CISA Protection of Information Assets Practice Question
An IS auditor is reviewing a penetration test report that shows a critical vulnerability in a web application. The IT manager states that the vulnerability will not be fixed because it requires significant code changes and the application is being decommissioned in six months. What should the auditor do?
⚠ Common exam trap
The trap is the auditor's role confusion — candidates either overstep by escalating or recommending decommissioning, or understep by accepting the risk themselves, instead of verifying formal acceptance and compensating controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the risk has been formally accepted and compensating controls are implemented
The auditor's proper action is to verify that the risk has been formally accepted by the appropriate authority and that compensating controls are implemented (D). Risk acceptance is a legitimate management decision, but it must be documented, approved at the right level, and supported by mitigating controls given the criticality of the vulnerability. The auditor's role is to validate that this governance process occurred, not to unilaterally accept, escalate, or demand decommissioning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the decision as business risk acceptance
Why it's wrong here
An IS auditor cannot accept risk on management's behalf; acceptance requires the business owner's documented, authorised sign-off, which the IT manager has not provided. Risk acceptance is the correct route when the accountable owner formally approves the residual risk with informed justification and a defined review date.
- ✗
Escalate to senior management as a critical finding
Why it's wrong here
Escalation is premature: the auditor must first obtain documented risk acceptance from the accountable business owner, since the IT manager lacks authority to accept risk. Escalation is the right step when management refuses to accept or remediate a finding, or when the risk exceeds the agreed tolerance threshold.
- ✗
Recommend immediate decommissioning of the application
Why it's wrong here
Recommending decommissioning exceeds the auditor's advisory role and pre-empts management's decision; the auditor reports and verifies, not directs remediation. Recommending decommissioning would be appropriate only where continued operation breaches law, regulation or contractual obligation, making the risk non-negotiable.
- ✓
Verify that the risk has been formally accepted and compensating controls are implemented
Why this is correct
Verifying formal risk acceptance and compensating controls confirms the residual risk is documented, authorised by accountable management and mitigated, satisfying the auditor's duty to ensure the unfixed vulnerability is consciously owned rather than silently ignored before decommissioning.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.