hardMultiple ChoiceObjective-mapped
CISA Practice Question: The lead IT auditor for a multinational…
You are the lead IT auditor for a multinational corporation that recently completed a merger with another company. During the post-merger integration audit, you discover that the acquired company's legacy HR system contains sensitive personal data of 20,000 employees and has been directly accessible from the internet for the last 18 months. The system runs on an unsupported operating system (Windows Server 2008) and uses a custom-built application with no logging enabled. The acquired company's IT manager argues that the server is isolated behind a firewall and has never been compromised. However, your review of firewall logs shows numerous connection attempts from unknown IP addresses. The integration team plans to decommission this system in three months. You need to determine the appropriate audit response. Which of the following should you do NEXT?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Issue an urgent audit report to senior management highlighting the risk and recommending immediate isolation or remediation
The severity of the risk—exposed sensitive data on an unsupported system with active external connection attempts—requires immediate escalation to senior management. Waiting (B) or adding compensating controls (D) without management approval could delay critical action. Forensic analysis (A) may be warranted but should be directed by management after the risk is reported.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct a forensic analysis of the server to determine if a breach has occurred
Why it's wrong here
Incorrect: While forensic analysis might be needed, the immediate next step is to inform management to contain the risk.
- ✗
Wait for the decommissioning timeline and monitor the server logs for any signs of breach
Why it's wrong here
Incorrect: This passive approach ignores the ongoing risk of data exposure.
- ✓
Issue an urgent audit report to senior management highlighting the risk and recommending immediate isolation or remediation
Why this is correct
Correct: Auditors must escalate critical findings promptly to management for action.
- ✗
Propose a compensating control, such as requiring VPN access to the server
Why it's wrong here
Incorrect: Proposing specific controls without management's awareness and direction is beyond the auditor's role at this stage.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.