Courseiva
mediumMultiple Choice

CISA Practice Question: A security auditor discovers that a server has…

A security auditor discovers that a server has been compromised due to an unpatched vulnerability. Which of the following would have most effectively prevented this incident?

⚠ Common exam trap

Many candidates choose a detective or preventive control (like a firewall or HIDS) that mitigates the attack surface or detects the breach, rather than recognizing that patching is the only option that eliminates the root cause of the vulnerability itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing a vulnerability management program with regular patching.

A vulnerability management program with regular patching directly addresses the root cause of the compromise: the unpatched vulnerability. By systematically identifying, prioritizing, and applying security patches, the organization eliminates the known weakness that the attacker exploited. This proactive measure prevents the initial compromise, whereas other controls only detect or limit the attack after the vulnerability is exploited.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enabling firewall rules to limit access.

    Why it's wrong here

    Firewall rules restrict network reachability, yet the vulnerability remained exploitable on any permitted path, so patching was still required. It is tempting because segmentation genuinely reduces exposure, and it would be correct had the attacker reached an internal service that should have been blocked.

  • ✓

    Implementing a vulnerability management program with regular patching.

    Why this is correct

    A vulnerability management programme with regular patching directly addresses the root cause: the unpatched software flaw. Continuous scanning identifies missing updates, and scheduled remediation closes the exposure window before attackers exploit it, which no detective or compensating control could achieve as effectively.

  • ✗

    Installing a host-based intrusion detection system (HIDS).

    Why it's wrong here

    A HIDS detects and alerts on suspicious host activity after exploitation; it does not remove the vulnerability, so the incident still occurs. It is tempting because intrusion detection supports response, and it would be the right choice if the requirement were earlier detection rather than prevention.

  • ✗

    Using strong passwords on the server.

    Why it's wrong here

    Strong passwords control authentication, but the compromise exploited an unpatched vulnerability, which password strength cannot remediate. It is tempting because credential hardening is a core control, and it would be the right answer had the breach resulted from brute force or credential stuffing rather than a missing software patch.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.