CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An IS auditor is evaluating an organization's SDLC controls for a new system. Which TWO of the following are key controls that should be in place during the design phase? (Select TWO.)
⚠ Common exam trap
Many candidates confuse security testing techniques like SAST with design-phase controls, or they mistakenly think UAT or regression testing occur early in the SDLC, when in fact they belong to later phases.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Architecture review by a senior architect
Option A (Architecture review by a senior architect) is correct because the design phase is exactly when the proposed system architecture, integration points, and technology choices must be validated against enterprise standards, scalability, and security requirements before costly build work begins. Option E (Threat modeling to identify security threats) is correct because threat modeling is a design-phase activity that systematically identifies threats, attack surfaces, and required mitigations (e.g., using STRIDE or DREAD) so that security controls are built into the design rather than retrofitted. Option B (SAST) is not a design-phase control; static application security testing analyzes source code or binaries during coding/build, so it belongs to development and testing phases. Option C (UAT) is a testing-phase control performed by end users to confirm the system meets business requirements before go-live. Option D (Regression testing) is also a testing-phase control executed after changes to verify that existing functionality has not been broken.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Architecture review by a senior architect
Why this is correct
Architecture review by a senior architect validates design decisions against security, scalability and compliance requirements before coding begins, satisfying the design-phase control objective. It provides independent scrutiny of proposed structures, catching flaws when remediation is cheapest. This directly addresses the stem's requirement for key design-phase SDLC controls.
- ✗
Static application security testing (SAST)
Why it's wrong here
SAST scans source code for vulnerabilities, requiring code to exist, so it cannot run during design when only specifications and models are produced. It is tempting because it shifts security left, and it would be correct during coding or build, where analysers inspect committed source.
- ✗
User acceptance testing (UAT)
Why it's wrong here
UAT executes the built system against business scenarios, so it belongs to the testing phase, after design is baselined. It is tempting because UAT validates that requirements were met, and it would be the correct control once code exists and testers verify the delivered functionality.
- ✗
Regression testing
Why it's wrong here
Regression testing re-runs existing test cases after changes to confirm nothing previously working has broken, which occurs during testing and maintenance, not design. It is tempting because it protects existing functionality, and it would be correct after code modifications in later lifecycle phases.
- ✓
Threat modeling to identify security threats
Why this is correct
Threat modelling systematically enumerates threats and attack vectors against the proposed design, letting the team embed mitigating controls before code is written. It satisfies the design-phase control objective of identifying security threats early, when remediation is cheapest.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.