releases do not negatively impact production systems?
⚠ Common exam trap
CISA often tests the distinction between preventive and detective controls, and candidates may incorrectly select rollback plans or CAB approval as the most important because they are prominent in change management, but the question asks for the control that ensures releases do not negatively impact production, which is preventive testing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Testing in a pre-production environment
Testing in a pre-production environment is the most critical control because it validates that the new release functions correctly and integrates with existing systems before it reaches production. This environment mirrors production, allowing defects, compatibility issues, and performance problems to be identified and resolved without impacting live operations. While other controls like rollback plans and approvals are important, they are reactive or administrative; pre-production testing is the primary proactive measure to prevent negative impacts.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Testing in a pre-production environment
Why this is correct
Testing in a pre-production environment replicates production configuration, letting defects surface before deployment and satisfying the requirement to prevent negative production impact. Unlike post-implementation review or change approval alone, it validates functional and integration behaviour against realistic data, providing detective evidence that the release is safe to promote.
- ✗
Rollback plan
Why it's wrong here
A rollback plan restores the prior state after a failed release, so it mitigates impact rather than preventing it; the stem asks for the control ensuring releases do not negatively affect production. Rollback is the right choice when recovery time objectives demand rapid reversion, but it cannot stop defective code reaching live systems.
- ✗
Communication to users
Why it's wrong here
Communication to users informs stakeholders of changes but cannot prevent production impact; it neither validates the release against production baselines nor provides rollback capability. It is tempting because user notification genuinely supports change management adoption and expectation-setting, and would be the right control where the risk is user confusion or unmanaged demand, rather than technical failure.
- ✗
Approval from the change advisory board
Why it's wrong here
CAB approval authorises a change but does not itself verify that the release will not harm production; testing evidence and rollback readiness do that. CAB approval is the correct control when the question concerns change authorisation and scheduling.
Visual reference
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.