CISA Governance and Management of IT Practice Question
A multinational corporation operates in a highly regulated industry. The IT governance framework includes a risk appetite statement approved by the board. Recently, the company suffered a significant data breach due to an unpatched vulnerability that had been identified three months earlier. The IT audit found that the vulnerability was reported to the IT department but was not prioritized for remediation because it was deemed low risk by the IT operations team. The incident response plan was not activated because the breach was not initially detected. The board wants to strengthen governance to prevent recurrence. The most effective course of action for the auditor to recommend is:
⚠ Common exam trap
CISA often tests the distinction between technical controls (patching, IDS) and governance controls (policy, escalation, risk appetite alignment); candidates frequently pick the technical fix when the scenario describes a governance failure.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establishing a formal vulnerability management policy that requires risk-based prioritization in accordance with the risk appetite and escalation to the IT risk committee for decisions outside tolerance
The root cause is a governance failure: the IT operations team made a risk-acceptance decision that exceeded its authority, without a formal process tying vulnerability prioritization to the board-approved risk appetite. A vulnerability management policy that mandates risk-based prioritization aligned with the risk appetite and requires escalation to the IT risk committee when findings fall outside tolerance directly addresses this governance gap. This is the most effective recommendation because it fixes the decision-making framework, not just the symptom.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploying an intrusion detection system to identify breaches sooner
Why it's wrong here
Detection addresses the breach going unnoticed, but the vulnerability was already identified and wrongly deprioritised, so the governance failure lies in risk assessment and escalation against the board's risk appetite. It tempts because IDS genuinely shortens dwell time where breaches go undetected.
- ✓
Establishing a formal vulnerability management policy that requires risk-based prioritization in accordance with the risk appetite and escalation to the IT risk committee for decisions outside tolerance
Why this is correct
A risk-based vulnerability management policy directly ties remediation priority to the board-approved risk appetite, closing the gap where IT operations unilaterally downgraded a known vulnerability. Mandatory escalation to the IT risk committee for items exceeding tolerance ensures governance oversight, preventing recurrence of undetected, unactioned exposures.
- ✗
Disciplining the IT operations team for not escalating the vulnerability
Why it's wrong here
Disciplining the team treats a symptom; the root cause is that no mechanism reconciled the team's low-risk rating with the board-approved risk appetite, so escalation criteria and oversight failed. It tempts because accountability for ignored findings is a legitimate control, but only where governance processes already exist.
- ✗
Implementing a more robust patch management system with automated patching
Why it's wrong here
Automated patching does not address the governance failure: the vulnerability was known and consciously deprioritised against the board's risk appetite, so the gap is risk escalation and oversight, not patch deployment speed. It tempts because automation genuinely reduces unpatched exposure where remediation backlogs stem from manual effort.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.