Certified Information Systems Auditor CISA · Free Practice Question Medium

Question 25

You are an information system auditor of HDA Inc. You are auditing a software system that is still in regular use but is  out of date and no longer supported by the manufacturer. The auditee has stated that it will take six months to update the software to the current version. In this scenario, what would be the most effective approach to mitigate the immediate risk associated with using an unsupported version of the software?

  • A A. Implement compensating controls to mitigate the risks.
  • B B. Immediately cease using the outdated software and switch to an alternative.
  • C C. Control and monitor the traffic attempting to interact with the outdated system.
  • D D. Expedite the software upgrade process to minimize the unsupported period.
Reveal correct answer

Correct answer: C

Explanation

Correct Answer: C. Control and monitor the traffic attempting to interact with the outdated system. Explanation: When faced with the risk of using an unsupported version of software, the best way to reduce immediate risk is to control and monitor the traffic attempting to interact with the outdated system (option C). Using unsupported software can expose an organization to various security vulnerabilities, as there will be no vendor support or updates to address newly discovered vulnerabilities. It is not always feasible to immediately switch to an alternative software or expedite the upgrade process due to various reasons such as time, cost, or compatibility issues. Therefore, implementing compensating controls (option A) or expediting the upgrade process (option D) may not be the most practical or efficient options in the immediate term. By controlling and monitoring the traffic attempting to interact with the outdated system, the organization can implement additional security measures to reduce the risk of exploitation. This can include implementing network security controls, intrusion detection systems, and closely monitoring and analyzing network traffic for any suspicious or malicious activities. While this approach does not eliminate the underlying risk of using unsupported software, it helps to mitigate the immediate risk by enhancing the security posture and reducing the likelihood of successful attacks or compromises. Option B suggests immediately ceasing the use of the outdated software and switching to an alternative. While this may be a valid long-term solution, it may not be feasible in the immediate term due to dependencies, compatibility issues, or the need for additional planning and implementation. Therefore, the best immediate action for the IS auditor is to control and monitor the traffic attempting to interact with the outdated system (option C), which helps to strengthen the security of the environment and minimize the risk exposure while the upgrade process is being completed.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need