exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1146 discussion

Actual exam question from Isaca's CISA
Question #: 1146
Topic #: 1
[All CISA Questions]

Which of the following should be of GREATEST concern to an IS auditor who is assessing an organization’s configuration and release management process?

  • A. The organization does not use an industry-recognized methodology.
  • B. Changes and change approvals are not documented.
  • C. There is no centralized configuration management database (CMDB).
  • D. All changes require middle and senior management approval.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
3008
1 month ago
Selected Answer: B
B. Changes and change approvals are not documented. This is because the lack of documentation for changes and approvals can lead to a lack of accountability, traceability, and control. It can also make it difficult to verify that changes have been properly implemented and approved. This could potentially lead to unauthorized changes being made, which could impact the stability and security of the system. Therefore, it is crucial for an organization to document all changes and approvals as part of their configuration and release management process.
upvoted 4 times
...
FAGFUR
1 month, 3 weeks ago
Selected Answer: C
Of the options provided, the absence of a centralized configuration management database (CMDB) should be of GREATEST concern to an IS auditor assessing an organization's configuration and release management process. A centralized CMDB is a critical component of effective configuration and release management. It serves as a centralized repository for storing and managing information about configuration items (CIs), including hardware, software, and their relationships. Without a CMDB, it becomes challenging to track and manage changes, dependencies, and configurations in a systematic and controlled manner.
upvoted 2 times
...
BA27
2 months, 3 weeks ago
B. Changes and change approvals are not documented.
upvoted 3 times
...
JONESKA
5 months, 2 weeks ago
I think its C - No CMDB is a problematic
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago