CISA Practice Question: Information Systems Acquisition, Development, and Implementation
In a spiral SDLC model, what is the primary purpose of risk analysis in each iteration?
⚠ Common exam trap
A common mix-up: candidates confuse the spiral model's risk analysis with general project risk management or with other phases like planning or requirements gathering; candidates may pick an answer that sounds plausible but is not the specific purpose of risk analysis in each iteration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To identify and resolve potential project risks early
In the spiral model, each iteration begins with risk analysis to identify and resolve potential project risks early, which is the core differentiator of this model. This allows the team to address high-risk areas before investing heavily in development, reducing the chance of costly failures later. The risk analysis directly informs whether to proceed, modify, or abandon the iteration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
To identify and resolve potential project risks early
Why this is correct
Each spiral cycle begins by analysing risks so that high-exposure items are addressed through prototyping and mitigation before major investment continues. This early resolution reduces the likelihood of costly rework or failure in later, more expensive iterations.
- ✗
To assess user satisfaction with the prototype
Why it's wrong here
Risk analysis evaluates technical and project risks to steer the next spiral; measuring user satisfaction is the purpose of prototype evaluation, a separate activity. It is tempting because prototypes are built in the spiral, but satisfaction assessment is not risk analysis.
- ✗
To plan the next iteration's tasks
Why it's wrong here
Risk analysis in the spiral model drives the decision to proceed, iterate or abort, and shapes risk-mitigation strategy; task scheduling belongs to the planning phase that follows. It is tempting because risk findings do inform subsequent planning, but the analysis itself evaluates exposure, not task allocation.
- ✗
To define detailed functional requirements
Why it's wrong here
Risk analysis ranks and mitigates uncertainty; it does not elicit or document functional requirements, which are captured during engineering phases. It is tempting because requirements refinement recurs each spiral, yet the risk-analysis activity addresses threat exposure, not specification of system functions.
Visual reference
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.