Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

An organization is using a spiral model for a high-risk project. The IS auditor wants to ensure that risk assessment is performed at each iteration. Which of the following is the BEST evidence that this control is effective?

⚠ Common exam trap

The trap is selecting a planning document (risk management plan) or a schedule as evidence of control effectiveness, rather than looking for actual execution artifacts like risk analysis documents produced during each iteration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Each spiral iteration includes a risk analysis document

The best evidence that risk assessment is performed at each iteration of a spiral model is the existence of a risk analysis document for each spiral iteration. The spiral model is iterative and risk-driven, so each cycle should include risk analysis. A document per iteration provides tangible, auditable proof that the control is operating effectively.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The project schedule shows spiral iterations

    Why it's wrong here

    A schedule listing spiral iterations only evidences that the methodology was planned, not that risk assessment occurred within each loop. It is tempting because iteration tracking is genuine project-management evidence, and would satisfy an audit of process adherence. Here, the control under test is risk assessment per iteration, so artefacts such as updated risk registers or assessment outputs are required.

  • ✓

    Each spiral iteration includes a risk analysis document

    Why this is correct

    The spiral model's defining feature is iteration-level risk analysis, so a risk analysis document produced within each spiral iteration provides direct, repeatable evidence that risk assessment occurs at every cycle, not merely at project initiation.

  • ✗

    The project manager has a risk management plan

    Why it's wrong here

    A risk management plan documents intended approach, not evidence that assessment actually occurred each spiral iteration; it may be written once and never revisited. It is tempting because such a plan is the correct artefact when establishing governance before a project begins, but here the auditor needs iteration-level outputs, such as updated risk registers or assessment records.

  • ✗

    The system has passed user acceptance testing

    Why it's wrong here

    User acceptance testing confirms the delivered system meets business requirements at project completion, not that risk assessment recurs each spiral iteration. It is tempting because UAT is genuine assurance evidence, and would be the correct choice if the stem asked how an auditor verifies that a finished system satisfies agreed user needs before go-live.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.