Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IS auditor is evaluating how an organization manages operating system patches on internet-facing web servers. The patch management procedure requires testing in a staging environment, approval by the change manager, and deployment within 30 days of release. The auditor finds that emergency patches for critical vulnerabilities are deployed directly to production within 24 hours without staging tests. Which of the following is the MOST appropriate conclusion?

⚠ Common exam trap

The trap here is concluding that any deviation from the standard patch process is automatically a finding, rather than evaluating whether the emergency path has its own compensating controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The emergency process is acceptable if it includes documented authorization, a rollback plan, and post-deployment verification.

Emergency patching is a necessary capability when critical vulnerabilities on internet-facing systems could be exploited before a normal change cycle completes. The control objective is not to prohibit the bypass but to ensure it is governed: authorized by an accountable person, accompanied by a rollback plan, and verified after deployment. If those compensating controls are documented and evidenced, the emergency path is an acceptable risk-based exception to the standard patch procedure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The staging environment should be eliminated so all patches follow the same emergency path.

    Why it's wrong here

    Removing staging tests for all patches would eliminate the safeguard that catches compatibility and stability problems before they affect production. Staging exists precisely to reduce the chance that a patch disrupts critical services. The correct response is to preserve routine testing while defining a controlled exception for emergencies, not to abandon testing as a practice and expose every change to production risk.

  • ✗

    The emergency process is a control weakness because it bypasses testing entirely.

    Why it's wrong here

    Bypassing staging tests does introduce risk, but a blanket conclusion that the process is a weakness ignores the reality that critical internet-facing vulnerabilities may be exploited within hours. The appropriate control is not to forbid emergency deployment but to govern it with documented authorization, a rollback plan, and post-deployment verification. The auditor should assess whether those compensating controls exist rather than condemning the practice outright.

  • ✓

    The emergency process is acceptable if it includes documented authorization, a rollback plan, and post-deployment verification.

    Why this is correct

    Emergency patching of critical vulnerabilities on internet-facing systems is a legitimate risk response when the exposure window is short. What makes it acceptable is compensating control: a documented approval by an authorized person, a tested rollback plan in case the patch breaks the service, and verification after deployment that the patch applied and the service functions. This balances the security risk of delay against the operational risk of untested change.

  • ✗

    The 30-day deployment window for routine patches is too long and should be shortened to 7 days.

    Why it's wrong here

    Shortening the routine window may be advisable for some risk profiles, but it does not address the control question raised by the emergency bypass. The auditor's focus is whether the exception path is governed, not whether the standard timeline is optimal. Recommending a specific new timeframe without analyzing the organization's risk tolerance and testing capacity would be premature and outside the immediate finding.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.