easyMultiple Choice
CISA Practice Question: A systems analyst is gathering requirements for a…
A systems analyst is gathering requirements for a new customer relationship management (CRM) system. Which of the following is the MOST important activity to ensure that the final system meets user needs?
⚠ Common exam trap
A common mix-up: candidates confuse 'documenting requirements' (Option D) with 'validating requirements,' assuming that formal documentation alone is sufficient to ensure user needs are met, whereas the CISA exam emphasizes that validation through stakeholder interaction is the critical step to prevent costly rework.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conducting a joint requirements validation session with stakeholders.
Conducting a joint requirements validation session with stakeholders (Option B) is the most important activity because it ensures that the requirements are accurate, complete, and agreed upon before development begins. This collaborative review process directly involves end users and business owners, allowing for immediate clarification and correction of misunderstandings, which is critical for aligning the CRM system with actual business processes. Without this validation, even a perfectly built system may fail to meet user needs, leading to costly rework.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Creating a prototype and asking for feedback after development.
Why it's wrong here
Feedback gathered only after development completes means defects in understanding surface too late to redirect design cheaply. Prototyping is genuinely valuable for eliciting and confirming requirements, but it must occur iteratively during analysis, before build, not as a single post-development review.
- ✓
Conducting a joint requirements validation session with stakeholders.
Why this is correct
A joint requirements validation session brings stakeholders together to review and confirm documented requirements, exposing gaps, conflicts and misunderstandings before design begins. This shared verification directly reduces the risk of building a CRM that fails to meet user needs.
- ✗
Developing a detailed technical specification before user sign-off.
Why it's wrong here
A technical specification fixes implementation detail before users have confirmed their needs, so it can entrench incorrect assumptions rather than validate them. It is tempting because detailed specifications are essential later for developers and testers, and would be correct after requirements have been elicited and formally agreed.
- ✗
Documenting all requirements in a formal specification.
Why it's wrong here
A formal specification captures what analysts believe users want, but written documents cannot reveal misunderstandings until delivery, so it does not validate needs. It is tempting because specifications are the recognised deliverable for sign-off and change control, and would be correct once requirements are already verified and baselined.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.