Courseiva
hardMultiple ChoiceObjective-mapped

CISA Practice Question: Uses a COTS (commercial off-the-shelf) ERP system…

An organization uses a COTS (commercial off-the-shelf) ERP system with significant customizations. The IS auditor is reviewing the system's configuration management. Which of the following findings would MOST indicate a weakness?

⚠ Common exam trap

The trap here is that candidates often focus on patch management or testing environments as the most critical weakness, but the CISA exam prioritizes segregation of duties as a fundamental control, especially in customized COTS systems where configuration changes can directly impact data integrity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The system administrator has the ability to modify both configuration and production data.

In a COTS ERP system with significant customizations, allowing the system administrator to modify both configuration and production data violates the principle of segregation of duties (SoD). This creates a risk of unauthorized or undetected changes, as the same individual can alter system configurations and then manipulate production data to conceal the impact, bypassing audit trails and controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The vendor releases quarterly patches but the organization only applies critical security patches.

    Why it's wrong here

    While not ideal, focusing on critical patches is common.

  • The system administrator has the ability to modify both configuration and production data.

    Why this is correct

    This is a direct violation of segregation of duties, significantly increasing risk of unauthorized changes.

  • Customizations are not tracked in a separate change management system.

    Why it's wrong here

    Lack of tracking is a weakness but not the highest risk.

  • The organization does not have a formal testing environment for customizations.

    Why it's wrong here

    Lack of testing environment increases risk of errors but is less direct than segregation of duties.

About these practice questions

One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.