What Is the Greatest Audit Concern in Patch Management?

Vulnerability & Patch Management
Answer Correct answer: D — Implementing network vulnerability scanning is required first to identify missing patches before any remediation or quarantine actions can be effective.

Which of the following should be of GREATEST concern to an IS auditor assessing an organization's patch management program?

  1. Patches for medium- and low-risk vulnerabilities are omitted.
  2. Patches are deployed from multiple deployment servers.
  3. There is no process in place to quarantine servers that have not been patched.
  4. There is no process in place to scan the network to identify missing patches. Correct Answer

Community Votes

D
75%
C
25%

75% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the foundational dependency of patch management, where candidates often overvalue containment controls like quarantining while overlooking mandatory discovery processes.

Effective patch management relies on continuous vulnerability discovery before remediation steps can occur. This analysis confirms why failing to scan for missing patches represents the most critical audit finding.

Option C is frequently chosen because quarantining unpatched systems seems like a direct security control, but auditors must prioritize discovery mechanisms since you cannot protect what you cannot detect.

Community Discussion (3 comments)

46080f2 👍 1 Selected: D
This conclusion is grounded in the CISA Official Review Manual 28th Edition, which underscores the necessity of identifying vulnerabilities as the cornerstone of effective patch management and security (pp. 564, 566).
blehbleh 👍 2 Selected: D
I have to go with D. If you aren't even scanning your network to find vulnerabilities how would you know what to quarantine or what patches to release on which systems or servers. D makes the most sense as it is the starting point to patch management.
PurpleParrot 👍 1 Selected: C
Not having a quarantine process is the biggest risk

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Effective patch management follows a strict lifecycle that begins with vulnerability discovery. Without a systematic network scanning process, auditors cannot verify which systems require updates, rendering prioritization, testing, and deployment entirely blind. ISACA audit doctrine emphasizes that identification precedes remediation, making the absence of scanning the most fundamental control failure. Consequently, this gap exposes the organization to unmanaged risks across all infrastructure tiers.

Why the Other Options Are Wrong

Omitting medium- and low-risk patches (Option A) is often an acceptable business decision aligned with defined risk appetites and resource constraints. Deploying patches from multiple servers (Option B) reflects standard load-balancing architecture and introduces no inherent security deficiency. While quarantining unpatched hosts (Option C) provides valuable containment, it is a reactive measure that becomes impossible to execute accurately without the underlying discovery mechanism provided by network scanning.

Community Comment Notes

Top contributors consistently highlight that discovery serves as the operational foundation for all subsequent patching activities. As one detailed explanation reasoned, asking how an organization could know "how would you know what to quarantine or what patches to release" without scanning highlights the logical dependency. Another participant emphasized that skipping the scanning phase breaks the entire remediation workflow, reinforcing the audit principle that detection must precede mitigation. These insights align directly with established vulnerability management frameworks.

Official Reference

Exam Strategy

When ISACA questions ask for the greatest concern, always trace the control backward to its prerequisite. Foundational capabilities like asset discovery and vulnerability mapping must exist before tactical mitigations like isolation or deployment can function effectively.

Frequently Asked Questions

Why is quarantining unpatched servers not the highest priority?

Quarantine is a containment tactic that depends on prior discovery. Without scanning to identify vulnerable assets, isolation processes cannot be triggered or managed.

Can medium and low-risk patches be safely ignored?

Yes, if the organization defines an acceptable risk threshold. Auditors focus on foundational controls like discovery rather than enforcing uniform patching.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide