nerdexam
Isaca

CISA · Question #558

Which of the following is the PRIMARY concern related to unapproved software usage within an organization?

The correct answer is C. Risk of data exposure and security breaches. The primary concern with unapproved (shadow IT) software is the risk of data exposure and security breaches. Unapproved software has not been vetted by IT security, may contain malware or unpatched vulnerabilities, can exfiltrate sensitive data, and may violate data handling…

Submitted by deeparc· Apr 18, 2026Protection of Information Assets

Question

Which of the following is the PRIMARY concern related to unapproved software usage within an organization?

Options

  • ALack of compliance with internal IT procedures
  • BInefficient IT support and maintenance
  • CRisk of data exposure and security breaches
  • DIncreased costs of software licenses and subscriptions

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    84% (21)
  • D
    4% (1)

Explanation

The primary concern with unapproved (shadow IT) software is the risk of data exposure and security breaches. Unapproved software has not been vetted by IT security, may contain malware or unpatched vulnerabilities, can exfiltrate sensitive data, and may violate data handling requirements. While lack of compliance with internal procedures (A), inefficient IT support (B), and licensing costs (D) are valid concerns, they are secondary to the direct security and data protection risk that unvetted software introduces into the environment.

Topics

#Unapproved software#Security risk management#Data exposure#Information asset protection

Community Discussion

No community discussion yet for this question.

Full CISA Practice