Courseiva
mediumMultiple Choice

CISA Practice Question: An IT policy exception is requested to allow a…

An IT policy exception is requested to allow a legacy system that cannot be patched to remain in operation. What is the BEST way to manage this exception?

⚠ Common exam trap

CISA often tests the principle that exceptions are never permanent — the trap is choosing 'approve indefinitely' as the business-friendly answer when the correct answer always includes compensating controls and a time limit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Approve with compensating controls and a sunset date

The best way to manage a policy exception for an unpatachable legacy system is to approve it conditionally — with compensating controls that reduce the residual risk and a sunset date that forces eventual decommissioning or replacement. This aligns with ISACA's risk management guidance: exceptions should be time-bound, risk-assessed, and mitigated, never open-ended. Compensating controls (e.g., network segmentation, enhanced monitoring, virtual patching) address the risk that patching would normally cover.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Approve with compensating controls and a sunset date

    Why this is correct

    Compensating controls mitigate the unpatched system's exposure while a sunset date bounds the residual risk and forces eventual remediation. This satisfies the exception-management requirement by providing documented, time-limited acceptance rather than indefinite tolerance of an unpatchable legacy system.

  • ✗

    Reject the request and force the system to be patched

    Why it's wrong here

    Forcing patching is unachievable where the vendor no longer supplies fixes, so the request would simply be bypassed. Rejection is tempting because it enforces policy absolutely, yet the correct approach documents compensating controls, residual risk acceptance and a time-bound remediation plan.

  • ✗

    Escalate to the board for decision

    Why it's wrong here

    Board escalation bypasses the risk owner who holds authority to accept the residual risk and compensating controls. Escalation is tempting for high-impact exposures, yet routine exceptions belong with management, with the board reserved for enterprise-level risk appetite decisions rather than individual legacy-system approvals.

  • ✗

    Approve the exception indefinitely to avoid disruption

    Why it's wrong here

    Indefinite approval removes any review trigger, so the unpatched exposure persists unmanaged. It is tempting because it avoids immediate disruption, yet the correct approach grants a time-bound exception with compensating controls, a remediation deadline and scheduled reassessment of the residual risk.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.