Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

During a post-implementation review of a new financial system, the IS auditor finds that user acceptance testing (UAT) was completed with only 60% of test cases passed. Which of the following is the MOST significant risk?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The system may not fully meet business requirements, leading to user workarounds

Low UAT pass rate indicates unresolved defects or unmet user requirements, leading to user dissatisfaction and potential workarounds that compromise controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The system deployment was delayed

    Why it's wrong here

    Schedule slippage is a project-management concern, not the risk arising from 40% of UAT cases failing; the real exposure is undetected defects reaching production in a financial system. It is tempting because failed testing often precedes delayed deployment, but delay is a symptom, not the control failure the auditor must report.

  • ✗

    The system performance is below expectations

    Why it's wrong here

    Performance shortfalls are one possible defect class, but the stem gives no evidence of throughput or response-time failures; the risk is that 40% of test cases failed for unknown reasons. It is tempting because UAT failures can include performance cases, yet the auditor cannot assume that specific cause from the pass rate alone.

  • ✗

    The project was not completed within the planned budget

    Why it's wrong here

    Budget overrun is a project-governance metric unrelated to the 40% of UAT cases that failed; the significant risk is defective functionality entering production. It is tempting because post-implementation reviews examine cost variance, but budget status does not indicate whether the financial system processes transactions correctly.

  • ✓

    The system may not fully meet business requirements, leading to user workarounds

    Why this is correct

    Passing only 60% of UAT cases means 40% of tested business scenarios failed, so the system may not satisfy requirements and users will adopt manual workarounds that undermine controls and reporting integrity. This is the most significant risk.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.