hardMultiple Choice
CISA Practice Question: During system implementation, a critical defect…
During system implementation, a critical defect is found in the production environment. The project manager wants to apply an emergency patch without full testing. Which of the following is the BEST course of action?
⚠ Common exam trap
CISA often tests the misconception that emergency situations justify bypassing change control; the correct answer always involves risk assessment and proper approval.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a risk assessment and obtain approval from the change control board
When a critical defect is found in production and an emergency patch is proposed without full testing, the BEST course of action is to conduct a risk assessment and obtain approval from the change control board (CAB). This ensures that the risk of applying an untested patch is formally evaluated, documented, and approved by the appropriate authority, balancing the need for a quick fix with proper change management controls. The CAB can also determine if emergency testing or a rollback plan is needed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply the patch immediately without testing
Why it's wrong here
Applying the patch untested introduces unverified changes into production, risking new failures without any rollback assurance. Immediate patching is tempting because critical defects demand speed, and it would be correct only under a documented emergency change process with testing, approval and rollback plans in place.
- ✗
Delay deployment until full testing can be completed
Why it's wrong here
Delaying deployment leaves the critical production defect live, extending exposure while the business operates on a faulty system. Full testing is tempting because it is the standard control for change, and it would be correct for a non-critical, non-production change where no immediate risk exists.
- ✗
Revert to the previous version of the system
Why it's wrong here
Reverting discards the fix and restores the previous version, which still contains the critical defect, so the production problem persists. Rollback is tempting because it is the standard recovery action, and it would be correct when the new release itself caused the failure rather than an underlying defect.
- ✓
Conduct a risk assessment and obtain approval from the change control board
Why this is correct
Emergency changes still require documented risk assessment and change control board authorisation before deployment. This balances the need to remediate the critical production defect against the risk of introducing untested code, satisfying the governance constraint that changes are approved and recorded.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.