Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An IS auditor is reviewing a software development project that uses a DevOps pipeline. The auditor observes that developers can push code directly to production without independent review. Which of the following is the MOST significant risk arising from this practice?

⚠ Common exam trap

The trap here is focusing on deployment speed or version control, when the core issue is the lack of independent review enabling unauthorized or defective code.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unauthorized or defective code being deployed to production.

Allowing developers to push code directly to production without independent review violates segregation of duties and removes a critical quality gate. This increases the likelihood that defective or unauthorized code will be deployed, leading to system outages, security breaches, or data integrity issues. The most significant risk is therefore the deployment of unauthorized or defective code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Inability to track changes due to lack of version control.

    Why it's wrong here

    DevOps pipelines usually rely heavily on version control systems like Git. The scenario does not indicate a lack of version control; it states developers can push directly to production. Version control may still be in place, but the absence of independent review is the issue. Thus, this is not the primary risk, as tracking changes is likely still possible through the pipeline.

  • ✗

    Increased time to deploy new features.

    Why it's wrong here

    Direct pushes to production typically accelerate deployment, not delay it. The risk is not about speed but about control. Without independent review, defects or malicious code may reach production, but the deployment time itself is likely reduced. Therefore, this is not the most significant risk; it is actually a benefit in terms of speed, though it comes with other risks.

  • ✓

    Unauthorized or defective code being deployed to production.

    Why this is correct

    Without independent review, developers can deploy code that contains errors, security vulnerabilities, or even malicious logic. This bypasses a key segregation of duties control and increases the risk of system compromise, data corruption, or fraud. The lack of review means defects may not be caught before impacting users, and accountability is weakened. This is the most significant risk because it directly affects the integrity and security of the production environment.

  • ✗

    Increased infrastructure costs due to automated deployments.

    Why it's wrong here

    Automated deployments can sometimes reduce costs by minimizing manual effort, but the scenario does not suggest cost issues. The primary concern is not financial but operational and security-related. While infrastructure costs could increase, this is not the most significant risk compared to the potential for unauthorized or defective code. The focus should be on the control weakness.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.