Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

In a waterfall SDLC, which phase requires formal sign-off from the business owner before proceeding to the next phase?

⚠ Common exam trap

CISA often tests whether candidates know which waterfall phase requires business owner sign-off, trapping those who pick design or testing because those phases also involve approvals but not the formal scope-baselining gate.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Requirements phase

In a waterfall SDLC, the requirements phase concludes with formal business owner sign-off because it establishes the baseline for all subsequent design, development, and testing work. Once requirements are approved, changes become costly and require change control, so the business owner must formally accept the documented requirements before the project proceeds. This sign-off ensures mutual agreement on scope and reduces the risk of rework downstream.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Development phase

    Why it's wrong here

    Development produces the solution from approved specifications; the business owner signs off earlier, on the requirements baseline, before design or coding starts. It is tempting because developers do hand work back for review, yet that review confirms technical build quality, not the business authorisation to proceed.

  • ✓

    Requirements phase

    Why this is correct

    Requirements are baselined and formally approved by the business owner before design begins, since later phases build directly on that frozen scope. Sign-off here authorises the project to proceed, whereas design and testing approvals occur within their own phases.

  • ✗

    Design phase

    Why it's wrong here

    The design phase produces specifications from approved requirements; business sign-off there is internal review, not the formal gate authorising the project to proceed. Formal business-owner approval belongs to the requirements phase, where the baseline is accepted. Design sign-off would be the correct answer only if the stem asked which phase validates technical specifications.

  • ✗

    Testing phase

    Why it's wrong here

    Testing verifies the built solution against requirements, so business sign-off there validates the finished product rather than authorising progression from requirements. It is tempting because testing does involve business users confirming acceptance, but that approval occurs after development, not as the gate before design begins.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.