Information Systems Acquisition, Development, and Implementation →hardMultiple SelectObjective-mapped
CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An organization is adopting a DevOps approach for system development. Which THREE controls should an IS auditor expect to see in place to maintain security and compliance?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Automated security scanning integrated into the CI/CD pipeline
In DevOps, automated security scanning, infrastructure as code with security review, and continuous monitoring are key controls to integrate security into the pipeline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Annual penetration testing after the release
Why it's wrong here
DevOps requires continuous testing, not just annual.
- ✓
Automated security scanning integrated into the CI/CD pipeline
Why this is correct
Ensures security checks are performed with every build.
- ✓
Version control and change tracking for infrastructure as code
Why this is correct
Ensures traceability and auditability of infrastructure changes.
- ✗
Manual code review for every change before deployment
Why it's wrong here
In DevOps, automation is preferred; manual review may be too slow.
- ✓
Real-time monitoring and logging of production systems
Why this is correct
Enables detection of security incidents.
Go deeper
Related to this question
About these practice questions
One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.