CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An IS auditor is assessing the implementation of a new system that uses a relational database. The project team plans to migrate data from several legacy sources. Which TWO of the following controls are MOST important to include in the data conversion plan to help ensure the integrity of migrated data? (Choose two.)
⚠ Common exam trap
The trap here is treating project logistics like legacy decommissioning or environment setup as data integrity controls, when the real assurance comes from reconciliation and referential integrity validation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verification that referential integrity constraints are enabled and validated after the data load.
Data migration integrity depends on detecting missing or corrupted records and ensuring that relationships between tables remain valid. Reconciliation of counts and totals provides independent verification that all expected data arrived, while validated referential integrity constraints ensure that foreign key relationships are sound. Together, these detective and preventive controls give the auditor the strongest evidence that the conversion preserved data accuracy and completeness.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Confirmation that the legacy system is decommissioned immediately after the conversion cutover.
Why it's wrong here
Decommissioning the legacy system is a project closure activity, not a data integrity control. In fact, retiring the source too early can eliminate the ability to re-extract or compare data if conversion errors are found. For this scenario, the auditor needs controls that validate the migrated data itself, not controls that remove the original source before reconciliation and validation are complete.
- ✗
Use of a parallel test environment that mirrors production hardware and software configurations for the conversion rehearsal.
Why it's wrong here
A parallel test environment is valuable for rehearsing the conversion and identifying performance issues, but it does not by itself prove that the production data is complete and accurate. The environment is a preparatory measure. The most important integrity controls are those that validate the actual converted data, such as reconciliation and referential integrity checks, rather than the infrastructure used to practice the migration.
- ✓
Verification that referential integrity constraints are enabled and validated after the data load.
Why this is correct
Referential integrity constraints prevent orphaned records and invalid relationships in the new database. If they are disabled during the load and not re-enabled and validated afterward, the database may contain inconsistent foreign key values that corrupt business logic and reporting. Confirming that constraints are active and that validation completed ensures the migrated data conforms to the target schema's relational rules.
- ✗
Approval of the data mapping document by the database administrator before the conversion begins.
Why it's wrong here
A data mapping document is important for planning, but approval by only the database administrator does not ensure data integrity. Mapping decisions require business validation to confirm that fields are correctly translated. This option is a documentation review step, not a detective control that verifies the actual migrated values. It is therefore less important for confirming integrity than reconciliation and referential integrity validation.
- ✓
Reconciliation of record counts and financial totals between legacy sources and the new database after conversion.
Why this is correct
Reconciliation provides independent evidence that all expected records and financial balances arrived in the new database. It detects dropped rows, duplicated entries, and truncation errors that might otherwise go unnoticed. Because this control compares source and target at an aggregate level, it is a fundamental integrity check for any data migration and directly addresses completeness and accuracy of the converted data.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.