Courseiva
easyMultiple Choice

CISA Practice Question: During a post-implementation review of a…

During a post-implementation review of a financial system, an IS auditor finds that several critical reports are not being generated correctly. Which of the following should the auditor recommend FIRST?

⚠ Common exam trap

CISA often tests the principle that auditors should diagnose before remediating — candidates who pick 'patch immediately' or 'disable the reports' confuse the auditor's assurance role with an IT operations role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the system configuration and compare with user requirements.

When reports are not generating correctly post-implementation, the auditor's first step should be to determine the root cause by reviewing the system configuration against documented user requirements. This diagnostic step identifies whether the issue is a configuration gap, a requirements misunderstanding, or a defect — informing any subsequent remediation. Jumping to fixes or workarounds without understanding the cause risks masking the real problem.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conduct a new round of user acceptance testing.

    Why it's wrong here

    Re-running user acceptance testing does not diagnose why reports fail in production; it repeats validation rather than investigating the defect. UAT is appropriate before go-live to confirm requirements, not as the first response to live reporting errors.

  • ✓

    Review the system configuration and compare with user requirements.

    Why this is correct

    Comparing system configuration against documented user requirements establishes whether the reporting defects stem from misconfiguration or from requirements never implemented. This diagnostic step precedes remediation, ensuring recommendations target the actual cause rather than merely retraining users or patching reports.

  • ✗

    Disable the incorrect reports and create manual workarounds.

    Why it's wrong here

    Disabling reports and relying on manual workarounds leaves the root cause unresolved and introduces control gaps in financial reporting. This approach suits emergency containment only, not a post-implementation review where the auditor must first determine why reports fail.

  • ✗

    Immediately patch the system to fix the report generation.

    Why it's wrong here

    Patching immediately without root-cause analysis risks introducing further defects and bypasses change control. Emergency patching is warranted for active exploits or outages, not for a post-implementation review where the auditor should first establish the cause of the reporting failure.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.