hardMultiple ChoiceObjective-mapped
CISA Practice Question: During system implementation, a critical defect…
During system implementation, a critical defect is found in the production environment. The project manager wants to apply an emergency patch without full testing. Which of the following is the BEST course of action?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conduct a risk assessment and obtain approval from the change control board
The best course of action because applying an emergency patch should be preceded by a risk assessment to evaluate the impact and risk, and proper approval from the change control board ensures that the change is controlled and authorized. Option A bypasses change management controls and could introduce new issues. Option B (reverting) may not address the defect and could lead to significant downtime. Option C (delaying for full testing) may not be feasible for critical defects that need immediate resolution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply the patch immediately without testing
Why it's wrong here
Bypassing change control increases the risk of introducing new issues and lacks oversight.
- ✗
Delay deployment until full testing can be completed
Why it's wrong here
For a critical defect, delay may cause significant business impact; a full test cycle may be impractical.
- ✗
Revert to the previous version of the system
Why it's wrong here
Reverting may remove the defect but also loses other changes; it may not be the best long-term solution.
- ✓
Conduct a risk assessment and obtain approval from the change control board
Why this is correct
A risk-based approach ensures that the urgency is balanced with proper oversight, allowing a controlled emergency change.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.