Courseiva
easyMultiple Choice

CISA Is implementing a new financial system Practice Question

An organization is implementing a new financial system. Which of the following is the MOST important control to ensure data integrity during the data migration phase?

⚠ Common exam trap

Many candidates confuse data integrity controls with security controls (like encryption) or validation activities (like UAT), failing to recognize that reconciliation is the only option that directly verifies the accuracy and completeness of the migrated data itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing reconciliation controls between source and target

Reconciliation controls between source and target systems are the most critical control for ensuring data integrity during migration because they provide a systematic method to verify that every record has been accurately transferred without loss, duplication, or corruption. This typically involves comparing record counts, hash totals, or checksums (e.g., using MD5 or SHA-256) between the legacy and new databases, and flagging any discrepancies for correction before the system goes live.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conducting a post-implementation review

    Why it's wrong here

    A post-implementation review happens after go-live, so it cannot prevent corrupted or incomplete records entering the new financial system during migration. It is tempting because it validates whether project objectives were met, and would be the right control for closing a project or feeding lessons-learned into governance.

  • ✓

    Implementing reconciliation controls between source and target

    Why this is correct

    Reconciliation controls compare source and target records, detecting omissions, duplications and value mismatches introduced during migration. This directly satisfies the stem's data integrity constraint, since completeness and accuracy of migrated financial data are verified before the new system goes live.

  • ✗

    Encrypting data in transit

    Why it's wrong here

    Encryption in transit protects data moving across the network but does not verify completeness, accuracy or reconciliation of migrated records. The temptation is that migration involves transfer, so transit protection appears relevant. Data integrity during migration is assured by reconciliation and validation controls comparing source and target records, confirming totals and detecting omissions or corruption.

  • ✗

    Performing user acceptance testing

    Why it's wrong here

    User acceptance testing validates business functionality against requirements, not the completeness, accuracy and reconciliation of migrated records. It is tempting because it is a recognised migration-phase control, and would be correct for confirming the new system meets user needs before sign-off.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.