hardMultiple Choice
CISA Is implementing a COTS application Practice Question
An organization is implementing a COTS application. The project team plans to heavily customize the application to meet unique business processes. Which of the following is the most significant risk?
⚠ Common exam trap
CISA often tests the distinction between customization risks and general implementation risks; candidates may choose vendor lock-in or high cost because they sound plausible, but the most significant risk from heavy customization is the difficulty of applying future vendor upgrades, which directly impacts maintainability and security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Difficulties in applying future vendor upgrades
Heavy customization of a COTS application modifies its core code or configuration in ways that diverge from the vendor's standard product. When the vendor releases updates or patches, these customizations often conflict with the new code, making upgrades complex, risky, or even impossible without rework. This directly threatens the organization's ability to stay current with security fixes and new features, which is a critical operational and compliance risk. Thus, difficulties in applying future vendor upgrades is the most significant risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Vendor lock-in
Why it's wrong here
Vendor lock-in arises from proprietary data formats and migration costs, which exist regardless of customisation depth. It tempts because COTS procurement genuinely creates dependency, and lock-in would be the leading risk if the organisation were choosing a proprietary platform over open standards.
- ✗
Incompatibility with future releases
Why it's wrong here
Customisations modify the vendor's core code, so patches and upgrades may overwrite them or fail to apply, creating rework and version lock-in. It is tempting because integration and compatibility concerns feel abstract, and incompatibility would be the correct risk when the COTS product itself cannot interoperate with existing platforms.
- ✓
Difficulties in applying future vendor upgrades
Why this is correct
Heavy customisation modifies vendor-supplied code and data structures, so future vendor upgrades and patches may conflict with or overwrite those changes. This creates significant rework and regression risk each time the vendor releases a new version, making upgrade difficulties the primary risk of the COTS implementation.
- ✗
High implementation cost
Why it's wrong here
Customisation cost is a one-off budget overrun, not the enduring risk that heavy modification creates. It tempts because COTS projects do carry licence and consultancy costs, so cost control is a legitimate concern in a standard, lightly configured deployment where scope stays fixed.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.