CISA Protection of Information Assets Practice Question
During an audit of patch management, the IS auditor notes that several critical patches have not been applied within the defined SLA. Which of the following is the BEST approach to evaluate the risk acceptance of these unpatched vulnerabilities?
⚠ Common exam trap
CISA often tests the distinction between evaluating risk acceptance (reviewing documentation) and performing risk assessment or remediation (computing scores or patching), so candidates may incorrectly choose a technical action over a governance review.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the risk acceptance documentation approved by the system owner and CISO.
The question asks how to evaluate the risk acceptance of unpatched vulnerabilities. Risk acceptance is a formal management decision that must be documented and approved by the appropriate authorities—typically the system owner and the CISO. Reviewing this documentation provides direct evidence that the organization has consciously accepted the risk, which is exactly what the auditor needs to evaluate. Computing a risk score or recommending patching does not address whether the risk has been formally accepted.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Compute the aggregate risk score using a vulnerability management tool.
Why it's wrong here
Aggregate risk scoring quantifies vulnerability severity but does not evidence whether management has formally accepted the SLA breach; risk acceptance requires documented sign-off against defined tolerance. Scoring tools suit prioritising remediation queues, not evaluating acceptance decisions.
- ✓
Review the risk acceptance documentation approved by the system owner and CISO.
Why this is correct
Documented risk acceptance approved by the system owner and CISO evidences that the business knowingly accepted the unpatched vulnerabilities within its risk appetite. Reviewing that documentation lets the auditor evaluate whether acceptance was authorised, justified and consistent with policy.
- ✗
Recommend immediate application of all missing patches.
Why it's wrong here
Recommending immediate patching addresses remediation, not evaluation of risk acceptance; the auditor must determine whether management formally acknowledged and accepted the unpatched exposure. Immediate application would be the right response when no acceptance exists and the SLA mandates enforcement.
- ✗
Verify that the patches are not applicable to the environment.
Why it's wrong here
Confirming non-applicability removes the finding entirely rather than evaluating acceptance; if patches genuinely do not affect the environment, no risk exists to accept. This is the correct approach when patch applicability, not SLA compliance, is the actual audit question.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.