ExamGecko
Question list
Search
Search

Related questions

Question 371 - CISA discussion

Report
Export

An IS auditor is reviewing documentation of application systems change control and identifies several patches that were not tested before being put into production. Which of the following is the MOST significant risk from this situation?

A.
Loss of application support
Answers
A.
Loss of application support
B.
Lack of system integrity
Answers
B.
Lack of system integrity
C.
Outdated system documentation
Answers
C.
Outdated system documentation
D.
Developer access 1o production
Answers
D.
Developer access 1o production
Suggested answer: B

Explanation:

The most significant risk from not testing patches before putting them into production is the lack of system integrity. Patches are software updates that fix bugs, vulnerabilities or performance issues in an application system.However, patches may also introduce new errors, conflicts or compatibility issues that could affect the functionality, reliability or security of the system4. By not testing patches before putting them into production, the organization exposes itself to the risk of system failures, data corruption or unauthorized access. Loss of application support, outdated system documentation and developer access to production are also risks from not testing patches, but they are not as significant as the lack of system integrity.Reference:

CISA Review Manual, 27th Edition, page 2951

CISA Review Questions, Answers & Explanations Database - 12 Month Subscription

asked 18/09/2024
Meena Utsaha
33 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first