nerdexam
Isaca

CISA · Question #365

Which of the following should be of GREATEST concern to an IS auditor reviewing onsite preventive maintenance for an organization's business-critical server hardware?

The correct answer is D. Preventive maintenance has not been approved by the information system owner. The greatest concern for an IS auditor would be if preventive maintenance has not been approved by the information system owner. Approval from the system owner ensures that the maintenance aligns with the organization's risk management and operational needs, and any unapproved ch

Submitted by rania.sa· Apr 18, 2026Governance and Management of IT

Question

Which of the following should be of GREATEST concern to an IS auditor reviewing onsite preventive maintenance for an organization’s business-critical server hardware?

Options

  • APreventive maintenance costs exceed the business's allocated budget
  • BPreventive maintenance is outsourced to multiple vendors without requiring nondisclosure
  • CThe preventive maintenance schedule is based on mean time between failures (MTBF)
  • DPreventive maintenance has not been approved by the information system owner

How the community answered

(44 responses)
  • A
    9% (4)
  • B
    5% (2)
  • C
    18% (8)
  • D
    68% (30)

Explanation

The greatest concern for an IS auditor would be if preventive maintenance has not been approved by the information system owner. Approval from the system owner ensures that the maintenance aligns with the organization's risk management and operational needs, and any unapproved changes could introduce unforeseen risks or vulnerabilities to business-critical

Topics

#Preventive Maintenance#System Owner#IT Governance#Authorization

Community Discussion

No community discussion yet for this question.

Full CISA Practice