CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An organization is implementing a large ERP system. The project manager is concerned about segregation of duties conflicts. Which THREE controls should the IS auditor recommend to mitigate segregation of duties risks during implementation? (Select THREE)
⚠ Common exam trap
The trap is the absolutist option — candidates are drawn to 'delay deployment until all conflicts are resolved' because it sounds rigorous, but CISA expects recognition that compensating controls, not elimination, are the practical mitigation for inherent SoD conflicts.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use automated segregation of duties monitoring tools
Option A is correct because automated segregation of duties (SoD) monitoring tools continuously analyze user role assignments and transaction authorizations against a ruleset of conflicting access combinations, enabling early detection and remediation of toxic combinations during ERP implementation. Option C is correct because role-based access controls (RBAC) map permissions to defined job functions rather than to individuals, which prevents the accumulation of conflicting duties and provides a maintainable, auditable authorization structure in the ERP. Option E is correct because requiring dual approval (two-person integrity) for sensitive transactions such as vendor master changes or payment runs compensates for residual SoD conflicts by ensuring no single user can complete a high-risk action alone. Option B is not appropriate because halting deployment until every conflict is resolved is impractical and ignores the use of compensating controls and risk acceptance. Option D is not appropriate because a single end-of-project UAT would not provide the continuous, iterative control testing needed to detect SoD conflicts throughout implementation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use automated segregation of duties monitoring tools
Why this is correct
Continuous automated monitoring detects toxic access combinations across the ERP as roles and users change, flagging conflicts that manual reviews miss. It provides detective coverage throughout implementation, when role design is still fluid and SoD conflicts are introduced.
- ✗
Delay deployment until all segregation conflicts are resolved
Why it's wrong here
Deployment delay resolves nothing technically: segregation conflicts persist in the configured role design until duties are reassigned or compensating controls added. It is tempting because halting go-live feels risk-averse, and postponement would suit a project lacking any remediation plan, but the stem asks for controls mitigating risk during implementation, not avoidance.
- ✓
Implement role-based access controls (RBAC) aligned with job functions
Why this is correct
RBAC grants permissions by job function rather than individual, preventing the accumulation of conflicting duties within one user account. Aligning roles to job functions at design stage removes the root cause of SoD conflicts before they are built into the ERP.
- ✗
Conduct a single user acceptance test (UAT) at the end of the project
Why it's wrong here
A single end-of-project UAT leaves conflicting access combinations undetected until go-live, when remediation is costly; SoD needs role design review and testing throughout. It is tempting because consolidated UAT is the right choice when validating end-to-end business process flows before final cutover.
- ✓
Require dual approval for sensitive transactions
Why this is correct
Dual approval inserts a second, independent authoriser into sensitive transactions, so no single user can initiate and complete a high-risk action alone. This compensating control mitigates residual SoD conflicts that cannot be removed through role design.
Visual reference
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.