Courseiva

CISA Information System Auditing Process Practice Question

During an audit of a data center, an IS auditor discovers that a critical server's operating system has not been patched for eight months because the vendor's patch conflicted with a legacy application. Management accepts the risk and documents a compensating control of enhanced network monitoring. Which of the following should the IS auditor do NEXT?

⚠ Common exam trap

The trap here is assuming that documented management risk acceptance ends the auditor's work, when the auditor must still assess whether the compensating control actually reduces risk to an acceptable level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Evaluate the design and operating effectiveness of the compensating control before concluding

Because management chose to accept the risk and rely on a compensating control, the auditor's next step is to test whether that control genuinely mitigates the risk. Only after evaluating its design and operating effectiveness can the auditor judge residual risk and decide how to report the matter. Simply accepting the documentation, dictating remediation, or jumping to application replacement all bypass the required evaluation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Remove the finding from the report because management formally accepted the risk

    Why it's wrong here

    Management's risk acceptance does not obligate the auditor to omit the matter. The auditor should still evaluate whether the acceptance is informed and whether the compensating control is effective, then report the situation, including management's response. Removing the finding entirely would prevent the audit committee from understanding that a critical server remains unpatched for eight months and that risk was accepted based on an untested control.

  • ✗

    Recommend replacing the legacy application to eliminate the patching conflict

    Why it's wrong here

    Recommending application replacement is premature and outside the immediate scope of evaluating the control deficiency. Before proposing such a costly, long-term solution, the auditor must first determine whether the compensating control adequately mitigates the risk. The next step is assessing the control's effectiveness; a recommendation of that magnitude would follow only if residual risk remains unacceptable after that assessment.

  • ✓

    Evaluate the design and operating effectiveness of the compensating control before concluding

    Why this is correct

    When management accepts a risk and relies on a compensating control, the auditor must assess whether that control actually reduces the risk to an acceptable level. Enhanced network monitoring may or may not detect exploitation of the unpatched server. Testing the compensating control's design and operation allows the auditor to form a supportable conclusion about residual risk rather than accepting the documentation at face value.

  • ✗

    Report the finding as a high-risk issue and demand immediate patching

    Why it's wrong here

    Demanding immediate patching overrides management's documented risk acceptance, which is management's prerogative, not the auditor's. The auditor's role is to evaluate and report, not to direct remediation or dictate risk appetite. Escalating as a high-risk issue may be appropriate after evaluating the compensating control, but insisting on patching ignores the conflict with the legacy application and the documented acceptance decision.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.