CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 307


A legacy application is running on an operating system that is no longer supported by the vendor. If the organization continues to use the current application, which of the following should be the IS auditor's GREATEST concern?

Show Answer
Correct Answer: AC

When an application runs on an operating system that is no longer supported by the vendor, the greatest concern for an IS auditor should be the potential exploitation of zero-day vulnerabilities. Unsupported systems do not receive security updates or patches, making them more susceptible to exploitation by attackers who discover new vulnerabilities. This poses a significant risk to the organization's security. While issues like increased maintenance costs, database update challenges, and potential license issues are valid concerns, they do not present an immediate and critical threat similar to security vulnerabilities.

Discussion

8 comments
Sign in to comment
SaBoOption: B
Dec 10, 2021

zero-day vulnerabilities has the same impact in updated or out of support system, because is alredy unknown from comunity. Out of support system does not resolve known vulnerability. The correct answer is B

SuperiorMatt
Apr 14, 2022

No, zero-day vulnerability is something unknown to the community. A supported system will receive updated protection against that.

DeeplaxmiOption: A
Oct 1, 2022

A can be the coorect answer as unsupported OS will increase the chances of 0 day vulnerabilities. Increased cost of maintenace should not be prob for IS auditor.. It can be organisations concern.

007GeorgeoOption: A
May 6, 2023

Should be A

KAP2HURUFOption: A
Mar 3, 2024

Increased cost of maintenance (Option C): While a valid concern, it's often a secondary consequence compared to the immediate security risk posed by zero-day vulnerabilities. Database updates (Option B): Depending on the specific architecture, database updates might still be possible even on an unsupported OS. However, it doesn't mitigate the security risks associated with the underlying operating system itself. License issues (Option D): While using unsupported software might violate license agreements, the immediate security risk posed by zero-day vulnerabilities is a more critical concern for an IS auditor.

JulianleehkOption: A
Nov 26, 2022

should be A

Aqua_Jk09Option: A
Jan 15, 2023

should be A

BA27Option: A
Aug 25, 2023

A. Potential exploitation of zero-day vulnerabilities in the system

analuisamoreiraOption: A
Jun 27, 2024

I think A is correct