hardMultiple Choice
Data Migration Integrity: Risks of Cleaning Only at Extraction
During data conversion from a legacy system to a new ERP, the project team decides to clean data during extraction but not during loading. What is the PRIMARY risk associated with this approach?
Quick Answer
The answer is that data integrity issues may remain undetected in the target system. This is correct because cleaning data only during extraction, without a parallel validation during loading, fails to catch problems introduced by the extraction process itself or by schema mapping mismatches—such as referential integrity violations, duplicate keys, or format errors—that only become visible when data lands in the target ERP. On the CISA exam, this scenario tests your understanding of the full data conversion lifecycle and the common trap of assuming a single cleaning pass is sufficient; auditors must recognize that integrity risks persist wherever validation gaps exist. A useful memory tip is “clean twice, trust once”—extraction cleaning removes source grime, but loading cleaning catches mapping scars.
⚠ Common exam trap
The trap here is that candidates focus on operational concerns like speed or cost, rather than the core IS audit principle that data integrity is the paramount risk when data is not validated at the final point of entry into the target system.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data integrity issues may remain undetected in the target system.
Cleaning data only during extraction and not during loading means that any data quality issues introduced during the extraction process or that become apparent only after mapping to the target schema will not be caught. This creates a primary risk that data integrity issues—such as referential integrity violations, duplicate keys, or format mismatches—will remain undetected in the new ERP system, potentially corrupting business operations and reporting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Data integrity issues may remain undetected in the target system.
Why this is correct
Cleaning only at extraction leaves errors introduced or exposed during transformation and loading unchecked, so corrupt records reach the target ERP without a validation gate. The absence of load-stage cleansing removes the final detection point, letting integrity defects persist silently in production data.
- ✗
The legacy system performance may degrade.
Why it's wrong here
Legacy system performance degradation is not the primary risk; extraction-time cleaning does not impose unusual load patterns on the source. It is tempting because extraction queries can affect a production legacy system, which is why extraction windows are scheduled during low-usage periods.
- ✗
The project may exceed its budget due to rework.
Why it's wrong here
Budget overrun from rework is a secondary consequence; the primary risk is that defects introduced or missed after extraction pass into the new ERP undetected. It is tempting because rework is a genuine project-management concern whenever data quality problems surface late in conversion.
- ✗
The conversion process will be significantly slower.
Why it's wrong here
Slower conversion is a performance symptom, not the primary risk; the real exposure is that uncleaned data loaded into the ERP corrupts records and reports. It is tempting because loading large volumes without cleansing does extend run times, making throughput the visible problem.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
3 more ways this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO of the following are essential controls to ensure data integrity during a cloud migration project?
medium- A.Granting all migration team members full database access
- ✓ B.Implementing encryption at rest and in transit
- C.Using a phased migration approach without rollback capability
- ✓ D.Running reconciliation checks comparing source and target data counts
- E.Performing a single full data validation after migration
Why B: Option B is correct because implementing encryption at rest and in transit protects data from unauthorized modification or interception during transfer and storage, directly preserving integrity throughout the migration. Option D is correct because reconciliation checks that compare source and target data counts (and ideally checksums or hashes) detect any data loss, duplication, or corruption introduced during migration, verifying that the transferred data matches the original. Option A is wrong because granting all team members full database access violates least privilege and increases the risk of accidental or malicious data alteration. Option C is wrong because a phased migration without rollback capability removes the ability to revert corrupted or incomplete transfers, undermining integrity safeguards. Option E is wrong because a single full validation only after migration is too late and too coarse; integrity must be verified continuously or at multiple checkpoints, not once at the end.
Variation 2. An organization is replacing its legacy customer relationship management (CRM) system. Which of the following is the MOST important control to ensure data integrity during the data conversion process?
easy- ✓ A.Perform reconciliation of total record counts and key field sums before and after conversion.
- B.Implement encryption for data in transit during migration.
- C.Conduct user acceptance testing on the new system.
- D.Ensure data mapping documents are approved by business owners.
Why A: Reconciliation of total record counts and key field sums before and after conversion is the most direct control to ensure data integrity during data conversion. It verifies that all records were transferred and that key values (e.g., totals, hashes) match, detecting any loss or alteration. While encryption, UAT, and data mapping are important, they do not provide the same level of assurance that the data itself is complete and accurate after conversion.
Variation 3. During a data migration from a legacy system to a new ERP, the following log entries were generated. Which TWO issues should the IS auditor flag as high risk?
easy- A.Source system downtime
- B.Rapid growth of rollback segment
- ✓ C.Constraint violation due to missing parent records
- ✓ D.Duplicate key violation
- E.Data type mismatch between source and target
Why C: Option C is correct because a constraint violation caused by missing parent records indicates referential integrity failures in the migrated data — child rows are being loaded without their corresponding parent rows, meaning the foreign key relationships in the new ERP will be broken and the data will be inconsistent or unusable. Option D is correct because duplicate key violations mean the migration is attempting to insert records that violate primary or unique key constraints, which signals data quality problems (e.g., duplicate master records) that can corrupt the ERP's core entities and cause transaction failures. These two issues are high risk for an IS auditor because they directly compromise data integrity and completeness in the target ERP, whereas source system downtime (A) is an availability/operational concern rather than a data integrity defect, rapid growth of the rollback segment (B) is a performance/tuning symptom that may be expected during large batch loads, and a data type mismatch (E) is typically a mapping/ETL design issue that would normally be caught and corrected during testing rather than representing an inherent integrity violation in the migrated data.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.