CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An IS auditor is reviewing a software development project that uses a DevOps pipeline. The auditor observes that developers can push code directly to production without independent review. Which of the following is the MOST significant risk arising from this practice?
⚠ Common exam trap
The trap here is focusing on deployment speed or version control, when the core issue is the lack of independent review enabling unauthorized or defective code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Unauthorized or defective code being deployed to production.
Allowing developers to push code directly to production without independent review violates segregation of duties and removes a critical quality gate. This increases the likelihood that defective or unauthorized code will be deployed, leading to system outages, security breaches, or data integrity issues. The most significant risk is therefore the deployment of unauthorized or defective code.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Inability to track changes due to lack of version control.
Why it's wrong here
DevOps pipelines usually rely heavily on version control systems like Git. The scenario does not indicate a lack of version control; it states developers can push directly to production. Version control may still be in place, but the absence of independent review is the issue. Thus, this is not the primary risk, as tracking changes is likely still possible through the pipeline.
- ✗
Increased time to deploy new features.
Why it's wrong here
Direct pushes to production typically accelerate deployment, not delay it. The risk is not about speed but about control. Without independent review, defects or malicious code may reach production, but the deployment time itself is likely reduced. Therefore, this is not the most significant risk; it is actually a benefit in terms of speed, though it comes with other risks.
- ✓
Unauthorized or defective code being deployed to production.
Why this is correct
Without independent review, developers can deploy code that contains errors, security vulnerabilities, or even malicious logic. This bypasses a key segregation of duties control and increases the risk of system compromise, data corruption, or fraud. The lack of review means defects may not be caught before impacting users, and accountability is weakened. This is the most significant risk because it directly affects the integrity and security of the production environment.
- ✗
Increased infrastructure costs due to automated deployments.
Why it's wrong here
Automated deployments can sometimes reduce costs by minimizing manual effort, but the scenario does not suggest cost issues. The primary concern is not financial but operational and security-related. While infrastructure costs could increase, this is not the most significant risk compared to the potential for unauthorized or defective code. The focus should be on the control weakness.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.