CISA Practice Question: Information Systems Acquisition, Development, and Implementation
An organization is using a spiral model for a high-risk project. The IS auditor wants to ensure that risk assessment is performed at each iteration. Which of the following is the BEST evidence that this control is effective?
⚠ Common exam trap
The trap is selecting a planning document (risk management plan) or a schedule as evidence of control effectiveness, rather than looking for actual execution artifacts like risk analysis documents produced during each iteration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Each spiral iteration includes a risk analysis document
The best evidence that risk assessment is performed at each iteration of a spiral model is the existence of a risk analysis document for each spiral iteration. The spiral model is iterative and risk-driven, so each cycle should include risk analysis. A document per iteration provides tangible, auditable proof that the control is operating effectively.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The project schedule shows spiral iterations
Why it's wrong here
A schedule listing spiral iterations only evidences that the methodology was planned, not that risk assessment occurred within each loop. It is tempting because iteration tracking is genuine project-management evidence, and would satisfy an audit of process adherence. Here, the control under test is risk assessment per iteration, so artefacts such as updated risk registers or assessment outputs are required.
- ✓
Each spiral iteration includes a risk analysis document
Why this is correct
The spiral model's defining feature is iteration-level risk analysis, so a risk analysis document produced within each spiral iteration provides direct, repeatable evidence that risk assessment occurs at every cycle, not merely at project initiation.
- ✗
The project manager has a risk management plan
Why it's wrong here
A risk management plan documents intended approach, not evidence that assessment actually occurred each spiral iteration; it may be written once and never revisited. It is tempting because such a plan is the correct artefact when establishing governance before a project begins, but here the auditor needs iteration-level outputs, such as updated risk registers or assessment records.
- ✗
The system has passed user acceptance testing
Why it's wrong here
User acceptance testing confirms the delivered system meets business requirements at project completion, not that risk assessment recurs each spiral iteration. It is tempting because UAT is genuine assurance evidence, and would be the correct choice if the stem asked how an auditor verifies that a finished system satisfies agreed user needs before go-live.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.