Courseiva
mediumMultiple Choice

CISA Practice Question: Is evaluating a vendor for a custom application…

An organization is evaluating a vendor for a custom application development. The vendor states they are assessed at CMMI Level 2 (Managed). Which of the following best describes the implication of this rating?

⚠ Common exam trap

Many candidates confuse CMMI Level 2 (Managed) with Level 3 (Defined) or Level 4 (Quantitatively Managed), leading candidates to select options that describe higher maturity levels where processes are standardized or statistically controlled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The vendor's projects have a basic project management process that is planned and executed.

CMMI Level 2 (Managed) indicates that the vendor has established basic project management processes to plan, execute, monitor, and control projects. This means projects are managed according to documented plans, with defined requirements, project planning, and configuration management, but processes are not yet standardized across the organization. Option D correctly captures this foundational level of process maturity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The vendor's processes are defined and tailored from organization-wide standards.

    Why it's wrong here

    CMMI Level 2 means processes are managed at the project level, with basic planning and tracking; organisation-wide defined standards appear at Level 3. It tempts because Level 2 sounds mature, but the stem's description of tailored organisation-wide standards matches Level 3, not this rating.

  • ✗

    The vendor's processes are continuously improved through quantitative feedback.

    Why it's wrong here

    Level 2 requires only that processes are planned, performed, measured and controlled at the project level; continuous quantitative improvement belongs to Level 4 (Quantitatively Managed) and Level 5 (Optimising). It tempts because Level 2 does introduce basic measurement, but those metrics do not feed organisation-wide process improvement.

  • ✗

    The vendor has a quantitatively managed process with statistical control.

    Why it's wrong here

    Statistical process control over subprocesses defines CMMI Level 4 (Quantitatively Managed), not Level 2. Level 2 (Managed) only demands that requirements, planning, measurement, verification and configuration are managed per project. It tempts because Level 2 does mandate measurement, but not quantitative control of process performance.

  • ✓

    The vendor's projects have a basic project management process that is planned and executed.

    Why this is correct

    CMMI Level 2 (Managed) denotes that projects apply basic project management: requirements, planning, measurement and control are established per project, though organisation-wide standardisation is absent. This matches the stem's constraint of describing what a Level 2 rating implies for the vendor's development work.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.