In a waterfall SDLC, when should user acceptance testing (UAT) typically occur?
In a waterfall SDLC, phases execute sequentially, so UAT follows completed system testing, confirming the built system meets business requirements before release. Placing it after system testing and before deployment satisfies the stem's waterfall sequencing constraint, ensuring defects are caught prior to production cutover.
Why this answer
In a waterfall SDLC, UAT is the final validation step performed by end users after the system has been fully built and verified by the development team. System testing confirms the solution meets technical specifications, and only then do users validate it against business requirements in a production-like environment. Deployment follows only after users formally accept the system, ensuring defects are caught before go-live.
Exam trap
CISA often tests the sequencing of SDLC test phases, and candidates confuse UAT with system testing or place it after deployment because they conflate 'acceptance' with 'post-implementation review'.
How to eliminate wrong answers
Option A is wrong because UAT after deployment defeats its purpose — defects would already be in production and remediation costs escalate dramatically. Option B is wrong because UAT cannot occur before unit testing; unit testing validates individual modules and must precede integration, system, and acceptance testing in the V-model sequence. Option D is wrong because the requirements phase produces the acceptance criteria used later in UAT, not the test execution itself — UAT requires a built system to validate against.