Courseiva
hardMultiple ChoiceObjective-mapped

CISA Practice Question: Is adopting an agile development methodology for…

An organization is adopting an agile development methodology for a new financial application. During a sprint review, the product owner expresses concern that the system does not enforce segregation of duties (SoD). The development team argues that SoD will be addressed in a future sprint. As the IS auditor, what is the BEST recommendation?

⚠ Common exam trap

Many exam-takers confuse 'accepting the risk' (Option A) with a valid risk management approach, but in this context, the auditor must advocate for timely implementation of a critical control rather than deferring to the product owner's risk appetite.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Insist that SoD be implemented in the next sprint.

In agile development, security and compliance requirements like segregation of duties (SoD) must be addressed as early as possible, especially for a financial application where regulatory compliance is critical. Delaying SoD to a future sprint introduces significant risk and violates the principle of 'secure by design.' The IS auditor's best recommendation is to insist that SoD be implemented in the next sprint, ensuring that the control is prioritized and integrated into the development lifecycle without waiting for an indefinite future iteration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Suggest that the product owner accept the residual risk.

    Why it's wrong here

    Acceptance should be formal, but the auditor should not default to acceptance.

  • Insist that SoD be implemented in the next sprint.

    Why this is correct

    SoD should be addressed as soon as possible.

  • Accept the team's plan and document the risk.

    Why it's wrong here

    Documentation alone does not mitigate the risk.

  • Require immediate implementation of SoD in this sprint.

    Why it's wrong here

    This may disrupt the sprint but is necessary.

About these practice questions

One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.