Courseiva
Protection of Information AssetshardMultiple ChoiceObjective-mapped

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing a penetration test report that shows a critical vulnerability in a web application. The IT manager states that the vulnerability will not be fixed because it requires significant code changes and the application is being decommissioned in six months. What should the auditor do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Verify that the risk has been formally accepted and compensating controls are implemented

The auditor should verify that the risk is formally accepted by management and that compensating controls are in place to protect the application until decommissioning.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Accept the decision as business risk acceptance

    Why it's wrong here

    The auditor should ensure formal acceptance and compensating controls.

  • Escalate to senior management as a critical finding

    Why it's wrong here

    Escalation is warranted only if risk acceptance is not formalized.

  • Recommend immediate decommissioning of the application

    Why it's wrong here

    Decommissioning may have business impact and is not the auditor's call.

  • Verify that the risk has been formally accepted and compensating controls are implemented

    Why this is correct

    This ensures the risk is managed appropriately.

About these practice questions

This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.