CISA Practice Question: Information Systems Acquisition, Development, and Implementation
During a post-implementation review of a new payroll system, the IS auditor identifies several outstanding issues. Which TWO issues should be considered most critical to address immediately? (Select TWO)
⚠ Common exam trap
CISA often tests the ability to prioritize issues based on risk, tempting candidates to select operational inefficiencies like performance slowdowns or training gaps over critical financial and compliance failures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The system's tax calculation module produced incorrect results for a subset of employees
Option B is critical because incorrect tax calculations in a payroll system directly violate legal and regulatory compliance requirements, can result in penalties from tax authorities, and harm employee trust through inaccurate pay and withholding. Option D is critical because unauthorized overtime payments from a configuration error represent a direct financial loss and indicate a control failure in the payroll processing logic that could recur and compound if not remediated immediately. In contrast, option A (5% performance degradation) is a performance/efficiency concern that does not affect data integrity or compliance and can be tuned later. Option C (incomplete training) is a people/process issue that, while important, does not by itself cause incorrect or unauthorized transactions. Option E (unfinalized user manual) is a documentation gap with no immediate financial, legal, or control impact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The system is running 5% slower than expected
Why it's wrong here
Performance degradation of 5% rarely blocks payroll processing or compromises data integrity, so it is not among the two most critical issues. It tempts auditors because performance monitoring is a standard post-implementation check, and a significant slowdown in a high-volume transaction system would warrant prompt investigation.
- ✓
The system's tax calculation module produced incorrect results for a subset of employees
Why this is correct
Incorrect tax calculations breach statutory withholding and reporting obligations, producing wrong net pay and filing errors for affected employees. This is a data integrity failure in a legally mandated function, so it demands immediate correction ahead of cosmetic or efficiency issues.
- ✗
Some employees have not completed training
Why it's wrong here
Incomplete training does not itself corrupt payroll data or halt processing; it is an operational readiness concern rather than a control failure. It tempts because user competence is a recognised post-implementation factor, and in a system where manual intervention drives calculations, untrained staff would be the correct critical finding.
- ✓
Unauthorized overtime payments were processed due to a configuration error
Why this is correct
A configuration error permitting unauthorised overtime payments is a direct financial loss and a breakdown of authorisation controls. Because it is actively misappropriating funds, it requires immediate remediation, unlike issues that are latent or affect only usability.
- ✗
The user manual is not yet finalized
Why it's wrong here
An unfinalised manual affects documentation quality, not payroll accuracy or processing integrity, so it does not rank among the two most critical issues. It tempts because documentation is a standard post-implementation deliverable, and in a regulated environment where procedures must be auditable, missing manuals would be the correct critical finding.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.