hardMultiple Choice
CISA Practice Question: The lead IT auditor for a multinational…
You are the lead IT auditor for a multinational corporation that recently completed a merger with another company. During the post-merger integration audit, you discover that the acquired company's legacy HR system contains sensitive personal data of 20,000 employees and has been directly accessible from the internet for the last 18 months. The system runs on an unsupported operating system (Windows Server 2008) and uses a custom-built application with no logging enabled. The acquired company's IT manager argues that the server is isolated behind a firewall and has never been compromised. However, your review of firewall logs shows numerous connection attempts from unknown IP addresses. The integration team plans to decommission this system in three months. You need to determine the appropriate audit response. Which of the following should you do NEXT?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Issue an urgent audit report to senior management highlighting the risk and recommending immediate isolation or remediation
The severity of the risk—exposed sensitive data on an unsupported system with active external connection attempts—requires immediate escalation to senior management. Waiting (B) or adding compensating controls (D) without management approval could delay critical action. Forensic analysis (A) may be warranted but should be directed by management after the risk is reported.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct a forensic analysis of the server to determine if a breach has occurred
Why it's wrong here
Forensics examines the server's current state, but with no application logging and an unsupported OS, evidence of historical compromise is largely unrecoverable; it also delays protecting live data. Forensic analysis is the right response once a breach is suspected and evidence is preserved, not as the immediate containment step here.
- ✗
Wait for the decommissioning timeline and monitor the server logs for any signs of breach
Why it's wrong here
Monitoring is impossible because the custom application has no logging enabled, so no breach indicators could ever surface. Waiting three months also leaves 20,000 employees' data exposed on an unsupported OS. Deferring to the decommissioning timeline is acceptable only when compensating controls and detection capability already exist.
- ✓
Issue an urgent audit report to senior management highlighting the risk and recommending immediate isolation or remediation
Why this is correct
Internet-exposed unsupported Windows Server 2008 holding 20,000 employees' personal data, with no logging and active unknown connection attempts, constitutes a reportable risk. Escalating urgently to senior management with isolation or remediation recommendations satisfies the auditor's duty to act on material exposure before the three-month decommission.
- ✗
Propose a compensating control, such as requiring VPN access to the server
Why it's wrong here
VPN access restricts reachability but leaves the unsupported OS, unlogged custom application and 18 months of unmonitored internet exposure untouched; firewall logs already show hostile connection attempts. Compensating controls suit interim risk reduction where the underlying system is supportable and monitored, not here where breach evidence must first be established.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.