Courseiva

CCNA Information Systems Acquisition, Development, and Implementation Questions

75 of 114 questions · Page 1/2 · Information Systems Acquisition, Development, and Implementation · Answers revealed

1
MCQmedium

During a build vs. buy analysis, the IS auditor observes that the organization decided to build a custom application because no vendor solution met all requirements. Which of the following risks should the auditor emphasize?

A.Lack of customization
B.Dependence on external support
C.Vendor lock-in
D.Increased time-to-market and development costs
AnswerD

Building custom software demands staffing, tooling and iterative testing that vendor licensing avoids, so delivery slips and budgets overrun — directly satisfying the stem's build-versus-buy constraint. The auditor should emphasise that no vendor solution met all requirements, meaning bespoke development absorbs the full cost and schedule risk internally.

Why this answer

When an organization chooses to build a custom application instead of buying a vendor solution, the primary risks shift from external dependencies to internal development challenges. Building custom software typically requires significant upfront investment in time, skilled personnel, and financial resources, and it often takes longer to deliver than implementing an existing product. Therefore, the auditor should emphasize increased time-to-market and development costs as the key risk in this scenario.

Exam trap

CISA often tests the ability to distinguish between risks associated with building versus buying software; candidates may incorrectly associate vendor-related risks like lock-in or external support dependence with custom development, when in fact the primary risks of building are internal, such as increased time-to-market and development costs.

How to eliminate wrong answers

Option A is wrong because lack of customization is actually a risk of buying a vendor solution, not building one; custom-built applications are inherently customizable. Option B is wrong because dependence on external support is a risk associated with purchasing vendor software, where the organization relies on the vendor for updates and fixes, whereas building in-house reduces external support dependence. Option C is wrong because vendor lock-in occurs when an organization is tied to a specific vendor's proprietary technology, which is a risk of buying, not building; building custom avoids vendor lock-in but introduces other risks.

2
MCQmedium

A hospital is implementing a new electronic health record (EHR) system to replace a legacy system. During the implementation phase, the project manager proposes using a parallel changeover strategy. Which of the following is the MOST significant risk associated with this approach?

A.The high cost of training users on both systems simultaneously.
B.The need to maintain and reconcile data in both systems, increasing the risk of data inconsistencies.
C.The inability to roll back to the legacy system if the new system fails.
D.The prolonged project timeline due to extended testing phases.
AnswerB

Parallel changeover runs old and new systems simultaneously, requiring dual data entry and reconciliation. In a hospital, this can lead to discrepancies between the legacy EHR and the new system, potentially affecting patient care. The main risk is the complexity and cost of maintaining data integrity across both systems during the overlap period.

Why this answer

Parallel changeover involves running both old and new systems concurrently, which introduces significant data reconciliation challenges. In a hospital, where accurate patient data is critical, the risk of inconsistencies between the two systems is the most significant concern. This approach is often chosen for high-risk systems to provide a fallback, but it requires robust controls to ensure data integrity.

Exam trap

The trap here is assuming that parallel changeover eliminates risk because it provides a fallback, but it actually introduces new risks related to data consistency and operational complexity.

3
MCQmedium

An IS auditor is reviewing a post-implementation review report for a new financial system. Which finding would most indicate that the project did not meet its objectives?

A.Three minor change requests were submitted in the first month
B.Users required additional training after go-live
C.The project budget was exceeded by 5%
D.The system processed transactions 20% slower than projected
AnswerD

Throughput below the projected baseline means the system fails its defined performance objective, so the project did not deliver the agreed benefits. Budget compliance and delivery date are irrelevant to this finding; processing speed is a measurable acceptance criterion.

Why this answer

A system processing transactions 20% slower than projected directly indicates that the system failed to meet a key performance objective, which is a core project objective. Post-implementation reviews assess whether the system delivers expected performance, functionality, and benefits; a significant performance shortfall is a clear sign objectives were not met. This finding most strongly indicates a failure to meet objectives.

Exam trap

CISA often tests the difference between normal post-go-live issues (training, minor changes, small budget variance) and substantive failures to meet objectives — the trap is over-weighting minor issues as objective failures.

How to eliminate wrong answers

Option A is wrong because three minor change requests in the first month are normal and expected as users adapt to the system, not an indication of failure to meet objectives. Option B is wrong because additional training after go-live is common and does not necessarily mean objectives were unmet — it may reflect normal user onboarding. Option C is wrong because a 5% budget overrun, while not ideal, is relatively minor and does not by itself indicate that the project failed to meet its objectives, especially if benefits are realized.

4
MCQeasy

Which type of change in ITIL requires approval from the Change Advisory Board (CAB) before implementation?

A.Emergency change
B.Normal change
C.Standard change
D.All changes
AnswerB

Normal changes follow the full assessment and authorisation path, so they require CAB approval before implementation. Standard changes are pre-authorised by a defined procedure, and emergency changes use a separate expedited route, typically with retrospective CAB review.

Why this answer

Normal changes are those that are not pre-approved or emergency. They require assessment and approval by the CAB to evaluate risks and impacts.

5
Multi-Selectmedium

An organization is implementing a new customer relationship management (CRM) system using an agile methodology. Which THREE areas should the IS auditor focus on to assess the effectiveness of controls during the development process?

Select 3 answers
A.Use of formal change request documentation for each change
B.Inclusion of security requirements in user stories
C.Conduct of sprint retrospectives to identify improvements
D.Performance of code reviews and static analysis
E.Adherence to the original detailed project plan
AnswersB, C, D

Embedding security requirements in user stories makes them estimable, testable and traceable within sprints. The auditor examines whether stories carry explicit security acceptance criteria, since this determines whether controls are actually built rather than deferred to post-release remediation.

Why this answer

Option B is correct because in agile development, security requirements must be embedded into user stories and the product backlog so that controls are designed and tested iteratively rather than bolted on at the end; an IS auditor should verify that security acceptance criteria exist for each story. Option C is correct because sprint retrospectives are the agile mechanism for inspecting the process and identifying control and quality improvements, so their consistent conduct demonstrates an effective feedback loop for the development process. Option D is correct because code reviews and static analysis (e.g., SAST tools) provide technical verification of secure coding and defect detection at each increment, which is a key control compensating for the reduced reliance on phase-gate documentation in agile.

Option A is not the best focus because formal change request documentation for every change reflects a traditional waterfall change-control model, whereas agile relies on backlog refinement and continuous integration rather than per-change formal requests. Option E is not appropriate because adherence to an original detailed project plan contradicts agile's adaptive, iterative planning, where scope and plans evolve across sprints.

Exam trap

CISA often tests the misconception that agile projects should still follow waterfall-style documentation and plan adherence — candidates who pick A or E apply traditional audit thinking to an agile context.

6
MCQeasy

Which of the following is a key control in the deployment phase of the SDLC?

A.Rollback plan
B.Threat modeling
C.User acceptance testing
D.Code review
AnswerA

A rollback plan provides a tested mechanism to revert to the prior stable state if deployment fails or introduces critical defects. This directly addresses the deployment phase's key risk — production disruption — by enabling rapid restoration of service, satisfying the stem's requirement for a key deployment control.

Why this answer

A rollback plan ensures that if deployment fails, the system can be restored to a known good state.

7
MCQeasy

In a spiral SDLC model, what is the primary purpose of risk analysis in each iteration?

A.To identify and resolve potential project risks early
B.To assess user satisfaction with the prototype
C.To plan the next iteration's tasks
D.To define detailed functional requirements
AnswerA

Each spiral cycle begins by analysing risks so that high-exposure items are addressed through prototyping and mitigation before major investment continues. This early resolution reduces the likelihood of costly rework or failure in later, more expensive iterations.

Why this answer

In the spiral model, each iteration begins with risk analysis to identify and resolve potential project risks early, which is the core differentiator of this model. This allows the team to address high-risk areas before investing heavily in development, reducing the chance of costly failures later. The risk analysis directly informs whether to proceed, modify, or abandon the iteration.

Exam trap

The trap here is confusing the spiral model's risk analysis with general project risk management or with other phases like planning or requirements gathering; candidates may pick an answer that sounds plausible but is not the specific purpose of risk analysis in each iteration.

How to eliminate wrong answers

Option B is wrong because assessing user satisfaction with the prototype is part of the evaluation phase, not the primary purpose of risk analysis. Option C is wrong because planning the next iteration's tasks is a separate activity that follows risk analysis, not its purpose. Option D is wrong because defining detailed functional requirements is typically done during requirements elicitation, not during risk analysis in the spiral model.

8
Multi-Selectmedium

An organization is migrating from a legacy system to a new ERP. Which TWO of the following are the HIGHEST risks during data migration?

Select 2 answers
A.Incorrect data mapping between old and new systems
B.Insufficient network bandwidth during cutover
C.Lack of user training on the new system
D.Lack of segregation of duties in the new system
E.Incomplete or inaccurate source data
AnswersA, E

Incorrect mapping transfers values into wrong fields, corrupting balances, inventory and master data that downstream processes depend on. Because errors propagate silently and are costly to unwind post-cutover, mapping validation is a highest-risk migration concern.

Why this answer

Option A is correct because incorrect data mapping between the legacy and new ERP schemas directly causes fields to be transformed, truncated, or populated into the wrong target columns, producing corrupt or unusable records in the new system — a core data migration risk. Option E is correct because incomplete or inaccurate source data (missing values, duplicates, inconsistent formats) propagates defects into the ERP and undermines the integrity of the migrated dataset, regardless of how well the mapping is designed. These two are the highest risks because they directly threaten the accuracy and completeness of the migrated data itself, which is the primary objective of the migration.

Option B is not a top migration risk since bandwidth affects cutover performance/throughput rather than data correctness and is typically mitigated by scheduling and sizing. Option C concerns post-migration adoption and user competence, not the integrity of the migrated data. Option D is an access-control/governance risk in the new system's design, not a data migration risk.

Exam trap

The trap is that candidates may focus on technical or training risks that are more visible, but the exam expects recognition that data integrity risks (mapping and source data quality) are the highest during data migration.

9
MCQmedium

An IS auditor is reviewing change management procedures. Which of the following situations would be of GREATEST concern?

A.A standard change was implemented without CAB approval
B.An emergency change was implemented and not reviewed after resolution
C.The change request did not include an impact analysis
D.A normal change had a rollback plan that was not tested
AnswerB

Emergency changes bypass normal review, so the absence of post-implementation review leaves the change permanently unverified, with no confirmation it was authorised, tested, or documented. This defeats the control's compensating mechanism and represents the greatest change management concern.

Why this answer

An emergency change bypasses the normal CAB review and testing gates, so the only compensating control is a mandatory post-implementation review (PIR) to confirm the change worked, assess side effects, and retroactively authorize it. If that review never happens, the change remains unauthorized and unverified, leaving a permanent gap in the change management audit trail. This is the greatest concern because it defeats the entire purpose of the emergency-change exception.

Exam trap

CISA often tests the distinction between process-documentation weaknesses (missing impact analysis, untested rollback) and control-bypass weaknesses (unreviewed emergency change) — candidates pick the more 'visible' documentation gap instead of the actual loss of control.

How to eliminate wrong answers

Option A is wrong because standard (pre-approved, low-risk) changes are by definition pre-authorized through a standing CAB-approved model, so implementing one without a per-change CAB vote is normal and not a control failure. Option C is wrong because a missing impact analysis is a documentation/process weakness that is typically caught and remediated during normal change review, not a bypass of the control framework. Option D is wrong because an untested rollback plan on a normal change is a risk-mitigation weakness, but the change still went through CAB approval, testing, and post-implementation verification — a lesser concern than an unreviewed emergency change.

10
MCQeasy

An IS auditor is reviewing the post-implementation review (PIR) of a newly deployed human resources (HR) system. Which of the following should be the PRIMARY focus of the PIR?

A.Verifying that the system meets business requirements and delivers expected benefits.
B.Ensuring that all project documentation is archived.
C.Comparing actual project costs to the approved budget.
D.Confirming that the project team has been released from their assignments.
AnswerA

The primary purpose of a post-implementation review is to determine if the system achieved its intended business objectives and benefits. This involves assessing user satisfaction, system performance, and alignment with business needs. Cost and schedule are inputs, but the core focus is on benefits realization and whether the system is fit for purpose.

Why this answer

A post-implementation review should primarily evaluate whether the system meets business requirements and delivers the expected benefits. This assessment helps organizations learn from the project and ensure the system is providing value. While cost, documentation, and resource release are relevant, they are secondary to the core goal of benefits realization.

Exam trap

The trap here is equating the post-implementation review with a financial audit or administrative closeout, rather than a benefits realization assessment.

11
MCQmedium

An IS auditor is assessing the controls in an agile development environment. What is the MOST effective way to verify that security testing is performed iteratively?

A.Observing a daily standup meeting
B.Interviewing the product owner about security priorities
C.Examining the final security test report after release
D.Reviewing the project's definition of done for each sprint
AnswerD

The definition of done is agreed per sprint and should explicitly include security testing criteria. Auditing each sprint's definition of done confirms whether security activities are embedded iteratively, providing direct evidence rather than relying on retrospective claims or final-phase testing.

Why this answer

In agile development, security testing must be integrated into each sprint to ensure continuous validation. The 'definition of done' (DoD) is the team's checklist for completing a user story; if it explicitly includes security testing tasks (e.g., static analysis, dynamic scans, or penetration tests), then verifying the DoD proves that security testing was performed iteratively. Option D directly examines this artifact, providing objective evidence of iterative security testing.

Exam trap

The trap here is that candidates confuse 'planning for security' (e.g., standups or product owner interviews) with 'evidence of security execution' (the DoD), or they mistakenly think a final report proves iterative testing when it only shows a single snapshot.

How to eliminate wrong answers

Option A is wrong because observing a daily standup meeting only reveals what the team plans to discuss, not whether security testing was actually completed; standups are status updates, not evidence of testing execution. Option B is wrong because interviewing the product owner about security priorities captures intent and backlog ordering, but does not confirm that security testing was performed in each iteration. Option C is wrong because examining the final security test report after release shows only a single point-in-time assessment, not iterative testing across sprints; it misses the continuous integration of security checks throughout development.

12
MCQmedium

An IS auditor is reviewing a project to implement a new loan origination system. The project manager has produced a detailed work breakdown structure (WBS), a critical path schedule, and a resource-loaded plan. Which of the following should the auditor verify FIRST to assess whether the project schedule is realistic?

A.That the project sponsor has signed the project charter and that the budget has been approved by the finance committee.
B.That the WBS has been decomposed to at least three levels and that each work package has a unique identifier.
C.That all project risks have been entered into the risk register and assigned an owner with a mitigation plan.
D.That the critical path includes all tasks with zero float and that resource constraints have been leveled against actual availability.
AnswerD

A credible schedule must reflect both logical dependencies and real resource availability. If the critical path is calculated without leveling against actual staff, the plan can show an impossibly short duration. The auditor should first confirm that zero-float tasks are correctly sequenced and that resourcing assumptions match the people actually assigned, because every later schedule claim depends on this foundation.

Why this answer

A realistic schedule requires correct logical dependencies and accurate resource assumptions. Zero-float tasks define the critical path, but if that path is built without leveling against actual staff availability, the projected end date is unreliable. Confirming that critical path tasks are sequenced properly and that resourcing reflects real capacity gives the auditor the strongest evidence about schedule feasibility before examining other project artifacts.

Exam trap

The trap here is assuming that an approved charter and budget validate the schedule, when schedule realism depends on dependency logic and resource leveling.

13
MCQhard

An organization is deciding between building a custom application and purchasing a commercial off-the-shelf (COTS) product. The primary factor favoring the build option is:

A.Greater control over features
B.Faster time to market
C.Lower initial cost
D.Reduced vendor dependency
AnswerA

Building in-house gives the organization direct authority over the application's feature roadmap, letting it tailor functionality to unique business processes rather than adapting to a vendor's fixed release cycle. This satisfies the stem's decision factor: where differentiation or specialised requirements matter, custom development delivers feature control that COTS licensing cannot.

Why this answer

Building a custom application allows for tailored functionality that meets unique business requirements, which is a key advantage over COTS.

14
MCQeasy

Which of the following is a key control during the deployment phase of a system development life cycle?

A.Rollback plan
B.Code review
C.Threat modeling
D.User acceptance testing (UAT)
AnswerA

A rollback plan is the key deployment-phase control because it provides a tested mechanism to revert to the previous stable state if the release fails, directly satisfying the need to manage deployment risk and minimise disruption to production services. It addresses the stem's deployment-phase constraint, unlike design or post-implementation controls.

Why this answer

During the deployment phase, the system is moved into production, and a rollback plan is a critical control to revert to a previous stable state if the deployment fails or introduces defects. It ensures business continuity and minimizes downtime. Code review, threat modeling, and UAT occur earlier in the SDLC (development, design, and testing phases, respectively).

Exam trap

The trap is confusing deployment-phase controls with testing-phase controls — candidates often pick UAT because it sounds like a final check, but UAT occurs before deployment, while rollback planning is specifically executed during deployment.

How to eliminate wrong answers

Option B is wrong because code review is a development-phase control focused on identifying defects and security issues in source code before it is built or deployed. Option C is wrong because threat modeling is a design-phase activity that identifies potential threats and mitigations before code is written. Option D is wrong because user acceptance testing is a testing-phase activity that validates the system against business requirements before deployment, not during it.

15
MCQmedium

An organization is migrating data from a legacy system to a new ERP. What is the most critical data migration risk?

A.Data loss or corruption
B.Increased storage costs
C.Longer migration time
D.Incompatible hardware
AnswerA

Data loss or corruption directly threatens the migration's integrity, since legacy-to-ERP transfers involve format conversions, field mapping and bulk loads where truncation, encoding faults or failed batches can silently corrupt records. This satisfies the stem's "most critical" constraint because corrupted financial data undermines the ERP's ledger accuracy and auditability irreversibly.

Why this answer

Data loss or corruption is the most critical risk because it directly compromises the integrity and completeness of the migrated data, which is the core asset being transferred. Unlike cost or schedule overruns, corrupted data can lead to incorrect business decisions, regulatory non-compliance, and financial misstatements that may go undetected for long periods. The primary objective of any data migration is to preserve data accuracy and completeness, making this the highest-priority risk.

Exam trap

CISA often tests the distinction between project management risks (cost, schedule, hardware) and information asset risks (integrity, confidentiality, availability), expecting candidates to prioritize the risk that threatens the data itself.

How to eliminate wrong answers

Option B is wrong because increased storage costs are a financial concern that can be managed through capacity planning and does not threaten the integrity of the business data itself. Option C is wrong because longer migration time affects project schedule but can be mitigated with rollback plans and does not inherently damage the data. Option D is wrong because incompatible hardware is a technical infrastructure issue typically resolved during planning and testing, and it does not directly cause data integrity loss once the migration environment is validated.

16
Multi-Selectmedium

An IS auditor is assessing the implementation of a new system that uses a relational database. The project team plans to migrate data from several legacy sources. Which TWO of the following controls are MOST important to include in the data conversion plan to help ensure the integrity of migrated data? (Choose two.)

Select 2 answers
A.Confirmation that the legacy system is decommissioned immediately after the conversion cutover.
B.Use of a parallel test environment that mirrors production hardware and software configurations for the conversion rehearsal.
C.Verification that referential integrity constraints are enabled and validated after the data load.
D.Approval of the data mapping document by the database administrator before the conversion begins.
E.Reconciliation of record counts and financial totals between legacy sources and the new database after conversion.
AnswersC, E

Referential integrity constraints prevent orphaned records and invalid relationships in the new database. If they are disabled during the load and not re-enabled and validated afterward, the database may contain inconsistent foreign key values that corrupt business logic and reporting. Confirming that constraints are active and that validation completed ensures the migrated data conforms to the target schema's relational rules.

Why this answer

Data migration integrity depends on detecting missing or corrupted records and ensuring that relationships between tables remain valid. Reconciliation of counts and totals provides independent verification that all expected data arrived, while validated referential integrity constraints ensure that foreign key relationships are sound. Together, these detective and preventive controls give the auditor the strongest evidence that the conversion preserved data accuracy and completeness.

Exam trap

The trap here is treating project logistics like legacy decommissioning or environment setup as data integrity controls, when the real assurance comes from reconciliation and referential integrity validation.

17
Multi-Selecthard

During a post-implementation review of a new accounting system, the IS auditor notes the following: the project was completed on time and within budget, but user satisfaction is low and there are several outstanding defect reports. Which THREE of the following are the MOST appropriate recommendations?

Select 3 answers
A.Compare actual benefits achieved against the business case
B.Establish a formal plan to resolve outstanding defects
C.Request additional budget to fix the defects
D.Immediately escalate the defect reports to the project sponsor
E.Conduct a lessons learned session to identify process improvements
AnswersA, B, E

On-time, on-budget delivery says nothing about value, so comparing realised benefits against the original business case tests whether the system actually delivered the expected outcomes — the gap the low satisfaction and defect backlog hint at.

Why this answer

Option A is correct because a post-implementation review must measure realized benefits against the original business case to determine whether the system delivered the expected value, especially when satisfaction is low. Option B is correct because outstanding defect reports represent unresolved risks to data integrity and operational reliability in an accounting system, so a formal remediation plan with ownership, priorities, and target dates is the appropriate control response. Option E is correct because a lessons learned session captures root causes of the schedule/budget-versus-quality gap and feeds process improvements into future projects.

Option C is not appropriate as a primary recommendation because additional budget is a funding request, not a control or governance action, and cost should follow an approved defect remediation plan. Option D is not appropriate because escalation to the sponsor may be a communication step, but it does not by itself resolve the defects or address the underlying process weaknesses.

Exam trap

CISA often tests whether candidates recommend process-based, governance-aligned actions rather than reactive or escalation-based responses, so options that skip formal remediation planning are typically distractors.

18
MCQhard

An IS auditor is reviewing an emergency change that was implemented to fix a critical security vulnerability. What is the most important post-implementation step?

A.Document the change and obtain retrospective approval
B.Update the configuration management database
C.Notify all users
D.Conduct a risk assessment
AnswerA

Emergency changes bypass the normal change advisory board, so retrospective approval restores governance while documentation preserves the audit trail. This satisfies the IS auditor's requirement that emergency fixes still receive formal authorisation and traceability after implementation.

Why this answer

Documenting the change and obtaining retrospective approval is the most important step because emergency changes bypass normal change control, and without proper documentation and after-the-fact authorization, the organization loses accountability and auditability. This step ensures the change is formally recorded in the change log and reviewed by the change advisory board (CAB) or equivalent authority, closing the governance gap created by the emergency. It also provides the audit trail needed for future reviews and compliance.

Exam trap

CISA often tests the principle that emergency changes still require retrospective approval and documentation, and candidates who prioritize technical follow-ups like CMDB updates or risk assessments over governance controls pick the wrong answer.

How to eliminate wrong answers

Option B is wrong because updating the configuration management database (CMDB) is important for asset accuracy but is a secondary administrative task that does not address the governance gap of an unauthorized change. Option C is wrong because notifying all users is a communication activity that does not satisfy change management control requirements and may not even be necessary for a security patch. Option D is wrong because conducting a risk assessment after the change is implemented is too late to inform the decision; the emergency change was already made, and the priority is to legitimize it through documentation and retrospective approval.

19
Multi-Selecthard

An IS auditor is reviewing the implementation of a new payroll system. The project team has decided to use a pilot conversion approach. Which TWO of the following are the MOST significant advantages of this approach? (Choose two.)

Select 2 answers
A.It allows for testing the system in a live environment with a subset of users before full rollout.
B.It allows for incremental learning and refinement of the implementation process before full deployment.
C.It minimizes the need for user training because only a few users are affected initially.
D.It provides a fallback option to revert to the old system if the pilot fails.
E.It eliminates the need for parallel testing with the old system.
AnswersA, B

Pilot conversion involves implementing the new system for a small group of users, such as one department or location. This allows the organization to test the system in a real production environment, identify issues, and make adjustments before rolling out to the entire organization. This reduces the risk of widespread failure.

Why this answer

Pilot conversion offers two key advantages: it enables live testing with a subset of users, allowing real-world validation and issue identification, and it facilitates incremental learning so that the implementation process can be refined before full deployment. These benefits reduce risk and improve the chances of a smooth organization-wide rollout.

Exam trap

The trap here is assuming that pilot conversion reduces training or eliminates parallel testing, when in fact it still requires training for all users and may still involve parallel runs for verification.

20
MCQmedium

An organization is considering whether to build a custom application or purchase a commercial off-the-shelf (COTS) product. Which of the following factors would most strongly support a build decision?

A.Short time to market is critical.
B.The vendor offers a robust service-level agreement (SLA).
C.The required functionality is unique to the organization's competitive advantage.
D.The organization has limited in-house development resources.
AnswerC

Functionality delivering competitive advantage is organisation-specific and unlikely to exist in a COTS product, so purchasing would force costly customisation or forfeit differentiation. Building internally lets the organisation own and tailor that capability, satisfying the strategic requirement that drives the build decision.

Why this answer

When the required functionality is unique to the organization's competitive advantage, building a custom application is justified because COTS products cannot provide differentiated capabilities that create strategic value. Custom development allows the organization to tailor features, integrate proprietary processes, and maintain exclusive control over the intellectual property. This factor most strongly supports a build decision because it directly ties the software to business differentiation.

Exam trap

CISA often tests whether candidates can distinguish strategic differentiation (build) from operational efficiency (buy), so options emphasizing speed, SLAs, or resource constraints are distractors that actually favor buying.

How to eliminate wrong answers

Option A is wrong because a critical need for short time to market favors purchasing COTS, since custom development typically takes longer to deliver. Option B is wrong because a robust vendor SLA is a benefit of COTS procurement, not a reason to build; it reduces the risk of purchasing. Option D is wrong because limited in-house development resources is a constraint that argues against building and favors buying a COTS solution with vendor support.

21
Multi-Selectmedium

Which TWO of the following are benefits of an iterative SDLC approach compared to waterfall? (Select two.)

Select 2 answers
A.Early and frequent feedback from stakeholders
B.Simpler documentation requirements
C.Predictable project timeline
D.Ability to incorporate changing requirements
E.Reduced need for user involvement
AnswersA, D

Iterative delivery produces working increments each cycle, so stakeholders review functioning software rather than documents, surfacing requirement defects while change remains cheap. This directly satisfies the stem's comparison against waterfall, whose single late validation phase defers feedback until rework is costly.

Why this answer

Option A is correct because iterative SDLC delivers working increments at the end of each short iteration, letting stakeholders review and provide feedback early and frequently rather than waiting until the end of the project as in waterfall. Option D is correct because iterative development welcomes and accommodates changing requirements between iterations, whereas waterfall typically freezes requirements after the initial phase and makes late changes costly. Option B is not inherently true, since iterative methods still require documentation and may even produce more artifacts across iterations.

Option C is wrong because iterative projects are generally less predictable in overall timeline due to evolving scope, unlike waterfall's fixed sequential plan. Option E is incorrect because iterative approaches actually increase, not reduce, the need for ongoing user involvement through regular reviews and feedback.

Exam trap

The trap is picking 'predictable timeline' or 'reduced user involvement' as iterative benefits — those are waterfall strengths or Agile misconceptions, and the exam expects you to distinguish feedback/change-adaptability from schedule predictability.

22
MCQeasy

Which of the following is the PRIMARY objective of a post-implementation review of an information system?

A.To assess the performance of the project team
B.To evaluate whether the system achieved its planned objectives and benefits
C.To document the technical architecture for future reference
D.To identify new requirements for future enhancements
AnswerB

A post-implementation review compares actual outcomes against the business case and stated benefits, determining whether the system delivered its planned objectives. This addresses the primary governance objective rather than technical performance or user satisfaction alone.

Why this answer

The primary objective of a post-implementation review (PIR) is to evaluate whether the system achieved its planned objectives and delivered the expected benefits. It assesses the system against the original business case, requirements, and success criteria to determine if the investment realized its intended value. This evaluation informs future investment decisions and identifies lessons learned.

Exam trap

CISA often tests the difference between primary and secondary objectives, tempting candidates to select project management concerns like team performance or technical documentation instead of the core benefit realization focus.

How to eliminate wrong answers

Option A is wrong because assessing project team performance is a secondary or incidental outcome, not the primary objective; PIR focuses on system outcomes, not individual performance. Option C is wrong because documenting technical architecture is a design or documentation activity, not the purpose of a PIR; architecture should already be documented. Option D is wrong because identifying new requirements is a forward-looking enhancement activity, not the primary objective of a PIR, which is retrospective evaluation of achieved benefits.

23
MCQmedium

An IS auditor is reviewing a project that is developing a new customer relationship management (CRM) system using the Agile Scrum framework. The project team has completed several sprints, and the product owner has accepted the increments. The auditor wants to ensure that the system will meet the organization's security requirements before go-live. Which of the following is the MOST effective way for the auditor to achieve this?

A.Verify that the product owner has signed off on all functional requirements, as this ensures security is also covered.
B.Examine the project charter to confirm that security testing is listed as a deliverable in the overall project plan.
C.Review the user stories and acceptance criteria to verify that security requirements are included and tested in each sprint.
D.Recommend that a comprehensive security assessment be conducted only after the final sprint, just before deployment.
AnswerC

In Agile development, security requirements must be integrated into the product backlog as user stories or acceptance criteria to be addressed during sprints. By reviewing these, the auditor can confirm that security is continuously validated, not deferred to the end. This approach aligns with the principle of building security in from the start, ensuring that each increment meets security expectations. The other options either postpone security testing or focus on documentation rather than actual implementation.

Why this answer

In Agile Scrum, security requirements should be treated as backlog items and tested within sprints to ensure continuous validation. The most effective audit approach is to examine user stories and acceptance criteria for security content and evidence of testing. This provides real-time assurance that security is being addressed, rather than relying on post-hoc assessments or high-level plans.

Thus, reviewing user stories and acceptance criteria is the correct approach.

Exam trap

The trap here is assuming that security is automatically covered by functional acceptance or that a final security assessment is sufficient, when in Agile it must be integrated into each sprint.

24
MCQmedium

An IS auditor is evaluating the vendor selection process for a new system. Which of the following is the most important factor to include in the contract?

A.Timeframe for delivery
B.Fixed price
C.Audit rights
D.Warranty period
AnswerC

Audit rights contractually permit the buyer to examine the vendor's controls, records and compliance evidence, providing ongoing assurance over the outsourced system. This is the most important factor because it preserves the organisation's ability to verify security and regulatory compliance, satisfying the stem's vendor selection requirement.

Why this answer

Audit rights are critical for the organization to verify the vendor's controls and compliance, especially for outsourced systems.

25
MCQhard

An IS auditor is reviewing the requirements definition phase of a new system development project. The business analyst has documented functional requirements but has not yet defined non-functional requirements. Which of the following is the MOST significant risk of proceeding to the design phase without non-functional requirements?

A.The system may not meet performance, security, and availability expectations.
B.The development team may not understand the business processes.
C.The project timeline may be extended due to rework.
D.The project budget may be exceeded.
AnswerA

Non-functional requirements define quality attributes such as performance, security, and availability. Without them, designers may make assumptions that lead to a system that fails to meet stakeholder expectations. These attributes are often costly to retrofit later. The auditor should ensure non-functional requirements are defined and approved before design begins to mitigate this risk.

Why this answer

Non-functional requirements specify criteria such as performance, security, and availability that are essential for system acceptance. Proceeding without them increases the likelihood that the system will fail to meet stakeholder expectations and may require costly rework. The auditor should verify that both functional and non-functional requirements are defined and approved before design begins.

Exam trap

The trap here is focusing on project management symptoms like timeline or budget overruns, rather than the core risk of delivering a system that does not meet quality attributes.

26
Multi-Selectmedium

During a post-implementation review of a new payroll system, the IS auditor identifies several outstanding issues. Which TWO issues should be considered most critical to address immediately? (Select TWO)

Select 2 answers
A.The system is running 5% slower than expected
B.The system's tax calculation module produced incorrect results for a subset of employees
C.Some employees have not completed training
D.Unauthorized overtime payments were processed due to a configuration error
E.The user manual is not yet finalized
AnswersB, D

Incorrect tax calculations breach statutory withholding and reporting obligations, producing wrong net pay and filing errors for affected employees. This is a data integrity failure in a legally mandated function, so it demands immediate correction ahead of cosmetic or efficiency issues.

Why this answer

Option B is critical because incorrect tax calculations in a payroll system directly violate legal and regulatory compliance requirements, can result in penalties from tax authorities, and harm employee trust through inaccurate pay and withholding. Option D is critical because unauthorized overtime payments from a configuration error represent a direct financial loss and indicate a control failure in the payroll processing logic that could recur and compound if not remediated immediately. In contrast, option A (5% performance degradation) is a performance/efficiency concern that does not affect data integrity or compliance and can be tuned later.

Option C (incomplete training) is a people/process issue that, while important, does not by itself cause incorrect or unauthorized transactions. Option E (unfinalized user manual) is a documentation gap with no immediate financial, legal, or control impact.

Exam trap

CISA often tests the ability to prioritize issues based on risk, tempting candidates to select operational inefficiencies like performance slowdowns or training gaps over critical financial and compliance failures.

27
MCQhard

An IS auditor is reviewing a post-implementation review report for a new ERP system. Which of the following findings would be of greatest concern to the auditor?

A.Several segregation of duties conflicts were identified and not resolved.
B.The implementation took three months longer than planned.
C.The project exceeded the budget by 15%.
D.User acceptance testing (UAT) was completed with only 80% test coverage.
AnswerA

Unresolved segregation of duties conflicts leave incompatible functions, such as creating a vendor and approving its payment, with one person. Unlike tuning or training issues, this is a live control failure that enables fraud or error, so it is the finding of greatest concern in a post-implementation review.

Why this answer

Unresolved segregation of duties (SoD) conflicts in an ERP system pose a significant risk of fraud, unauthorized transactions, and financial misstatement. SoD is a fundamental internal control that prevents any single individual from having control over all aspects of a transaction. Unresolved conflicts indicate a control deficiency that could lead to material misstatement and is of greatest concern to an IS auditor.

Exam trap

CISA often tests the auditor's ability to distinguish between control deficiencies and project management variances, tempting candidates to select budget or schedule overruns over unresolved SoD conflicts that directly impact control effectiveness.

How to eliminate wrong answers

Option B is wrong because a three-month delay is a schedule variance that, while notable, does not directly compromise control integrity or financial accuracy. Option C is wrong because a 15% budget overrun is a financial performance issue but does not inherently indicate a control weakness or risk of fraud. Option D is wrong because 80% UAT coverage, although not ideal, is a testing completeness issue that may be acceptable if risks are mitigated; it is less critical than unresolved SoD conflicts that directly threaten control objectives.

28
MCQhard

An organization is implementing a large ERP system. The project team plans to migrate legacy data to the new system. Which of the following is the MOST significant risk associated with data migration?

A.Insufficient training of end users
B.Lack of executive sponsorship
C.Inadequate segregation of duties in the new system
D.Inaccurate data mapping between legacy and new systems
AnswerD

Mapping errors propagate corrupted or misaligned values into the new ERP, so migrated records may be incomplete or wrongly attributed. Because mapping defects are systemic, they affect entire data sets rather than isolated rows, undermining financial reporting and downstream processing long after go-live.

Why this answer

Data migration often involves mapping old data to new structures. Inaccurate mapping can lead to data corruption or loss, which is a critical risk.

29
MCQmedium

An IS auditor is reviewing the change management process for a critical financial application. Which of the following is the most important element to verify in an emergency change request?

A.Approval from the Change Advisory Board (CAB)
B.Extensive user acceptance testing (UAT) results
C.A completed impact analysis
D.A documented rollback plan
AnswerD

A documented rollback plan directly satisfies the emergency change constraint by enabling rapid restoration of the financial application if the change fails, minimising disruption to critical processing. Verifying it confirms the organisation can reverse unplanned modifications without extended downtime, which matters more than retrospective approvals when emergency changes bypass normal change management controls.

Why this answer

In an emergency change, the most critical element to verify is a documented rollback plan. Emergency changes are implemented with minimal testing and often bypass normal approval processes; a rollback plan ensures that if the change fails or causes unintended consequences, the system can be restored to its previous state quickly, minimizing disruption to critical financial operations.

Exam trap

CISA often tests the prioritization of controls in emergency changes, tempting candidates to select standard controls like CAB approval or UAT that are often bypassed in emergencies, instead of the rollback plan that is the key risk mitigation.

How to eliminate wrong answers

Option A is wrong because while CAB approval is important, in an emergency, approval may be retrospective; the immediate priority is having a rollback plan to mitigate failure. Option B is wrong because extensive UAT is typically not feasible in an emergency; the focus is on minimizing risk through rollback rather than comprehensive testing. Option C is wrong because an impact analysis, though valuable, may be abbreviated in an emergency; the rollback plan is the key safeguard against unforeseen negative impacts.

30
MCQmedium

An IS auditor is assessing an ERP implementation. Which of the following control concerns is MOST likely to arise from segregation of duties conflicts?

A.Data migration errors
B.Inadequate system performance
C.Integration complexity
D.Unauthorized transactions or fraud
AnswerD

When one person can initiate, approve and record a transaction, no independent check exists, enabling fictitious vendors, duplicate payments or unauthorised adjustments to pass undetected. This is the classic fraud exposure that segregation of duties controls are designed to prevent.

Why this answer

ERP systems often combine roles that were separate in legacy systems, increasing risk of fraud.

31
MCQmedium

Which of the following is the PRIMARY purpose of a change advisory board (CAB) in the change management process?

A.To approve all standard changes without review
B.To assess, prioritize, and authorize changes
C.To authorize emergency changes immediately
D.To develop technical solutions for change requests
AnswerB

The change advisory board's primary function is to assess each change's risk and impact, prioritise it against other changes, and authorise or reject it, satisfying the stem's focus on the change management process. Implementation and post-implementation review sit with other roles, not the CAB.

Why this answer

The CAB is responsible for reviewing and approving changes, assessing risks, and ensuring proper planning and testing.

32
MCQeasy

During which phase of the SDLC should security requirements be formally documented and approved?

A.Design phase
B.Requirements phase
C.Development phase
D.Testing phase
AnswerB

Documenting and approving security requirements during the requirements phase ensures controls are baselined before design and coding begin. This satisfies the stem's constraint that security requirements be formally documented and approved at the earliest phase, preventing costly retrofitting later.

Why this answer

Security requirements must be formally documented and approved during the Requirements phase of the SDLC because this is when functional and non-functional needs, including security controls, are defined before any design or coding begins. Integrating security at this stage ensures that confidentiality, integrity, and availability requirements are captured in the system specification, preventing costly rework later. The Requirements phase is the earliest point where stakeholders can review and approve security constraints, such as encryption standards or access control policies, aligning them with business objectives.

Exam trap

The trap here is that candidates often confuse the Requirements phase with the Design phase, mistakenly thinking security requirements are documented during design because that is when security controls are technically specified, but formal approval must occur earlier in the requirements stage to drive the entire development lifecycle.

How to eliminate wrong answers

Option A is wrong because the Design phase translates approved requirements into technical architecture and detailed specifications, but security requirements must already be documented and approved before design begins to guide secure design decisions. Option C is wrong because the Development phase focuses on coding and unit testing based on the design, and introducing security requirements at this stage would lead to retrofitting controls, increasing risk and cost. Option D is wrong because the Testing phase validates that the system meets documented requirements, including security ones, but it is too late to formally document and approve security requirements; they must be established earlier to define test cases.

33
Multi-Selectmedium

Which THREE of the following are typical controls in the design phase of the SDLC?

Select 3 answers
A.Designing security controls
B.Architecture review
C.Code review
D.Threat modeling
E.User acceptance testing
AnswersA, B, D

The design phase translates requirements into technical specifications, so designing security controls here embeds confidentiality, integrity and availability measures into the solution before coding begins. Addressing security at design prevents costly retrofitting and satisfies the SDLC control objective of proactive risk mitigation.

Why this answer

Option A (Designing security controls) is correct because the design phase is exactly where security requirements are translated into concrete controls such as encryption schemes, authentication mechanisms, and access control models before any code is written. Option B (Architecture review) is correct because reviewing the proposed system architecture during design ensures that structural weaknesses, trust boundaries, and integration points are evaluated and corrected early, when changes are cheapest. Option D (Threat modeling) is correct because threat modeling is a design-phase activity that systematically identifies threats, attack vectors, and mitigations against the planned architecture and data flows.

Option C (Code review) does not belong because it occurs during the implementation or development phase, after code exists to inspect. Option E (User acceptance testing) does not belong because UAT is a testing/validation activity performed late in the SDLC, after the system is built, to confirm it meets business requirements.

Exam trap

CISA often tests whether candidates can correctly place security activities into the right SDLC phase, luring them into selecting code review or UAT because those sound security-adjacent when they actually belong to later phases.

34
MCQmedium

An organization is implementing a new ERP system and is concerned about segregation of duties (SoD) conflicts. What is the BEST approach to address this during the implementation?

A.Assign all administrative rights to a single user for efficiency
B.Configure role-based access controls with SoD rules in the system
C.Rely on manual compensating controls after go-live
D.Document SoD conflicts for future resolution
AnswerB

Embedding SoD rules into role-based access controls means the ERP enforces conflicting-duty separation at design time, preventing toxic combinations such as creating a vendor and approving its payment. Configuring this during implementation satisfies the stem's concern before go-live.

Why this answer

Configuring SoD rules within the ERP system helps enforce segregation and prevent conflicts during operations.

35
MCQeasy

In a waterfall SDLC, which phase requires formal sign-off from the business owner before proceeding to the next phase?

A.Development phase
B.Requirements phase
C.Design phase
D.Testing phase
AnswerB

Requirements are baselined and formally approved by the business owner before design begins, since later phases build directly on that frozen scope. Sign-off here authorises the project to proceed, whereas design and testing approvals occur within their own phases.

Why this answer

In a waterfall SDLC, the requirements phase concludes with formal business owner sign-off because it establishes the baseline for all subsequent design, development, and testing work. Once requirements are approved, changes become costly and require change control, so the business owner must formally accept the documented requirements before the project proceeds. This sign-off ensures mutual agreement on scope and reduces the risk of rework downstream.

Exam trap

CISA often tests whether candidates know which waterfall phase requires business owner sign-off, trapping those who pick design or testing because those phases also involve approvals but not the formal scope-baselining gate.

How to eliminate wrong answers

Option A (Development phase) is wrong because development sign-off is typically a technical milestone, not a business owner gate; the business owner's critical approval point is earlier, at requirements. Option C (Design phase) is wrong because design sign-off is usually a technical review (architecture, security) rather than the business owner's formal acceptance of scope. Option D (Testing phase) is wrong because testing sign-off (UAT) validates the built system against requirements, but the formal business owner gate that locks scope occurs at the end of requirements.

36
MCQmedium

During an agile software development project, a sprint review meeting is conducted. What is the PRIMARY purpose of this meeting from an IS audit perspective?

A.To identify and document lessons learned for process improvement
B.To demonstrate the working product increment to stakeholders and gather feedback
C.To assign tasks to team members for the current sprint
D.To plan the tasks for the next sprint
AnswerB

The sprint review inspects the completed increment against acceptance criteria, giving stakeholders tangible evidence of progress and a forum to raise issues. This transparency lets auditors verify that delivered functionality matches requirements rather than relying solely on documentation.

Why this answer

The sprint review is a key control in agile to demonstrate completed work to stakeholders and obtain feedback. It serves as a form of user acceptance testing and helps ensure the product meets stakeholder needs.

37
MCQeasy

Which testing type is performed by end-users to verify that the system meets their needs?

A.Security testing
B.Integration testing
C.User acceptance testing
D.Unit testing
AnswerC

User acceptance testing is executed by end-users themselves, directly satisfying the stem's requirement that testing be performed by end-users. It validates the system against business needs and real-world workflows rather than technical specifications, confirming fitness for purpose before go-live. This distinguishes it from unit, integration and system testing, which developers or testers conduct.

Why this answer

User acceptance testing (UAT) is the final phase of the testing lifecycle where actual end-users validate that the system fulfills their business requirements and is ready for production deployment. Unlike technical testing types, UAT focuses on real-world workflows, data accuracy, and usability to confirm the system meets the agreed-upon acceptance criteria.

Exam trap

The trap here is that candidates often confuse user acceptance testing with system testing or integration testing, assuming any 'end-user' involvement means UAT, but UAT specifically requires users to validate business needs, not technical correctness.

How to eliminate wrong answers

Option A is wrong because security testing is a specialized technical test focused on identifying vulnerabilities, threats, and compliance gaps (e.g., OWASP Top 10, penetration testing), not on verifying that the system meets end-user needs. Option B is wrong because integration testing verifies that individual modules or services interact correctly (e.g., API contracts, data flow between subsystems), but it does not involve end-user validation of business requirements. Option D is wrong because unit testing is performed by developers on individual code components (e.g., functions, methods) to catch defects early, and it has no involvement from end-users.

38
MCQmedium

Which of the following is the BEST control to ensure that user acceptance testing (UAT) is effective?

A.UAT scripts are written by developers
B.UAT is performed after deployment
C.UAT testers are from the business and use realistic data
D.UAT is conducted by the quality assurance team
AnswerC

Effectiveness depends on testers representing real users exercising genuine business workflows against representative data. Business testers with realistic data validate that the system meets actual operational needs, whereas IT staff or synthetic data would miss usability and process gaps.

Why this answer

UAT should be performed by actual end users using real data to validate business requirements.

39
Multi-Selectmedium

An IS auditor is reviewing a change management process. Which TWO elements should be documented in a normal change request to ensure adequate governance? (Select TWO)

Select 2 answers
A.Test plan
B.Vendor contact information
C.Change requester's name
D.Rollback plan
E.Project budget remaining
AnswersA, D

A test plan evidences that the change was verified before release, confirming the requester identified how functionality and related controls would be validated. Without it, governance cannot demonstrate that the change works as intended or that regression risk was assessed prior to production deployment.

Why this answer

A test plan (A) is correct because a normal change request must document how the change will be verified before implementation, including test cases, expected results, and acceptance criteria, which provides evidence that the change was validated and supports governance over change risk. A rollback plan (D) is correct because it defines the documented steps, triggers, and responsible parties for reverting the change if it fails or causes an incident, ensuring business continuity and recoverability are addressed before approval. Vendor contact information (B) is not a required element of a standard change request; it is only relevant for vendor-supported changes and is not part of the governance documentation for every change.

The change requester's name (C) is typically captured as basic identification metadata, but it does not by itself ensure adequate governance of the change's risk and validation. Project budget remaining (E) relates to financial tracking and is not a required component of a change request's governance documentation.

Exam trap

CISA often tests the misconception that administrative details (requester name, vendor contact, budget) are governance elements — the exam expects candidates to identify the two elements that directly support change validation and risk mitigation: test plan and rollback plan.

40
MCQmedium

An IS auditor is evaluating the change management process. Which of the following is the BEST indicator that emergency changes are being properly controlled?

A.Emergency changes are documented with a justification and promptly reviewed after implementation
B.Emergency changes are approved by the change manager within 24 hours
C.Emergency changes are tested in a production-like environment before implementation
D.Emergency changes require approval from the CAB before implementation
AnswerA

Documenting each emergency change with justification and reviewing it promptly afterwards confirms the control operated: the change was authorised retrospectively and assessed, rather than bypassing governance entirely, which is the strongest evidence of proper control.

Why this answer

The best indicator that emergency changes are properly controlled is that they are documented with a justification and promptly reviewed after implementation. Emergency changes, by definition, bypass the normal pre-approval and testing cycle, so the compensating control is retrospective review and documentation to ensure accountability and to catch any issues. This aligns with ITIL and COBIT guidance that emergency changes must be logged, justified, and reviewed post-implementation.

Exam trap

CISA often tests the misconception that emergency changes should still go through full pre-approval or testing — the correct control is post-implementation review and documentation, not pre-approval.

How to eliminate wrong answers

Option B is wrong because approval within 24 hours still implies pre-approval, which defeats the purpose of an emergency change and may delay critical fixes; it also does not address post-implementation review. Option C is wrong because testing in a production-like environment before implementation is a normal change control, not an emergency change control — emergencies often cannot wait for testing. Option D is wrong because requiring CAB approval before implementation contradicts the definition of an emergency change, which is invoked precisely when the CAB cannot convene in time.

41
MCQhard

An IS auditor is reviewing a system development project that uses a commercial software package customized with vendor-supplied extension points. The project team has documented customizations in a separate repository but has not maintained a traceability matrix linking business requirements to configuration items. Which of the following is the GREATEST risk arising from this situation?

A.The project may exceed its budget because customization effort cannot be accurately estimated for future phases.
B.Future upgrades may fail or require extensive rework because the impact of vendor changes on customizations cannot be reliably assessed.
C.Developers may introduce unauthorized changes because the separate customization repository is not integrated with the change management system.
D.User acceptance testing may be incomplete because test cases cannot be traced back to the original business requirements.
AnswerB

Without traceability from requirements to configuration items, the team cannot quickly determine which customizations support which business needs or which vendor patches will affect them. During an upgrade, this gap forces costly discovery work and increases the chance of breaking critical functionality. The greatest risk is therefore an inability to assess upgrade impact, which can delay patching and introduce production outages.

Why this answer

A traceability matrix connects business requirements to the configuration items and customizations that satisfy them. Without it, the organization cannot determine which customizations are affected by a vendor upgrade or patch. That uncertainty forces expensive manual analysis, delays security updates, and raises the likelihood of production failures.

While testing gaps and budget overruns matter, the enduring operational risk of unmanageable upgrades is the most severe consequence for a customized commercial package.

Exam trap

The trap here is focusing on testing or budgeting gaps, when the missing traceability matrix most severely undermines the ability to manage vendor upgrades and patches.

42
MCQmedium

An IS auditor is reviewing a waterfall SDLC project that has completed the requirements phase. Which of the following is the greatest risk to the project?

A.The project manager left the company.
B.A key business stakeholder did not sign off on the requirements.
C.The development team is unfamiliar with the technology.
D.The design phase is behind schedule.
AnswerB

Unsigned requirements leave scope unbaselined, so later changes cascade through design, build and test with no approved reference point. In waterfall, defects introduced at requirements cost most to correct, and the missing sign-off removes the control that would otherwise catch stakeholder misalignment before construction begins.

Why this answer

In waterfall, requirements are defined upfront and changes are difficult. If a key stakeholder did not sign off, there is a risk that later phases will be based on incomplete or incorrect requirements.

43
MCQhard

An IS auditor is reviewing the change management process for a critical financial application. Which of the following findings would be of GREATEST concern?

A.Standard changes are documented but not tracked individually
B.Change requests are logged in a spreadsheet instead of a dedicated system
C.Emergency changes are implemented without subsequent CAB approval
D.The CAB meets only once per month
AnswerC

Emergency changes bypassing subsequent CAB review leave the most critical control gap: changes reach production without retrospective scrutiny, risking undocumented, untested modifications to a financial application. Other findings are less severe because normal changes still receive approval before deployment.

Why this answer

Emergency changes implemented without subsequent CAB approval represent a critical control failure because emergency changes bypass the normal review and approval process, and if they are not retroactively reviewed, unauthorized or risky changes may remain in production. This creates a significant risk of undetected errors, fraud, or security vulnerabilities in a critical financial application. The lack of post-implementation approval means no oversight exists for changes that could directly affect financial reporting or data integrity.

Exam trap

CISA often tests the misconception that emergency changes are acceptable without any approval, but the real issue is the lack of subsequent CAB approval, which is a critical control gap.

How to eliminate wrong answers

Option A is wrong because standard changes are pre-approved, low-risk, and documented; not tracking them individually is acceptable and not a major concern. Option B is wrong because using a spreadsheet instead of a dedicated system is a tooling inefficiency, not a control weakness that directly compromises change integrity. Option D is wrong because a monthly CAB meeting may slow down changes but does not bypass approval controls; it is a scheduling issue, not a critical control failure.

44
Multi-Selectmedium

Which TWO of the following are key elements of a change request document?

Select 2 answers
A.Vendor contract
B.Justification
C.Project budget
D.Rollback plan
E.User manual
AnswersB, D

Justification records the business or technical reason the change is needed, letting the Change Advisory Board weigh benefit against risk and cost. Without it, approvers cannot judge whether the change is warranted, so the document fails its decision-support purpose.

Why this answer

Option B (Justification) is correct because a change request must state the business or technical reason the change is needed, so the change advisory board (CAB) can assess its value and priority before approval. Option D (Rollback plan) is correct because every change request must document how to revert the change if it fails or causes an outage, which is essential for risk mitigation and restoring the configuration item to its prior baseline. A vendor contract (A) is a procurement/legal artifact, not a standard component of a change request.

A project budget (C) relates to financial planning and cost control, not to the change management process itself. A user manual (E) is end-user documentation and has no role in defining or approving a change.

Exam trap

CISA often tests whether candidates confuse supporting documents (contracts, budgets, manuals) with the intrinsic elements of a change request—candidates pick budget because cost impact feels relevant, but the budget itself is not an RFC component.

45
MCQmedium

During a post-implementation review of a new financial system, the IS auditor finds that user acceptance testing (UAT) was completed with only 60% of test cases passed. Which of the following is the MOST significant risk?

A.The system deployment was delayed
B.The system performance is below expectations
C.The project was not completed within the planned budget
D.The system may not fully meet business requirements, leading to user workarounds
AnswerD

Passing only 60% of UAT cases means 40% of tested business scenarios failed, so the system may not satisfy requirements and users will adopt manual workarounds that undermine controls and reporting integrity. This is the most significant risk.

Why this answer

Low UAT pass rate indicates unresolved defects or unmet user requirements, leading to user dissatisfaction and potential workarounds that compromise controls.

46
MCQeasy

During which phase of the SDLC should security requirements be formally documented and approved by the business owner?

A.Design phase
B.Requirements phase
C.Testing phase
D.Development phase
AnswerB

Security requirements must be captured alongside functional requirements so they are baselined and approved before design begins. Documenting them in the requirements phase lets the business owner formally accept them, preventing costly retrofitting of controls during coding or testing.

Why this answer

Security requirements must be identified and approved early to ensure proper controls are built into the system. The requirements phase is the appropriate stage for this.

47
MCQmedium

An organization is acquiring a new financial system. The contract includes a clause that allows the organization to audit the vendor's controls. Which type of report would most efficiently provide assurance over the vendor's internal controls?

A.Financial audit report
B.SOC 2 report
C.Penetration test report
D.ISO 27001 certificate
AnswerB

A SOC 2 report covers the vendor's controls against trust services criteria, giving the organisation independent assurance over security and processing integrity. It is obtained once and shared with many customers, avoiding the cost of exercising the contractual audit right.

Why this answer

A SOC 2 report is specifically designed to provide assurance over a service organization's controls related to security, availability, processing integrity, confidentiality, and privacy, which directly addresses the need to audit the vendor's internal controls for a financial system. It is more efficient than other options because it is a standardized, independent assessment that covers the control environment relevant to financial data processing.

Exam trap

The trap here is that candidates may confuse a SOC 2 report with a financial audit report (Option A) because both involve auditors, but SOC 2 is specifically for service organization controls, not financial statement accuracy.

How to eliminate wrong answers

Option A is wrong because a financial audit report focuses on the accuracy of financial statements, not on the operational or security controls of the vendor's systems. Option C is wrong because a penetration test report only provides a point-in-time assessment of security vulnerabilities, not a comprehensive evaluation of ongoing internal controls. Option D is wrong because an ISO 27001 certificate confirms that a vendor has an information security management system (ISMS) in place, but it does not provide a detailed, auditable report of control effectiveness or specific control activities like a SOC 2 report does.

48
MCQmedium

An IS auditor is reviewing a systems acquisition project that involves purchasing an ERP system. Which of the following is the MOST significant risk related to data migration during implementation?

A.Inadequate security controls in the new system
B.Insufficient training of end users on the new system
C.Incomplete or inaccurate data conversion from legacy systems
D.Lack of integration testing between modules
AnswerC

Incomplete or inaccurate conversion transfers corrupt, missing or duplicated records into the ERP, directly undermining financial reporting, payroll accuracy and subsequent processing. This is the most significant migration risk because defects introduced silently during conversion are difficult to detect and costly to remediate once live.

Why this answer

Incomplete or inaccurate data conversion from legacy systems is the most significant data migration risk because it directly corrupts the new ERP's foundational data, leading to erroneous transactions, reporting failures, and compliance issues. Data integrity is the core objective of migration, and failures here cascade across all modules.

Exam trap

CISA often tests whether candidates prioritize data integrity over training or security in migration contexts—candidates may pick training because it feels user-centric, but the question asks about the most significant data migration risk.

How to eliminate wrong answers

Option A is wrong because inadequate security controls, while serious, are a system-wide risk addressed by security architecture and controls—not specific to data migration. Option B is wrong because insufficient training affects user adoption and productivity but does not corrupt the data itself. Option D is wrong because lack of integration testing affects module interoperability, which is a testing-phase risk, not a data migration risk per se.

49
MCQhard

In a spiral model SDLC, risk analysis is performed at the beginning of each iteration. What is the PRIMARY benefit of this approach?

A.It reduces the number of deliverables
B.It eliminates the need for user acceptance testing
C.It ensures all requirements are gathered upfront
D.It allows for early detection and mitigation of project risks
AnswerD

Analysing risk at the start of every spiral iteration surfaces threats and uncertainties before significant design and coding effort is committed, so mitigation can be planned into the next loop. This early detection reduces the cost of rework compared with deferring risk assessment to later lifecycle phases.

Why this answer

In the spiral model, risk analysis at the start of each iteration allows the team to identify, assess, and mitigate risks early before they escalate. This iterative risk-driven approach is the defining characteristic of the spiral model and its primary benefit over waterfall or pure prototyping.

Exam trap

CISA often tests whether candidates confuse the spiral model's iterative risk focus with waterfall's upfront requirements gathering—candidates may pick 'ensures all requirements are gathered upfront' because it sounds thorough, but that contradicts the spiral model's iterative nature.

How to eliminate wrong answers

Option A is wrong because the spiral model does not reduce deliverables—it typically produces incremental releases per spiral, potentially increasing deliverable count. Option B is wrong because user acceptance testing is still required in the spiral model; risk analysis does not replace validation. Option C is wrong because gathering all requirements upfront is a waterfall characteristic—the spiral model explicitly embraces evolving requirements through iterations.

50
MCQhard

An IS auditor is assessing the security controls in a newly developed mobile banking application. The development team used the OWASP Mobile Application Security Verification Standard (MASVS) as a guide. Which of the following would be the MOST effective evidence that the application meets the standard's requirements for secure data storage?

A.A penetration test report showing no critical vulnerabilities in the application's data storage mechanisms.
B.A static application security testing (SAST) report that identifies all hardcoded secrets and insecure storage APIs.
C.A combination of static and dynamic analysis reports, plus a manual review of data storage locations, mapped to MASVS controls.
D.A code review checklist signed off by the lead developer confirming that sensitive data is encrypted.
AnswerC

MASVS verification requires a mix of automated and manual testing to cover all storage locations and data types. Static and dynamic analyses identify code-level and runtime issues, while manual review ensures that all sensitive data is stored securely. This comprehensive approach provides strong evidence of compliance with the standard's requirements.

Why this answer

The most effective evidence is a combination of static and dynamic analysis with manual review, as it covers code and runtime aspects and ensures all storage locations are examined. This aligns with MASVS's requirement for thorough verification. Other options are partial or self-attested and do not provide the depth needed to confirm secure data storage fully.

Exam trap

The trap here is assuming that a single penetration test or a developer's checklist is sufficient to prove compliance with a comprehensive standard like MASVS.

51
MCQmedium

An IS auditor is reviewing an agile project that uses Scrum. Which event provides the best opportunity for the auditor to assess whether completed user stories meet the defined acceptance criteria?

A.Sprint review
B.Daily standup
C.Retrospective
D.Sprint planning
AnswerA

The sprint review is where the team demonstrates completed user stories against their acceptance criteria with stakeholders present. This gives the auditor direct evidence of whether each story actually satisfies the defined criteria before it is accepted.

Why this answer

The sprint review is the Scrum event where the team demonstrates completed work to stakeholders and gathers feedback, making it the best opportunity for an IS auditor to assess whether completed user stories meet the defined acceptance criteria. During the sprint review, the product owner and stakeholders review the increment and verify that it meets the acceptance criteria, providing a clear checkpoint for audit evidence. This event directly addresses the completion and acceptance of user stories.

Exam trap

CISA often tests the confusion between Scrum events, leading candidates to select the retrospective or daily standup instead of the sprint review for assessing completed work.

How to eliminate wrong answers

Option B is wrong because the daily standup is a brief coordination meeting for the development team to synchronize activities, not to review acceptance criteria. Option C is wrong because the retrospective focuses on process improvement, not on verifying completed work against criteria. Option D is wrong because sprint planning is for selecting backlog items for the upcoming sprint, not for assessing completed stories.

52
MCQmedium

An organization is implementing a new system using a rapid application development (RAD) approach. The IS auditor is concerned about the lack of formal documentation. Which of the following is the MOST appropriate audit response?

A.Report a finding that the lack of documentation is a material weakness.
B.Recommend that the organization switch to a waterfall methodology to ensure documentation.
C.Assess whether critical design and control documentation is being maintained to support future changes and audits.
D.Suspend the project until full documentation is produced.
AnswerC

In RAD, documentation may be lighter, but critical design decisions and control specifications should still be documented to enable maintenance, audits, and compliance. The auditor should verify that essential documentation exists, even if it is not as extensive as in waterfall. This ensures the system remains auditable and maintainable without stifling the RAD approach.

Why this answer

In a RAD environment, documentation may be less formal, but critical design and control documentation must still be maintained to support future changes, audits, and compliance. The auditor should assess whether such documentation exists and is adequate, rather than recommending a methodology change or taking extreme actions. This balances the need for agility with the need for auditability.

Exam trap

The trap here is assuming that RAD inherently lacks documentation and therefore must be replaced or penalized, rather than evaluating whether essential documentation is present.

53
Multi-Selecthard

An organization is implementing a large ERP system. The project manager is concerned about segregation of duties conflicts. Which THREE controls should the IS auditor recommend to mitigate segregation of duties risks during implementation? (Select THREE)

Select 3 answers
A.Use automated segregation of duties monitoring tools
B.Delay deployment until all segregation conflicts are resolved
C.Implement role-based access controls (RBAC) aligned with job functions
D.Conduct a single user acceptance test (UAT) at the end of the project
E.Require dual approval for sensitive transactions
AnswersA, C, E

Continuous automated monitoring detects toxic access combinations across the ERP as roles and users change, flagging conflicts that manual reviews miss. It provides detective coverage throughout implementation, when role design is still fluid and SoD conflicts are introduced.

Why this answer

Option A is correct because automated segregation of duties (SoD) monitoring tools continuously analyze user role assignments and transaction authorizations against a ruleset of conflicting access combinations, enabling early detection and remediation of toxic combinations during ERP implementation. Option C is correct because role-based access controls (RBAC) map permissions to defined job functions rather than to individuals, which prevents the accumulation of conflicting duties and provides a maintainable, auditable authorization structure in the ERP. Option E is correct because requiring dual approval (two-person integrity) for sensitive transactions such as vendor master changes or payment runs compensates for residual SoD conflicts by ensuring no single user can complete a high-risk action alone.

Option B is not appropriate because halting deployment until every conflict is resolved is impractical and ignores the use of compensating controls and risk acceptance. Option D is not appropriate because a single end-of-project UAT would not provide the continuous, iterative control testing needed to detect SoD conflicts throughout implementation.

Exam trap

The trap is the absolutist option — candidates are drawn to 'delay deployment until all conflicts are resolved' because it sounds rigorous, but CISA expects recognition that compensating controls, not elimination, are the practical mitigation for inherent SoD conflicts.

54
MCQmedium

An IS auditor is reviewing an agile software development project. Which of the following would be the BEST evidence that adequate controls are in place for user acceptance?

A.The product backlog is managed by the product owner
B.Daily standup meetings are held to track progress
C.Retrospectives are conducted after each sprint
D.Each sprint concludes with a sprint review attended by stakeholders
AnswerD

Sprint reviews provide evidence that stakeholders inspect the increment each sprint, satisfying the need for continuous user acceptance in agile delivery. Unlike a single end-of-project sign-off, this recurring stakeholder validation demonstrates acceptance controls operate throughout development, directly addressing the stem's requirement for adequate user acceptance evidence.

Why this answer

In agile development, the sprint review is the ceremony where the team demonstrates the completed increment to stakeholders, who provide feedback and formally accept or reject the work. This stakeholder participation at the end of each sprint is the strongest evidence that user acceptance controls are functioning, because acceptance is continuous rather than deferred to a single end-of-project event. It directly addresses the risk that delivered functionality diverges from business needs.

Exam trap

CISA often tests the confusion between the sprint review (product acceptance with stakeholders) and the sprint retrospective (internal process improvement), causing candidates to select the retrospective as evidence of user acceptance.

How to eliminate wrong answers

Option A is wrong because the product owner managing the backlog is a prioritization and requirements-grooming control, not a user acceptance control — it ensures the right work is queued, not that delivered work is accepted. Option B is wrong because daily standups are an internal team coordination mechanism for tracking progress and removing impediments; they involve the development team, not business stakeholders, and produce no acceptance decision. Option C is wrong because retrospectives focus on process improvement — inspecting how the team worked and identifying changes for the next sprint — not on validating or accepting the product increment with users.

55
MCQhard

During a spiral SDLC project, the IS auditor should focus on which aspect as the primary risk?

A.Scope creep
B.Lack of documentation
C.Inadequate user involvement
D.Incomplete risk assessment
AnswerD

Spiral development iterates through repeated risk analysis cycles, so an incomplete or superficial risk assessment undermines the model's core control. The auditor's primary focus is therefore whether each spiral iteration properly identifies, evaluates and mitigates risk before proceeding.

Why this answer

The spiral model is explicitly risk-driven — each spiral iteration begins with identifying and evaluating risks before determining whether to proceed, and the model was designed by Barry Boehm precisely to manage risk in large, complex projects. Therefore, the IS auditor's primary focus should be on whether risk assessment is performed completely and rigorously at each cycle, since an incomplete risk assessment undermines the model's core control mechanism.

Exam trap

The trap is selecting a generic SDLC risk such as scope creep or user involvement instead of recognizing that the spiral model's defining characteristic — and therefore its primary audit focus — is its risk-driven nature.

How to eliminate wrong answers

Option A is wrong because scope creep, while a common project risk, is not unique to the spiral model and is not its defining risk characteristic — the spiral model's iterative nature actually provides more opportunities to reassess and control scope than waterfall. Option B is wrong because lack of documentation is a general criticism of agile and rapid-development approaches, not the primary risk of the spiral model, which produces substantial documentation at each phase. Option C is wrong because inadequate user involvement is a generic SDLC risk applicable to all methodologies; it does not reflect the spiral model's distinctive risk-driven design, which mandates stakeholder evaluation at each spiral.

56
MCQeasy

Which of the following is a key advantage of using an iterative SDLC model over a waterfall model?

A.Reduces the need for user involvement
B.Better suited for projects with stable requirements
C.Easier to manage project costs
D.Provides more flexibility to adapt to changing requirements
AnswerD

Iterative models deliver working increments in short cycles, allowing requirements to be revisited between iterations. Waterfall freezes requirements after the analysis phase, so late changes are costly; iteration directly satisfies the need to accommodate evolving requirements.

Why this answer

Iterative SDLC models develop software in repeated cycles, delivering working increments and incorporating feedback between iterations, which allows requirements to evolve as understanding deepens. This built-in adaptability is the key advantage over waterfall, where requirements are frozen after the requirements phase and changes become expensive and disruptive. The iterative approach directly addresses the reality that requirements often change during long projects.

Exam trap

The trap is the option that sounds plausible but reverses the model's characteristic — candidates may pick 'reduces the need for user involvement' when iterative models actually demand more frequent user engagement than waterfall.

How to eliminate wrong answers

Option A is wrong because iterative models actually increase user involvement — each iteration typically requires user feedback and validation — rather than reducing it; claiming they reduce user involvement inverts the model's core strength. Option B is wrong because waterfall, not iterative, is better suited to stable requirements; iterative models shine precisely when requirements are uncertain or volatile, so this option describes a waterfall advantage. Option C is wrong because iterative projects can be harder to manage cost-wise, not easier — the scope may shift between iterations, making fixed-price contracting and budget forecasting more challenging than in waterfall's linear structure.

57
MCQmedium

An IS auditor is reviewing the acquisition of a new software package. The vendor provides a Service Organization Control (SOC) 2 Type II report. Which of the following is the MOST important factor for the auditor to consider when relying on this report?

A.The report is issued by a reputable audit firm.
B.The report's scope covers the specific services and systems that the organization will use.
C.The report covers the period that includes the current fiscal year.
D.The report includes a description of the vendor's system and the suitability of the design of controls.
AnswerB

The most critical factor is whether the SOC 2 report's scope aligns with the services the organization will consume. If the report excludes relevant systems or processes, it cannot be relied upon to provide assurance over those areas. The auditor must verify that the controls tested are relevant to the organization's use of the vendor's services.

Why this answer

When relying on a SOC 2 Type II report, the auditor must ensure that the report's scope covers the specific services and systems the organization uses. A report that excludes relevant components provides no assurance for those areas. Other factors like period, description, and auditor reputation are secondary to scope alignment.

Exam trap

The trap here is focusing on the auditor's reputation or the report period while overlooking that the report must cover the exact services the organization consumes.

58
MCQhard

An IS auditor is reviewing the implementation of a new payroll system that was developed in-house. The project team followed a traditional waterfall SDLC. During the post-implementation review, the auditor found that the system was delivered on time and within budget, but several critical payroll calculations were incorrect, leading to employee underpayments. The root cause was traced to a misunderstanding of tax law changes that occurred during the requirements phase. Which of the following is the MOST likely control weakness that contributed to this issue?

A.Inadequate segregation of duties between developers and testers, allowing developers to test their own code.
B.Insufficient involvement of tax experts and business stakeholders in requirements definition and validation.
C.Inadequate user acceptance testing (UAT) that did not include valid tax scenarios.
D.Lack of a formal change management process to handle tax law updates during development.
AnswerB

The root cause was a misunderstanding of tax law changes, which indicates that the requirements were not accurately captured or validated. Involving tax experts and business stakeholders would have ensured that the requirements reflected current tax laws. This is a critical control in the requirements phase. Without their input, the system was built on incorrect assumptions, leading to payroll errors. Thus, this is the most likely control weakness.

Why this answer

The payroll errors stemmed from a misunderstanding of tax law changes during requirements. The most likely control weakness is insufficient involvement of tax experts and business stakeholders in defining and validating requirements. Their participation ensures that requirements are accurate and complete.

While UAT, change management, and segregation of duties are important, they do not directly prevent requirements misunderstandings. Thus, the correct answer is the lack of expert involvement in requirements.

Exam trap

The trap here is focusing on testing or change management as the primary control, when the root cause is flawed requirements due to missing stakeholder input.

59
MCQmedium

During a system development project, the IS auditor notes that code reviews are performed only after the code is unit tested. Which of the following is the MOST significant risk associated with this practice?

A.Code reviews may be less effective because developers are reluctant to critique tested code
B.Defects may be discovered later in the development lifecycle, increasing rework costs
C.Unit tests may mask code quality issues
D.The code review process may overlook security vulnerabilities
AnswerB

Reviewing code only after unit testing delays defect detection until later lifecycle stages, when remediation requires reworking tested components and dependent code. Defects found earlier during review are cheaper to fix, so this sequencing inflates rework cost and schedule risk.

Why this answer

Performing code reviews only after unit testing delays defect detection to a later stage in the development lifecycle, when rework costs are significantly higher. Code reviews are most effective when conducted early, before testing, because they catch design flaws, logic errors, and security issues at the source. The later a defect is found, the more expensive and time-consuming it is to fix, especially if it has propagated to other modules.

Exam trap

CISA often tests the principle that early detection reduces cost — candidates who focus on cultural or security-specific concerns miss the broader lifecycle cost risk that is the primary audit concern.

How to eliminate wrong answers

Option A is wrong because while developer reluctance may be a cultural concern, it is not the most significant risk — the primary risk is the increased cost and effort of late defect detection. Option C is wrong because unit tests are designed to validate specific functionality and do not inherently mask code quality issues; the risk is that code reviews after testing miss the opportunity for early defect prevention. Option D is wrong because while security vulnerabilities could be overlooked, this is a subset of the broader risk of late defect discovery, and the question asks for the MOST significant risk, which is lifecycle cost escalation.

60
MCQhard

An organization is considering acquiring a commercial off-the-shelf (COTS) ERP system. Which of the following risks is most effectively mitigated by including a contractual clause for audit rights?

A.Incompatibility with existing infrastructure
B.Inadequate vendor security controls
C.Vendor lock-in due to proprietary data formats
D.Cost overruns from customization
AnswerB

Audit rights clauses let the organisation inspect the vendor's control environment, obtain evidence and enforce remediation, directly addressing the risk that the vendor's security controls are inadequate. Without this contractual leverage, assurance over a COTS ERP's hosted processing depends solely on the vendor's own reporting.

Why this answer

A contractual clause for audit rights allows the organization to assess the vendor's security controls, ensuring they meet the organization's requirements and mitigating the risk of inadequate vendor security. This is critical because the organization relies on the vendor to protect its data, and without audit rights, it cannot verify the effectiveness of the vendor's controls. The other risks are not directly addressed by audit rights: incompatibility is a technical integration issue, vendor lock-in relates to data portability, and cost overruns stem from project management.

Exam trap

CISA often tests the misconception that audit rights mitigate all vendor-related risks, but they specifically address security and compliance verification, not technical compatibility, data portability, or cost control.

How to eliminate wrong answers

Option A is wrong because incompatibility with existing infrastructure is a technical risk mitigated through thorough requirements analysis and compatibility testing, not audit rights. Option C is wrong because vendor lock-in due to proprietary data formats is mitigated by contractual clauses requiring data export in standard formats and exit provisions, not audit rights. Option D is wrong because cost overruns from customization are mitigated by fixed-price contracts, change control procedures, and detailed scoping, not audit rights.

61
MCQmedium

During a post-implementation review of a new customer relationship management (CRM) system, the IS auditor finds that the system is processing transactions slower than anticipated. What is the BEST initial course of action for the auditor?

A.Recommend immediate performance tuning to resolve the issue
B.Report the issue to senior management immediately
C.Conduct a load test to identify bottlenecks
D.Compare actual performance to the performance criteria in the business case
AnswerD

Performance criteria were defined in the business case, so the auditor must first compare measured transaction throughput against those agreed benchmarks. This establishes whether the shortfall is a genuine deviation before investigating root cause or recommending remediation.

Why this answer

The auditor's best initial action is to compare actual system performance against the performance criteria defined in the business case. This establishes whether the slowdown represents a genuine deviation from expected outcomes and provides an objective basis for further investigation. Without this comparison, any recommendation or escalation would lack context and could be premature.

Exam trap

CISA often tests the audit principle of evidence before action — candidates who jump to technical remediation or escalation without first validating against business criteria fall for the 'solution-first' trap.

How to eliminate wrong answers

Option A is wrong because recommending performance tuning before confirming the performance gap against business case criteria is premature and may address a non-issue or the wrong root cause. Option B is wrong because reporting to senior management immediately without first validating the deviation against expected performance criteria bypasses the auditor's due diligence and may cause unnecessary alarm. Option C is wrong because conducting a load test is a technical diagnostic step that should follow, not precede, the determination that a performance gap actually exists relative to business requirements.

62
MCQeasy

An organization is acquiring a new software package. The IS auditor is asked to review the contract with the vendor. Which of the following clauses is MOST important to ensure the organization can continue to use the software even if the vendor goes out of business?

A.Software escrow agreement.
B.Acceptance testing criteria.
C.Service level agreement (SLA) with performance metrics.
D.Indemnification clause.
AnswerA

A software escrow agreement ensures that source code and related materials are held by a third party and released to the customer if the vendor fails to meet obligations, such as going bankrupt. This allows the organization to maintain and modify the software independently, ensuring business continuity. It directly addresses the risk of vendor failure, making it the most important clause in this scenario.

Why this answer

A software escrow agreement is designed to protect the customer by providing access to source code and documentation if the vendor cannot fulfill its obligations, such as bankruptcy or acquisition. This enables the organization to maintain, modify, and continue using the software, ensuring business continuity. It is the key contractual safeguard against vendor failure.

Exam trap

The trap here is confusing legal protections like indemnification with continuity mechanisms, when escrow specifically addresses vendor failure.

63
Multi-Selecteasy

Which TWO of the following are characteristics of the iterative SDLC model?

Select 2 answers
A.The final product is delivered only at the end of the project
B.User feedback is incorporated after each iteration
C.Requirements are defined in detail at the start of the project
D.The system is developed and refined through multiple cycles
E.Risk analysis is performed only at the beginning
AnswersB, D

Each iteration ends with a working increment that users evaluate, and their feedback shapes the next cycle's requirements and design. This continuous user involvement is a defining trait of iterative development, satisfying the stem's requirement for a characteristic of that model.

Why this answer

Option B is correct because the iterative SDLC model builds the product in repeated cycles, and after each iteration the working increment is reviewed with users so their feedback can be incorporated into the next iteration. Option D is correct because the defining trait of the iterative model is that the system is developed and refined through multiple cycles, with each cycle producing a progressively more complete version of the product. Options A, C, and E describe characteristics of plan-driven or waterfall-style approaches rather than iterative development: delivering the final product only at the end (A) and freezing detailed requirements at the start (C) reflect a single-pass sequential model, and performing risk analysis only at the beginning (E) contradicts the iterative practice of reassessing risks in each cycle.

Exam trap

CISA often tests whether candidates can distinguish iterative SDLC characteristics (feedback per iteration, multiple cycles) from waterfall characteristics (upfront requirements, single delivery, initial risk analysis).

64
Multi-Selecthard

An IS auditor is reviewing the requirements definition phase of a new system development project. The auditor finds that business users have provided functional requirements, but non-functional requirements are largely missing. Which TWO of the following are the MOST significant risks of proceeding without well-defined non-functional requirements? (Choose two.)

Select 2 answers
A.The development team may not understand the business processes.
B.The project may exceed its budget due to scope creep.
C.The system may lack necessary security controls.
D.The system may be difficult to maintain due to lack of documentation.
E.The system may not meet performance and scalability expectations.
AnswersC, E

Security requirements, including authentication, authorization, encryption, and auditing, are often classified as non-functional. If they are not specified, developers may not implement them, leaving the system vulnerable to breaches. This is a critical risk because security is essential for protecting data and complying with regulations. Thus, this is a major consequence of missing non-functional requirements.

Why this answer

Non-functional requirements cover critical aspects such as performance, scalability, security, and availability. Omitting them increases the risk that the system will fail to meet operational expectations and security needs. These failures can lead to system outages, data breaches, and user rejection, making them the most significant risks.

Exam trap

The trap here is focusing on functional gaps or project management issues, while overlooking that non-functional requirements encompass security and performance.

65
Multi-Selecthard

During a post-implementation review of a new ERP system, the IS auditor identified that the project was delivered within budget but user satisfaction scores are low. Which THREE areas should the auditor examine further?

Select 3 answers
A.Extent of integration testing performed
B.Whether all predefined user requirements were met
C.Accuracy and completeness of data migration
D.Compliance with the original project budget
E.Adequacy of user training provided
AnswersB, C, E

Low satisfaction despite budget compliance suggests functional shortfalls, so the auditor should test whether the system delivered the predefined user requirements. Unmet requirements directly explain user dissatisfaction and indicate the project missed its stated objectives.

Why this answer

Option B is correct because low user satisfaction often stems from unmet functional requirements, so the auditor should verify whether the delivered ERP actually satisfies the predefined user requirements captured during the requirements-gathering phase. Option C is correct because inaccurate or incomplete data migration directly degrades usability and trust in the new ERP, making data accuracy and completeness a key area to examine. Option E is correct because inadequate user training is a leading cause of poor satisfaction and low adoption, so the adequacy of the training provided must be reviewed.

Option A is not marked correct because integration testing is more relevant to technical defects and interface failures than to the stated symptom of low user satisfaction. Option D is not marked correct because budget compliance was already confirmed (delivered within budget) and does not explain low user satisfaction.

Exam trap

CISA often tests the distinction between project management success (on time, on budget) and product success (meets user needs) — candidates who equate budget compliance with project success pick the wrong options.

66
MCQeasy

During an agile software development project, which of the following events provides the best opportunity for the IS auditor to assess the effectiveness of controls implemented in the current sprint?

A.Sprint planning meeting
B.Sprint review
C.Daily standup meeting
D.Sprint retrospective
AnswerB

The sprint review demonstrates the completed increment to stakeholders, exposing working functionality and the controls embedded in it. This gives the auditor direct evidence of control effectiveness for the current sprint, unlike planning or retrospective sessions.

Why this answer

The sprint review is where the team demonstrates the completed increment to stakeholders, making it the best venue for the auditor to observe working software and evaluate whether controls built into the sprint were actually implemented and effective. It provides tangible evidence of the increment, unlike planning or standup meetings which discuss future or in-progress work.

Exam trap

CISA often tests the confusion between the sprint review (product demonstration) and the sprint retrospective (process improvement) — candidates who conflate the two pick the retrospective as the control-assessment venue.

How to eliminate wrong answers

Option A is wrong because sprint planning focuses on selecting and estimating work for the upcoming sprint, not on demonstrating completed controls. Option C is wrong because the daily standup is a brief coordination ceremony covering progress and blockers, with no demonstration or verification of control effectiveness. Option D is wrong because the sprint retrospective examines process improvement and team dynamics, not the functional effectiveness of implemented controls.

67
MCQmedium

During a vendor evaluation for a critical system, the IS auditor notes that the vendor's SOC 2 report includes an adverse opinion. What should be the auditor's PRIMARY recommendation?

A.Negotiate a lower price to offset the risk
B.Evaluate compensating controls or seek an alternative vendor
C.Accept the risk because the vendor is well-known
D.Request a customized SOC 2 report
AnswerB

An adverse SOC 2 opinion means the vendor's controls failed to meet trust services criteria, so the auditor should recommend evaluating compensating controls or selecting an alternative vendor. This directly addresses the assurance gap the adverse opinion creates for a critical system.

Why this answer

An adverse SOC 2 opinion means the service auditor found that controls were not suitably designed or operating effectively, so the vendor cannot be relied upon to protect the organization's data. The auditor's primary recommendation must therefore be to evaluate compensating controls the organization can apply or to seek an alternative vendor, since accepting the vendor as-is would transfer unacceptable risk.

Exam trap

CISA often tests the misconception that a well-known vendor's reputation or a price concession can offset an adverse SOC 2 opinion — candidates who pick A or C fail to recognize that control failures are not mitigated by commercial or reputational factors.

How to eliminate wrong answers

Option A is wrong because a price reduction does not mitigate the underlying control failure — risk transfer through discounting is not a valid audit recommendation. Option C is wrong because vendor reputation is irrelevant when an independent service auditor has issued an adverse opinion; accepting the risk on brand recognition alone violates due professional care. Option D is wrong because a SOC 2 report is issued by the service auditor based on the vendor's system description — the client cannot 'request a customized' report to change the opinion, only request a different report type or period.

68
MCQeasy

An organization is implementing a new human resources system. The IS auditor wants to determine whether the system will enforce segregation of duties (SoD) for sensitive transactions such as payroll changes and employee master data updates. Which of the following is the MOST appropriate source of evidence?

A.Interviews with HR managers to confirm that they monitor user activity and would detect any conflicting transactions.
B.Review of the role design and access control configuration within the application, including conflicting role analysis.
C.Review of the user access request forms to confirm that each user's manager approved the requested access.
D.Inspection of the organization's written security policy that prohibits employees from performing conflicting duties.
AnswerB

Segregation of duties is enforced through the application's role design and access control configuration. Reviewing role definitions, permission assignments, and conflicting role analysis provides direct evidence that incompatible duties cannot be performed by one user. This is the most appropriate source because it shows how the system actually restricts access, rather than relying on policy statements or user interviews that may not reflect the implemented controls.

Why this answer

Segregation of duties in an application is enforced through role design and access control settings. The auditor obtains the strongest evidence by examining how roles are defined, which permissions are assigned, and whether conflicting combinations are identified and blocked. Policy documents, interviews, and access request forms are all indirect and do not prove that the system itself prevents a single user from performing incompatible payroll and master data functions.

Exam trap

The trap here is accepting a policy or approval form as evidence of SoD enforcement, when only the application's role and access configuration shows whether conflicts are actually prevented.

69
MCQmedium

An organization is considering whether to build a custom application or purchase a commercial off-the-shelf (COTS) product. Which of the following factors is MOST important when deciding to build rather than buy?

A.Reduced need for ongoing maintenance
B.Faster time to market
C.Lower initial cost
D.Need for highly specialized functionality not available in the market
AnswerD

Build decisions are justified when required functionality is unavailable commercially, since a COTS product cannot be modified to deliver it. This specialised-functionality gap is the decisive factor; cost, integration and support considerations matter but do not by themselves mandate building.

Why this answer

When an organization requires highly specialized functionality that is not available in any commercial off-the-shelf (COTS) product, building a custom application becomes the only viable option. COTS products are designed for broad market needs and often lack the unique features or compliance requirements that a custom solution can provide. This factor overrides cost, time, and maintenance considerations because no amount of configuration or customization of a COTS product can meet the specific functional gap.

Exam trap

The trap here is that candidates often prioritize lower initial cost or faster time to market, failing to recognize that if the required functionality does not exist in the market, those benefits are irrelevant because the COTS product cannot fulfill the core business need.

How to eliminate wrong answers

Option A is wrong because custom applications typically require more ongoing maintenance, not less, due to the need for in-house support, updates, and bug fixes, whereas COTS products include vendor-provided maintenance and patches. Option B is wrong because building a custom application generally takes longer to develop and deploy than purchasing a ready-made COTS product, which can be implemented immediately. Option C is wrong because custom development usually has a higher initial cost due to design, coding, testing, and deployment efforts, while COTS products have a fixed license fee that is often lower than bespoke development.

70
Multi-Selectmedium

An organization is implementing a new payroll system using an agile methodology. Which TWO of the following are the MOST important controls for the IS auditor to assess?

Select 2 answers
A.Comprehensive documentation of all design decisions
B.A formal change control board to approve all changes
C.A detailed project plan with all tasks upfront
D.The product backlog is prioritized and includes security requirements
E.Sprint reviews are conducted with stakeholders to demonstrate working software
AnswersD, E

A prioritised product backlog containing security requirements ensures controls are scheduled and delivered within sprints rather than deferred indefinitely. This satisfies the agile payroll scenario by embedding security into iterative planning, giving the auditor evidence that compliance and data protection needs are tracked alongside functional features.

Why this answer

Option D is correct because in agile development the product backlog is the authoritative, prioritized list of work items, and the IS auditor must verify that security requirements (e.g., access controls, encryption, audit logging for payroll data) are explicitly captured and prioritized there rather than deferred, since payroll systems handle sensitive PII and financial data. Option E is correct because sprint reviews are the key agile ceremony where stakeholders inspect the working increment and provide feedback, giving the auditor evidence of governance, stakeholder accountability, and that delivered functionality meets requirements. Option A is not the most important control in agile, where working software and lightweight documentation are favored over comprehensive design documentation.

Option B is not the most important control because a formal change control board is characteristic of waterfall governance, whereas agile relies on backlog refinement and sprint-level change management. Option C is not the most important control because agile deliberately avoids a detailed upfront project plan with all tasks defined in advance, favoring iterative planning.

Exam trap

CISA often tests whether candidates recognize that agile replaces heavyweight documentation and CCB gates with backlog prioritization and sprint reviews — those who default to waterfall controls pick A, B, or C.

71
MCQeasy

Which of the following is a primary advantage of fixed-price contracts in systems acquisition?

A.Vendor has incentive to complete quickly
B.Greater flexibility to change requirements
C.Lower total cost compared to time-and-materials
D.Predictable cost for the buyer
AnswerD

A fixed-price contract sets the total cost before work begins, so the buyer bears no risk of cost overruns, giving predictable budgeting. The seller absorbs overrun risk instead, which is why vendors often price such contracts higher.

Why this answer

The defining characteristic of a fixed-price contract is that the buyer pays a set amount regardless of the vendor's actual costs, giving the buyer cost predictability and transferring cost-overrun risk to the vendor. This predictability is the primary advantage for the acquiring organization's budgeting and financial planning.

Exam trap

CISA often tests the confusion between cost predictability (the buyer's primary benefit) and cost minimization — candidates who pick 'lower total cost' fail to recognize that fixed-price contracts may actually cost more due to vendor risk premiums.

How to eliminate wrong answers

Option A is wrong because while a fixed-price contract does incentivize the vendor to control costs, the incentive is to complete efficiently, not necessarily quickly — speed is not the primary advantage and can even conflict with quality. Option B is wrong because fixed-price contracts offer the least flexibility to change requirements; changes typically require contract modifications and additional cost. Option C is wrong because fixed-price contracts are not inherently lower total cost than time-and-materials — they may be higher if the vendor builds in risk contingency, and T&M can be cheaper when scope is uncertain.

72
MCQmedium

During a post-implementation review of a system, an IS auditor finds that the actual transaction processing time is 30% slower than projected. What should the auditor recommend FIRST?

A.Upgrade the server hardware immediately
B.Reject the system and revert to the legacy system
C.Conduct a performance analysis to identify bottlenecks
D.Adjust user expectations to match actual performance
AnswerC

Performance analysis isolates which component causes the 30% shortfall before any fix is chosen. Recommending tuning, hardware or redesign first would address symptoms without evidence; identifying bottlenecks satisfies the review's need for a root cause.

Why this answer

Conducting a performance analysis to identify bottlenecks is the correct first step because the auditor must determine the root cause of the 30% slowdown before recommending any remediation. Jumping to hardware upgrades or system rejection without diagnosis is premature and may waste resources or disrupt operations unnecessarily. ISACA audit principles emphasize evidence-based recommendations grounded in root cause analysis.

Exam trap

CISA often tests the auditor's instinct to recommend the most 'obvious' fix (hardware upgrade) versus the methodical audit approach (analyze first) — the trap is skipping diagnosis in favor of a quick fix.

How to eliminate wrong answers

Option A is wrong because upgrading hardware immediately assumes the bottleneck is hardware-related without any diagnostic evidence — the slowdown could be caused by inefficient code, database queries, or network latency. Option B is wrong because rejecting the system and reverting to legacy is an extreme, disruptive action that should only follow a documented failure to remediate, not a performance variance. Option D is wrong because adjusting user expectations is a management cop-out that ignores the auditor's responsibility to identify and recommend corrective action for performance gaps.

73
MCQeasy

An organization is implementing a new financial system using the waterfall SDLC model. Which of the following is the MOST critical control to ensure that business requirements are met?

A.Automated unit testing results
B.Code reviews by the development team
C.Detailed technical design documents
D.Formal user acceptance testing (UAT) sign-off
AnswerD

Formal UAT sign-off requires business users to validate the system against documented requirements before go-live, providing the definitive control that confirms business requirements are met. This satisfies the waterfall model's need for verification at the testing phase before implementation proceeds.

Why this answer

In a waterfall SDLC, formal user acceptance testing (UAT) sign-off is the definitive control that confirms the delivered system satisfies the documented business requirements before go-live. UAT is performed by business users against requirements-based test scenarios, so their formal sign-off provides auditable evidence that the system meets business needs. This is the last gate where business stakeholders validate fitness for purpose.

Exam trap

CISA often tests the distinction between technical verification (unit tests, code reviews, design docs) and business validation (UAT), so candidates who equate 'testing' with 'requirements met' pick A or B instead of the business-facing UAT sign-off.

How to eliminate wrong answers

Option A is wrong because automated unit testing verifies individual code components against technical specifications, not business requirements, and is performed by developers rather than business users. Option B is wrong because code reviews by the development team address code quality, standards, and defect detection at the technical level — they do not validate that business requirements have been fulfilled. Option C is wrong because detailed technical design documents describe how the system will be built (architecture, interfaces, data structures) and are inputs to development, not evidence that business requirements were actually met.

74
MCQmedium

Which of the following BEST describes the role of threat modeling in the design phase of the SDLC?

A.To define functional requirements for the system
B.To analyze the system architecture for potential security threats
C.To test the application's resilience to attacks
D.To identify and mitigate security vulnerabilities in the code
AnswerB

Threat modeling examines the proposed architecture, data flows and trust boundaries to identify threats before code exists, so design flaws can be remediated cheaply. This directly satisfies the stem's design-phase constraint, where controls are cheapest to embed and rework costs are lowest.

Why this answer

Threat modeling is a structured design-phase activity that analyzes the system architecture, data flows, trust boundaries, and entry points to identify potential security threats before code is written. It uses frameworks such as STRIDE, PASTA, or attack trees to enumerate threats and drive security requirements and design controls. Because it happens during design, it is far cheaper to remediate issues than after deployment.

Exam trap

The trap here is confusing design-phase security activities (threat modeling) with later-phase activities (penetration testing, code review), so candidates who see 'security' and 'vulnerabilities' pick D even though it describes a development-time control.

How to eliminate wrong answers

Option A is wrong because defining functional requirements is a requirements-phase activity (what the system must do), whereas threat modeling addresses security concerns about how the system could be attacked. Option C is wrong because testing the application's resilience to attacks is penetration testing or dynamic security testing, which occurs during testing/operations, not design. Option D is wrong because identifying and mitigating vulnerabilities in code is static code analysis or secure code review, which happens during development — threat modeling operates at the architecture level before code exists.

75
MCQhard

An organization is deploying a major system upgrade. The change request has been approved by CAB, but the deployment plan does not include a rollback procedure. As an IS auditor, what should you recommend?

A.Perform the deployment during off-peak hours to minimize impact
B.Document the decision to skip rollback in the change record
C.Proceed with deployment as CAB approval is sufficient
D.Delay the deployment until a rollback plan is created and tested
AnswerD

Without a tested rollback procedure, a failed upgrade could leave the system unrecoverable, breaching availability and change-management controls. Delaying deployment until rollback is created and tested ensures the approved change can be safely reversed, satisfying the auditor's requirement that changes remain recoverable before implementation proceeds.

Why this answer

A rollback plan is a mandatory component of any production change because it provides the mechanism to restore the prior known-good state if the deployment fails or causes outages. Without a tested rollback procedure, the organization has no controlled recovery path, exposing it to extended downtime and data integrity risk. As an IS auditor, the correct recommendation is to delay deployment until a rollback plan is created and tested, regardless of CAB approval.

Exam trap

CISA often tests whether candidates treat CAB approval as sufficient authorization, but the trap is that approval does not equal operational readiness — the missing rollback plan is the real control gap the auditor must flag.

How to eliminate wrong answers

Option A is wrong because timing the deployment during off-peak hours reduces user impact but does nothing to address the absence of a recovery mechanism if the change fails. Option B is wrong because documenting the decision to skip rollback merely records a control gap — it does not mitigate the risk and would itself be an audit finding. Option C is wrong because CAB approval authorizes the change but does not substitute for the operational safeguards (including rollback) that change management standards require; approval and rollback planning are complementary, not interchangeable.

Page 1 of 2 · 114 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Information Systems Acquisition, Development, and Implementation questions.