Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An IS auditor is reviewing an emergency change that was implemented to fix a critical security vulnerability. What is the most important post-implementation step?

⚠ Common exam trap

CISA often tests the principle that emergency changes still require retrospective approval and documentation, and candidates who prioritize technical follow-ups like CMDB updates or risk assessments over governance controls pick the wrong answer.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the change and obtain retrospective approval

Documenting the change and obtaining retrospective approval is the most important step because emergency changes bypass normal change control, and without proper documentation and after-the-fact authorization, the organization loses accountability and auditability. This step ensures the change is formally recorded in the change log and reviewed by the change advisory board (CAB) or equivalent authority, closing the governance gap created by the emergency. It also provides the audit trail needed for future reviews and compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Document the change and obtain retrospective approval

    Why this is correct

    Emergency changes bypass the normal change advisory board, so retrospective approval restores governance while documentation preserves the audit trail. This satisfies the IS auditor's requirement that emergency fixes still receive formal authorisation and traceability after implementation.

  • ✗

    Update the configuration management database

    Why it's wrong here

    Updating the configuration management database records the change but does not verify that the emergency fix was authorised, tested and documented after the fact. It is tempting because CMDB accuracy is a genuine change-management control, and would be correct once the change's legitimacy has been confirmed through review.

  • ✗

    Notify all users

    Why it's wrong here

    Notifying users communicates the change but verifies nothing about whether the emergency fix was properly authorised, tested or documented. It is tempting because communication is a recognised change-management activity, and would be correct when the change materially alters user-facing functionality or requires user action.

  • ✗

    Conduct a risk assessment

    Why it's wrong here

    A risk assessment evaluates exposure generally, but the emergency change has already been implemented, so the priority is retrospective review and approval of what was deployed. It is tempting because risk assessment underpins change management, and would be correct before approving a planned change.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.