Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

Which testing type is performed by end-users to verify that the system meets their needs?

⚠ Common exam trap

Candidates often confuse user acceptance testing with system testing or integration testing, assuming any 'end-user' involvement means UAT, but UAT specifically requires users to validate business needs, not technical correctness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User acceptance testing

User acceptance testing (UAT) is the final phase of the testing lifecycle where actual end-users validate that the system fulfills their business requirements and is ready for production deployment. Unlike technical testing types, UAT focuses on real-world workflows, data accuracy, and usability to confirm the system meets the agreed-upon acceptance criteria.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Security testing

    Why it's wrong here

    Security testing assesses vulnerabilities, access controls and resilience, not whether the system fulfils user needs. It is tempting because it is a recognised test type often mandated before go-live, making it correct for assurance or compliance scenarios, but it does not gather end-user acceptance.

  • ✗

    Integration testing

    Why it's wrong here

    Integration testing verifies interfaces between combined modules and is executed by developers or testers during construction, not by end-users. It is tempting because it validates that components work together, which suits system-integration scenarios, but it cannot confirm the delivered system satisfies user needs.

  • ✓

    User acceptance testing

    Why this is correct

    User acceptance testing is executed by end-users themselves, directly satisfying the stem's requirement that testing be performed by end-users. It validates the system against business needs and real-world workflows rather than technical specifications, confirming fitness for purpose before go-live. This distinguishes it from unit, integration and system testing, which developers or testers conduct.

  • ✗

    Unit testing

    Why it's wrong here

    Unit testing validates individual components in isolation and is performed by developers, not end-users. It is tempting because it catches defects early at code level, making it correct during development, but it never exercises the complete system against user requirements.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.