Courseiva
hardMultiple Choice

CISA Is implementing a COTS application Practice Question

An organization is implementing a COTS application. The project team plans to heavily customize the application to meet unique business processes. Which of the following is the most significant risk?

⚠ Common exam trap

CISA often tests the distinction between customization risks and general implementation risks; candidates may choose vendor lock-in or high cost because they sound plausible, but the most significant risk from heavy customization is the difficulty of applying future vendor upgrades, which directly impacts maintainability and security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Difficulties in applying future vendor upgrades

Heavy customization of a COTS application modifies its core code or configuration in ways that diverge from the vendor's standard product. When the vendor releases updates or patches, these customizations often conflict with the new code, making upgrades complex, risky, or even impossible without rework. This directly threatens the organization's ability to stay current with security fixes and new features, which is a critical operational and compliance risk. Thus, difficulties in applying future vendor upgrades is the most significant risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Vendor lock-in

    Why it's wrong here

    Vendor lock-in arises from proprietary data formats and migration costs, which exist regardless of customisation depth. It tempts because COTS procurement genuinely creates dependency, and lock-in would be the leading risk if the organisation were choosing a proprietary platform over open standards.

  • ✗

    Incompatibility with future releases

    Why it's wrong here

    Customisations modify the vendor's core code, so patches and upgrades may overwrite them or fail to apply, creating rework and version lock-in. It is tempting because integration and compatibility concerns feel abstract, and incompatibility would be the correct risk when the COTS product itself cannot interoperate with existing platforms.

  • ✓

    Difficulties in applying future vendor upgrades

    Why this is correct

    Heavy customisation modifies vendor-supplied code and data structures, so future vendor upgrades and patches may conflict with or overwrite those changes. This creates significant rework and regression risk each time the vendor releases a new version, making upgrade difficulties the primary risk of the COTS implementation.

  • ✗

    High implementation cost

    Why it's wrong here

    Customisation cost is a one-off budget overrun, not the enduring risk that heavy modification creates. It tempts because COTS projects do carry licence and consultancy costs, so cost control is a legitimate concern in a standard, lightly configured deployment where scope stays fixed.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.