Courseiva

CISA Practice Question: Information Systems Operations and Business Resilience

An IS auditor is reviewing change management for a financial application. Which TWO of the following findings would most likely indicate a control weakness?

⚠ Common exam trap

The trap here is that candidates may incorrectly consider emergency changes authorized only by the change manager as acceptable, but it is a control weakness because it bypasses proper segregation of duties and approval hierarchy. Even emergency changes should require authorization from a higher authority or be subject to post-implementation review.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Regression testing is not performed for minor changes.

Option A is a control weakness because regression testing verifies that a change has not broken existing functionality; skipping it even for minor changes to a financial application risks undetected defects or integrity failures in production. Option B is a control weakness because emergency changes should be authorized by an appropriate business or IT authority (and later reviewed by the change advisory board), not by the change manager alone, which creates an improper segregation-of-duties conflict since the same person manages and approves the change. Option C is not a weakness because testing normal changes in a development environment before production is a sound change management control. Option D is not a weakness because a weekly change advisory board reviewing all changes provides proper oversight and authorization. Option E is not a weakness because documenting all changes in a change log supports traceability and auditability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Regression testing is not performed for minor changes.

    Why this is correct

    Regression testing verifies that existing functionality still works after a change. Skipping it for minor changes allows unintended side effects to reach production undetected, directly weakening change control in a financial application where data integrity and transaction accuracy are critical.

  • ✓

    Emergency changes are authorized by the change manager only.

    Why this is correct

    Emergency changes bypass normal approval, so authorisation by the change manager alone removes the segregation of duties between requesting, approving and implementing. This single-person control permits unauthorised or fraudulent changes to the financial application to go unchallenged.

  • ✗

    Normal changes are tested in a development environment before production.

    Why it's wrong here

    Testing normal changes in a development environment before production is a segregation-of-duties control that prevents untested code reaching live systems, so it is not a weakness. It is tempting to question because development environments can differ from production, but the finding describes the prescribed control being performed.

  • ✗

    The change advisory board meets weekly to review all changes.

    Why it's wrong here

    A change advisory board reviewing all changes weekly provides authorisation and oversight, which is a control strength, not a weakness. It is tempting to flag because weekly cadence may delay emergency changes, but the scenario asks for weaknesses, and scheduled CAB review is standard practise for normal changes.

  • ✗

    All changes are documented in a change log.

    Why it's wrong here

    Documenting every change in a change log is a fundamental control that provides audit trail and traceability, so it evidences effective change management rather than a weakness. It is tempting to flag as a finding because documentation is often incomplete, but the scenario asks for weaknesses, and this is the expected control.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.