What Is the Greatest Audit Concern in Patch Management?
Which of the following should be of GREATEST concern to an IS auditor assessing an organization's patch management program?
Community Votes
75% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the foundational dependency of patch management, where candidates often overvalue containment controls like quarantining while overlooking mandatory discovery processes.
Effective patch management relies on continuous vulnerability discovery before remediation steps can occur. This analysis confirms why failing to scan for missing patches represents the most critical audit finding.
Option C is frequently chosen because quarantining unpatched systems seems like a direct security control, but auditors must prioritize discovery mechanisms since you cannot protect what you cannot detect.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Effective patch management follows a strict lifecycle that begins with vulnerability discovery. Without a systematic network scanning process, auditors cannot verify which systems require updates, rendering prioritization, testing, and deployment entirely blind. ISACA audit doctrine emphasizes that identification precedes remediation, making the absence of scanning the most fundamental control failure. Consequently, this gap exposes the organization to unmanaged risks across all infrastructure tiers.Why the Other Options Are Wrong
Omitting medium- and low-risk patches (Option A) is often an acceptable business decision aligned with defined risk appetites and resource constraints. Deploying patches from multiple servers (Option B) reflects standard load-balancing architecture and introduces no inherent security deficiency. While quarantining unpatched hosts (Option C) provides valuable containment, it is a reactive measure that becomes impossible to execute accurately without the underlying discovery mechanism provided by network scanning.Community Comment Notes
Top contributors consistently highlight that discovery serves as the operational foundation for all subsequent patching activities. As one detailed explanation reasoned, asking how an organization could know "how would you know what to quarantine or what patches to release" without scanning highlights the logical dependency. Another participant emphasized that skipping the scanning phase breaks the entire remediation workflow, reinforcing the audit principle that detection must precede mitigation. These insights align directly with established vulnerability management frameworks.Official Reference
Exam Strategy
When ISACA questions ask for the greatest concern, always trace the control backward to its prerequisite. Foundational capabilities like asset discovery and vulnerability mapping must exist before tactical mitigations like isolation or deployment can function effectively.
Frequently Asked Questions
Why is quarantining unpatched servers not the highest priority?
Quarantine is a containment tactic that depends on prior discovery. Without scanning to identify vulnerable assets, isolation processes cannot be triggered or managed.
Can medium and low-risk patches be safely ignored?
Yes, if the organization defines an acceptable risk threshold. Auditors focus on foundational controls like discovery rather than enforcing uniform patching.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →