exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 446 discussion

Actual exam question from Isaca's CISA
Question #: 446
Topic #: 1
[All CISA Questions]

Which of the following applications has the MOST inherent risk and should be prioritized during audit planning?

  • A. An internally developed application
  • B. An onsite application that is unsupported
  • C. A decommissioned legacy application
  • D. An outsourced accounting application
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
roxannebadenhorst
6 days, 11 hours ago
Selected Answer: B
Unsupported applications carry the most risk because they are no longer maintained by the vendor, meaning that any security vulnerabilities, bugs, or system failures that arise may not be patched or resolved. Additionally, without vendor support, the organization may struggle to obtain critical updates, security fixes, and technical assistance. This creates both operational and security risks, as the application may become more vulnerable to cyber threats and compatibility issues over time.
upvoted 1 times
...
1Naa
1 week, 6 days ago
Selected Answer: D
A might involve risks related to development and maintenance, these are typically within the organization’s control, reducing inherent risk compared to outsourcing. But D (Outsourced accounting applications) pose the most inherent risk because they involve critical financial data that is handled outside the organization’s direct control.
upvoted 1 times
...
3008
7 months, 2 weeks ago
Selected Answer: A
Security Defects: Internal applications consist of code written by developers. A security flaw can be hidden in this code, which can lead to data leakage, authentication bypass, and malicious code execution. Legacy code and technology stack: Internal applications can use older technology stacks. This can lead to difficulty in maintenance and security vulnerabilities.
upvoted 1 times
ChaBum
3 months, 3 weeks ago
yeah A. An internally developed application can be fall of flaws, but B. An onsite application that is unsupported, has "unsupported", so that one is for sure full of unpatched bugs.
upvoted 2 times
...
...
MohamedAbdelaal
1 year, 2 months ago
Selected Answer: A
Why not A
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago