Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IS auditor is reviewing the end-of-life (EOL) software policy. Which THREE risks are associated with running unsupported software? (Select THREE).

⚠ Common exam trap

The trap is the distractor 'higher software licensing costs' — candidates assume old software is expensive, but EOL software is typically cheaper to license (or free) while being far riskier; the exam tests whether you focus on risk, not cost.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Regulatory non-compliance

Option B (Regulatory non-compliance) is correct because running EOL software often violates frameworks and mandates such as PCI DSS, HIPAA, or ISO 27001, which require supported, patched components, exposing the organization to fines and audit findings. Option D (Compatibility issues with newer systems) is correct because unsupported software no longer receives vendor updates, drivers, or patches, so it can fail to interoperate with current operating systems, databases, APIs, and hardware, causing integration and availability problems. Option E (Increased vulnerability to security breaches) is correct because once a vendor ends support, no new security patches are issued, leaving known and newly discovered CVEs permanently exploitable by attackers. Option A is not a risk of unsupported software; backups remain necessary regardless of support status, and EOL software does not reduce backup requirements. Option C is not inherently a risk of EOL software; licensing costs may actually drop or become irrelevant, and cost changes are not a standard risk associated with running unsupported software.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Reduced need for data backups

    Why it's wrong here

    Backup frequency and retention are driven by recovery objectives and data criticality, not by whether software is vendor-supported; running EOL code does not remove the need to back up. Reduced backup effort would only follow from decommissioning the system entirely, which is a separate decision.

  • ✓

    Regulatory non-compliance

    Why this is correct

    Unsupported software no longer receives security patches, so known vulnerabilities remain exploitable, undermining controls required by regulations such as GDPR, PCI DSS or HIPAA. This exposes the organisation to fines, sanctions and audit findings, satisfying the stem's regulatory non-compliance risk.

  • ✗

    Higher software licensing costs

    Why it's wrong here

    Unsupported software typically carries no vendor licence fee, so licensing costs fall rather than rise; the real risks are unpatched vulnerabilities, absent vendor support and compliance exposure. This option confuses EOL with subscription renewals, where rising per-user licence costs genuinely are a budget concern.

  • ✓

    Compatibility issues with newer systems

    Why this is correct

    Unsupported software lacks vendor updates and certification for current operating systems, middleware and hardware, so integration with newer platforms breaks or becomes unsupportable. This creates operational disruption and blocks upgrades, satisfying the stem's compatibility risk.

  • ✓

    Increased vulnerability to security breaches

    Why this is correct

    Unsupported software no longer receives vendor security patches, so known exploits remain unmitigated. This directly satisfies the EOL policy risk by exposing systems to breaches that supported versions would have fixed, making it a core risk the auditor must report.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.