Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An IS auditor is reviewing a post-implementation review report for a new financial system. Which finding would most indicate that the project did not meet its objectives?

⚠ Common exam trap

CISA often tests the difference between normal post-go-live issues (training, minor changes, small budget variance) and substantive failures to meet objectives — the trap is over-weighting minor issues as objective failures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The system processed transactions 20% slower than projected

A system processing transactions 20% slower than projected directly indicates that the system failed to meet a key performance objective, which is a core project objective. Post-implementation reviews assess whether the system delivers expected performance, functionality, and benefits; a significant performance shortfall is a clear sign objectives were not met. This finding most strongly indicates a failure to meet objectives.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Three minor change requests were submitted in the first month

    Why it's wrong here

    A few minor change requests in the first month are normal post-implementation tuning and signal user adoption rather than objective failure. It tempts because change volume is a recognised project metric, and it would be the correct finding when the audit question concerns scope creep or requirements quality.

  • ✗

    Users required additional training after go-live

    Why it's wrong here

    Post-go-live training needs indicate a transition or knowledge-transfer gap, not that the system failed to deliver its intended business objectives. It tempts because training shortfalls are common project findings, and they would be the correct indicator when the audit question addresses user readiness or change management effectiveness.

  • ✗

    The project budget was exceeded by 5%

    Why it's wrong here

    Budget variance measures cost performance, not whether the system delivers the intended business benefits, so a 5% overspend alone does not evidence failed objectives. It tempts because cost control is a standard project metric, and overruns would be the correct finding when the audit question concerns budget management rather than objective achievement.

  • ✓

    The system processed transactions 20% slower than projected

    Why this is correct

    Throughput below the projected baseline means the system fails its defined performance objective, so the project did not deliver the agreed benefits. Budget compliance and delivery date are irrelevant to this finding; processing speed is a measurable acceptance criterion.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.