Courseiva
hardMultiple ChoiceObjective-mapped

CISA Practice Question: During system implementation, a critical defect…

During system implementation, a critical defect is found in the production environment. The project manager wants to apply an emergency patch without full testing. Which of the following is the BEST course of action?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Conduct a risk assessment and obtain approval from the change control board

The best course of action because applying an emergency patch should be preceded by a risk assessment to evaluate the impact and risk, and proper approval from the change control board ensures that the change is controlled and authorized. Option A bypasses change management controls and could introduce new issues. Option B (reverting) may not address the defect and could lead to significant downtime. Option C (delaying for full testing) may not be feasible for critical defects that need immediate resolution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Apply the patch immediately without testing

    Why it's wrong here

    Bypassing change control increases the risk of introducing new issues and lacks oversight.

  • Delay deployment until full testing can be completed

    Why it's wrong here

    For a critical defect, delay may cause significant business impact; a full test cycle may be impractical.

  • Revert to the previous version of the system

    Why it's wrong here

    Reverting may remove the defect but also loses other changes; it may not be the best long-term solution.

  • Conduct a risk assessment and obtain approval from the change control board

    Why this is correct

    A risk-based approach ensures that the urgency is balanced with proper oversight, allowing a controlled emergency change.

About these practice questions

This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.