CISA Practice Question: Information Systems Operations and Business Resilience
During a change management review, an IS auditor discovers that a recent database upgrade was implemented without prior approval from the Change Advisory Board (CAB) because it was classified as a 'standard change.' However, the change involved migrating to a new database version that required application code modifications. What should concern the auditor most?
⚠ Common exam trap
The trap here is that candidates focus on the operational details (missing backout plan, business hours, testing) instead of recognizing that the misclassification of the change type is the fundamental control weakness that undermines the entire change management process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The change was implemented without CAB approval.
The core issue is that the change was misclassified as a 'standard change' to bypass CAB approval, but it required application code modifications, which means it was not pre-authorized and should have been treated as a normal or emergency change. Standard changes are low-risk, pre-approved, and typically involve no application code changes (e.g., applying a routine patch to a database that does not alter the schema or API). By bypassing CAB review, the organization lost the opportunity to assess risks, dependencies, and rollback procedures, which is a critical control failure in change management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The change was implemented without CAB approval.
Why this is correct
The change required code modifications, so it should not have been standard; thus CAB approval was needed.
- ✗
The change did not include a backout plan.
Why it's wrong here
A backout plan is important but not the most immediate concern given the misclassification.
- ✗
The change was implemented during business hours.
Why it's wrong here
Timing is a consideration but not the core issue.
- ✗
The change was implemented without testing.
Why it's wrong here
While testing is important, the primary issue is that the change was incorrectly categorized, bypassing CAB.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.