easyMultiple Choice
CISA Practice Question: During a post-implementation review of a…
During a post-implementation review of a financial system, an IS auditor finds that several critical reports are not being generated correctly. Which of the following should the auditor recommend FIRST?
⚠ Common exam trap
CISA often tests the principle that auditors should diagnose before remediating — candidates who pick 'patch immediately' or 'disable the reports' confuse the auditor's assurance role with an IT operations role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Review the system configuration and compare with user requirements.
When reports are not generating correctly post-implementation, the auditor's first step should be to determine the root cause by reviewing the system configuration against documented user requirements. This diagnostic step identifies whether the issue is a configuration gap, a requirements misunderstanding, or a defect — informing any subsequent remediation. Jumping to fixes or workarounds without understanding the cause risks masking the real problem.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conduct a new round of user acceptance testing.
Why it's wrong here
Re-running user acceptance testing does not diagnose why reports fail in production; it repeats validation rather than investigating the defect. UAT is appropriate before go-live to confirm requirements, not as the first response to live reporting errors.
- ✓
Review the system configuration and compare with user requirements.
Why this is correct
Comparing system configuration against documented user requirements establishes whether the reporting defects stem from misconfiguration or from requirements never implemented. This diagnostic step precedes remediation, ensuring recommendations target the actual cause rather than merely retraining users or patching reports.
- ✗
Disable the incorrect reports and create manual workarounds.
Why it's wrong here
Disabling reports and relying on manual workarounds leaves the root cause unresolved and introduces control gaps in financial reporting. This approach suits emergency containment only, not a post-implementation review where the auditor must first determine why reports fail.
- ✗
Immediately patch the system to fix the report generation.
Why it's wrong here
Patching immediately without root-cause analysis risks introducing further defects and bypasses change control. Emergency patching is warranted for active exploits or outages, not for a post-implementation review where the auditor should first establish the cause of the reporting failure.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.