CISA Protection of Information Assets Practice Question
During an audit of the incident management process, the IS auditor finds that tabletop exercises have not been conducted in the past two years. What is the MOST significant risk associated with this finding?
⚠ Common exam trap
CISA often tests the distinction between detection capabilities and response readiness — candidates may incorrectly attribute detection failures to a lack of exercises when exercises actually test response roles and plan effectiveness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Employees may not know their roles during an incident
Tabletop exercises are primarily designed to validate and practice the incident response plan by walking participants through simulated scenarios, which reveals whether employees understand their roles, responsibilities, and decision-making authority during an incident. Without them, the most significant risk is that staff will be unprepared and confused when a real incident occurs, leading to delayed or ineffective response.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The organization may fail to detect an incident in a timely manner
Why it's wrong here
Tabletop exercises test response procedures and decision-making, not detection capability; detection depends on monitoring, SIEM alerts and logging. The option is tempting because exercises do surface gaps in escalation and communication, but timely detection is addressed by tuning monitoring tools, not by rehearsing scenarios.
- ✗
The organization may not comply with regulatory reporting requirements
Why it's wrong here
Regulatory reporting is governed by legal obligations and notification workflows, which tabletop exercises only incidentally touch. The option tempts because exercises can reveal unclear reporting chains, yet compliance failures stem from absent policies or missed deadlines, not from a lack of scenario rehearsals.
- ✗
The incident response plan may be outdated
Why it's wrong here
An outdated plan is a documentation concern; the graver risk is that staff cannot execute the plan under pressure, leaving response capability unvalidated. It is tempting because plan currency is auditable, but it would be correct if the finding were that the plan had never been reviewed or updated.
- ✓
Employees may not know their roles during an incident
Why this is correct
Without tabletop exercises, staff never rehearse incident roles, so during a real event they may duplicate effort, miss escalation steps or fail to contain the breach promptly. This directly addresses the stem's two-year gap in exercising, leaving role familiarity untested.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.