CISA Practice Question: Information Systems Operations and Business Resilience
During a software asset management (SAM) audit, the IS auditor discovers that the organization is using software versions that are no longer supported by the vendor. What is the primary risk?
⚠ Common exam trap
The trap here is that candidates may focus on operational inconveniences like migration difficulty or licensing costs, overlooking the fact that the most critical and immediate risk from unsupported software is the lack of security patches, which directly enables exploitation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exposure to security vulnerabilities without patches.
The primary risk of using unsupported software versions is the absence of vendor-provided security patches. Without these patches, known vulnerabilities remain unaddressed, exposing the organization to exploitation, data breaches, and system compromise. This directly impacts the confidentiality, integrity, and availability of information assets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Exposure to security vulnerabilities without patches.
Why this is correct
Unsupported software no longer receives vendor security patches, so known vulnerabilities remain permanently exploitable. This directly satisfies the stem's primary risk: unmitigated exposure, since no remediation path exists until the version is upgraded or replaced.
- ✗
Inability to recover data from backups.
Why it's wrong here
Backup recovery depends on backup tooling and media integrity, not on whether the application vendor still supports its version. It is tempting because unsupported software may lack vendor remediation, yet restoring data from backups is unaffected by support status; the real exposure is unpatched vulnerabilities.
- ✗
Increased licensing costs due to non-compliance.
Why it's wrong here
Unsupported versions primarily expose the organisation to unpatched vulnerabilities, not higher fees; licensing cost arises from over-deployment or audit true-ups, not version age. It is tempting because vendor audits do levy penalties, but that risk stems from licence counts, not from running end-of-support software.
- ✗
Difficulty in migrating to new versions.
Why it's wrong here
Migration difficulty is an operational inconvenience, not the primary risk; unsupported software's core exposure is unpatched vulnerabilities that attackers can exploit. It is tempting because staying on old versions does complicate upgrades, but that is a future project cost rather than the immediate security risk the audit targets.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.