Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

During an ERP implementation, the project team decides to disable segregation of duties (SoD) controls in the system to accelerate go-live. After go-live, the IS auditor identifies that a single user can perform incompatible functions. What is the BEST course of action?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement compensating controls such as enhanced monitoring and audit logs

SoD conflicts are a high-risk issue. The auditor should recommend immediate implementation of compensating controls (e.g., enhanced monitoring, dual approval) to mitigate risk until the system is reconfigured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Require reconfiguration of SoD controls before the next audit

    Why it's wrong here

    While reconfiguration is ideal, immediate compensating controls are needed to mitigate current risk.

  • Document the issue and accept the risk

    Why it's wrong here

    Accepting risk may be an option but the auditor should first recommend controls to reduce risk to an acceptable level.

  • Implement compensating controls such as enhanced monitoring and audit logs

    Why this is correct

    Compensating controls provide a temporary but effective mitigation until the system can be properly configured.

  • Advise management to terminate the project manager

    Why it's wrong here

    Personnel actions are not within the auditor's scope; the focus should be on risk mitigation.

About these practice questions

One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.