Question 302 of 995
hardMultiple ChoiceObjective-mapped
UAT Defect Handling — Impact Analysis Before Fix
During the user acceptance testing (UAT) phase of a new financial application, the business users report that the system calculates interest incorrectly for certain loan types. The project manager wants to fix this quickly. Which of the following is the BEST course of action?
Quick Answer
The correct answer is to log the defect and perform impact analysis before approving a fix. This is because the UAT defect handling process demands that any reported issue, especially one affecting financial calculations, must be formally documented and assessed for its potential ripple effects on existing functionality, data integrity, and regulatory compliance before any code change is made. On the CISA exam, this scenario tests your understanding of change management controls during the final validation phase, where the focus shifts from speed to risk mitigation; a common trap is choosing to fix immediately to satisfy the project manager, which bypasses the structured impact analysis required to prevent cascading failures in a live-like environment. Remember the mnemonic “LIP” — Log, Impact, then Proceed — to reinforce that in UAT, a quick fix without analysis is a compliance risk, not a solution.
⚠ Common exam trap
It's easy for candidates to choose Option B (immediate fix) because it seems efficient, but CISA emphasizes that any change during UAT must follow a controlled process to avoid introducing new risks, especially in financial systems where accuracy and auditability are paramount.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Log the defect and perform impact analysis before approving a fix
In the UAT phase, any defect must be formally logged and subjected to impact analysis before a fix is approved. This ensures that the proposed change does not introduce new risks, break other functionality, or violate regulatory compliance—critical for a financial application handling interest calculations. Skipping this process could lead to cascading failures or audit findings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Instruct the business to work around the issue until the next release
Why it's wrong here
Does not solve the problem.
- ✗
Authorize the development team to fix the bug immediately and re-deploy
Why it's wrong here
Skipping change control introduces risk.
- ✗
Roll back to the previous version of the application
Why it's wrong here
May not address the root cause.
- ✓
Log the defect and perform impact analysis before approving a fix
Why this is correct
Ensures proper change management.
About these practice questions
Courseiva creates original exam-style practice questions with explanations and wrong-answer analysis. It does not publish real exam questions, exam dumps, or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An organization is implementing a new financial system and has completed user acceptance testing (UAT). The project manager reports that all critical defects have been fixed and retested, but several low-severity issues remain unresolved. What is the BEST course of action?
medium- ✓ A.Document the unresolved defects as known issues in a risk acceptance form with a remediation plan, then proceed with go-live
- B.Re-run all UAT test cases to ensure no regression occurs
- C.Delay go-live until all defects are resolved
- D.Obtain sign-off from business stakeholders acknowledging the risks and proceed with go-live
Why A: In a financial system implementation, low-severity issues that do not impair core financial processing or controls can be accepted as known risks. Documenting them with a remediation plan and proceeding with go-live aligns with ISACA’s guidance that UAT sign-off does not require zero defects, only that critical and high-severity defects are resolved. This approach balances business needs with risk management, avoiding unnecessary delays while ensuring accountability through formal risk acceptance.
Variation 2. An organization is implementing a custom ERP system. During user acceptance testing (UAT), critical bugs are found that affect core financial processing. The project sponsor suggests deploying the system on schedule and fixing bugs after go-live. What is the BEST course of action?
medium- ✓ A.Delay go-live until all critical bugs are resolved and UAT is successfully completed
- B.Go live as planned and fix bugs post-implementation
- C.Accept the bugs with documented risk acceptance from management
- D.Go live but include a rollback plan and deploy fixes immediately
Why A: Deploying an ERP system with unresolved critical bugs in core financial processing violates the fundamental principle of system integrity and accuracy. UAT must be successfully completed to validate that the system meets business requirements and processes financial transactions correctly; going live with known critical defects introduces unacceptable risk of financial misstatement, regulatory non-compliance, and data corruption. Delaying go-live ensures that all critical bugs are resolved and retested, preserving the reliability of financial data and audit trails.
Last reviewed: Jun 11, 2026
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.
Question Discussion
Share a tip, memory trick, or ask about the reasoning behind this question. Do not post real exam questions, leaked content, braindumps, or copyrighted exam material. Comments are moderated and may be removed without notice.
Sign in to join the discussion.