easyMultiple Choice
CISA Practice Question: Is replacing its legacy customer relationship…
An organization is replacing its legacy customer relationship management (CRM) system. Which of the following is the MOST important control to ensure data integrity during the data conversion process?
⚠ Common exam trap
CISA often tests the difference between preventive controls (encryption, mapping) and detective controls (reconciliation); candidates may choose UAT or mapping because they sound thorough, but reconciliation is the most direct integrity check.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Perform reconciliation of total record counts and key field sums before and after conversion.
Reconciliation of total record counts and key field sums before and after conversion is the most direct control to ensure data integrity during data conversion. It verifies that all records were transferred and that key values (e.g., totals, hashes) match, detecting any loss or alteration. While encryption, UAT, and data mapping are important, they do not provide the same level of assurance that the data itself is complete and accurate after conversion.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Perform reconciliation of total record counts and key field sums before and after conversion.
Why this is correct
Reconciliation of record counts and key field sums verifies completeness and accuracy by comparing source and target totals. This detective control directly confirms that no records were lost, duplicated or corrupted during conversion, satisfying the data integrity objective.
- ✗
Implement encryption for data in transit during migration.
Why it's wrong here
Encryption in transit protects data from interception on the network, not from corruption, truncation or transformation errors during extraction, transformation and load. It is tempting because it is a genuine migration safeguard, and would be the right control when data crosses untrusted networks or must satisfy confidentiality requirements.
- ✗
Conduct user acceptance testing on the new system.
Why it's wrong here
User acceptance testing validates business fit and usability after conversion, not the accuracy of migrated records. It is tempting as a standard assurance step, and would be correct for confirming the new CRM meets user requirements, whereas reconciliation and validation of converted data address integrity.
- ✗
Ensure data mapping documents are approved by business owners.
Why it's wrong here
Approved data mapping documents define source-to-target field relationships but do not verify that converted values are complete, accurate or reconciled after loading. It is tempting because mapping sign-off is a real conversion control, and would be correct when the primary risk is ambiguous field definitions rather than post-load integrity.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.