Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

During a software asset management (SAM) audit, the IS auditor discovers that the organization is using software versions that are no longer supported by the vendor. What is the primary risk?

⚠ Common exam trap

The trap here is that candidates may focus on operational inconveniences like migration difficulty or licensing costs, overlooking the fact that the most critical and immediate risk from unsupported software is the lack of security patches, which directly enables exploitation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Exposure to security vulnerabilities without patches.

The primary risk of using unsupported software versions is the absence of vendor-provided security patches. Without these patches, known vulnerabilities remain unaddressed, exposing the organization to exploitation, data breaches, and system compromise. This directly impacts the confidentiality, integrity, and availability of information assets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Exposure to security vulnerabilities without patches.

    Why this is correct

    End-of-life software no longer receives security updates.

  • Inability to recover data from backups.

    Why it's wrong here

    Backup recovery is not directly affected by software support.

  • Increased licensing costs due to non-compliance.

    Why it's wrong here

    Licensing compliance is separate from support status.

  • Difficulty in migrating to new versions.

    Why it's wrong here

    Migration difficulty is a secondary concern.

About these practice questions

One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.