CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An organization is implementing a new financial system using the waterfall SDLC model. Which of the following is the MOST critical control to ensure that business requirements are met?
⚠ Common exam trap
CISA often tests the distinction between technical verification (unit tests, code reviews, design docs) and business validation (UAT), so candidates who equate 'testing' with 'requirements met' pick A or B instead of the business-facing UAT sign-off.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Formal user acceptance testing (UAT) sign-off
In a waterfall SDLC, formal user acceptance testing (UAT) sign-off is the definitive control that confirms the delivered system satisfies the documented business requirements before go-live. UAT is performed by business users against requirements-based test scenarios, so their formal sign-off provides auditable evidence that the system meets business needs. This is the last gate where business stakeholders validate fitness for purpose.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Automated unit testing results
Why it's wrong here
Unit tests verify that individual code units behave as the developers intended; they do not confirm the system satisfies documented business requirements. They would be the right control for validating code correctness during construction, whereas waterfall demands formal requirements traceability and user acceptance testing before sign-off.
- ✗
Code reviews by the development team
Why it's wrong here
Code reviews check implementation quality, style and defects among developers; they cannot confirm the system meets documented business requirements. They are the right control for improving code correctness during development, whereas waterfall requires formal requirements traceability and user acceptance testing before the system is accepted.
- ✗
Detailed technical design documents
Why it's wrong here
Technical design documents describe how the system will be built, not whether it delivers the agreed business requirements. They are the correct artefact for guiding developers during construction, but waterfall's requirements phase needs traceability and user acceptance testing to confirm business needs are actually met.
- ✓
Formal user acceptance testing (UAT) sign-off
Why this is correct
Formal UAT sign-off requires business users to validate the system against documented requirements before go-live, providing the definitive control that confirms business requirements are met. This satisfies the waterfall model's need for verification at the testing phase before implementation proceeds.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.