CISA Practice Question: Information Systems Acquisition, Development, and Implementation
In a spiral model SDLC, risk analysis is performed at the beginning of each iteration. What is the PRIMARY benefit of this approach?
⚠ Common exam trap
CISA often tests whether candidates confuse the spiral model's iterative risk focus with waterfall's upfront requirements gathering—candidates may pick 'ensures all requirements are gathered upfront' because it sounds thorough, but that contradicts the spiral model's iterative nature.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It allows for early detection and mitigation of project risks
In the spiral model, risk analysis at the start of each iteration allows the team to identify, assess, and mitigate risks early before they escalate. This iterative risk-driven approach is the defining characteristic of the spiral model and its primary benefit over waterfall or pure prototyping.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It reduces the number of deliverables
Why it's wrong here
The spiral model still produces deliverables each iteration, typically prototypes and increments, so risk analysis does not reduce their number. Fewer deliverables suits a linear predictive approach, not the iterative spiral, whose purpose is managing risk through repeated cycles.
- ✗
It eliminates the need for user acceptance testing
Why it's wrong here
Risk analysis per iteration addresses uncertainty and may reduce rework, but it cannot replace user acceptance testing, which validates the delivered system against business needs. UAT remains necessary in the spiral model, so this is not the benefit sought.
- ✗
It ensures all requirements are gathered upfront
Why it's wrong here
The spiral model deliberately gathers and refines requirements iteratively rather than upfront; upfront freezing contradicts its incremental nature. Complete upfront requirements suit a waterfall approach, so this is not the benefit of per-iteration risk analysis.
- ✓
It allows for early detection and mitigation of project risks
Why this is correct
Analysing risk at the start of every spiral iteration surfaces threats and uncertainties before significant design and coding effort is committed, so mitigation can be planned into the next loop. This early detection reduces the cost of rework compared with deferring risk assessment to later lifecycle phases.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.