CISA Protection of Information Assets Practice Question
An IS auditor is evaluating the patch management process. The auditor notes that critical security patches are applied within 30 days, but the policy requires 7 days. The IT manager states that the delay is due to testing requirements. What should the auditor recommend?
⚠ Common exam trap
CISA often tests the confusion between policy compliance and risk management; candidates may choose to modify the policy or accept the delay, but the correct answer is to recommend a risk-based approach that satisfies both security and operational needs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a risk-based patching process that allows faster deployment for critical patches
A risk-based patching process prioritizes critical patches for immediate deployment while allowing less critical patches to undergo standard testing. This balances security needs with operational stability, addressing the policy violation without sacrificing testing entirely. The auditor should recommend this approach because it aligns with industry best practices (e.g., NIST, ISO 27001) and enables faster remediation of high-risk vulnerabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement a risk-based patching process that allows faster deployment for critical patches
Why this is correct
A risk-based process lets critical patches be deployed faster than the current 30-day cycle while retaining testing for lower-risk updates, closing the gap against the 7-day policy requirement. It directly resolves the conflict between the IT manager's testing constraint and the mandated remediation timeline.
- ✗
Require automated patching without testing
Why it's wrong here
Deploying critical patches without any testing risks destabilising production systems and can introduce new vulnerabilities, so it replaces one exposure with another. It is tempting because speed closes the 7-day gap, but the correct approach is expedited, risk-based testing that still validates the patch before deployment.
- ✗
Accept the current practice as a compensating control
Why it's wrong here
A compensating control must provide equivalent mitigation; a 30-day delay for critical patches does not reduce exposure to the level the 7-day requirement demands, so nothing is actually compensated. It is tempting because testing does add assurance, but that is a process step, not a control substituting for timely remediation.
- ✗
Modify the policy to align with the actual patching timeline
Why it's wrong here
Lowering the mandated remediation window to match observed performance removes the control objective rather than closing the gap, leaving critical vulnerabilities exploitable for 30 days. It is tempting because policies should reflect operational reality, but a policy is revised only after risk acceptance by the appropriate authority, not to excuse non-compliance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.