CISA Protection of Information Assets Practice Question
An IS auditor is reviewing the vulnerability management program. The auditor notes that a critical vulnerability was identified in a production system six months ago and has not been patched due to a business impact assessment. Which of the following should the auditor examine NEXT?
⚠ Common exam trap
CISA often tests the principle that unpatched vulnerabilities are acceptable only with formal risk acceptance and compensating controls, so the trap is focusing on technical remediation or patch scheduling instead of verifying governance documentation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Whether a formal risk acceptance and compensating controls are in place
When a critical vulnerability remains unpatched due to a business impact assessment, the auditor's next step is to verify whether a formal risk acceptance and compensating controls are in place, because unpatched critical vulnerabilities require documented management approval and mitigating measures. This ensures the organization has consciously accepted the risk with proper governance rather than leaving it unaddressed. The auditor must confirm that the decision was authorized, documented, and supported by controls that reduce the residual risk to an acceptable level.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The technical details of the vulnerability
Why it's wrong here
Technical details of the vulnerability describe exploit mechanics, not whether the business impact assessment was properly authorised, documented or risk-accepted. It is tempting because understanding severity and exploitability informs risk decisions, and would be the correct focus when triaging a newly discovered vulnerability before any acceptance decision exists.
- ✗
The patch deployment schedule for the next quarter
Why it's wrong here
A future quarterly schedule shows planned remediation timing, not whether the existing deferral was formally risk-accepted and reviewed. It is tempting because scheduling is a genuine part of vulnerability management, and would be the correct focus once the auditor has confirmed that an approved, documented exception justifies the delay.
- ✓
Whether a formal risk acceptance and compensating controls are in place
Why this is correct
Unpatched critical vulnerabilities accepted for six months require documented risk acceptance and compensating controls. Examining these satisfies the stem's constraint by verifying that the business impact assessment was formally approved and that residual risk is mitigated, rather than merely deferred.
- ✗
The vendor's patch release notes
Why it's wrong here
Vendor patch release notes describe the fix and its prerequisites, not the governance of the six-month deferral. They are tempting because they confirm whether a remediating patch actually exists, and would be the right artefact when validating that a proposed patch addresses the specific vulnerability before scheduling deployment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.