nerdexam
Isaca

CISA · Question #62

An IS auditor finds that firewalls are outdated and not supported by vendors. Which of the following should be the auditor's NEXT course of action?

The correct answer is B. Determine the risk of not replacing the firewall.. Upon discovering outdated and unsupported firewalls, the IS auditor's immediate next step should be to determine the specific risks these vulnerabilities pose to the organization.

Submitted by yasin.bd· Apr 18, 2026Information System Auditing Process

Question

An IS auditor finds that firewalls are outdated and not supported by vendors. Which of the following should be the auditor’s NEXT course of action?

Options

  • AReport the security posture of the organization.
  • BDetermine the risk of not replacing the firewall.
  • CReport the mitigating controls.
  • DDetermine the value of the firewall.

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    78% (25)
  • C
    6% (2)
  • D
    13% (4)

Why each option

Upon discovering outdated and unsupported firewalls, the IS auditor's immediate next step should be to determine the specific risks these vulnerabilities pose to the organization.

AReport the security posture of the organization.

Reporting the security posture of the organization should only occur after understanding the level of risk, as the report needs to accurately reflect the severity and implications of the outdated firewalls.

BDetermine the risk of not replacing the firewall.Correct

Determining the risk involves evaluating the likelihood of an outdated, unsupported firewall being exploited and the potential impact of such an exploitation on the organization's assets and operations. This risk assessment provides the necessary context and justification for subsequent reporting and remediation recommendations, making it the critical step after identifying the deficiency.

CReport the mitigating controls.
DDetermine the value of the firewall.

Concept tested: Auditor's response to security vulnerabilities

Source: https://nvlpubs.nist.gov/nistpubs/legacy/sp/nistspecialpublication800-30r1.pdf

Topics

#IS audit process#Risk assessment#Vulnerability management#Security controls

Community Discussion

No community discussion yet for this question.

Full CISA Practice