Courseiva

CCNA Information Systems Acquisition, Development, and Implementation Questions

39 of 114 questions · Page 2/2 · Information Systems Acquisition, Development, and Implementation · Answers revealed

76
MCQeasy

In a waterfall SDLC, when should user acceptance testing (UAT) typically occur?

A.After deployment
B.After coding but before unit testing
C.After system testing and before deployment
D.During the requirements phase
AnswerC

In a waterfall SDLC, phases execute sequentially, so UAT follows completed system testing, confirming the built system meets business requirements before release. Placing it after system testing and before deployment satisfies the stem's waterfall sequencing constraint, ensuring defects are caught prior to production cutover.

Why this answer

In a waterfall SDLC, UAT is the final validation step performed by end users after the system has been fully built and verified by the development team. System testing confirms the solution meets technical specifications, and only then do users validate it against business requirements in a production-like environment. Deployment follows only after users formally accept the system, ensuring defects are caught before go-live.

Exam trap

CISA often tests the sequencing of SDLC test phases, and candidates confuse UAT with system testing or place it after deployment because they conflate 'acceptance' with 'post-implementation review'.

How to eliminate wrong answers

Option A is wrong because UAT after deployment defeats its purpose — defects would already be in production and remediation costs escalate dramatically. Option B is wrong because UAT cannot occur before unit testing; unit testing validates individual modules and must precede integration, system, and acceptance testing in the V-model sequence. Option D is wrong because the requirements phase produces the acceptance criteria used later in UAT, not the test execution itself — UAT requires a built system to validate against.

77
MCQeasy

Which of the following is a key objective of the design phase in the SDLC?

A.To conduct user acceptance testing
B.To define system architecture and integrate security controls
C.To develop code
D.To gather business requirements
AnswerB

The design phase translates requirements into a system architecture and specifies how security controls are embedded within it. Defining architecture and integrating controls here ensures security is built in rather than retrofitted during later build or testing phases.

Why this answer

The design phase translates approved business requirements into a technical blueprint, defining the system architecture (components, interfaces, data flows) and specifying how security controls will be integrated into that architecture. This ensures security is built in rather than bolted on later. It bridges the 'what' of requirements to the 'how' of construction.

Exam trap

The trap is confusing adjacent SDLC phases — candidates who see 'security controls' may associate it with testing or operations, but CISA expects recognition that architecture definition and security integration belong to the design phase.

How to eliminate wrong answers

Option A is wrong because user acceptance testing is a testing-phase activity performed after development to validate the system against business requirements. Option C is wrong because developing code is the construction/development phase, which follows design. Option D is wrong because gathering business requirements is the requirements/analysis phase that precedes design — it establishes what the system must do, not how it will be built.

78
MCQmedium

During an ERP implementation, the project team decides to customize the software to align with existing business processes. Which of the following risks is MOST likely to increase as a result of extensive customization?

A.Increased vendor lock-in
B.Simpler data migration
C.Reduced user acceptance
D.Higher costs for future upgrades
AnswerD

Customisations modify core ERP code, so vendor-supplied patches and new releases no longer apply cleanly. Each future upgrade then requires rework, retesting and regression effort to reapply and reconcile the customisations, directly increasing upgrade cost.

Why this answer

Extensive customization of an ERP system typically involves modifying the core code or configuration beyond standard parameters. This creates a custom code base that diverges from the vendor's standard release, making future upgrades significantly more complex and costly because each upgrade requires re-applying and testing all customizations against the new version, often requiring specialized skills and extensive regression testing.

Exam trap

The trap here is that candidates often confuse customization with configuration; customization modifies source code or adds custom objects, while configuration uses built-in parameters, and only customization significantly increases upgrade costs.

How to eliminate wrong answers

Option A is wrong because vendor lock-in is primarily driven by reliance on proprietary data formats, APIs, or licensing models, not by customization itself; in fact, customizations can sometimes reduce lock-in by making the system more tailored to the organization's unique needs. Option B is wrong because extensive customization often complicates data migration, as custom fields, tables, and logic must be mapped and transformed, increasing the risk of data loss or corruption. Option C is wrong because user acceptance typically increases when the system is customized to align with existing business processes, as it reduces the need for users to adapt to new workflows.

79
MCQeasy

An IS auditor is reviewing a software development project that follows the waterfall model. Which of the following is the MAIN advantage of this methodology?

A.Reduced risk of requirements misinterpretation
B.Clear milestones and documentation at each phase
C.Early delivery of working software increments
D.Ability to accommodate changing requirements easily
AnswerB

Waterfall's sequential phases each conclude with defined deliverables and sign-off, producing explicit milestones and documentation. This satisfies the auditor's need for verifiable phase-gate evidence and traceability, since requirements are frozen before design begins and each stage's completion is formally recorded.

Why this answer

The waterfall model is a sequential, plan-driven methodology where each phase (requirements, design, development, testing, deployment) is completed before the next begins. Its main advantage is that it produces clear, well-defined milestones and comprehensive documentation at each phase, which supports auditability, contractual clarity, and formal sign-off. This makes it attractive for projects with stable, well-understood requirements.

Exam trap

CISA often tests the confusion between waterfall's documentation/milestone strength and agile's flexibility/early-delivery strength, causing candidates to pick an agile benefit as a waterfall advantage.

How to eliminate wrong answers

Option A is wrong because waterfall does not reduce the risk of requirements misinterpretation — in fact, because requirements are frozen early and feedback comes late, misinterpretation risk is often higher. Option C is wrong because early delivery of working software increments is a characteristic of iterative/agile methodologies, not waterfall, which delivers a single working product at the end. Option D is wrong because waterfall is notoriously inflexible to changing requirements; accommodating change easily is a hallmark of agile, not waterfall.

80
MCQhard

During a spiral SDLC project, the project team has completed a risk analysis and created a prototype. What is the most likely next step in the spiral model?

A.Deploy the system to production
B.Obtain formal sign-off from the business owner on requirements
C.Develop the next level of the product based on the risk analysis
D.Conduct user acceptance testing (UAT)
AnswerC

The spiral model's defining sequence is risk analysis followed by engineering the next prototype or increment, so the team builds the next level of the product informed by the completed risk analysis. This iterative risk-driven cycle distinguishes spiral from waterfall's linear progression.

Why this answer

In the spiral model, each iteration begins with identifying objectives, evaluating alternatives, and resolving risks through risk analysis. After completing risk analysis and building a prototype, the next step is to develop the next level of the product, incorporating the risk analysis findings to refine requirements and design. This ensures that high-risk areas are addressed incrementally before proceeding to subsequent phases.

Exam trap

The trap here is that candidates confuse the spiral model's iterative prototyping with a linear waterfall approach, mistakenly thinking that a prototype leads directly to deployment or formal sign-off, rather than understanding that the spiral model uses risk-driven iteration to progressively refine the product.

How to eliminate wrong answers

Option A is wrong because deploying to production occurs only after multiple iterations and final validation, not immediately after a single risk analysis and prototype. Option B is wrong because formal sign-off on requirements is typically done earlier in the planning phase, not after risk analysis and prototyping; the spiral model emphasizes iterative refinement over rigid sign-offs. Option D is wrong because user acceptance testing (UAT) is performed later in the development cycle, after the product has been built and tested, not directly after risk analysis and prototyping.

81
MCQmedium

An IS auditor is reviewing the system design phase of a project. Which of the following activities is most important to ensure that security is adequately addressed?

A.Creating a data flow diagram
B.Developing a detailed project schedule
C.Conducting a threat modeling exercise
D.Reviewing the budget for security tools
AnswerC

Threat modelling examines data flows and trust boundaries during design, identifying security weaknesses while changes remain cheap. It directly satisfies the stem's requirement to ensure security is adequately addressed at the system design phase, before coding begins.

Why this answer

Threat modeling is a structured, design-phase activity that systematically identifies threats, attack surfaces, and mitigations before code is written. It is the most important activity to ensure security is adequately addressed in system design because it directly influences architecture, trust boundaries, and control selection. Data flow diagrams support threat modeling but are an input, not the primary security assurance activity.

Exam trap

CISA often tests the distinction between supporting artifacts (data flow diagrams) and the core security assurance activity (threat modeling), causing candidates to pick the input rather than the activity.

How to eliminate wrong answers

Option A is wrong because creating a data flow diagram is a supporting artifact used as input to threat modeling; by itself it does not ensure security is addressed. Option B is wrong because developing a detailed project schedule is a project management activity unrelated to security design assurance. Option D is wrong because reviewing the budget for security tools is a financial/resourcing activity and does not ensure that security is designed into the system.

82
MCQeasy

During which phase of the waterfall SDLC should security requirements be formally documented and approved by the business owner?

A.Development phase
B.Requirements phase
C.Design phase
D.Testing phase
AnswerB

Documenting and approving security requirements during the requirements phase embeds controls before any design or coding begins, satisfying the stem's demand for formal business-owner sign-off. Waterfall's sequential structure means later phases inherit these baselined requirements, so defects or omissions found downstream become far costlier to remediate.

Why this answer

In the waterfall SDLC, security requirements must be formally documented and approved during the requirements phase, because this phase establishes the baseline for all subsequent design, development, and testing activities. Approving security requirements early ensures they are traceable and funded, and prevents costly rework. The business owner signs off on requirements, including security, at this stage.

Exam trap

CISA often tests the timing of security requirements, and candidates mistakenly pick the design phase because that is where security controls are architected, forgetting that requirements must be baselined first.

How to eliminate wrong answers

Option A is wrong because the development phase is where code is written; documenting security requirements there is too late and leads to rework. Option C is wrong because the design phase translates requirements into architecture; security requirements should already be baselined before design begins. Option D is wrong because the testing phase verifies that requirements were met; documenting them there defeats the purpose of early assurance.

83
MCQeasy

Which of the following is the primary purpose of conducting a static application security test (SAST) during the development phase of the SDLC?

A.To ensure the application is free of runtime errors
B.To validate that the application meets business requirements
C.To identify security vulnerabilities in the source code
D.To test the application's performance under load
AnswerC

SAST analyses source code without executing it, tracing data flows to flag injection, buffer and input-validation flaws during development. This satisfies the stem's development-phase purpose: identifying security vulnerabilities in the source code before deployment, when fixes are cheapest.

Why this answer

Static Application Security Testing (SAST) analyzes source code, bytecode, or binaries without executing the application, to identify security vulnerabilities such as SQL injection, buffer overflows, and insecure cryptographic practices. Its primary purpose during development is to find security flaws early in the SDLC, when they are cheaper to fix. It does not validate business requirements or runtime behavior.

Exam trap

CISA often tests the confusion between SAST (static, code-level, security) and DAST (dynamic, runtime, security) or functional testing, causing candidates to pick a non-security or runtime option.

How to eliminate wrong answers

Option A is wrong because ensuring the application is free of runtime errors is the goal of dynamic testing or unit testing, not SAST, which does not execute code. Option B is wrong because validating that the application meets business requirements is the purpose of functional testing or requirements traceability, not SAST. Option D is wrong because testing performance under load is the domain of performance/load testing tools, not SAST.

84
MCQmedium

An IS auditor is reviewing change management procedures and finds that standard changes are approved by the change manager without CAB review. What is the auditor's BEST conclusion?

A.This is acceptable provided that standard changes are clearly defined and low-risk
B.The change manager should be a member of the CAB
C.The auditor should recommend that all changes go through CAB
D.This is a control weakness because all changes should be reviewed by the CAB
AnswerA

Standard changes are pre-authorised, low-risk, repeatable changes with documented procedures, so change manager approval without CAB review satisfies control objectives. The auditor's best conclusion is that this is acceptable provided the changes are clearly defined and genuinely low-risk.

Why this answer

Standard changes are pre-approved, low-risk, repeatable changes that follow a documented procedure, so it is acceptable for the change manager to approve them without CAB review provided they are clearly defined and low-risk. This aligns with ITIL and COBIT guidance that standard changes can be pre-authorized to avoid unnecessary bureaucracy. The auditor's best conclusion is that the process is acceptable under those conditions.

Exam trap

CISA often tests whether candidates understand that not all changes require CAB review, and the trap is assuming that any change without CAB approval is a control weakness, when standard changes are legitimately pre-approved.

How to eliminate wrong answers

Option B is wrong because whether the change manager sits on the CAB is irrelevant to the acceptability of pre-approved standard changes; the CAB is not required for standard changes. Option C is wrong because recommending that all changes go through CAB ignores the purpose of standard changes and would create unnecessary overhead, contradicting best practices. Option D is wrong because it incorrectly labels the process a control weakness; standard changes are designed to bypass CAB review when they are low-risk and well-defined.

85
MCQmedium

An organization is implementing a new customer relationship management (CRM) system. The project manager proposes using a pilot conversion strategy, where the new system is implemented in one department first, then gradually rolled out to others. Which of the following is the PRIMARY benefit of this approach?

A.It ensures that all data is migrated at once.
B.It minimizes the overall project cost.
C.It allows for early detection of issues before full-scale rollout.
D.It eliminates the need for user training.
AnswerC

A pilot conversion limits the impact of potential problems by testing the system in a controlled environment before organization-wide deployment. This enables the project team to identify and resolve issues, refine procedures, and provide targeted training. It reduces the risk of a failed full-scale implementation. This is the primary benefit, as it directly addresses the risk of unforeseen problems affecting the entire organization.

Why this answer

The primary benefit of a pilot conversion is risk mitigation. By implementing the system in a limited area first, the organization can uncover and address problems before they affect the entire enterprise. This approach allows for learning and adjustment, reducing the chance of a costly failure.

It is particularly useful for complex systems where full-scale rollout carries high risk.

Exam trap

The trap here is assuming that pilot conversion saves money or eliminates training, when its main advantage is controlled risk exposure.

86
MCQhard

During an ERP implementation, data migration is a critical activity. Which of the following controls would be most effective in ensuring the accuracy and completeness of migrated data?

A.Using automated data extraction tools
B.Performing a trial migration and reconciling the results
C.Assigning a data owner for each data field
D.Running parallel processing for one month
AnswerB

A trial migration replicates the full extract, transform and load process against a subset, then reconciles record counts and financial totals against source systems. This detects truncation, duplication and mapping errors before go-live, directly satisfying the accuracy and completeness objective.

Why this answer

A trial migration followed by reconciliation is the most effective control because it validates the accuracy and completeness of the migrated data by comparing source and target records before the final cutover. Reconciliation identifies discrepancies, missing records, and transformation errors, allowing correction before go-live. This directly addresses both accuracy and completeness.

Exam trap

CISA often tests the difference between preventive, detective, and corrective controls, and the trap is choosing a tool (automated extraction) or a responsibility assignment (data owner) instead of a detective control that actually verifies accuracy and completeness.

How to eliminate wrong answers

Option A is wrong because automated extraction tools improve efficiency but do not by themselves ensure accuracy or completeness; they can still extract incorrect or incomplete data. Option C is wrong because assigning data owners establishes accountability but does not verify that the migrated data is correct or complete. Option D is wrong because parallel processing tests the new system's outputs against the old system over time, which is more about operational readiness than validating the migration itself, and it is costly and time-consuming.

87
Multi-Selectmedium

An IS auditor is reviewing a post-implementation review of a new payroll system. Which TWO findings should most concern the auditor? (Select two.)

Select 2 answers
A.The project was completed 10% over budget.
B.User acceptance testing did not include all payroll scenarios.
C.The vendor's implementation team was helpful.
D.The system's response time is slower than expected.
E.Some employees reported inaccurate pay calculations.
AnswersB, E

Incomplete user acceptance testing coverage means untested payroll scenarios, such as overtime, deductions or tax bands, may fail silently in production. This directly undermines the control evidence that the system meets requirements, so the auditor should be most concerned.

Why this answer

Option B is correct because incomplete user acceptance testing means key payroll scenarios (e.g., overtime, deductions, tax withholding, leave accrual) were never validated before go-live, so defects in those paths can reach production undetected and directly affect pay accuracy and compliance. Option E is correct because inaccurate pay calculations are a realized material failure of the system's core control objective, indicating that payroll processing, calculation logic, or data conversion is faulty and that employees, tax filings, and statutory deductions may all be wrong. These two findings are the most concerning because they strike at the integrity of payroll data and the testing that should have prevented such errors.

Option A does not belong because a 10% budget overrun is a cost-management issue, not a control or data-integrity failure. Option C does not belong because a helpful vendor team is a positive observation with no audit significance. Option D does not belong because slower-than-expected response time is a performance issue that, while worth noting, does not by itself threaten the accuracy or completeness of payroll processing.

Exam trap

CISA often tests the distinction between project management issues (budget, schedule, vendor relations) and control/risk issues (incomplete testing, data integrity failures), so candidates must prioritize findings that threaten accuracy, compliance, or control effectiveness.

88
MCQhard

An IS auditor is reviewing a project that replaced a legacy system. The project used a phased cutover, with each phase going live in a different region. After the final phase, the auditor finds that the legacy system was kept in read-only mode for six months, but no formal reconciliation was performed between legacy and new system balances during that period. Which of the following is the MOST significant concern?

A.Undetected data discrepancies may have persisted, and the organization may have lost the ability to correct them after the legacy system was retired.
B.The project team may have incurred unnecessary licensing and maintenance costs by keeping the legacy system available for six months.
C.The phased cutover may have caused inconsistent business processes across regions, leading to operational inefficiencies.
D.Users may have continued to access the legacy system for reporting and made decisions based on outdated information.
AnswerA

Keeping the legacy system read-only provides a reference for reconciliation, but without a formal reconciliation, differences between legacy and new balances may go unnoticed. Once the legacy system is retired, the source data needed to investigate and correct those discrepancies may no longer be available. This creates a lasting risk of inaccurate financial or operational reporting, making it the most significant concern.

Why this answer

When a legacy system remains available after cutover, it offers a baseline for verifying that the new system contains complete and accurate data. Without formal reconciliation, differences can go undetected. Retiring the legacy system then eliminates the source data needed to investigate and correct those differences.

The most significant concern is therefore the permanent loss of the ability to identify and remediate data discrepancies, which can affect financial reporting and operational decisions.

Exam trap

The trap here is focusing on cost or user access to the legacy system, when the real risk is the lost opportunity to reconcile and correct data before the source is retired.

89
Multi-Selectmedium

An organization is evaluating two vendors for a critical cloud-based ERP system. Which TWO contractual clauses are most important to include to ensure the organization can monitor vendor performance and security? (Select TWO)

Select 2 answers
A.Data ownership clause
B.Indemnification clause
C.Audit rights
D.Service level agreements (SLAs)
E.Non-disclosure agreement (NDA)
AnswersC, D

Audit rights grant the organisation contractual authority to inspect vendor controls, logs and processes, directly satisfying the stem's requirement to monitor vendor security. Without this clause, assurance relies on vendor self-reporting, which is insufficient for a critical cloud ERP system.

Why this answer

Option C (Audit rights) is correct because it contractually grants the organization the ability to inspect, assess, and verify the vendor's security controls, processes, and compliance — for example through on-site audits, penetration test reports, or SOC 2 evidence — which is essential for ongoing security monitoring of a critical ERP system. Option D (Service level agreements (SLAs)) is correct because SLAs define measurable performance and availability commitments (e.g., uptime percentages, response and resolution times, penalties for misses), giving the organization the metrics and remedies needed to monitor vendor performance. Option A (Data ownership clause) is not correct here because it establishes who owns the data rather than providing a monitoring mechanism.

Option B (Indemnification clause) is not correct because it allocates financial/legal liability after a loss rather than enabling performance or security oversight. Option E (Non-disclosure agreement (NDA)) is not correct because it protects confidentiality of shared information but does not by itself provide performance or security monitoring rights.

Exam trap

CISA often tests the distinction between contractual clauses that enable monitoring (audit rights, SLAs) and those that address other concerns (ownership, indemnification, confidentiality), so candidates must focus on the specific objective of monitoring performance and security.

90
MCQmedium

An IS auditor is reviewing a project to implement a new customer relationship management (CRM) system. The project manager has created a work breakdown structure (WBS) and a Gantt chart. Which of the following should the auditor verify to ensure the project schedule is realistic?

A.The project manager has used project management software to create the schedule.
B.The schedule includes contingency reserves for known risks.
C.The WBS includes all deliverables and the Gantt chart reflects dependencies and resource availability.
D.The project budget is aligned with the schedule and approved by the steering committee.
AnswerC

A realistic schedule depends on a complete WBS that captures all deliverables and a Gantt chart that accurately models task dependencies and resource constraints. Without this, the schedule may be optimistic. The auditor should verify that the WBS is comprehensive and that the Gantt chart reflects logical sequencing and resource calendars, ensuring the timeline is achievable.

Why this answer

A realistic project schedule requires a complete work breakdown structure that captures all deliverables and a Gantt chart that accurately reflects task dependencies and resource availability. Without these elements, the schedule may be unachievable. The auditor should focus on the schedule's underlying assumptions and structure rather than ancillary factors like budget approval or software usage.

Exam trap

The trap here is assuming that a detailed Gantt chart alone guarantees a realistic schedule, without verifying that the WBS is complete and dependencies are correctly modeled.

91
MCQmedium

An organization is implementing an ERP system and is concerned about segregation of duties conflicts. What is the most effective control to address this risk during implementation?

A.Implementing role-based access controls
B.Performing a data migration risk assessment
C.Reviewing vendor SOC 2 reports
D.Conducting user acceptance testing
AnswerA

Role-based access controls assign permissions by job function rather than individual, preventing any single user from holding conflicting duties such as creating a vendor and approving its payment. This directly addresses the segregation of duties conflicts the ERP implementation raises.

Why this answer

Role-based access controls (RBAC) are the most effective control to address segregation of duties conflicts during ERP implementation because they allow the organization to define roles with specific permissions and assign users to roles, preventing conflicting access. RBAC enforces SoD by design, ensuring that no single user has incompatible duties.

Exam trap

CISA often tests the difference between controls that directly enforce SoD (RBAC) and those that are supportive but not directly addressing SoD, and the trap is choosing a testing or assessment activity instead of a preventive control.

How to eliminate wrong answers

Option B is wrong because a data migration risk assessment addresses data integrity risks, not SoD conflicts. Option C is wrong because reviewing vendor SOC 2 reports assesses the vendor's controls, not the organization's internal SoD within the ERP. Option D is wrong because user acceptance testing validates functionality and usability, not access control design or SoD enforcement.

92
MCQeasy

Which of the following is a key objective of a post-implementation review?

A.To conduct penetration testing
B.To approve the project budget
C.To determine if the system meets user requirements
D.To select the vendor
AnswerC

A post-implementation review compares delivered functionality against the original business case and user requirements, confirming the system actually delivers intended benefits. This satisfies the stem's objective of verifying that user requirements were met after go-live.

Why this answer

The key objective of a post-implementation review (PIR) is to determine whether the system meets user requirements and delivers the expected benefits. It evaluates the project's success against its original objectives, including functionality, performance, and user satisfaction. This helps the organization learn and improve future projects.

Exam trap

CISA often tests the timing and purpose of PIR, and the trap is confusing it with other project phases like testing, budgeting, or vendor selection.

How to eliminate wrong answers

Option A is wrong because penetration testing is a security assessment activity, not the objective of a PIR. Option B is wrong because budget approval occurs during project initiation or planning, not after implementation. Option D is wrong because vendor selection happens before implementation, not during a PIR.

93
Multi-Selecteasy

During the design phase of an SDLC, which TWO activities should be performed to ensure security is integrated into the system? (Select TWO)

Select 2 answers
A.User acceptance testing (UAT)
B.Code review
C.Threat modeling
D.Architecture review
E.Penetration testing
AnswersC, D

Threat modeling systematically identifies potential threats, attack vectors and required mitigations against the proposed design. Conducted during the design phase, it satisfies the requirement to integrate security before coding begins, when architectural changes remain inexpensive compared with remediation after implementation.

Why this answer

Threat modeling (C) is correct because it is a design-phase activity that systematically identifies potential threats, attack vectors, and mitigations against the proposed architecture and data flows before code is written. Architecture review (D) is correct because it evaluates the proposed system design against security requirements, standards, and best practices (e.g., segmentation, least privilege, trust boundaries) to catch structural weaknesses early. User acceptance testing (A) is wrong because UAT validates business functionality and user requirements during testing, not design.

Code review (B) is wrong because it examines implemented source code, which occurs after design. Penetration testing (E) is wrong because it is an active exploitation test performed on a built system, typically in later testing or deployment phases.

Exam trap

CISA often tests the phase-appropriateness of security activities; candidates incorrectly select testing-phase activities (UAT, code review, pen testing) for a design-phase question because they conflate 'security assurance' with 'security integration.'

94
MCQhard

An organization is implementing an enterprise resource planning (ERP) system. The project team plans to migrate legacy data without performing a full reconciliation between source and target systems. As an IS auditor, which of the following should be your PRIMARY concern?

A.The legacy system may be decommissioned prematurely
B.User acceptance testing may be delayed
C.The data migration may exceed the planned timeline
D.Incomplete or inaccurate data may be loaded into the new system
AnswerD

Skipping full reconciliation removes the control that detects records lost, duplicated or corrupted during migration. Without it, incomplete or inaccurate data enters the ERP and may drive incorrect transactions and reporting, making data integrity the auditor's primary concern.

Why this answer

The primary audit concern when legacy data is migrated without full reconciliation is that incomplete or inaccurate data will be loaded into the new ERP, leading to corrupted financial records, faulty reporting, and loss of data integrity. Reconciliation between source and target is a fundamental data migration control that detects missing, duplicated, or transformed records. Without it, the organization cannot assert data completeness or accuracy.

Exam trap

CISA often tests the auditor's ability to distinguish primary data integrity risks from secondary project risks (schedule, decommissioning); candidates pick timeline or UAT concerns because they sound plausible but miss the core data quality issue.

How to eliminate wrong answers

Option A is wrong because premature decommissioning of the legacy system is a secondary risk that only becomes relevant after migration validation; it is not the primary concern when reconciliation is skipped. Option B is wrong because UAT delay is a schedule issue, not a data integrity risk, and is unrelated to the absence of reconciliation. Option C is wrong because timeline overrun is a project management concern, whereas the auditor's primary focus is on the integrity and completeness of migrated data.

95
MCQmedium

An organization has just completed a post-implementation review of a new payroll system. Management is now deciding whether to formally transfer ownership of the system from the project team to IT operations. Which of the following is the MOST important prerequisite before this transfer is approved?

A.The project team has completed all user training sessions.
B.The system documentation, support procedures, and service level agreements have been reviewed and formally accepted by IT operations.
C.The project manager has released all team members to other assignments.
D.The internal audit department has completed a post-implementation audit of the project.
AnswerB

Formal acceptance by IT operations confirms that the support organization has the necessary documentation, procedures, and agreements to assume ownership. This is a critical control because it ensures accountability and operational readiness. Without this acceptance, the project team may remain responsible indefinitely, and operational support may be inadequate, leading to service disruptions and unclear escalation paths.

Why this answer

The transfer of ownership from a project team to IT operations requires formal acceptance by the receiving party. This ensures that operations has reviewed and agreed to support the system, including documentation, procedures, and service levels. Without this acceptance, accountability remains unclear, and the system may not receive adequate support, leading to operational risks.

Exam trap

The trap here is assuming that completion of user training or an audit is sufficient for handover, when formal operational acceptance is the key control.

96
MCQhard

An IS auditor is reviewing the testing phase of a new system development project. The project team has decided to use beta testing as the primary method for user acceptance testing (UAT). Which of the following is the MOST appropriate audit concern regarding this decision?

A.Beta testing does not allow for regression testing of existing functionality.
B.Beta testing is typically performed by developers rather than end users, reducing its effectiveness.
C.Beta testing is too expensive and time-consuming compared to other UAT methods.
D.Beta testing may not provide sufficient control over the test environment and user participation.
AnswerD

Beta testing involves releasing the system to a limited set of real users in a production-like environment, but the auditor cannot control who tests or how thoroughly. This lack of control can lead to incomplete coverage of requirements and unidentified defects. For UAT, a controlled environment with defined test cases and selected users is typically more reliable.

Why this answer

Beta testing can be a valuable part of UAT, but it lacks the structured control of a formal UAT process. Auditors should be concerned that without defined test cases, selected participants, and controlled environments, beta testing may not provide sufficient evidence that the system meets all requirements. It is best used as a supplement to, rather than a replacement for, controlled UAT.

Exam trap

The trap here is confusing beta testing with controlled UAT; beta testing is less formal and may not provide the audit evidence needed for compliance.

97
MCQhard

An IS auditor is reviewing a contract with a vendor for a new financial system. Which of the following clauses is MOST critical to ensure auditability?

A.Penalties for non-performance
B.Service level agreements (SLAs) for system uptime
C.Right to audit the vendor's operations and controls
D.Data ownership and confidentiality provisions
AnswerC

The right-to-audit clause contractually grants the IS auditor access to the vendor's operations, records and controls, enabling independent verification of the financial system's processing. Without it, assurance over outsourced processing relies solely on vendor assertions and third-party reports.

Why this answer

The right-to-audit clause is the most critical for ensuring auditability because it contractually grants the organization and its auditors the ability to examine the vendor's controls, records, and operations. Without this clause, the organization cannot independently verify that the vendor meets security, compliance, and operational requirements, regardless of other contractual protections.

Exam trap

CISA often tests the difference between contractual protections that address consequences (penalties, SLAs) and those that enable verification (right to audit); candidates pick SLAs or penalties because they sound like strong controls but do not provide auditability.

How to eliminate wrong answers

Option A is wrong because penalties for non-performance address consequences of failure but do not enable the organization to verify controls or investigate incidents. Option B is wrong because SLAs define uptime expectations but do not provide audit access to validate how those levels are achieved or measured. Option D is wrong because data ownership and confidentiality provisions protect data rights and privacy but do not grant the organization the ability to audit the vendor's environment or control effectiveness.

98
Multi-Selecthard

An organization is implementing a new CRM system using an iterative development methodology. The IS auditor wants to verify that appropriate controls are in place. Which THREE of the following are essential controls for iterative development? (Select THREE.)

Select 3 answers
A.Formal sign-off on a complete requirements document before development begins
B.Risk assessment at the start of each iteration
C.Version control and configuration management
D.A mandatory change control board for every change
E.Frequent stakeholder reviews and feedback after each iteration
AnswersB, C, E

Each iteration introduces new or changed functionality, so risks must be reassessed before development begins rather than once at project inception. Performing risk assessment at the start of every iteration ensures newly identified threats are addressed within that cycle, satisfying the iterative methodology's need for continuous control.

Why this answer

Option B is correct because iterative development delivers functionality in short cycles, so a risk assessment must be repeated at the start of each iteration to identify new or changing risks (e.g., scope creep, integration issues, security flaws) before that increment is built. Option C is correct because iterative projects produce frequent code and artifact changes across parallel workstreams, making version control and configuration management essential to maintain baselines, traceability, and rollback capability. Option E is correct because iterative methodologies depend on continuous stakeholder involvement, and reviews/feedback after each iteration validate that the evolving product meets business needs and allow course corrections early.

Option A is not appropriate because iterative development deliberately avoids freezing a complete requirements document up front; requirements evolve through iterations. Option D is not essential because requiring a change control board for every change would impose a heavyweight, waterfall-style gate that conflicts with the speed and flexibility of iterative delivery, where many changes are handled within the iteration backlog.

Exam trap

CISA often tests whether candidates can match controls to the development methodology; candidates incorrectly apply waterfall controls (upfront sign-off, universal change control boards) to iterative projects, misunderstanding that iterative methods require lightweight, continuous controls.

99
MCQhard

An IS auditor is reviewing a software development project that uses a DevOps pipeline. The auditor observes that developers can push code directly to production without independent review. Which of the following is the MOST significant risk arising from this practice?

A.Inability to track changes due to lack of version control.
B.Increased time to deploy new features.
C.Unauthorized or defective code being deployed to production.
D.Increased infrastructure costs due to automated deployments.
AnswerC

Without independent review, developers can deploy code that contains errors, security vulnerabilities, or even malicious logic. This bypasses a key segregation of duties control and increases the risk of system compromise, data corruption, or fraud. The lack of review means defects may not be caught before impacting users, and accountability is weakened. This is the most significant risk because it directly affects the integrity and security of the production environment.

Why this answer

Allowing developers to push code directly to production without independent review violates segregation of duties and removes a critical quality gate. This increases the likelihood that defective or unauthorized code will be deployed, leading to system outages, security breaches, or data integrity issues. The most significant risk is therefore the deployment of unauthorized or defective code.

Exam trap

The trap here is focusing on deployment speed or version control, when the core issue is the lack of independent review enabling unauthorized or defective code.

100
Multi-Selecthard

An organization is planning to purchase a cloud-based HR system. Which THREE of the following should be included in the vendor contract to ensure adequate control and oversight? (Select three.)

Select 3 answers
A.A list of all subprocessors
B.Right to audit the vendor's controls
C.Service-level agreement (SLA) specifying uptime and response times
D.A fixed-price payment schedule
E.Data ownership and data protection clauses
AnswersB, C, E

A right-to-audit clause grants the organisation contractual authority to examine the vendor's control environment, satisfying the oversight requirement for a cloud-hosted HR system holding sensitive employee data. Without it, assurance relies solely on vendor self-reporting, such as SOC 2 reports, which cannot be independently verified or scoped to the organisation's specific compliance obligations.

Why this answer

Option B is correct because a right-to-audit clause contractually guarantees the organization can assess the vendor's security controls, either directly or via a third-party assessment such as SOC 2, which is essential for ongoing oversight of a cloud HR system holding sensitive employee data. Option C is correct because an SLA defining uptime and response times establishes measurable performance and availability commitments, giving the organization enforceable remedies if service levels are missed. Option E is correct because data ownership and data protection clauses clarify that the organization retains ownership of its HR data and obligate the vendor to safeguard it in line with applicable privacy and security requirements.

Option A is not among the marked answers, and while subprocessor transparency is useful, it is not one of the three required contract elements here. Option D is not marked because a fixed-price payment schedule addresses commercial cost certainty, not control and oversight of the vendor's security and service performance.

Exam trap

The ISACA CISA exam often emphasizes the importance of contractual clauses that provide direct oversight and enforceability, such as right to audit and SLAs, rather than items that only offer transparency or commercial terms.

101
MCQeasy

What is the PRIMARY purpose of conducting a static application security testing (SAST) during the development phase?

A.To identify security vulnerabilities in the source code
B.To ensure the application is free of logic errors
C.To test the application's functionality
D.To validate that security requirements are met
AnswerA

SAST analyses source code without executing it, detecting vulnerabilities such as injection flaws and insecure coding patterns during development. This satisfies the stem's development-phase constraint, enabling remediation before deployment rather than detecting runtime or production threats.

Why this answer

SAST analyzes source code, bytecode, or binaries without executing the application, specifically to detect security weaknesses such as injection flaws, hardcoded credentials, and insecure API usage during development. Its primary purpose is identifying security vulnerabilities early in the SDLC, when remediation is cheapest.

Exam trap

The trap here is confusing SAST with DAST or functional testing; candidates must remember SAST is white-box, non-executing, and focused on source-code security flaws, not logic or functionality.

How to eliminate wrong answers

Option B is wrong because logic errors (e.g., off-by-one, incorrect business rules) are functional defects detected by unit testing, code review, or dynamic testing, not SAST's security-focused analysis. Option C is wrong because functional testing is the domain of unit, integration, and system testing; SAST does not execute code and cannot validate runtime functionality. Option D is wrong because validating that security requirements are met is a verification/validation activity typically performed through security testing, traceability matrices, and requirements reviews, not SAST's code-level pattern detection.

102
MCQmedium

An IS auditor is reviewing an agile software development project. Which of the following practices would BEST help ensure that security controls are adequately addressed?

A.Requiring sign-off from the project sponsor before each sprint review
B.Performing a single comprehensive security test after all sprints are complete
C.Conducting a formal design review at the end of each sprint
D.Including security acceptance criteria in user stories
AnswerD

Embedding security acceptance criteria in user stories makes controls testable within each sprint's definition of done. This integrates security into the iterative backlog rather than bolting it on later, directly satisfying the need to address controls continuously in agile delivery.

Why this answer

Embedding security acceptance criteria directly into user stories makes security requirements explicit, testable, and part of the definition of done for every increment, ensuring controls are addressed continuously throughout agile development. This shifts security left and integrates it into the team's normal workflow rather than treating it as a separate phase.

Exam trap

The trap is choosing a phase-gate or post-development security activity (like a final security test or design review) instead of the agile-native practice of embedding security into user stories and the definition of done.

How to eliminate wrong answers

Option A is wrong because sponsor sign-off at sprint reviews is a governance/acceptance activity, not a mechanism for ensuring security controls are built into the product. Option B is wrong because a single comprehensive security test after all sprints is a waterfall-style approach that delays detection and increases remediation cost; agile requires continuous security validation. Option C is wrong because a formal design review at the end of each sprint is too late and too narrow—security must be considered during story refinement and coding, not only after design is complete.

103
Multi-Selecthard

An IS auditor is reviewing a project that uses an iterative SDLC approach. Which THREE controls should the auditor expect to see in place during the development iterations? (Select THREE)

Select 3 answers
A.Formal sign-off on requirements before each iteration
B.Code reviews
C.User acceptance testing (UAT) before each iteration
D.Static application security testing (SAST)
E.Unit testing
AnswersB, D, E

Code reviews provide independent peer examination of each iteration's changes, catching defects and insecure coding before release. This satisfies the iterative SDLC's need for verification controls applied repeatedly within development iterations rather than only at final testing.

Why this answer

In an iterative SDLC, controls must fit each short development cycle, so the auditor should expect code reviews (B), because peer inspection of each increment catches defects and insecure coding early before they propagate into later iterations. Static application security testing (D) is also expected, since SAST tools scan source code or bytecode for vulnerabilities such as injection flaws during development, aligning with the shift-left security principle in iterative builds. Unit testing (E) is likewise a core iterative control, as developers verify individual functions or modules after each change, providing fast feedback and regression protection within the iteration.

Formal sign-off on requirements before each iteration (A) is not typical because iterative methods embrace evolving requirements and continuous stakeholder feedback rather than frozen, pre-iteration approvals. User acceptance testing before each iteration (C) is also not expected, since UAT is normally performed at the end of a release or increment on a potentially shippable product, not before every development iteration.

Exam trap

CISA often tests the distinction between iterative and waterfall controls; candidates select waterfall-style gates (formal sign-off, UAT before each iteration) instead of the code-level, continuous controls that actually fit iterative development.

104
Multi-Selecthard

An organization is adopting a DevOps approach for system development. Which THREE controls should an IS auditor expect to see in place to maintain security and compliance?

Select 3 answers
A.Annual penetration testing after the release
B.Automated security scanning integrated into the CI/CD pipeline
C.Version control and change tracking for infrastructure as code
D.Manual code review for every change before deployment
E.Real-time monitoring and logging of production systems
AnswersB, C, E

Automated security scanning embedded in the CI/CD pipeline tests each build for vulnerabilities before deployment, providing continuous preventive assurance. This satisfies the DevOps demand for security controls that keep pace with frequent, rapid releases rather than periodic manual review.

Why this answer

Option B is correct because automated security scanning (e.g., SAST, DAST, or SCA tools) integrated into the CI/CD pipeline provides continuous, shift-left detection of vulnerabilities before code reaches production, which is essential for maintaining security in a fast-paced DevOps environment. Option C is correct because version control and change tracking for infrastructure as code (e.g., Git repositories with commit history and pull-request approvals) ensure that infrastructure modifications are auditable, traceable, and reversible, directly supporting compliance and change-management requirements. Option E is correct because real-time monitoring and logging of production systems (e.g., via SIEM, centralized log aggregation, and alerting) enable timely detection of security incidents and provide the evidence trail needed for compliance and forensic review.

Option A does not belong because annual penetration testing only after release is periodic and post-deployment, which is too infrequent and too late for a DevOps model that requires continuous assurance. Option D does not belong because mandating manual code review for every change creates a bottleneck that undermines DevOps velocity and is not a scalable control; automated reviews and peer approvals within the pipeline are more appropriate.

105
Multi-Selectmedium

During a change management audit, which TWO of the following are essential elements of a normal change request? (Select two.)

Select 2 answers
A.The name of the developer who will implement the change
B.Justification for the change
C.The project manager's approval
D.Impact analysis
E.A list of all users affected
AnswersB, D

A change request must state why the change is needed, letting the change advisory board weigh business benefit against risk and cost. Without documented justification, approval decisions lack a defensible basis, so this is essential for normal changes.

Why this answer

Option B (Justification for the change) is correct because a normal change request must document the business or technical reason for the change so the Change Advisory Board (CAB) can assess whether the change is warranted and aligned with organizational objectives. Option D (Impact analysis) is correct because it identifies the potential effects of the change on services, configuration items, users, and risk levels, which is essential for the CAB to evaluate risk and approve, defer, or reject the change. Option A is not essential because the specific developer's name is an implementation detail typically captured in the change schedule or task assignment, not a required element of the change request itself.

Option C is not essential because approval authority for normal changes rests with the Change Advisory Board or designated change manager, not necessarily the project manager. Option E is not essential because listing every affected user is impractical and unnecessary; impact analysis addresses affected user groups and services at an appropriate level of detail.

Exam trap

CISA often tests the confusion between elements of a change request and steps in the change management process, such as approval or implementation assignment, leading candidates to select non-essential items.

106
MCQmedium

An organization is implementing a new CRM system using an agile methodology. The IS auditor wants to assess whether security requirements are being addressed. What is the best evidence for the auditor to review?

A.The security policy
B.The sprint retrospective minutes
C.The system architecture document
D.The product backlog
AnswerD

In agile development, security requirements must be captured as backlog items to be estimated, built and tested. Reviewing the product backlog shows whether such requirements exist as user stories with acceptance criteria, providing direct evidence that security is being addressed rather than assumed.

Why this answer

In agile development, the product backlog is the single source of truth for all work items, including security requirements. Security features and controls are captured as backlog items (e.g., user stories, acceptance criteria) and prioritized alongside functional requirements. Therefore, reviewing the product backlog provides direct evidence that security requirements are being addressed in the current development effort.

Other artifacts like policies or architecture documents may exist but do not show whether security is actively being worked on in the sprint.

Exam trap

CISA often tests the misconception that high-level documents like security policies or architecture diagrams provide sufficient evidence of security implementation in agile projects, when in fact the product backlog is the authoritative source for work items.

How to eliminate wrong answers

Option A is wrong because a security policy is a high-level governance document that states management intent but does not provide evidence that security requirements are being addressed in the CRM development. Option B is wrong because sprint retrospective minutes focus on process improvement and team dynamics, not on whether security requirements are included in the product backlog or being implemented. Option C is wrong because a system architecture document may describe security controls at a design level, but it does not show that security requirements are being actively managed and prioritized in the agile development process.

107
MCQhard

An organization is using a spiral model for a high-risk project. The IS auditor wants to ensure that risk assessment is performed at each iteration. Which of the following is the BEST evidence that this control is effective?

A.The project schedule shows spiral iterations
B.Each spiral iteration includes a risk analysis document
C.The project manager has a risk management plan
D.The system has passed user acceptance testing
AnswerB

The spiral model's defining feature is iteration-level risk analysis, so a risk analysis document produced within each spiral iteration provides direct, repeatable evidence that risk assessment occurs at every cycle, not merely at project initiation.

Why this answer

The best evidence that risk assessment is performed at each iteration of a spiral model is the existence of a risk analysis document for each spiral iteration. The spiral model is iterative and risk-driven, so each cycle should include risk analysis. A document per iteration provides tangible, auditable proof that the control is operating effectively.

Exam trap

The trap is selecting a planning document (risk management plan) or a schedule as evidence of control effectiveness, rather than looking for actual execution artifacts like risk analysis documents produced during each iteration.

How to eliminate wrong answers

Option A is wrong because a project schedule showing spiral iterations only indicates that iterations are planned, not that risk assessment was actually performed within them. Option C is wrong because having a risk management plan is a planning artifact; it does not prove that risk assessment is executed at each iteration. Option D is wrong because passing user acceptance testing is a validation activity at the end of development and does not provide evidence of iterative risk assessment.

108
MCQhard

An organization is implementing an agile methodology for a new software project. Which of the following is the MOST effective control to ensure that security requirements are addressed?

A.Conducting a single security requirements review at the start of the project
B.Including security requirements in the product backlog
C.Requiring a separate security sprint after development
D.Performing a security audit only at the end of the project
AnswerB

Placing security requirements in the product backlog makes them backlog items the team estimates, prioritises and completes each sprint, so they are continuously addressed rather than bolted on. This satisfies agile's iterative delivery while ensuring security is not deferred.

Why this answer

In agile methodologies, security requirements must be treated as first-class backlog items so they are prioritized, estimated, and delivered iteratively alongside functional requirements. Including them in the product backlog ensures continuous visibility and integration into each sprint, rather than being an afterthought. This approach aligns with the principle of building security in from the start and adapting to evolving threats.

Exam trap

CISA often tests the misconception that security can be handled in a separate phase or at the end; candidates may incorrectly choose a single review or final audit instead of continuous backlog integration.

How to eliminate wrong answers

Option A is wrong because a single security requirements review at the start is insufficient in agile, where requirements evolve; security must be revisited continuously. Option C is wrong because a separate security sprint after development creates a waterfall-like phase that delays security integration and often leads to rework, contradicting agile's iterative nature. Option D is wrong because performing a security audit only at the end is a reactive approach that fails to address security throughout the development lifecycle, leading to costly fixes and vulnerabilities.

109
MCQmedium

An organization is implementing a new CRM system and has chosen a build (in-house development) approach over buying a COTS product. Which of the following is the most significant risk of this decision?

A.Inability to customize the system to meet user requirements
B.Higher likelihood of project delays and budget overruns
C.Reduced control over security and data privacy
D.Vendor lock-in due to proprietary technology
AnswerB

In-house development demands the organisation define, build and test bespoke functionality itself, so scope creep and underestimated effort routinely extend timelines and budgets. COTS products carry vendor delivery risk instead, making schedule and cost overrun the most significant exposure unique to the build decision.

Why this answer

The most significant risk of choosing an in-house build over a COTS product is the higher likelihood of project delays and budget overruns. Custom development is complex, time-consuming, and prone to scope creep, underestimation, and technical challenges. While in-house development offers customization and control, it often leads to cost and schedule overruns compared to implementing a pre-built solution.

Exam trap

CISA often tests the risks associated with build vs. buy, and candidates may incorrectly attribute COTS risks (e.g., vendor lock-in, reduced customization) to in-house development, or overlook the inherent schedule and cost risks of custom development.

How to eliminate wrong answers

Option A is wrong because in-house development typically allows for greater customization, not inability to customize; COTS products may require customization that is limited. Option C is wrong because in-house development often provides more control over security and data privacy, not reduced control, as the organization manages the entire stack. Option D is wrong because vendor lock-in is a risk of COTS products, not in-house development, which avoids reliance on a vendor's proprietary technology.

110
MCQmedium

In the context of ITIL change management, which change type requires approval from the Change Advisory Board (CAB)?

A.Emergency change
B.Normal change
C.Minor change
D.Standard change
AnswerB

Normal changes are non-standard, requiring a full assessment and authorisation process due to their potential impact and risk. Consequently, these changes necessitate formal evaluation and approval by the Change Advisory Board (CAB). The CAB's primary function is to assess the proposed change, its risks, and benefits, ensuring all stakeholders are considered before authorising its implementation, directly addressing the stem's criterion for CAB approval.

Why this answer

In ITIL change management, a 'Normal change' is any change that is not a standard (pre-approved) change and is not urgent enough to be an emergency change. Normal changes must be assessed, evaluated, and authorized by the Change Advisory Board (CAB) before implementation. The CAB reviews the change's risk, impact, and resource requirements to decide whether to approve, reject, or defer it.

Exam trap

CISA often tests the misconception that all changes require CAB approval, but standard changes are pre-approved and emergency changes use an ECAB or delegated authority, so only normal changes go to the full CAB.

How to eliminate wrong answers

Option A is wrong because emergency changes are handled by the Emergency CAB (ECAB) or a smaller delegated authority, not the full CAB, to expedite urgent fixes. Option C is wrong because 'minor change' is not a formal ITIL change type; minor changes are typically a subset of normal changes but still require CAB approval unless they are pre-authorized as standard changes. Option D is wrong because standard changes are pre-approved, low-risk, routine changes that follow a documented procedure and do not require CAB review for each occurrence.

111
Multi-Selectmedium

Which TWO of the following are typical controls in the testing phase of the SDLC? (Select two.)

Select 2 answers
A.Rollback plan testing
B.Code reviews
C.Security testing (DAST/pen test)
D.Threat modeling
E.User acceptance testing (UAT)
AnswersC, E

Security testing such as dynamic application security testing and penetration testing probes the running application for exploitable weaknesses during the testing phase. It verifies that security requirements are implemented before go-live, satisfying the testing-phase control criterion rather than development or operations.

Why this answer

Security testing such as DAST and penetration testing (C) is a typical testing-phase control because it validates the running application against vulnerabilities after code is built, exercising the deployed system rather than the design. User acceptance testing (E) is also a testing-phase control, as it verifies the completed system meets business requirements and is fit for release before go-live. Rollback plan testing (A) belongs to change/release management or deployment readiness, not the SDLC testing phase.

Code reviews (B) are a build/development-phase control performed on source code before or during integration. Threat modeling (D) is a design-phase activity that identifies threats and mitigations before code is written.

Exam trap

CISA often tests the confusion between design-phase controls (threat modeling), development-phase controls (code reviews), and testing-phase controls (DAST, UAT), so candidates must map each control to the correct SDLC phase.

112
MCQmedium

An IS auditor is reviewing a post-implementation review (PIR) of a new CRM system. The auditor finds that the project was completed on time and within budget, but the business case benefits have not been realized. Which of the following is the MOST likely cause?

A.The PIR was conducted too early to measure benefits.
B.The project team focused on technical delivery rather than business outcomes.
C.The system was delivered with more features than required, leading to complexity.
D.The budget was insufficient to cover change management activities.
AnswerB

A common reason for unrealized benefits is that the project team prioritizes technical milestones (e.g., on-time, on-budget) over achieving the business objectives. Without clear alignment to business goals and benefit realization planning, the system may be delivered but not used effectively to generate the intended value.

Why this answer

When a project is delivered on time and within budget but benefits are not realized, the root cause is often that the project was managed as a technical exercise rather than a business change initiative. Without explicit focus on benefit realization, user adoption, and process alignment, the system may not deliver the expected value.

Exam trap

The trap here is assuming that on-time and on-budget delivery equates to project success, whereas benefit realization is the ultimate measure of success.

113
Multi-Selectmedium

An IS auditor is evaluating an organization's SDLC controls for a new system. Which TWO of the following are key controls that should be in place during the design phase? (Select TWO.)

Select 2 answers
A.Architecture review by a senior architect
B.Static application security testing (SAST)
C.User acceptance testing (UAT)
D.Regression testing
E.Threat modeling to identify security threats
AnswersA, E

Architecture review by a senior architect validates design decisions against security, scalability and compliance requirements before coding begins, satisfying the design-phase control objective. It provides independent scrutiny of proposed structures, catching flaws when remediation is cheapest. This directly addresses the stem's requirement for key design-phase SDLC controls.

Why this answer

Option A (Architecture review by a senior architect) is correct because the design phase is exactly when the proposed system architecture, integration points, and technology choices must be validated against enterprise standards, scalability, and security requirements before costly build work begins. Option E (Threat modeling to identify security threats) is correct because threat modeling is a design-phase activity that systematically identifies threats, attack surfaces, and required mitigations (e.g., using STRIDE or DREAD) so that security controls are built into the design rather than retrofitted. Option B (SAST) is not a design-phase control; static application security testing analyzes source code or binaries during coding/build, so it belongs to development and testing phases.

Option C (UAT) is a testing-phase control performed by end users to confirm the system meets business requirements before go-live. Option D (Regression testing) is also a testing-phase control executed after changes to verify that existing functionality has not been broken.

Exam trap

The trap here is that candidates confuse security testing techniques like SAST with design-phase controls, or they mistakenly think UAT or regression testing occur early in the SDLC, when in fact they belong to later phases.

114
MCQmedium

An organization is selecting a vendor for a new procurement system. Which of the following is the MOST important factor to include in the contract?

A.A clause limiting vendor liability
B.Fixed price for the entire contract term
C.Detailed service level agreements (SLAs)
D.Right to audit the vendor's security controls
AnswerD

A contractual right to audit lets the organisation independently verify the vendor's security controls, rather than relying on self-attestation. This directly addresses the stem's constraint: the vendor will process organisational data, so the contract must preserve ongoing assurance over those controls.

Why this answer

The right to audit the vendor's security controls is the most important factor because it provides the organization with the ability to verify that the vendor is complying with security requirements and contractual obligations. Without this right, the organization has no assurance that its data is protected, especially when the vendor handles sensitive information. This is a critical governance and risk management control.

Exam trap

The trap is selecting options that seem important for contract management (e.g., SLAs, liability limits) but do not provide the organization with the ability to verify security controls; the exam expects you to prioritize the right to audit as a fundamental assurance mechanism.

How to eliminate wrong answers

Option A is wrong because a clause limiting vendor liability may protect the vendor financially but does not ensure security; it could even reduce the vendor's incentive to maintain strong controls. Option B is wrong because a fixed price for the entire contract term is a financial consideration, not a security or compliance control; it does not address the protection of organizational assets. Option C is wrong because detailed SLAs are important for defining performance expectations, but they do not provide the organization with the ability to independently verify security controls; SLAs typically focus on availability, response times, and other service metrics, not security assurance.

← PreviousPage 2 of 2 · 114 questions total

Ready to test yourself?

Try a timed practice session using only Information Systems Acquisition, Development, and Implementation questions.