CISA Practice Question: Information Systems Operations and Business Resilience
During a change management process review, an IS auditor finds that the change advisory board (CAB) approved a change that subsequently caused a major service outage. The change was classified as 'normal' with no emergency. What is the auditor's primary concern?
⚠ Common exam trap
The trap here is that candidates may focus on operational details (like testing or classification) rather than the governance failure of the CAB's impact assessment, which is the core audit concern in change management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The CAB did not adequately assess the potential impact of the change.
The primary concern is that the CAB approved a 'normal' change without adequately assessing its potential impact, leading to a major service outage. In ITIL-based change management, the CAB is responsible for evaluating the risk, impact, and resource requirements of a change before approval. A failure in this assessment indicates a breakdown in the change management process, which is the core issue an IS auditor must address.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The service desk was not notified of the change.
Why it's wrong here
Notification of the service desk is a procedural communication step, not the control that prevents an approved change from causing an outage. It would matter where impact assessment or scheduling depends on service desk awareness, but here the CAB already approved the change, so the failure lies in the assessment itself.
- ✓
The CAB did not adequately assess the potential impact of the change.
Why this is correct
The CAB approved a normal change without adequate impact assessment, so the review process failed to identify the outage risk before implementation. Since the change was not an emergency, it should have undergone full risk evaluation; the primary concern is that impact analysis was insufficient, allowing a disruptive change through the standard approval route.
- ✗
The change should have been classified as emergency.
Why it's wrong here
Reclassifying as emergency would have bypassed the CAB's normal review, yet the CAB did review and approve it, so classification was not the defect. Emergency classification suits urgent fixes that cannot wait for a scheduled CAB meeting; here the outage stemmed from the approved change's content, not its urgency.
- ✗
The change was not tested in a pre-production environment.
Why it's wrong here
Testing in pre-production is a control weakness, but the CAB approved a normal change, so the primary concern is why the change proceeded without adequate testing evidence or risk assessment reaching the board. It is tempting because untested changes commonly cause outages, yet the question centres on the approval decision itself.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.