Courseiva
hardMultiple Choice

CISA Practice Question: A multinational corporation is implementing a new…

A multinational corporation is implementing a new enterprise resource planning (ERP) system across multiple regions. The project uses a phased roll-out. After the first phase in Asia, the system experiences intermittent synchronization errors between the central database and regional servers. The IT team suspects network latency but cannot reproduce the issue consistently. The project sponsor wants to proceed with the next phase in Europe to avoid further delays. The IS auditor is performing a post-implementation review. What is the MOST appropriate recommendation?

⚠ Common exam trap

Many exam-takers choose Option A (proceed and monitor) because it seems pragmatic and avoids project delays, but the CISA exam emphasizes that unresolved control weaknesses in a post-implementation review must be addressed before expanding the system to prevent cascading failures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a thorough root cause analysis of the synchronization issue before any further roll-out.

The intermittent synchronization errors indicate a potential data integrity or consistency issue that must be fully understood before expanding the system's footprint. Proceeding without root cause analysis risks propagating the defect to the European phase, which could lead to widespread data corruption, increased remediation costs, and regulatory non-compliance. A thorough root cause analysis (e.g., examining network latency, transaction log replication, or database conflict resolution) is essential to ensure the ERP's distributed architecture is reliable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Proceed with the European roll-out and monitor for similar issues.

    Why it's wrong here

    Proceeding to Europe leaves the unresolved synchronisation defect in production and replicates it into a second region, widening impact before root cause is established. It is tempting because phased roll-outs tolerate parallel regional workstreams, which is correct when earlier phases have passed their exit criteria.

  • ✗

    Switch to a different ERP vendor that offers better cloud capabilities.

    Why it's wrong here

    Replacing the vendor discards the phased roll-out and existing configuration without diagnosing the latency-driven synchronisation faults, so the same defect would recur. It is tempting because cloud-native ERP hosting can reduce regional latency, which is correct only once root cause confirms the platform itself is the constraint.

  • ✓

    Conduct a thorough root cause analysis of the synchronization issue before any further roll-out.

    Why this is correct

    Proceeding to Europe while the Asia synchronisation fault remains undiagnosed risks replicating the defect across regions and compounding data integrity issues. Root cause analysis first satisfies the audit objective of confirming the phased roll-out is controlled before further deployment, rather than masking an unresolved defect.

  • ✗

    Document the synchronization error as a known issue and accept the operational risk.

    Why it's wrong here

    Accepting the errors as a known issue closes the defect without correcting the central-to-regional synchronisation mechanism, so data integrity failures persist. It is tempting because risk acceptance is valid for low-impact issues, which is correct only when the fault cannot be remediated and its business impact is quantified.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.