CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An organization is migrating from a legacy system to a new ERP. Which TWO of the following are the HIGHEST risks during data migration?
⚠ Common exam trap
The trap is that candidates may focus on technical or training risks that are more visible, but the exam expects recognition that data integrity risks (mapping and source data quality) are the highest during data migration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Incorrect data mapping between old and new systems
Option A is correct because incorrect data mapping between the legacy and new ERP schemas directly causes fields to be transformed, truncated, or populated into the wrong target columns, producing corrupt or unusable records in the new system — a core data migration risk. Option E is correct because incomplete or inaccurate source data (missing values, duplicates, inconsistent formats) propagates defects into the ERP and undermines the integrity of the migrated dataset, regardless of how well the mapping is designed. These two are the highest risks because they directly threaten the accuracy and completeness of the migrated data itself, which is the primary objective of the migration. Option B is not a top migration risk since bandwidth affects cutover performance/throughput rather than data correctness and is typically mitigated by scheduling and sizing. Option C concerns post-migration adoption and user competence, not the integrity of the migrated data. Option D is an access-control/governance risk in the new system's design, not a data migration risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Incorrect data mapping between old and new systems
Why this is correct
Incorrect mapping transfers values into wrong fields, corrupting balances, inventory and master data that downstream processes depend on. Because errors propagate silently and are costly to unwind post-cutover, mapping validation is a highest-risk migration concern.
- ✗
Insufficient network bandwidth during cutover
Why it's wrong here
Bandwidth shortfalls slow transfers and can be scheduled around or upgraded before cutover, so they rarely threaten data integrity or project viability. Bandwidth planning is genuinely important for large-volume migrations, but it is an operational performance concern rather than a highest-risk data migration failure.
- ✗
Lack of user training on the new system
Why it's wrong here
Training gaps degrade adoption and productivity after go-live, but they do not corrupt or lose the migrated records themselves. Training is a change-management concern, addressed by rollout and hypercare planning; it would be the priority in an end-user readiness assessment, not in a data migration risk ranking.
- ✗
Lack of segregation of duties in the new system
Why it's wrong here
Segregation of duties is an access-design control configured in the new ERP's roles, not a data migration risk. It matters during security design and post-implementation audit; migration risk instead centres on data completeness, accuracy and reconciliation between legacy and target records.
- ✓
Incomplete or inaccurate source data
Why this is correct
Incomplete or inaccurate source data directly undermines the migration's core constraint: the new ERP inherits whatever quality exists at extraction. Legacy systems often accumulate duplicate, stale or unvalidated records, so errors propagate into financial postings and reporting before validation controls exist, making remediation costly and audit findings likely.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.