CISA Practice Question: Information Systems Acquisition, Development, and Implementation
During a post-implementation review of a new accounting system, the IS auditor notes the following: the project was completed on time and within budget, but user satisfaction is low and there are several outstanding defect reports. Which THREE of the following are the MOST appropriate recommendations?
⚠ Common exam trap
CISA often tests whether candidates recommend process-based, governance-aligned actions rather than reactive or escalation-based responses, so options that skip formal remediation planning are typically distractors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Compare actual benefits achieved against the business case
Option A is correct because a post-implementation review must measure realized benefits against the original business case to determine whether the system delivered the expected value, especially when satisfaction is low. Option B is correct because outstanding defect reports represent unresolved risks to data integrity and operational reliability in an accounting system, so a formal remediation plan with ownership, priorities, and target dates is the appropriate control response. Option E is correct because a lessons learned session captures root causes of the schedule/budget-versus-quality gap and feeds process improvements into future projects. Option C is not appropriate as a primary recommendation because additional budget is a funding request, not a control or governance action, and cost should follow an approved defect remediation plan. Option D is not appropriate because escalation to the sponsor may be a communication step, but it does not by itself resolve the defects or address the underlying process weaknesses.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Compare actual benefits achieved against the business case
Why this is correct
On-time, on-budget delivery says nothing about value, so comparing realised benefits against the original business case tests whether the system actually delivered the expected outcomes — the gap the low satisfaction and defect backlog hint at.
- ✓
Establish a formal plan to resolve outstanding defects
Why this is correct
Establishing a formal defect-resolution plan directly addresses the outstanding defect reports that undermine user satisfaction, satisfying the stem's requirement to remediate post-implementation quality gaps. A structured plan assigns ownership, prioritisation and target dates, converting ad hoc fixes into tracked closure, which restores confidence in the accounting system's reliability.
- ✗
Request additional budget to fix the defects
Why it's wrong here
Requesting budget presumes funding is the constraint, yet the stem identifies low user satisfaction alongside defects, which may stem from requirements or change management. It is tempting because remediation costs money. The auditor should recommend defect triage, root-cause analysis and a remediation plan before seeking funding.
- ✗
Immediately escalate the defect reports to the project sponsor
Why it's wrong here
Escalation alone transfers visibility without addressing root cause, and the sponsor already knows delivery succeeded. It is tempting because unresolved defects warrant management attention. The auditor should instead recommend defect triage, root-cause analysis and a remediation plan with owners and dates.
- ✓
Conduct a lessons learned session to identify process improvements
Why this is correct
A lessons learned session directly addresses the process gaps that allowed defects and low satisfaction despite on-time, on-budget delivery. By capturing what failed in requirements gathering, testing, and user involvement, it satisfies the stem's need for recommendations targeting root causes rather than symptoms, enabling improvements for future projects.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.