CISA Governance and Management of IT Practice Question
An organization's IT department implemented a new change management process that requires all changes to be approved by a change advisory board (CAB). A critical security patch needs to be deployed within 2 hours to address an active zero-day vulnerability. The change request was submitted but the CAB is not scheduled to meet for another 24 hours. What is the BEST course of action?
⚠ Common exam trap
A common mix-up: candidates assume any critical security patch can be deployed immediately without approval (Option C) or that informing the CAB after the fact (Option A) is acceptable, but CISA emphasizes that even emergency changes must follow a defined process with expedited approval to maintain control and accountability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the emergency change process to obtain expedited approval from a designated CAB member.
It aligns with the ITIL-based emergency change process, which allows for expedited approval from a designated CAB member or emergency authority when a critical security patch must be deployed within hours to mitigate an active zero-day vulnerability. This ensures the change is authorized without waiting for the full CAB meeting, maintaining security while preserving governance and audit trails.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy the patch and inform the CAB after the fact during the next meeting.
Why it's wrong here
While prompt action is needed, proper emergency change procedures should be used, not a post-hoc notification without prior approval.
- ✗
Wait for the next scheduled CAB meeting to approve the change.
Why it's wrong here
Waiting 24 hours could expose the organization to the zero-day vulnerability for too long.
- ✗
Deploy the patch immediately without any approval as it is a critical security fix.
Why it's wrong here
Bypassing the change management process entirely is not appropriate; emergency procedures should be followed.
- ✓
Use the emergency change process to obtain expedited approval from a designated CAB member.
Why this is correct
An emergency change process allows swift approval for critical patches, balancing security and control.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.