Courseiva
easyMultiple ChoiceObjective-mapped

CISA Practice Question: An IS auditor is evaluating the effectiveness of…

An IS auditor is evaluating the effectiveness of an organization's change management process. Which of the following is the most important control to verify during the audit?

⚠ Common exam trap

The trap here is that candidates often focus on approval or prioritization controls (options A and D) as the most important, overlooking the foundational technical control of segregation of duties that directly prevents unauthorized code from reaching production.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

A segregation of duties exists between development and production.

Segregation of duties between development and production environments ensures that code cannot be directly moved from development to production without independent review and testing. This control prevents unauthorized or untested code from affecting live systems, which is a fundamental principle of change management. Without this separation, a developer could introduce malicious or defective code directly into production, bypassing all quality and security checks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • All changes are approved by the IT manager.

    Why it's wrong here

    Approval by a single individual may not provide adequate oversight.

  • Emergency changes are documented after implementation.

    Why it's wrong here

    Documentation after implementation is important but not the most important control.

  • A segregation of duties exists between development and production.

    Why this is correct

    Segregation of duties is a key preventive control.

  • Change requests are prioritized by business impact.

    Why it's wrong here

    Prioritization is a process efficiency, not a control.

About these practice questions

Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.