mediumMultiple Choice
CISA Practice Question: An IT auditor is reviewing the change management…
An IT auditor is reviewing the change management process for a financial application. The auditor finds that emergency changes are frequently implemented without post-implementation review. What is the MOST significant risk?
⚠ Common exam trap
CISA often tests the distinction between operational risks (e.g., outages, documentation) and security risks, expecting candidates to prioritize the risk with the most severe impact on confidentiality, integrity, and availability of financial data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security vulnerabilities may be introduced and remain undetected
Emergency changes bypass the normal change management controls, including post-implementation review. Without a post-implementation review, any security vulnerabilities introduced by the change (e.g., misconfigurations, unpatched code, or weakened access controls) will not be identified and remediated. In a financial application, this can lead to data breaches, fraud, or regulatory non-compliance. Thus, the most significant risk is that security vulnerabilities remain undetected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The change may not be documented properly
Why it's wrong here
Documentation gaps are secondary; the absence of post-implementation review means unauthorised or faulty changes may reach production undetected. It is tempting because incomplete records are a familiar audit finding, and would be correct if the concern were audit trail completeness rather than unverified change outcomes.
- ✗
The change may cause an outage during the next backup cycle
Why it's wrong here
Outages during backup are speculative and narrow; the real exposure is unauthorised or defective code reaching production with no verification, so errors and fraud persist undetected. Post-implementation review exists precisely to validate emergency changes retrospectively. Backup-window timing is an availability concern addressed by scheduling, not change control.
- ✓
Security vulnerabilities may be introduced and remain undetected
Why this is correct
Without post-implementation review, emergency changes bypass verification, so malicious or accidental code and misconfigurations can enter production and persist unnoticed. This exposes the financial application to exploitable vulnerabilities that normal change controls would otherwise catch.
- ✗
Users may not be notified of the change
Why it's wrong here
User notification is a communication and training concern, not the core control failure. Without post-implementation review, a faulty or fraudulent emergency change can remain in production indefinitely, undermining financial reporting integrity. Notification matters for user-facing functionality changes, but it does not verify that the change itself was authorised, tested and correct.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.