Courseiva
mediumMultiple Choice

CISA Practice Question: An IT auditor is reviewing the change management…

An IT auditor is reviewing the change management process for a financial application. The auditor finds that emergency changes are frequently implemented without post-implementation review. What is the MOST significant risk?

⚠ Common exam trap

CISA often tests the distinction between operational risks (e.g., outages, documentation) and security risks, expecting candidates to prioritize the risk with the most severe impact on confidentiality, integrity, and availability of financial data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Security vulnerabilities may be introduced and remain undetected

Emergency changes bypass the normal change management controls, including post-implementation review. Without a post-implementation review, any security vulnerabilities introduced by the change (e.g., misconfigurations, unpatched code, or weakened access controls) will not be identified and remediated. In a financial application, this can lead to data breaches, fraud, or regulatory non-compliance. Thus, the most significant risk is that security vulnerabilities remain undetected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The change may not be documented properly

    Why it's wrong here

    Documentation gaps are secondary; the absence of post-implementation review means unauthorised or faulty changes may reach production undetected. It is tempting because incomplete records are a familiar audit finding, and would be correct if the concern were audit trail completeness rather than unverified change outcomes.

  • ✗

    The change may cause an outage during the next backup cycle

    Why it's wrong here

    Outages during backup are speculative and narrow; the real exposure is unauthorised or defective code reaching production with no verification, so errors and fraud persist undetected. Post-implementation review exists precisely to validate emergency changes retrospectively. Backup-window timing is an availability concern addressed by scheduling, not change control.

  • ✓

    Security vulnerabilities may be introduced and remain undetected

    Why this is correct

    Without post-implementation review, emergency changes bypass verification, so malicious or accidental code and misconfigurations can enter production and persist unnoticed. This exposes the financial application to exploitable vulnerabilities that normal change controls would otherwise catch.

  • ✗

    Users may not be notified of the change

    Why it's wrong here

    User notification is a communication and training concern, not the core control failure. Without post-implementation review, a faulty or fraudulent emergency change can remain in production indefinitely, undermining financial reporting integrity. Notification matters for user-facing functionality changes, but it does not verify that the change itself was authorised, tested and correct.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.