CISA Practice Question: Information Systems Acquisition, Development, and Implementation
Which THREE of the following are typical controls in the design phase of the SDLC?
⚠ Common exam trap
CISA often tests whether candidates can correctly place security activities into the right SDLC phase, luring them into selecting code review or UAT because those sound security-adjacent when they actually belong to later phases.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Designing security controls
Option A (Designing security controls) is correct because the design phase is exactly where security requirements are translated into concrete controls such as encryption schemes, authentication mechanisms, and access control models before any code is written. Option B (Architecture review) is correct because reviewing the proposed system architecture during design ensures that structural weaknesses, trust boundaries, and integration points are evaluated and corrected early, when changes are cheapest. Option D (Threat modeling) is correct because threat modeling is a design-phase activity that systematically identifies threats, attack vectors, and mitigations against the planned architecture and data flows. Option C (Code review) does not belong because it occurs during the implementation or development phase, after code exists to inspect. Option E (User acceptance testing) does not belong because UAT is a testing/validation activity performed late in the SDLC, after the system is built, to confirm it meets business requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Designing security controls
Why this is correct
The design phase translates requirements into technical specifications, so designing security controls here embeds confidentiality, integrity and availability measures into the solution before coding begins. Addressing security at design prevents costly retrofitting and satisfies the SDLC control objective of proactive risk mitigation.
- ✓
Architecture review
Why this is correct
Architecture review during design validates that the proposed structure aligns with enterprise standards, integrates with existing systems and supports scalability and resilience. Conducting it before construction begins satisfies the design phase's control objective of confirming the solution's technical soundness prior to costly development.
- ✗
Code review
Why it's wrong here
Code review examines implemented source code during development or testing, after design artefacts are produced. It is tempting because secure design principles influence what reviewers check, but review is a build-phase control; design-phase controls include requirements traceability, design walkthroughs and threat modelling.
- ✓
Threat modeling
Why this is correct
Threat modelling during design systematically identifies potential attack vectors and weaknesses in the proposed architecture, allowing mitigations to be built in rather than patched later. This satisfies the design phase's control objective of anticipating security risks before code is written.
- ✗
User acceptance testing
Why it's wrong here
User acceptance testing validates the finished system against business requirements during testing or implementation, after design is baselined. It is tempting because acceptance criteria are defined during design, but executing UAT is a later-phase control, not a design-phase control such as design reviews or security architecture sign-off.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.