Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An IS auditor is reviewing the change management process for a critical financial application. Which of the following is the most important element to verify in an emergency change request?

⚠ Common exam trap

CISA often tests the prioritization of controls in emergency changes, tempting candidates to select standard controls like CAB approval or UAT that are often bypassed in emergencies, instead of the rollback plan that is the key risk mitigation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A documented rollback plan

In an emergency change, the most critical element to verify is a documented rollback plan. Emergency changes are implemented with minimal testing and often bypass normal approval processes; a rollback plan ensures that if the change fails or causes unintended consequences, the system can be restored to its previous state quickly, minimizing disruption to critical financial operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Approval from the Change Advisory Board (CAB)

    Why it's wrong here

    Emergency changes frequently bypass the full CAB, which convenes periodically; the auditor should verify that a designated emergency approver authorised the change, with CAB ratification afterwards. It is tempting because CAB approval is the norm for standard changes, but it would be correct only for routine changes routed through the normal change process.

  • ✗

    Extensive user acceptance testing (UAT) results

    Why it's wrong here

    Extensive UAT cannot precede an emergency change, since the change is deployed immediately to resolve an incident; the auditor should verify post-implementation review and testing instead. It is tempting because UAT is expected for standard changes, but it would be correct only for planned changes with a normal lead time before deployment.

  • ✗

    A completed impact analysis

    Why it's wrong here

    An emergency change is implemented under time pressure to restore service, so a completed impact analysis is often produced retrospectively; the auditor should verify that the change was authorised and documented, not that full analysis preceded it. It is tempting because impact analysis is standard for normal changes, but it would be correct only for planned, non-emergency changes.

  • ✓

    A documented rollback plan

    Why this is correct

    A documented rollback plan directly satisfies the emergency change constraint by enabling rapid restoration of the financial application if the change fails, minimising disruption to critical processing. Verifying it confirms the organisation can reverse unplanned modifications without extended downtime, which matters more than retrospective approvals when emergency changes bypass normal change management controls.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.