🔥 3-day streak
ISACA CISA — Certified Information Systems Auditor105 / 148
Question 105 of 148
A critical zero-day vulnerability affecting an internet-facing application server has been publicly disclosed, and an active exploit is circulating. The vendor has released an emergency patch. During a review of the organization's response, an IS auditor notes that the operations team deployed the patch directly to production within hours, bypassing the normal test cycle, but did complete a documented emergency change request approved by the change advisory board on-call authority. What should the auditor conclude?
Reviewed for accuracy · Report an issueNext question