easyMultiple Choice
CISA Practice Question: In the process of acquiring a new customer…
A company is in the process of acquiring a new customer relationship management (CRM) system. During which phase of the systems development life cycle (SDLC) should the business requirements be formally documented?
⚠ Common exam trap
Candidates often confuse the Requirements phase with the Design phase, mistakenly thinking that requirements are documented during design, but in reality, design assumes requirements are already formally approved and focuses on how to implement them, not what to implement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Requirements phase (Planning)
The business requirements for a new CRM system must be formally documented during the Requirements phase (Planning) of the SDLC. This phase establishes the functional and non-functional needs that the system must satisfy, serving as the foundation for all subsequent design, development, and testing activities. Without a formal requirements document, the project risks scope creep, misalignment with business objectives, and costly rework during later phases.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implementation phase
Why it's wrong here
Implementation covers coding, configuration and deployment of the chosen CRM, so requirements must already exist to build against. It is tempting because configuration decisions occur then, and it would be correct for executing the approved design rather than capturing business needs.
- ✓
Requirements phase (Planning)
Why this is correct
Business requirements must be captured during the requirements phase, where stakeholder needs are elicited, analysed and formally documented as the baseline for design. Planning precedes this and only scopes feasibility and resources, so documenting requirements there would leave the CRM's functional and non-functional needs undefined before build.
- ✗
Design phase
Why it's wrong here
Design translates already-approved business requirements into technical specifications, so documenting them here reverses the sequence and leaves design without validated inputs. It is tempting because requirements are refined alongside design, and it would be correct for specifying architecture, data models and interfaces.
- ✗
Maintenance phase
Why it's wrong here
Maintenance handles post-deployment fixes, patches and enhancements, so requirements documented there arrive after the CRM is already built and acquired. It is tempting because changing needs surface during support, and it would be correct for documenting enhancement requests or defect corrections.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.