CISA Information System Auditing Process Practice Question
An IS auditor is evaluating the results of a penetration test performed by an external vendor on a web-facing application. The report identifies a critical SQL injection vulnerability. Which of the following is the MOST appropriate action for the IS auditor to recommend FIRST?
⚠ Common exam trap
The trap here is allowing process steps such as report finalization, vendor confirmation, or committee escalation to take precedence over immediate containment of an actively exploitable critical vulnerability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Immediately remediate or mitigate the vulnerability and validate the fix before the report is finalized
A critical SQL injection vulnerability in an internet-facing application can be exploited to access or modify data, so the priority is to remediate or mitigate it immediately and confirm the fix. Reporting, re-testing by another vendor, or waiting for governance direction are appropriate supporting activities but must not delay protection of the exposed system.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Include the finding in the audit report and schedule remediation during the next quarterly patch cycle
Why it's wrong here
Deferring remediation of a critical, exploitable SQL injection flaw to a routine patch cycle leaves the application exposed for weeks or months, during which an attacker could extract or alter data. The severity and external exposure demand immediate action, not alignment with a standard maintenance schedule that is appropriate for lower-risk issues.
- ✗
Escalate the finding to the audit committee and await their direction before recommending remediation
Why it's wrong here
Notifying governance is appropriate for significant findings, but waiting for the audit committee to direct remediation before any action is taken leaves the vulnerability exploitable. The auditor should recommend immediate mitigation while simultaneously ensuring management and governance are informed, allowing both urgency and oversight to be satisfied.
- ✓
Immediately remediate or mitigate the vulnerability and validate the fix before the report is finalized
Why this is correct
A critical exploitable vulnerability in a web-facing application represents an immediate risk of data compromise. The auditor should recommend urgent remediation or mitigation, such as applying a patch, input validation, or a web application firewall rule, and then validate that the fix works. Addressing the exposure takes precedence over documentation and longer-term process improvements.
- ✗
Repeat the penetration test with a different vendor to confirm the finding is not a false positive
Why it's wrong here
Confirming findings is good practice, but commissioning a second vendor before acting delays protection of an exposed system. SQL injection findings are typically reproducible and well understood. If any doubt exists, the remediation team can verify the vulnerability directly while mitigation is applied, but confirmation should not precede urgent protective action.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.