nerdexam
IsacaIsaca

CISA · Question #28

CISA Question #28: Real Exam Question with Answer & Explanation

Sign in or unlock CISA to reveal the answer and full explanation for question #28. The question stem and answer options stay visible for context.

Submitted by joshua94· Apr 18, 2026Information Systems Operations and Business Resilience

Question

Which of the following would be of MOST concern for an IS auditor evaluating the design of an organization's incident management processes?

Options

  • APrioritization criteria are not defined.
  • BService management standards are not followed.
  • CExpected time to resolve incidents is not specified.
  • DMetrics are not reported to senior management.

Unlock CISA to see the answer

You've previewed enough free CISA questions. Unlock CISA for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Incident Management#Process Design#Prioritization#IS Audit Concerns
Full CISA PracticeBrowse All CISA Questions