IsacaIsaca
CISA · Question #293
CISA Question #293: Real Exam Question with Answer & Explanation
Sign in or unlock CISA to reveal the answer and full explanation for question #293. The question stem and answer options stay visible for context.
Submitted by femi9· Apr 18, 2026Information Systems Acquisition, Development, and Implementation
Question
Which of the following would be of GREATEST concern to an is auditor reviewing continuous integration/continuous deployment (CI/CD) practices?
Options
- ADynamic application security testing (DAST) is not performed for every build
- BIf all pipeline tests pass, changes are allowed to be deployed into production without manual
- CThe time between deployments has varied from four hours to two weeks
- DCritical security test failures within the pipeline do not stop production deployment
Unlock CISA to see the answer
You've previewed enough free CISA questions. Unlock CISA for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#CI/CD Security#SDLC Controls#Application Security Testing#Deployment Pipeline