Courseiva

CISA · domain

Information Systems Acquisition, Development, and Implementation

This domain covers how organizations acquire, develop, and implement information systems, and how IS auditors evaluate those efforts. Expect questions on business case and feasibility, build-versus-buy and contract types, SDLC and agile controls, requirements and testing, change management, data migration, and post-implementation review. Questions are scenario-based, asking you to pick the best audit evidence or the greatest risk.

114 questions25 easy58 medium31 hard

Focused practice

Practice Information Systems Acquisition, Development, and Implementation questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Information Systems Acquisition, Development, and Implementation

Be able to select the best audit evidence and identify the greatest risk across acquisition, development, and implementation. The single most important thing is linking every control and test back to approved requirements, and confirming changes are authorized, tested, and approved before production.

Evaluating feasibility studies, business cases, and cost-benefit analysis before project approval

Choosing contract types such as fixed-price versus time-and-material and their risk transfer

Reviewing SDLC and agile artifacts: requirements, user stories, test plans, traceability matrices

Assessing change management, segregation of duties, and post-implementation review evidence

Watch out for

Common Information Systems Acquisition, Development, and Implementation exam traps

  • ▸Treating agile as lacking controls; instead look for security requirements in the backlog, definition of done, and sprint acceptance criteria
  • ▸Assuming fixed-price contracts remove all risk; scope changes, unclear requirements, and vendor disputes remain
  • ▸Accepting testing evidence without traceability to requirements, or ignoring data migration and rollback plans

Question index

All Information Systems Acquisition, Development, and Implementation questions (114)

Click any question to see the full explanation, or start a practice session above.

1

During a build vs. buy analysis, the IS auditor observes that the organization decided to build a custom application because no vendor solution met all requirements. Which of the following risks should the auditor emphasize?

Medium
2

A hospital is implementing a new electronic health record (EHR) system to replace a legacy system. During the implementation phase, the project manager proposes using a parallel changeover strategy. Which of the following is the MOST significant risk associated with this approach?

Medium
3

An IS auditor is reviewing a post-implementation review report for a new financial system. Which finding would most indicate that the project did not meet its objectives?

Medium
4

Which type of change in ITIL requires approval from the Change Advisory Board (CAB) before implementation?

Easy
5

An organization is implementing a new customer relationship management (CRM) system using an agile methodology. Which THREE areas should the IS auditor focus on to assess the effectiveness of controls during the development process?

Medium
6

Which of the following is a key control in the deployment phase of the SDLC?

Easy
7

In a spiral SDLC model, what is the primary purpose of risk analysis in each iteration?

Easy
8

An organization is migrating from a legacy system to a new ERP. Which TWO of the following are the HIGHEST risks during data migration?

Medium
9

An IS auditor is reviewing change management procedures. Which of the following situations would be of GREATEST concern?

Medium
10

An IS auditor is reviewing the post-implementation review (PIR) of a newly deployed human resources (HR) system. Which of the following should be the PRIMARY focus of the PIR?

Easy
11

An IS auditor is assessing the controls in an agile development environment. What is the MOST effective way to verify that security testing is performed iteratively?

Medium
12

An IS auditor is reviewing a project to implement a new loan origination system. The project manager has produced a detailed work breakdown structure (WBS), a critical path schedule, and a resource-loaded plan. Which of the following should the auditor verify FIRST to assess whether the project schedule is realistic?

Medium
13

An organization is deciding between building a custom application and purchasing a commercial off-the-shelf (COTS) product. The primary factor favoring the build option is:

Hard
14

Which of the following is a key control during the deployment phase of a system development life cycle?

Easy
15

An organization is migrating data from a legacy system to a new ERP. What is the most critical data migration risk?

Medium
16

An IS auditor is assessing the implementation of a new system that uses a relational database. The project team plans to migrate data from several legacy sources. Which TWO of the following controls are MOST important to include in the data conversion plan to help ensure the integrity of migrated data? (Choose two.)

Medium
17

During a post-implementation review of a new accounting system, the IS auditor notes the following: the project was completed on time and within budget, but user satisfaction is low and there are several outstanding defect reports. Which THREE of the following are the MOST appropriate recommendations?

Hard
18

An IS auditor is reviewing an emergency change that was implemented to fix a critical security vulnerability. What is the most important post-implementation step?

Hard
19

An IS auditor is reviewing the implementation of a new payroll system. The project team has decided to use a pilot conversion approach. Which TWO of the following are the MOST significant advantages of this approach? (Choose two.)

Hard
20

An organization is considering whether to build a custom application or purchase a commercial off-the-shelf (COTS) product. Which of the following factors would most strongly support a build decision?

Medium
21

Which TWO of the following are benefits of an iterative SDLC approach compared to waterfall? (Select two.)

Medium
22

Which of the following is the PRIMARY objective of a post-implementation review of an information system?

Easy
23

An IS auditor is reviewing a project that is developing a new customer relationship management (CRM) system using the Agile Scrum framework. The project team has completed several sprints, and the product owner has accepted the increments. The auditor wants to ensure that the system will meet the organization's security requirements before go-live. Which of the following is the MOST effective way for the auditor to achieve this?

Medium
24

An IS auditor is evaluating the vendor selection process for a new system. Which of the following is the most important factor to include in the contract?

Medium
25

An IS auditor is reviewing the requirements definition phase of a new system development project. The business analyst has documented functional requirements but has not yet defined non-functional requirements. Which of the following is the MOST significant risk of proceeding to the design phase without non-functional requirements?

Hard
26

During a post-implementation review of a new payroll system, the IS auditor identifies several outstanding issues. Which TWO issues should be considered most critical to address immediately? (Select TWO)

Medium
27

An IS auditor is reviewing a post-implementation review report for a new ERP system. Which of the following findings would be of greatest concern to the auditor?

Hard
28

An organization is implementing a large ERP system. The project team plans to migrate legacy data to the new system. Which of the following is the MOST significant risk associated with data migration?

Hard
29

An IS auditor is reviewing the change management process for a critical financial application. Which of the following is the most important element to verify in an emergency change request?

Medium
30

An IS auditor is assessing an ERP implementation. Which of the following control concerns is MOST likely to arise from segregation of duties conflicts?

Medium
31

Which of the following is the PRIMARY purpose of a change advisory board (CAB) in the change management process?

Medium
32

During which phase of the SDLC should security requirements be formally documented and approved?

Easy
33

Which THREE of the following are typical controls in the design phase of the SDLC?

Medium
34

An organization is implementing a new ERP system and is concerned about segregation of duties (SoD) conflicts. What is the BEST approach to address this during the implementation?

Medium
35

In a waterfall SDLC, which phase requires formal sign-off from the business owner before proceeding to the next phase?

Easy
36

During an agile software development project, a sprint review meeting is conducted. What is the PRIMARY purpose of this meeting from an IS audit perspective?

Medium
37

Which testing type is performed by end-users to verify that the system meets their needs?

Easy
38

Which of the following is the BEST control to ensure that user acceptance testing (UAT) is effective?

Medium
39

An IS auditor is reviewing a change management process. Which TWO elements should be documented in a normal change request to ensure adequate governance? (Select TWO)

Medium
40

An IS auditor is evaluating the change management process. Which of the following is the BEST indicator that emergency changes are being properly controlled?

Medium
41

An IS auditor is reviewing a system development project that uses a commercial software package customized with vendor-supplied extension points. The project team has documented customizations in a separate repository but has not maintained a traceability matrix linking business requirements to configuration items. Which of the following is the GREATEST risk arising from this situation?

Hard
42

An IS auditor is reviewing a waterfall SDLC project that has completed the requirements phase. Which of the following is the greatest risk to the project?

Medium
43

An IS auditor is reviewing the change management process for a critical financial application. Which of the following findings would be of GREATEST concern?

Hard
44

Which TWO of the following are key elements of a change request document?

Medium
45

During a post-implementation review of a new financial system, the IS auditor finds that user acceptance testing (UAT) was completed with only 60% of test cases passed. Which of the following is the MOST significant risk?

Medium
46

During which phase of the SDLC should security requirements be formally documented and approved by the business owner?

Easy
47

An organization is acquiring a new financial system. The contract includes a clause that allows the organization to audit the vendor's controls. Which type of report would most efficiently provide assurance over the vendor's internal controls?

Medium
48

An IS auditor is reviewing a systems acquisition project that involves purchasing an ERP system. Which of the following is the MOST significant risk related to data migration during implementation?

Medium
49

In a spiral model SDLC, risk analysis is performed at the beginning of each iteration. What is the PRIMARY benefit of this approach?

Hard
50

An IS auditor is assessing the security controls in a newly developed mobile banking application. The development team used the OWASP Mobile Application Security Verification Standard (MASVS) as a guide. Which of the following would be the MOST effective evidence that the application meets the standard's requirements for secure data storage?

Hard
51

An IS auditor is reviewing an agile project that uses Scrum. Which event provides the best opportunity for the auditor to assess whether completed user stories meet the defined acceptance criteria?

Medium
52

An organization is implementing a new system using a rapid application development (RAD) approach. The IS auditor is concerned about the lack of formal documentation. Which of the following is the MOST appropriate audit response?

Medium
53

An organization is implementing a large ERP system. The project manager is concerned about segregation of duties conflicts. Which THREE controls should the IS auditor recommend to mitigate segregation of duties risks during implementation? (Select THREE)

Hard
54

An IS auditor is reviewing an agile software development project. Which of the following would be the BEST evidence that adequate controls are in place for user acceptance?

Medium
55

During a spiral SDLC project, the IS auditor should focus on which aspect as the primary risk?

Hard
56

Which of the following is a key advantage of using an iterative SDLC model over a waterfall model?

Easy
57

An IS auditor is reviewing the acquisition of a new software package. The vendor provides a Service Organization Control (SOC) 2 Type II report. Which of the following is the MOST important factor for the auditor to consider when relying on this report?

Medium
58

An IS auditor is reviewing the implementation of a new payroll system that was developed in-house. The project team followed a traditional waterfall SDLC. During the post-implementation review, the auditor found that the system was delivered on time and within budget, but several critical payroll calculations were incorrect, leading to employee underpayments. The root cause was traced to a misunderstanding of tax law changes that occurred during the requirements phase. Which of the following is the MOST likely control weakness that contributed to this issue?

Hard
59

During a system development project, the IS auditor notes that code reviews are performed only after the code is unit tested. Which of the following is the MOST significant risk associated with this practice?

Medium
60

An organization is considering acquiring a commercial off-the-shelf (COTS) ERP system. Which of the following risks is most effectively mitigated by including a contractual clause for audit rights?

Hard
61

During a post-implementation review of a new customer relationship management (CRM) system, the IS auditor finds that the system is processing transactions slower than anticipated. What is the BEST initial course of action for the auditor?

Medium
62

An organization is acquiring a new software package. The IS auditor is asked to review the contract with the vendor. Which of the following clauses is MOST important to ensure the organization can continue to use the software even if the vendor goes out of business?

Easy
63

Which TWO of the following are characteristics of the iterative SDLC model?

Easy
64

An IS auditor is reviewing the requirements definition phase of a new system development project. The auditor finds that business users have provided functional requirements, but non-functional requirements are largely missing. Which TWO of the following are the MOST significant risks of proceeding without well-defined non-functional requirements? (Choose two.)

Hard
65

During a post-implementation review of a new ERP system, the IS auditor identified that the project was delivered within budget but user satisfaction scores are low. Which THREE areas should the auditor examine further?

Hard
66

During an agile software development project, which of the following events provides the best opportunity for the IS auditor to assess the effectiveness of controls implemented in the current sprint?

Easy
67

During a vendor evaluation for a critical system, the IS auditor notes that the vendor's SOC 2 report includes an adverse opinion. What should be the auditor's PRIMARY recommendation?

Medium
68

An organization is implementing a new human resources system. The IS auditor wants to determine whether the system will enforce segregation of duties (SoD) for sensitive transactions such as payroll changes and employee master data updates. Which of the following is the MOST appropriate source of evidence?

Easy
69

An organization is considering whether to build a custom application or purchase a commercial off-the-shelf (COTS) product. Which of the following factors is MOST important when deciding to build rather than buy?

Medium
70

An organization is implementing a new payroll system using an agile methodology. Which TWO of the following are the MOST important controls for the IS auditor to assess?

Medium
71

Which of the following is a primary advantage of fixed-price contracts in systems acquisition?

Easy
72

During a post-implementation review of a system, an IS auditor finds that the actual transaction processing time is 30% slower than projected. What should the auditor recommend FIRST?

Medium
73

An organization is implementing a new financial system using the waterfall SDLC model. Which of the following is the MOST critical control to ensure that business requirements are met?

Easy
74

Which of the following BEST describes the role of threat modeling in the design phase of the SDLC?

Medium
75

An organization is deploying a major system upgrade. The change request has been approved by CAB, but the deployment plan does not include a rollback procedure. As an IS auditor, what should you recommend?

Hard
76

In a waterfall SDLC, when should user acceptance testing (UAT) typically occur?

Easy
77

Which of the following is a key objective of the design phase in the SDLC?

Easy
78

During an ERP implementation, the project team decides to customize the software to align with existing business processes. Which of the following risks is MOST likely to increase as a result of extensive customization?

Medium
79

An IS auditor is reviewing a software development project that follows the waterfall model. Which of the following is the MAIN advantage of this methodology?

Easy
80

During a spiral SDLC project, the project team has completed a risk analysis and created a prototype. What is the most likely next step in the spiral model?

Hard
81

An IS auditor is reviewing the system design phase of a project. Which of the following activities is most important to ensure that security is adequately addressed?

Medium
82

During which phase of the waterfall SDLC should security requirements be formally documented and approved by the business owner?

Easy
83

Which of the following is the primary purpose of conducting a static application security test (SAST) during the development phase of the SDLC?

Easy
84

An IS auditor is reviewing change management procedures and finds that standard changes are approved by the change manager without CAB review. What is the auditor's BEST conclusion?

Medium
85

An organization is implementing a new customer relationship management (CRM) system. The project manager proposes using a pilot conversion strategy, where the new system is implemented in one department first, then gradually rolled out to others. Which of the following is the PRIMARY benefit of this approach?

Medium
86

During an ERP implementation, data migration is a critical activity. Which of the following controls would be most effective in ensuring the accuracy and completeness of migrated data?

Hard
87

An IS auditor is reviewing a post-implementation review of a new payroll system. Which TWO findings should most concern the auditor? (Select two.)

Medium
88

An IS auditor is reviewing a project that replaced a legacy system. The project used a phased cutover, with each phase going live in a different region. After the final phase, the auditor finds that the legacy system was kept in read-only mode for six months, but no formal reconciliation was performed between legacy and new system balances during that period. Which of the following is the MOST significant concern?

Hard
89

An organization is evaluating two vendors for a critical cloud-based ERP system. Which TWO contractual clauses are most important to include to ensure the organization can monitor vendor performance and security? (Select TWO)

Medium
90

An IS auditor is reviewing a project to implement a new customer relationship management (CRM) system. The project manager has created a work breakdown structure (WBS) and a Gantt chart. Which of the following should the auditor verify to ensure the project schedule is realistic?

Medium
91

An organization is implementing an ERP system and is concerned about segregation of duties conflicts. What is the most effective control to address this risk during implementation?

Medium
92

Which of the following is a key objective of a post-implementation review?

Easy
93

During the design phase of an SDLC, which TWO activities should be performed to ensure security is integrated into the system? (Select TWO)

Easy
94

An organization is implementing an enterprise resource planning (ERP) system. The project team plans to migrate legacy data without performing a full reconciliation between source and target systems. As an IS auditor, which of the following should be your PRIMARY concern?

Hard
95

An organization has just completed a post-implementation review of a new payroll system. Management is now deciding whether to formally transfer ownership of the system from the project team to IT operations. Which of the following is the MOST important prerequisite before this transfer is approved?

Medium
96

An IS auditor is reviewing the testing phase of a new system development project. The project team has decided to use beta testing as the primary method for user acceptance testing (UAT). Which of the following is the MOST appropriate audit concern regarding this decision?

Hard
97

An IS auditor is reviewing a contract with a vendor for a new financial system. Which of the following clauses is MOST critical to ensure auditability?

Hard
98

An organization is implementing a new CRM system using an iterative development methodology. The IS auditor wants to verify that appropriate controls are in place. Which THREE of the following are essential controls for iterative development? (Select THREE.)

Hard
99

An IS auditor is reviewing a software development project that uses a DevOps pipeline. The auditor observes that developers can push code directly to production without independent review. Which of the following is the MOST significant risk arising from this practice?

Hard
100

An organization is planning to purchase a cloud-based HR system. Which THREE of the following should be included in the vendor contract to ensure adequate control and oversight? (Select three.)

Hard
101

What is the PRIMARY purpose of conducting a static application security testing (SAST) during the development phase?

Easy
102

An IS auditor is reviewing an agile software development project. Which of the following practices would BEST help ensure that security controls are adequately addressed?

Medium
103

An IS auditor is reviewing a project that uses an iterative SDLC approach. Which THREE controls should the auditor expect to see in place during the development iterations? (Select THREE)

Hard
104

An organization is adopting a DevOps approach for system development. Which THREE controls should an IS auditor expect to see in place to maintain security and compliance?

Hard
105

During a change management audit, which TWO of the following are essential elements of a normal change request? (Select two.)

Medium
106

An organization is implementing a new CRM system using an agile methodology. The IS auditor wants to assess whether security requirements are being addressed. What is the best evidence for the auditor to review?

Medium
107

An organization is using a spiral model for a high-risk project. The IS auditor wants to ensure that risk assessment is performed at each iteration. Which of the following is the BEST evidence that this control is effective?

Hard
108

An organization is implementing an agile methodology for a new software project. Which of the following is the MOST effective control to ensure that security requirements are addressed?

Hard
109

An organization is implementing a new CRM system and has chosen a build (in-house development) approach over buying a COTS product. Which of the following is the most significant risk of this decision?

Medium
110

In the context of ITIL change management, which change type requires approval from the Change Advisory Board (CAB)?

Medium
111

Which TWO of the following are typical controls in the testing phase of the SDLC? (Select two.)

Medium
112

An IS auditor is reviewing a post-implementation review (PIR) of a new CRM system. The auditor finds that the project was completed on time and within budget, but the business case benefits have not been realized. Which of the following is the MOST likely cause?

Medium
113

An IS auditor is evaluating an organization's SDLC controls for a new system. Which TWO of the following are key controls that should be in place during the design phase? (Select TWO.)

Medium
114

An organization is selecting a vendor for a new procurement system. Which of the following is the MOST important factor to include in the contract?

Medium

Frequently asked questions

What does the Information Systems Acquisition, Development, and Implementation domain cover on the CISA exam?
Be able to select the best audit evidence and identify the greatest risk across acquisition, development, and implementation. The single most important thing is linking every control and test back to approved requirements, and confirming changes are authorized, tested, and approved before production.
How many questions are in this domain?
This page lists all 114 Information Systems Acquisition, Development, and Implementation questions in the CISA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Information Systems Acquisition, Development, and Implementation questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isaca-cisa ISACA-CISA cisa systems development Practice Questions