Information Systems Acquisition, Development, and Implementation →hardMultiple ChoiceObjective-mapped
CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An IS auditor is evaluating the change management process for a critical financial application. The auditor finds that all standard changes are approved by the Change Advisory Board (CAB). However, emergency changes are approved by the IT manager and later ratified by the CAB. Which of the following is the greatest risk associated with this process?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
There is no clear definition of what constitutes an emergency change.
Without a well-defined definition of what constitutes an emergency, changes could be misclassified to bypass CAB scrutiny, weakening controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The IT manager may not have sufficient technical expertise to approve emergency changes.
Why it's wrong here
While possible, the greater risk is misclassification.
- ✗
Emergency changes may be delayed while waiting for CAB ratification.
Why it's wrong here
Ratification after implementation is typical and not a major risk.
- ✗
The CAB may not have enough time to review emergency changes properly.
Why it's wrong here
Emergency changes are designed to bypass full review, so time is not the issue.
- ✓
There is no clear definition of what constitutes an emergency change.
Why this is correct
Without a clear definition, non-emergency changes could be inappropriately fast-tracked.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.