Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An organization is implementing a new financial system using the waterfall SDLC model. Which of the following is the MOST critical control to ensure that business requirements are met?

⚠ Common exam trap

CISA often tests the distinction between technical verification (unit tests, code reviews, design docs) and business validation (UAT), so candidates who equate 'testing' with 'requirements met' pick A or B instead of the business-facing UAT sign-off.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Formal user acceptance testing (UAT) sign-off

In a waterfall SDLC, formal user acceptance testing (UAT) sign-off is the definitive control that confirms the delivered system satisfies the documented business requirements before go-live. UAT is performed by business users against requirements-based test scenarios, so their formal sign-off provides auditable evidence that the system meets business needs. This is the last gate where business stakeholders validate fitness for purpose.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Automated unit testing results

    Why it's wrong here

    Unit tests verify that individual code units behave as the developers intended; they do not confirm the system satisfies documented business requirements. They would be the right control for validating code correctness during construction, whereas waterfall demands formal requirements traceability and user acceptance testing before sign-off.

  • ✗

    Code reviews by the development team

    Why it's wrong here

    Code reviews check implementation quality, style and defects among developers; they cannot confirm the system meets documented business requirements. They are the right control for improving code correctness during development, whereas waterfall requires formal requirements traceability and user acceptance testing before the system is accepted.

  • ✗

    Detailed technical design documents

    Why it's wrong here

    Technical design documents describe how the system will be built, not whether it delivers the agreed business requirements. They are the correct artefact for guiding developers during construction, but waterfall's requirements phase needs traceability and user acceptance testing to confirm business needs are actually met.

  • ✓

    Formal user acceptance testing (UAT) sign-off

    Why this is correct

    Formal UAT sign-off requires business users to validate the system against documented requirements before go-live, providing the definitive control that confirms business requirements are met. This satisfies the waterfall model's need for verification at the testing phase before implementation proceeds.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.