CISA Domain 4A-7 Practice Test 001

This practice test covers Domain 4 (Information Systems Operations & Business Resilience) Subdomain A-7 (Problem and Incident Management) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 4A-7 Problem and Incident Management Practice Test 001
10 questions • Single best answer
Question 1
A managed IT service provider supports multiple client environments through a central service desk. During an audit of the incident management process, the IS auditor notes that recurring incidents are consistently resolved individually and closed, yet none are ever escalated into the problem management process for root cause analysis. Which finding is MOST significant?
    Question 2
    An IS auditor is evaluating the effectiveness of a retail bank's problem management process. Management asserts that repeat incidents have declined steadily over the past year and that the process is operating well. The auditor must decide which support to rely on. Which of the following would provide the BEST evidence to support management's assertion?
      Question 3
      During fieldwork, an IS auditor finds that a healthcare organization stores its incident records and its problem records in two separate systems with no cross-referencing between them. The audit lead is preparing to draw a conclusion on the maturity of the overall process. What should the IS auditor do FIRST?
        Question 4
        A government agency prioritizes incidents based solely on the raw number of users who report each one, without reference to any other factor. An IS auditor reviewing the incident management process is assessing how incidents are ranked for response and remediation. Which weakness in this prioritization approach is MOST significant?
          Question 5
          Following a major outage that disrupted customer transactions, a financial services firm restored service within its recovery target but performed no structured review of the event afterward. An IS auditor is drafting recommendations intended to strengthen the incident management process. Which recommendation is MOST appropriate in these circumstances?
            Question 6
            An IS auditor wants assurance that a telecommunications company resolves its high-priority incidents within agreed service levels. Management describes several different controls that operate over incident handling. The auditor must judge which offers the strongest ongoing assurance. Which control provides the BEST assurance that high-priority incidents are consistently resolved on time?
              Question 7
              An IS auditor reviewing an enterprise's problem management process notes that resolved problems and their associated workarounds are not recorded in any knowledge base. As a direct result, the service desk frequently re-diagnoses the same underlying issues from scratch each time they recur. Which finding is MOST significant?
                Question 8
                During an audit of an enterprise IT operations function, the IS auditor observes that the same analysts who resolve incidents can also close the related records and mark the root cause as identified, with no independent review of either action being performed. Which risk is MOST significant in this arrangement?
                  Question 9
                  An IS auditor is testing whether critical incidents at a manufacturing company are escalated in accordance with the organization's defined escalation procedures. Several possible sources of assurance are available to the auditor. Which of the following would provide the BEST evidence that escalation is functioning as intended?
                    Question 10
                    An IS auditor previously reported that recurring incidents at an insurance company were not being analyzed for root cause. During the follow-up engagement, management states that the corrective action is now fully complete and the issue resolved. What should the IS auditor do to determine whether the identified risk has been sufficiently addressed?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top