CISA Protection of Information Assets Practice Question
An IS auditor is reviewing a penetration test report that shows a critical vulnerability in a web application. The IT manager states that the vulnerability will not be fixed because it requires significant code changes and the application is being decommissioned in six months. What should the auditor do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify that the risk has been formally accepted and compensating controls are implemented
The auditor should verify that the risk is formally accepted by management and that compensating controls are in place to protect the application until decommissioning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Accept the decision as business risk acceptance
Why it's wrong here
The auditor should ensure formal acceptance and compensating controls.
- ✗
Escalate to senior management as a critical finding
Why it's wrong here
Escalation is warranted only if risk acceptance is not formalized.
- ✗
Recommend immediate decommissioning of the application
Why it's wrong here
Decommissioning may have business impact and is not the auditor's call.
- ✓
Verify that the risk has been formally accepted and compensating controls are implemented
Why this is correct
This ensures the risk is managed appropriately.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.