hardMultiple Choice
CISA Practice Question: Wants to implement an exception management…
An organization wants to implement an exception management process for IT policies. Which of the following is the most important step to ensure effective control?
⚠ Common exam trap
The trap is selecting the option that sounds administratively convenient (auto-renewal or logging-only) instead of the one that enforces authorization, time-bounding, and review—the core control objectives of exception management.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Require a formal request with approval from an appropriate authority and a defined expiration date
An effective exception management process requires a formal request, approval by an appropriate authority (based on risk level), and a defined expiration date so the exception is time-bound and reviewed. This ensures exceptions are deliberate, authorized, and temporary rather than permanent control bypasses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Automatically renew exceptions every year unless revoked
Why it's wrong here
Automatic renewal perpetuates exceptions without re-validating the underlying business or risk justification, so stale exceptions survive indefinitely. It is tempting because scheduled review cycles suit low-risk, time-bound exceptions, but effective control demands periodic reassessment and explicit re-approval rather than default continuation.
- ✗
Allow any exception to be granted by the IT manager
Why it's wrong here
Concentrating approval authority in one IT manager removes segregation of duties and independent risk acceptance, letting operational staff self-authorise policy deviations. It is tempting because a single approver accelerates request handling, yet exceptions should be approved by the business owner or risk function accountable for the residual risk.
- ✓
Require a formal request with approval from an appropriate authority and a defined expiration date
Why this is correct
A formal request with authorised approval and a defined expiry date creates accountability and prevents exceptions becoming permanent. The expiry forces periodic re-evaluation, satisfying the need for an effective control rather than an open-ended waiver that quietly bypasses the policy.
- ✗
Log all exceptions but do not set expiration dates
Why it's wrong here
Logging without expiration dates leaves exceptions permanently open, so no mechanism forces re-evaluation or closure, and the risk register becomes stale. It is tempting because logging alone provides an audit trail, but effective exception management requires defined expiry and periodic review to limit exposure duration.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.