hardMultiple ChoiceObjective-mapped
CISA Practice Question: During the design phase of a waterfall project,…
During the design phase of a waterfall project, the development team discovers that a key security requirement was omitted from the functional specification. The design has already been partially completed based on the flawed specification. What is the MOST appropriate action?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Halt design activities and revisit the requirements phase to add the security requirement
In a waterfall methodology, each phase must be completed before moving to the next. Discovering a missing requirement during design means the requirements phase is incomplete. The proper action is to halt design and revisit the requirements phase to add the omitted security requirement, ensuring it is properly integrated from the start. Option A is wrong because deferring a security requirement to a future release violates the project's security objectives and could introduce risk. Option B is wrong because continuing design and hoping to incorporate the requirement during testing undermines the structured phase-gate approach and may lead to rework. Option C is wrong because the requirement was omitted, not a scope change; change requests are for modifications after baselines, but the baseline was never properly established for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Proceed with design and add the requirement as an enhancement in the next release
Why it's wrong here
Proceeding with design and deferring the requirement to the next release is inappropriate because security requirements should not be postponed; it also violates the waterfall principle of completing each phase before moving on.
- ✗
Continue design and incorporate the security requirement during testing
Why it's wrong here
Continuing design and attempting to incorporate the requirement during testing is incorrect because in waterfall, testing occurs after design and coding; missing requirements should be addressed by returning to the requirements phase.
- ✗
Implement the security requirement as a change request through the formal change control process
Why it's wrong here
Implementing the requirement as a change request is not appropriate because the requirement was omitted from the functional specification, not a later scope change. The proper action is to revisit the requirements phase.
- ✓
Halt design activities and revisit the requirements phase to add the security requirement
Why this is correct
Halting design and revisiting the requirements phase is correct because the omission must be corrected at the source, ensuring the design is based on complete and accurate requirements, following the sequential nature of waterfall.
Go deeper
Related to this question
About these practice questions
One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.