Courseiva
Question 994 of 995
hardMultiple ChoiceObjective-mapped

COTS Customization: Best Practice to Avoid Extensive Changes

A company plans to implement a commercial off-the-shelf (COTS) application and requires significant customization to match its unique business processes. The vendor advises against extensive customization because it may complicate future upgrades. What is the BEST course of action?

Quick Answer

The best course of action is to avoid customization and re-engineer business processes to match the COTS application, because this preserves the vendor’s standard codebase and ensures seamless application of future upgrades and patches. Extensive customization creates a forked version of the software, introducing costly regression testing, security vulnerabilities, and upgrade incompatibilities that erode the long-term value of the COTS investment. On the CISA exam, this scenario tests your grasp of the COTS customization best practice—specifically, the principle that organizations should adapt their workflows to the software rather than forcing the software to fit legacy processes. A common trap is selecting “customize only critical modules,” but auditors expect you to recognize that any significant deviation from the vendor baseline undermines upgrade integrity. Remember the memory tip: “Don’t fork the code—re-engineer the road.”

⚠ Common exam trap

Watch out — candidates often choose 'customize but document' (Option B) because it sounds like a balanced, pragmatic approach, but the CISA exam emphasizes that any customization that deviates from the vendor's standard configuration introduces unacceptable upgrade and maintenance risks, making process re-engineering the only truly sustainable choice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Avoid customization and re-engineer business processes to match the COTS application

The best course of action is to avoid customization and re-engineer business processes to match the COTS application. This approach preserves the integrity of the vendor's standard codebase, ensuring that future upgrades and patches can be applied with minimal friction. Extensive customization creates a fork from the vendor's baseline, leading to costly regression testing, potential security gaps, and upgrade incompatibilities that undermine the long-term value of the COTS investment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use the vendor's customization module to minimize upgrade risks

    Why it's wrong here

    Even vendor customization modules can cause upgrade issues.

  • Customize but maintain detailed documentation for upgrade impact analysis

    Why it's wrong here

    Documentation helps but does not eliminate upgrade risks.

  • Proceed with extensive customization to meet business needs

    Why it's wrong here

    Extensive customization complicates upgrades and increases costs.

  • Avoid customization and re-engineer business processes to match the COTS application

    Why this is correct

    Minimizing customization is best practice to ensure smooth upgrades.

About these practice questions

Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization is implementing a COTS application. The project team plans to heavily customize the application to meet unique business processes. Which of the following is the most significant risk?

hard
  • A.Vendor lock-in
  • B.Incompatibility with future releases
  • C.Difficulties in applying future vendor upgrades
  • D.High implementation cost

Why C: Heavy customization of a COTS application often leads to significant difficulties when applying future vendor upgrades, because custom code may not be compatible with new versions. This is the most direct and significant risk among the options. Vendor lock-in (A) is a concern but typically less immediate than upgrade issues. Incompatibility with future releases (B) is a symptom or consequence of upgrade difficulties, not the primary risk itself. High implementation cost (D) is a separate concern and not as critical as the long-term maintainability issue posed by upgrade difficulties.

Last reviewed: Jun 25, 2026

Question Discussion

Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.

Loading comments…

Sign in to join the discussion.

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.