Which Process Best Ensures Vendor Software Remains Up to Date?
Which of the following provides the BEST assurance that vendor-supported software remains up to date?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests understanding of operational vs. administrative controls, with the common trap being confusion between version tracking (B) and active patch deployment (D).
Release and patch management is the critical IT audit control for maintaining vendor-supported software currency. This guide explains why structured update processes provide superior assurance over basic version tracking or asset inventories.
Option B (Version management) is frequently chosen because it sounds technical, but it only records installed versions without guaranteeing timely updates or vulnerability remediation.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Release and patch management encompasses the end-to-end lifecycle of acquiring, validating, and deploying vendor updates. ISACA emphasizes that this process directly ensures systems remain aligned with current vendor support cycles and security baselines. By integrating vulnerability scanning and formal change control, auditors gain concrete evidence that software currency is actively maintained rather than passively recorded.
Why the Other Options Are Wrong
Software asset management focuses on inventory tracking and cost allocation, offering no mechanism for enforcing updates. Version management merely logs which builds are installed but does not mandate progression to supported releases or address emerging threats. Licensing agreements and escrow arrangements protect intellectual property rights and business continuity during vendor failure, completely unrelated to operational software freshness.
Community Comment Notes
Contributors consistently highlight that systematic update workflows serve as the definitive proof of currency, noting that real-world vendor support terminations force necessary upgrades. Some learners initially question version tracking, but experienced users clarify that version logging alone cannot verify whether teams actually apply vendor fixes or migrate away from end-of-life releases. As Hayati questioned, version management lacks the enforcement layer required to guarantee ongoing maintenance compliance.
Exam Strategy
When evaluating CISA maintenance questions, prioritize processes that involve active implementation and verification over passive tracking tools. Always look for the option that includes testing, deployment, and continuous monitoring of vendor updates.
Frequently Asked Questions
Why isn't version management sufficient for keeping software current?
Version management only logs installed builds. It lacks the enforcement mechanisms required to push vendor fixes, validate compatibility, or track end-of-support dates.
Does software asset management cover patching schedules?
No. SAM focuses on inventory, licensing, and cost optimization. Patch management handles the actual deployment and validation of vendor updates to maintain system currency.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →