mediumMultiple Choice
CISA Practice Question: Is evaluating a vendor for a custom application…
An organization is evaluating a vendor for a custom application development. The vendor states they are assessed at CMMI Level 2 (Managed). Which of the following best describes the implication of this rating?
⚠ Common exam trap
Many candidates confuse CMMI Level 2 (Managed) with Level 3 (Defined) or Level 4 (Quantitatively Managed), leading candidates to select options that describe higher maturity levels where processes are standardized or statistically controlled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The vendor's projects have a basic project management process that is planned and executed.
CMMI Level 2 (Managed) indicates that the vendor has established basic project management processes to plan, execute, monitor, and control projects. This means projects are managed according to documented plans, with defined requirements, project planning, and configuration management, but processes are not yet standardized across the organization. Option D correctly captures this foundational level of process maturity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The vendor's processes are defined and tailored from organization-wide standards.
Why it's wrong here
CMMI Level 2 means processes are managed at the project level, with basic planning and tracking; organisation-wide defined standards appear at Level 3. It tempts because Level 2 sounds mature, but the stem's description of tailored organisation-wide standards matches Level 3, not this rating.
- ✗
The vendor's processes are continuously improved through quantitative feedback.
Why it's wrong here
Level 2 requires only that processes are planned, performed, measured and controlled at the project level; continuous quantitative improvement belongs to Level 4 (Quantitatively Managed) and Level 5 (Optimising). It tempts because Level 2 does introduce basic measurement, but those metrics do not feed organisation-wide process improvement.
- ✗
The vendor has a quantitatively managed process with statistical control.
Why it's wrong here
Statistical process control over subprocesses defines CMMI Level 4 (Quantitatively Managed), not Level 2. Level 2 (Managed) only demands that requirements, planning, measurement, verification and configuration are managed per project. It tempts because Level 2 does mandate measurement, but not quantitative control of process performance.
- ✓
The vendor's projects have a basic project management process that is planned and executed.
Why this is correct
CMMI Level 2 (Managed) denotes that projects apply basic project management: requirements, planning, measurement and control are established per project, though organisation-wide standardisation is absent. This matches the stem's constraint of describing what a Level 2 rating implies for the vendor's development work.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.