CISA Practice Question: Information Systems Operations and Business Resilience
An organization is implementing a new release management process. Which TWO activities are essential components of a successful release?
⚠ Common exam trap
CISA often tests the boundary between release management and adjacent ITIL processes; the trap is selecting operational processes like incident or capacity management that support but are not components of a release.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Release planning
Release planning (B) is essential because it defines the scope, schedule, resources, and coordination of the release, ensuring that the release package and its deployment are agreed upon and aligned with business needs. Testing (E) is essential because the release must be validated against defined acceptance criteria and quality requirements before deployment, reducing the risk of defects or failed changes reaching production. The other options are not core release activities: service desk operations (A) handle day-to-day user support and incident intake, capacity management (C) ensures sufficient resource capacity for services, and incident management (D) restores normal service operation after disruptions, all of which are separate ITIL practices rather than essential components of a release itself.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Service desk operations
Why it's wrong here
Service desk operations handle user incidents and requests after deployment; they do not control the build, approval or deployment of a release. It is tempting because the service desk often receives release-related tickets, but release management's essential activities are change scheduling and configuration control of release components.
- ✓
Release planning
Why this is correct
Release planning defines scope, schedule, dependencies and acceptance criteria before build begins, giving the release process its controlled baseline. Without this upfront activity, subsequent build, test and deployment stages lack agreed entry criteria, so the release cannot be managed or authorised against defined expectations.
- ✗
Capacity management
Why it's wrong here
Capacity management ensures infrastructure resources meet current and future demand; it does not gate whether a release is authorised to enter production. It is tempting because releases depend on adequate capacity, but release management's essential components are change scheduling and configuration/version control of the release package.
- ✗
Incident management
Why it's wrong here
Incident management restores service after disruption; it reacts to failures rather than governing how changes are packaged, tested and deployed. It is tempting because releases can cause incidents, but release management's essential components are change scheduling and configuration/version control, not post-incident restoration.
- ✓
Testing
Why this is correct
Testing verifies that the release meets functional and regression requirements within a controlled environment before production deployment, directly reducing the risk of defects reaching live services. It provides the objective evidence release management needs to authorise promotion, satisfying the essential verification component of a successful release.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.