Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

In a spiral SDLC model, what is the primary purpose of risk analysis in each iteration?

⚠ Common exam trap

A common mix-up: candidates confuse the spiral model's risk analysis with general project risk management or with other phases like planning or requirements gathering; candidates may pick an answer that sounds plausible but is not the specific purpose of risk analysis in each iteration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To identify and resolve potential project risks early

In the spiral model, each iteration begins with risk analysis to identify and resolve potential project risks early, which is the core differentiator of this model. This allows the team to address high-risk areas before investing heavily in development, reducing the chance of costly failures later. The risk analysis directly informs whether to proceed, modify, or abandon the iteration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    To identify and resolve potential project risks early

    Why this is correct

    Each spiral cycle begins by analysing risks so that high-exposure items are addressed through prototyping and mitigation before major investment continues. This early resolution reduces the likelihood of costly rework or failure in later, more expensive iterations.

  • ✗

    To assess user satisfaction with the prototype

    Why it's wrong here

    Risk analysis evaluates technical and project risks to steer the next spiral; measuring user satisfaction is the purpose of prototype evaluation, a separate activity. It is tempting because prototypes are built in the spiral, but satisfaction assessment is not risk analysis.

  • ✗

    To plan the next iteration's tasks

    Why it's wrong here

    Risk analysis in the spiral model drives the decision to proceed, iterate or abort, and shapes risk-mitigation strategy; task scheduling belongs to the planning phase that follows. It is tempting because risk findings do inform subsequent planning, but the analysis itself evaluates exposure, not task allocation.

  • ✗

    To define detailed functional requirements

    Why it's wrong here

    Risk analysis ranks and mitigates uncertainty; it does not elicit or document functional requirements, which are captured during engineering phases. It is tempting because requirements refinement recurs each spiral, yet the risk-analysis activity addresses threat exposure, not specification of system functions.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.