CISA Practice Question: Information Systems Operations and Business Resilience
An organization uses automated job scheduling with dependency management. A critical nightly batch job failed because a prerequisite job did not complete successfully. The job scheduler automatically attempted to rerun the failed job three times, each time failing due to the same dependency. The operations team was not alerted until the next morning. What control should the auditor recommend to improve this process?
⚠ Common exam trap
The trap here is that candidates focus on the retry mechanism (Option A) or the dependency structure (Options C and D) instead of recognizing that the fundamental control gap is the absence of real-time notification, which is a core operations resilience requirement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement real-time alerts for job failures and dependency issues.
The core issue is the lack of timely notification, not the number of retries or the dependency logic itself. The job scheduler correctly identified the dependency failure and attempted reruns, but the operations team remained unaware until the next morning. Implementing real-time alerts for job failures and dependency issues (Option B) ensures that the operations team can intervene immediately, rather than discovering the problem hours later during a manual check.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the number of automatic rerun attempts.
Why it's wrong here
More reruns repeat the same dependency failure and still leave the team uninformed until morning, so the detection gap persists. Reruns suit transient faults such as brief network blips. Alerting on prerequisite-job failure or exhausted retries addresses the actual control weakness: no timely notification.
- ✓
Implement real-time alerts for job failures and dependency issues.
Why this is correct
Real-time alerts notify operations the moment a job fails or a dependency breaks, rather than after repeated silent retries. This satisfies the stem's detection constraint, since the failure went unnoticed until morning; alerting enables prompt intervention before downstream processing windows are missed.
- ✗
Remove dependency management for critical jobs.
Why it's wrong here
Removing dependency management lets the critical job run regardless of prerequisite state, producing corrupt or incomplete output, and still provides no alerting. Dependencies are the correct control when downstream jobs must consume upstream results; removal suits only fully independent jobs.
- ✗
Schedule all critical jobs to run sequentially without dependencies.
Why it's wrong here
Sequential scheduling without dependencies discards the dependency graph, so a failed prerequisite still cannot block downstream jobs and no alerting is added. Dependency management exists precisely to gate jobs on upstream success; it is the right choice when jobs genuinely have no interdependencies and strict ordering suffices.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.