Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An organization is implementing a large ERP system. The project manager is concerned about segregation of duties conflicts. Which THREE controls should the IS auditor recommend to mitigate segregation of duties risks during implementation? (Select THREE)

⚠ Common exam trap

The trap is the absolutist option — candidates are drawn to 'delay deployment until all conflicts are resolved' because it sounds rigorous, but CISA expects recognition that compensating controls, not elimination, are the practical mitigation for inherent SoD conflicts.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use automated segregation of duties monitoring tools

Option A is correct because automated segregation of duties (SoD) monitoring tools continuously analyze user role assignments and transaction authorizations against a ruleset of conflicting access combinations, enabling early detection and remediation of toxic combinations during ERP implementation. Option C is correct because role-based access controls (RBAC) map permissions to defined job functions rather than to individuals, which prevents the accumulation of conflicting duties and provides a maintainable, auditable authorization structure in the ERP. Option E is correct because requiring dual approval (two-person integrity) for sensitive transactions such as vendor master changes or payment runs compensates for residual SoD conflicts by ensuring no single user can complete a high-risk action alone. Option B is not appropriate because halting deployment until every conflict is resolved is impractical and ignores the use of compensating controls and risk acceptance. Option D is not appropriate because a single end-of-project UAT would not provide the continuous, iterative control testing needed to detect SoD conflicts throughout implementation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use automated segregation of duties monitoring tools

    Why this is correct

    Continuous automated monitoring detects toxic access combinations across the ERP as roles and users change, flagging conflicts that manual reviews miss. It provides detective coverage throughout implementation, when role design is still fluid and SoD conflicts are introduced.

  • ✗

    Delay deployment until all segregation conflicts are resolved

    Why it's wrong here

    Deployment delay resolves nothing technically: segregation conflicts persist in the configured role design until duties are reassigned or compensating controls added. It is tempting because halting go-live feels risk-averse, and postponement would suit a project lacking any remediation plan, but the stem asks for controls mitigating risk during implementation, not avoidance.

  • ✓

    Implement role-based access controls (RBAC) aligned with job functions

    Why this is correct

    RBAC grants permissions by job function rather than individual, preventing the accumulation of conflicting duties within one user account. Aligning roles to job functions at design stage removes the root cause of SoD conflicts before they are built into the ERP.

  • ✗

    Conduct a single user acceptance test (UAT) at the end of the project

    Why it's wrong here

    A single end-of-project UAT leaves conflicting access combinations undetected until go-live, when remediation is costly; SoD needs role design review and testing throughout. It is tempting because consolidated UAT is the right choice when validating end-to-end business process flows before final cutover.

  • ✓

    Require dual approval for sensitive transactions

    Why this is correct

    Dual approval inserts a second, independent authoriser into sensitive transactions, so no single user can initiate and complete a high-risk action alone. This compensating control mitigates residual SoD conflicts that cannot be removed through role design.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.