Question 994 of 995
hardMultiple ChoiceObjective-mapped
COTS Customization: Best Practice to Avoid Extensive Changes
A company plans to implement a commercial off-the-shelf (COTS) application and requires significant customization to match its unique business processes. The vendor advises against extensive customization because it may complicate future upgrades. What is the BEST course of action?
Quick Answer
The best course of action is to avoid customization and re-engineer business processes to match the COTS application, because this preserves the vendor’s standard codebase and ensures seamless application of future upgrades and patches. Extensive customization creates a forked version of the software, introducing costly regression testing, security vulnerabilities, and upgrade incompatibilities that erode the long-term value of the COTS investment. On the CISA exam, this scenario tests your grasp of the COTS customization best practice—specifically, the principle that organizations should adapt their workflows to the software rather than forcing the software to fit legacy processes. A common trap is selecting “customize only critical modules,” but auditors expect you to recognize that any significant deviation from the vendor baseline undermines upgrade integrity. Remember the memory tip: “Don’t fork the code—re-engineer the road.”
⚠ Common exam trap
Watch out — candidates often choose 'customize but document' (Option B) because it sounds like a balanced, pragmatic approach, but the CISA exam emphasizes that any customization that deviates from the vendor's standard configuration introduces unacceptable upgrade and maintenance risks, making process re-engineering the only truly sustainable choice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Avoid customization and re-engineer business processes to match the COTS application
The best course of action is to avoid customization and re-engineer business processes to match the COTS application. This approach preserves the integrity of the vendor's standard codebase, ensuring that future upgrades and patches can be applied with minimal friction. Extensive customization creates a fork from the vendor's baseline, leading to costly regression testing, potential security gaps, and upgrade incompatibilities that undermine the long-term value of the COTS investment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the vendor's customization module to minimize upgrade risks
Why it's wrong here
Even vendor customization modules can cause upgrade issues.
- ✗
Customize but maintain detailed documentation for upgrade impact analysis
Why it's wrong here
Documentation helps but does not eliminate upgrade risks.
- ✗
Proceed with extensive customization to meet business needs
Why it's wrong here
Extensive customization complicates upgrades and increases costs.
- ✓
Avoid customization and re-engineer business processes to match the COTS application
Why this is correct
Minimizing customization is best practice to ensure smooth upgrades.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization is implementing a COTS application. The project team plans to heavily customize the application to meet unique business processes. Which of the following is the most significant risk?
hard- A.Vendor lock-in
- B.Incompatibility with future releases
- ✓ C.Difficulties in applying future vendor upgrades
- D.High implementation cost
Why C: Heavy customization of a COTS application often leads to significant difficulties when applying future vendor upgrades, because custom code may not be compatible with new versions. This is the most direct and significant risk among the options. Vendor lock-in (A) is a concern but typically less immediate than upgrade issues. Incompatibility with future releases (B) is a symptom or consequence of upgrade difficulties, not the primary risk itself. High implementation cost (D) is a separate concern and not as critical as the long-term maintainability issue posed by upgrade difficulties.
Last reviewed: Jun 25, 2026
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.