Courseiva
hardMultiple ChoiceObjective-mapped

CISA Practice Question: During a systems audit, the auditor finds that…

During a systems audit, the auditor finds that the project did not follow the organization's systems development methodology. What should the auditor do FIRST?

⚠ Common exam trap

Watch out — candidates often confuse the auditor's investigative curiosity (interviewing the team) with the required procedural first step (reporting and assessing control impact), leading them to select Option D instead of the correct audit response.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Report the deviation and assess the impact on controls

The auditor's first responsibility upon discovering a deviation from the organization's systems development methodology is to report the finding and assess the impact on internal controls. This aligns with ISACA's audit standards, which require auditors to evaluate whether the deviation introduces risks to data integrity, security, or project governance. Without this assessment, the auditor cannot determine the severity of the non-compliance or recommend appropriate corrective actions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Accept if the project is on schedule

    Why it's wrong here

    Deviation from methodology must be addressed regardless of schedule.

  • Recommend that the project be stopped

    Why it's wrong here

    Stopping is not the first action; impact assessment is needed.

  • Report the deviation and assess the impact on controls

    Why this is correct

    The auditor must report and evaluate the risk.

  • Interview the project team to understand why

    Why it's wrong here

    Interviewing is part of assessment but reporting is the initial step.

About these practice questions

This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.