easyMultiple Choice
CISA Developing a custom application Practice Question
A company is developing a custom application. During the requirements phase, the project manager documents that the system must encrypt all sensitive data at rest. Which of the following is the BEST control to ensure this requirement is met throughout the development lifecycle?
⚠ Common exam trap
A common mix-up: candidates choose static code analysis (A) because it seems technical and security-focused, but they overlook that it only checks the final code and cannot enforce lifecycle-wide traceability of requirements.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a requirements traceability matrix (RTM).
A requirements traceability matrix (RTM) links each requirement to corresponding design, development, and testing artifacts. By mapping the encryption-at-rest requirement to specific code modules, configuration settings, and test cases, the RTM ensures that the control is implemented and verified at every stage of the lifecycle, not just at the end. This makes it the best proactive control for continuous compliance throughout development.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Perform static code analysis on the final code.
Why it's wrong here
Static code analysis on final code identifies insecure patterns only after development completes, so encryption omissions surface too late for cost-effective correction. It suits periodic code-quality checks. Continuous integration of the requirement across design, coding and testing is needed, not a single end-stage scan.
- ✓
Create a requirements traceability matrix (RTM).
Why this is correct
A requirements traceability matrix links the encryption-at-rest requirement to its design, code, and test artefacts, providing verifiable evidence throughout development. This directly satisfies the need to confirm the control is implemented and tested at each lifecycle stage.
- ✗
Conduct a post-implementation security review.
Why it's wrong here
A post-implementation review detects encryption gaps after code is written, too late to influence design or prevent rework. It suits verifying deployed controls during audit or acceptance. The requirement must be enforced from requirements through design, coding and testing, which a one-off review cannot do.
- ✗
Deploy a database activity monitoring tool.
Why it's wrong here
Database activity monitoring observes access to data already stored, detecting misuse rather than ensuring encryption is implemented. It suits runtime threat detection and compliance auditing. Encryption at rest must be designed and verified through the development lifecycle, which monitoring cannot enforce.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.