Free ISACA CISA Actual Exam Questions - Question 13 Discussion

Question No. 13
An IS auditor is reviewing documentation of application systems change control and
identifies several patches that were not tested before being put into production. Which of the
following is the MOST significant risk from this situation?
Select one option, then reveal solution.
US
IY
Irfan Y.
2026-02-19

Not A, since losing application support is more about vendor issues, not untested patches. The real problem here is B—untested patches can break the system or open security holes.

0
IY
Irfan Y.
2026-02-18

B Untested patches directly threaten system integrity by introducing unknown errors or vulnerabilities. The other options are less immediate risks compared to the potential damage from faulty updates.

0
MT
Mohammad T.
2026-02-17

B/D? Risk to system integrity (B) is obvious, but if patches weren’t tested, it also hints at poor controls like developers possibly having production access (D), which can be a big security risk too.

0
MT
Mohammad T.
2026-02-12

D imo, since untested patches might mean developers pushed changes directly into production.

0
SX
Sarah X.
2026-02-04

This situation screams risk of system integrity issues, so I go with B. Untested patches can cause unpredictable bugs or data corruption, which directly threatens the reliability of the application. Options like A and C seem off since support loss or outdated docs are less immediate concerns compared to a patch potentially breaking things. D could be a factor but the key problem here is the lack of testing itself, not necessarily who deployed the patches. So for me, B fits best as the biggest risk from skipping testing before production.

0
AF
Ali F.
2026-01-15

Maybe B makes the most sense here. If patches aren’t tested before going live, it’s likely to mess with system integrity-introduce bugs, corrupt data, or cause unexpected behavior. The other options seem less directly tied to untested changes.

0