hardMultiple Choice
CISA Practice Question: Uses a COTS (commercial off-the-shelf) ERP system…
An organization uses a COTS (commercial off-the-shelf) ERP system with significant customizations. The IS auditor is reviewing the system's configuration management. Which of the following findings would MOST indicate a weakness?
⚠ Common exam trap
The trap here is that candidates often focus on patch management or testing environments as the most critical weakness, but the CISA exam prioritizes segregation of duties as a fundamental control, especially in customized COTS systems where configuration changes can directly impact data integrity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The system administrator has the ability to modify both configuration and production data.
In a COTS ERP system with significant customizations, allowing the system administrator to modify both configuration and production data violates the principle of segregation of duties (SoD). This creates a risk of unauthorized or undetected changes, as the same individual can alter system configurations and then manipulate production data to conceal the impact, bypassing audit trails and controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The vendor releases quarterly patches but the organization only applies critical security patches.
Why it's wrong here
Deferring non-critical patches leaves known flaws un-remediated in a heavily customised ERP, so patch currency is the weakness. It is tempting because risk-based patching is defensible for standard software, and would be correct where vendor patches carry no functional or regression impact.
- ✓
The system administrator has the ability to modify both configuration and production data.
Why this is correct
Combining configuration and production data modification rights in one administrator account violates segregation of duties, letting a single person alter ERP settings and then manipulate the resulting production records undetected. This finding most strongly indicates a configuration management weakness in the customised COTS environment.
- ✗
Customizations are not tracked in a separate change management system.
Why it's wrong here
Untracked customisations escape the change management process, so their configuration baseline and authorisation cannot be verified. It is tempting because vendor-delivered code is tracked by the vendor, and a separate system would be correct where customisations are numerous and independently deployed.
- ✗
The organization does not have a formal testing environment for customizations.
Why it's wrong here
Testing customisations directly in production risks corrupting live ERP data and invalidating change verification. It is tempting because small organisations often lack dedicated environments, and a formal test environment would be the right control where customisation volume justifies the cost.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.