CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 252


Malicious program code was found in an application and corrected prior to release into production. After the release, the same issue was reported. Which of the following is the IS auditor's BEST recommendation?

Show Answer
Correct Answer: B

To prevent the recurrence of the same issue found post-release, the best recommendation is to ensure change management reports are independently reviewed. This allows for a thorough verification process to uncover any discrepancies or faults in the correction process and ensures that changes have been properly implemented and tested before going live.

Discussion

8 comments
Sign in to comment
007GeorgeoOption: B
May 5, 2023

is B , If a previously identified issue reoccurs after corrections have been made, it is possible that the corrections were not implemented correctly or that new issues were introduced during the correction process. Therefore, it is important to investigate why the issue was not fully resolved and to take steps to prevent a recurrence.

StaanleeOption: A
Dec 4, 2022

I think A is the right answer.

gomboragchaaOption: B
Dec 19, 2022

CAn't it be B?

RachyOption: C
Jan 15, 2024

The answer is C according to CISA Q&A

46080f2Option: B
Jun 1, 2024

B. must be the correct answer. From the description of the situation in the question, there is no indication of a possible cause for the recurrence of the problem in production. However, options A., C. and D. already suggest a cause and offer solutions. So it can only be B., always one after the other. There are a thousand possibilities in the whole change process that could be the cause. This must first be determined independently.

blues_leeOption: A
Jan 30, 2024

I think A is the right answer.

SwallowsOption: C
Apr 9, 2024

This is a question about the separation of duties between development and operations. Therefore, C is the correct answer.。

a84nOption: B
Apr 27, 2024

Q: After the release, the same issue was reported Answer: B recommendation to focus on improving the change management process