hardMultiple Select
CISA Is implementing a new cloud-based HR system Practice Question
An organization is implementing a new cloud-based HR system. The project sponsor wants to skip regular project status meetings to speed up delivery. Which THREE of the following are the MOST significant risks of eliminating these meetings?
⚠ Common exam trap
Many exam-takers confuse the purpose of status meetings with other project management artifacts, assuming that documentation alone (e.g., project plans, risk registers) can substitute for the real-time communication and decision-making that occurs in these meetings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Stakeholders may be unaware of critical project issues.
Option B is correct because regular status meetings are the primary mechanism for surfacing critical project issues to stakeholders; without them, stakeholders lose visibility into risks, blockers, and changes, which is especially dangerous in a cloud HR implementation with many interested parties. Option D is correct because status meetings serve as a forum where decisions are made, confirmed, and communicated; skipping them increases the likelihood that important decisions are never documented or shared, leading to misalignment and rework. Option E is correct because these meetings are where cross-team dependencies, task sequencing, and integration points (for example, between the cloud HR system and existing identity or payroll systems) are coordinated; without them, dependencies can be missed and cause schedule slips. Option A is not marked correct because security requirements are typically captured through dedicated security and compliance activities, architecture reviews, and requirements-gathering sessions rather than routine status meetings, so their omission is not the most direct risk of canceling status meetings. Option C is not marked correct because budget tracking is normally handled through financial reporting, earned value analysis, and cost-control processes, so overruns are not primarily detected in status meetings and would not be the most significant risk of eliminating them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security requirements may be overlooked.
Why it's wrong here
Security requirements should be defined early, not in status meetings.
- ✓
Stakeholders may be unaware of critical project issues.
Why this is correct
Status meetings are the primary channel for surfacing blockers, risks and slippage. Removing them leaves no structured forum for raising issues, so problems may remain hidden until they escalate, delaying delivery and forcing costly reactive work.
- ✗
Budget overruns may go unnoticed until the end.
Why it's wrong here
Budget tracking can be done via other means.
- ✓
Important decisions may not be documented or communicated.
Why this is correct
Status meetings create the record where decisions, approvals and changes are captured and shared. Skipping them means choices may be made verbally and never documented, leaving stakeholders without visibility and creating disputes over scope, budget or design later.
- ✓
Dependencies between project tasks may not be properly managed.
Why this is correct
Without status meetings, task interdependencies go unmonitored, so a delayed predecessor silently blocks successors and slips the critical path. The sponsor's speed objective is defeated because unmanaged dependencies surface late as rework, not as saved time.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.