Courseiva

CISA · topic practice

Information Systems Acquisition, Development, and Implementation practice questions

This domain covers how organizations acquire, develop, and implement information systems, and how IS auditors evaluate those efforts. Expect questions on business case and feasibility, build-versus-buy and contract types, SDLC and agile controls, requirements and testing, change management, data migration, and post-implementation review. Questions are scenario-based, asking you to pick the best audit evidence or the greatest risk.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Information Systems Acquisition, Development, and Implementation

What the exam tests

What to know about Information Systems Acquisition, Development, and Implementation

Be able to select the best audit evidence and identify the greatest risk across acquisition, development, and implementation. The single most important thing is linking every control and test back to approved requirements, and confirming changes are authorized, tested, and approved before production.

Evaluating feasibility studies, business cases, and cost-benefit analysis before project approval

Choosing contract types such as fixed-price versus time-and-material and their risk transfer

Reviewing SDLC and agile artifacts: requirements, user stories, test plans, traceability matrices

Assessing change management, segregation of duties, and post-implementation review evidence

Watch out for

Common Information Systems Acquisition, Development, and Implementation exam traps

  • ▸Treating agile as lacking controls; instead look for security requirements in the backlog, definition of done, and sprint acceptance criteria
  • ▸Assuming fixed-price contracts remove all risk; scope changes, unclear requirements, and vendor disputes remain
  • ▸Accepting testing evidence without traceability to requirements, or ignoring data migration and rollback plans

Practice set

Information Systems Acquisition, Development, and Implementation questions

20 questions · select your answer, then reveal the explanation

Which THREE of the following are essential elements of an emergency change request? (Select three.)

An IS auditor is reviewing a vendor's SOC 2 report as part of a systems acquisition. Which TWO aspects should the auditor verify to ensure the report is reliable?

An organization is considering replacing its legacy financial system with a new ERP solution. Which of the following is the PRIMARY advantage of purchasing a commercial off-the-shelf (COTS) ERP package over building a custom system?

During a spiral model SDLC project, an IS auditor is reviewing risk assessment documentation. Which of the following would be the GREATEST concern?

An organization is deciding between developing a custom application and purchasing a commercial off-the-shelf (COTS) product. The project manager favors a COTS solution because it offers faster deployment. Which of the following is the MOST important consideration for the IS auditor to evaluate in this build vs. buy decision?

During an SDLC audit, the IS auditor finds that security requirements were not formally documented during the requirements phase. Which of the following is the BEST recommendation to mitigate the associated risk?

An IS auditor is reviewing an emergency change that was implemented to fix a critical security vulnerability. Which of the following post-implementation controls is MOST important to ensure the change was properly managed?

An IS auditor is reviewing a contract for a new software solution. Which of the following contract types poses the HIGHEST risk to the buyer if requirements are not well-defined?

During an ERP implementation, the project team decides to disable segregation of duties (SoD) controls in the system to accelerate go-live. After go-live, the IS auditor identifies that a single user can perform incompatible functions. What is the BEST course of action?

An IS auditor is reviewing vendor management practices for a cloud-based SaaS solution. Which TWO of the following are critical elements to include in the contract's service level agreement (SLA)? (Select TWO.)

An IS auditor is reviewing an agile software development project. Which of the following is the most important control to assess?

Which of the following is an example of a detective control in the SDLC testing phase?

An IS auditor is reviewing an agile project. Which THREE of the following are controls the auditor should evaluate?

During a change management audit, the IS auditor notes that an emergency change was implemented to fix a critical security vulnerability. Which of the following should the auditor expect to find in the change documentation?

An IS auditor is evaluating the change management process for a critical financial application. The auditor finds that all standard changes are approved by the Change Advisory Board (CAB). However, emergency changes are approved by the IT manager and later ratified by the CAB. Which of the following is the greatest risk associated with this process?

An IS auditor is reviewing an agile software development project. Which TWO controls should the auditor expect to see in place?

An IS auditor is reviewing a project to replace a legacy claims processing system with a new cloud-based SaaS solution. The project team has completed the business case and feasibility study. Which of the following should be the auditor's PRIMARY concern at this stage?

An IS auditor is reviewing the implementation of a new payroll system. The project manager has decided to use a pilot conversion approach, running the new system in parallel with the legacy system for one pay cycle. Which of the following is the MOST significant risk associated with this approach?

During an audit of a software development project, the IS auditor finds that the project team is using a DevOps approach with continuous integration and continuous deployment (CI/CD). Which of the following controls is MOST important to ensure the integrity of code changes in this environment?

An IS auditor is reviewing the testing phase of a new system development project. The project team has conducted unit testing and system testing. Which TWO of the following additional tests are MOST important to ensure the system is ready for production? (Choose two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Information Systems Acquisition, Development, and Implementation sessions

Start a Information Systems Acquisition, Development, and Implementation only practice session

Every question in these sessions is drawn from the Information Systems Acquisition, Development, and Implementation domain — nothing else.

Related practice questions

Related CISA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CISA exam test about Information Systems Acquisition, Development, and Implementation?
Be able to select the best audit evidence and identify the greatest risk across acquisition, development, and implementation. The single most important thing is linking every control and test back to approved requirements, and confirming changes are authorized, tested, and approved before production.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Information Systems Acquisition, Development, and Implementation questions in a focused session?
Yes — the session launcher on this page draws every question from the Information Systems Acquisition, Development, and Implementation domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CISA topics?
Use the topic links above to move to related areas, or go back to the CISA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CISA exam covers. They are not copied from any real exam or dump site.