Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An organization is implementing a new CRM system using an agile methodology. The IS auditor wants to assess whether security requirements are being addressed. What is the best evidence for the auditor to review?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The product backlog

The product backlog contains user stories, including security-related stories. Reviewing them shows whether security requirements are explicitly included.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The security policy

    Why it's wrong here

    The policy is a general document, not evidence of implementation.

  • The sprint retrospective minutes

    Why it's wrong here

    Retrospectives discuss process, not specific requirements.

  • The system architecture document

    Why it's wrong here

    Architecture documents may be high-level and not updated frequently in agile.

  • The product backlog

    Why this is correct

    The backlog captures all requirements, including security, as user stories.

About these practice questions

One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.