Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

During a change management process review, an IS auditor finds that the change advisory board (CAB) approved a change that subsequently caused a major service outage. The change was classified as 'normal' with no emergency. What is the auditor's primary concern?

⚠ Common exam trap

The trap here is that candidates may focus on operational details (like testing or classification) rather than the governance failure of the CAB's impact assessment, which is the core audit concern in change management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The CAB did not adequately assess the potential impact of the change.

The primary concern is that the CAB approved a 'normal' change without adequately assessing its potential impact, leading to a major service outage. In ITIL-based change management, the CAB is responsible for evaluating the risk, impact, and resource requirements of a change before approval. A failure in this assessment indicates a breakdown in the change management process, which is the core issue an IS auditor must address.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The service desk was not notified of the change.

    Why it's wrong here

    Notification of the service desk is a procedural communication step, not the control that prevents an approved change from causing an outage. It would matter where impact assessment or scheduling depends on service desk awareness, but here the CAB already approved the change, so the failure lies in the assessment itself.

  • ✓

    The CAB did not adequately assess the potential impact of the change.

    Why this is correct

    The CAB approved a normal change without adequate impact assessment, so the review process failed to identify the outage risk before implementation. Since the change was not an emergency, it should have undergone full risk evaluation; the primary concern is that impact analysis was insufficient, allowing a disruptive change through the standard approval route.

  • ✗

    The change should have been classified as emergency.

    Why it's wrong here

    Reclassifying as emergency would have bypassed the CAB's normal review, yet the CAB did review and approve it, so classification was not the defect. Emergency classification suits urgent fixes that cannot wait for a scheduled CAB meeting; here the outage stemmed from the approved change's content, not its urgency.

  • ✗

    The change was not tested in a pre-production environment.

    Why it's wrong here

    Testing in pre-production is a control weakness, but the CAB approved a normal change, so the primary concern is why the change proceeded without adequate testing evidence or risk assessment reaching the board. It is tempting because untested changes commonly cause outages, yet the question centres on the approval decision itself.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.