Courseiva
mediumMultiple ChoiceObjective-mapped

CISA Practice Question: A large organization is implementing a new HR…

A large organization is implementing a new HR management system to handle payroll and employee data. The project is currently in the build phase with a planned go-live in three months. Recently, the vendor notified the project team that a critical security patch will be released in two months that addresses a data leakage vulnerability present in the current version. The patch includes new features that are not in the contract. The project manager estimates that integrating the patch and re-testing will delay the project by at least four months. Business stakeholders insist on meeting the original go-live date because the legacy system is being decommissioned. The organization has a strict policy that all systems processing sensitive data must have the latest security patches within 30 days of release. What should the project team do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Delay the go-live and integrate the security patch before going live

The organization's policy mandates that all systems processing sensitive data must have the latest security patches within 30 days of release. Going live without the patch would violate this policy and expose the system to a known data leakage vulnerability for up to 30 days, even with compensating controls. Delaying go-live to integrate the patch before going live ensures compliance and mitigates the risk. Option A is incorrect because applying a compensating control does not satisfy the policy requirement and leaves the vulnerability unpatched. Option B is incorrect because going live without the patch and applying it after go-live would still result in a period of non-compliance and potential data leakage. Option D is incorrect because relying on negotiation for an early fix is uncertain and may not resolve the issue within the required timeframe, and the delay for integration and testing would still occur.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Proceed with go-live but apply a compensating control to mitigate the vulnerability until the patch is applied

    Why it's wrong here

    Compensating controls may not fully mitigate, and policy requires patching within 30 days of release.

  • Continue with the current version, go live as planned, and schedule the security patch installation after go-live within the 30-day window

    Why it's wrong here

    Even if applied within 30 days, the system would be vulnerable for up to 30 days, violating the spirit of the policy which likely requires patching before production.

  • Delay the go-live and integrate the security patch before going live

    Why this is correct

    This ensures compliance with the patching policy and protects sensitive data from the vulnerability.

  • Negotiate with the vendor to obtain an early fix for the vulnerability without the new features to minimize delay

    Why it's wrong here

    Negotiations may not succeed and would still cause some delay.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.