Courseiva

CISA Protection of Information Assets Practice Question

An IS auditor is reviewing an organization's vulnerability management program. The auditor notes that a critical vulnerability in a key application has not been patched for 90 days, and there is no documented risk acceptance. What should the auditor do FIRST?

⚠ Common exam trap

CISA often tests the auditor's sequence of evidence gathering before drawing conclusions, so the trap is jumping to reporting or escalation without first assessing whether compensating controls mitigate the risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Determine if compensating controls exist to mitigate the vulnerability

The auditor should first determine if compensating controls exist to mitigate the vulnerability, because the presence of effective compensating controls may reduce the residual risk to an acceptable level even without patching. This step gathers evidence before concluding on the adequacy of risk treatment. Only after understanding the control environment can the auditor assess whether the lack of patching and risk acceptance constitutes a significant finding.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Report the finding as a non-compliance with the patch management policy

    Why it's wrong here

    Auditors must first gather sufficient evidence and validate the finding before reporting non-compliance; the 90-day gap and absent risk acceptance are indicators, not yet confirmed conclusions. Reporting immediately is tempting because policy breach appears obvious, but that step belongs after verification and discussion with management.

  • ✗

    Discuss with management the absence of a risk acceptance

    Why it's wrong here

    Discussing with management is a later step; the auditor must first gather sufficient evidence and understand why the patch is outstanding. Discussion is appropriate once facts are established and the auditor needs management's explanation or remediation commitment.

  • ✗

    Escalate the issue to senior management immediately

    Why it's wrong here

    Escalating immediately bypasses the auditor's duty to verify the finding and understand management's position; escalation follows documented evidence and prior communication. Immediate escalation suits situations involving imminent fraud or danger, not an unpatched vulnerability still under review.

  • ✓

    Determine if compensating controls exist to mitigate the vulnerability

    Why this is correct

    Before escalating or reporting, the auditor must establish whether existing compensating controls already reduce the vulnerability's exploitability, since unpatched systems are often mitigated by segmentation, virtual patching or monitoring, which determines the actual residual risk.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.