Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

During a post-implementation review of a new payroll system, the IS auditor identifies several outstanding issues. Which TWO issues should be considered most critical to address immediately? (Select TWO)

⚠ Common exam trap

CISA often tests the ability to prioritize issues based on risk, tempting candidates to select operational inefficiencies like performance slowdowns or training gaps over critical financial and compliance failures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The system's tax calculation module produced incorrect results for a subset of employees

Option B is critical because incorrect tax calculations in a payroll system directly violate legal and regulatory compliance requirements, can result in penalties from tax authorities, and harm employee trust through inaccurate pay and withholding. Option D is critical because unauthorized overtime payments from a configuration error represent a direct financial loss and indicate a control failure in the payroll processing logic that could recur and compound if not remediated immediately. In contrast, option A (5% performance degradation) is a performance/efficiency concern that does not affect data integrity or compliance and can be tuned later. Option C (incomplete training) is a people/process issue that, while important, does not by itself cause incorrect or unauthorized transactions. Option E (unfinalized user manual) is a documentation gap with no immediate financial, legal, or control impact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The system is running 5% slower than expected

    Why it's wrong here

    Performance degradation of 5% rarely blocks payroll processing or compromises data integrity, so it is not among the two most critical issues. It tempts auditors because performance monitoring is a standard post-implementation check, and a significant slowdown in a high-volume transaction system would warrant prompt investigation.

  • ✓

    The system's tax calculation module produced incorrect results for a subset of employees

    Why this is correct

    Incorrect tax calculations breach statutory withholding and reporting obligations, producing wrong net pay and filing errors for affected employees. This is a data integrity failure in a legally mandated function, so it demands immediate correction ahead of cosmetic or efficiency issues.

  • ✗

    Some employees have not completed training

    Why it's wrong here

    Incomplete training does not itself corrupt payroll data or halt processing; it is an operational readiness concern rather than a control failure. It tempts because user competence is a recognised post-implementation factor, and in a system where manual intervention drives calculations, untrained staff would be the correct critical finding.

  • ✓

    Unauthorized overtime payments were processed due to a configuration error

    Why this is correct

    A configuration error permitting unauthorised overtime payments is a direct financial loss and a breakdown of authorisation controls. Because it is actively misappropriating funds, it requires immediate remediation, unlike issues that are latent or affect only usability.

  • ✗

    The user manual is not yet finalized

    Why it's wrong here

    An unfinalised manual affects documentation quality, not payroll accuracy or processing integrity, so it does not rank among the two most critical issues. It tempts because documentation is a standard post-implementation deliverable, and in a regulated environment where procedures must be auditable, missing manuals would be the correct critical finding.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.