Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

Which THREE of the following are typical controls in the design phase of the SDLC?

⚠ Common exam trap

CISA often tests whether candidates can correctly place security activities into the right SDLC phase, luring them into selecting code review or UAT because those sound security-adjacent when they actually belong to later phases.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Designing security controls

Option A (Designing security controls) is correct because the design phase is exactly where security requirements are translated into concrete controls such as encryption schemes, authentication mechanisms, and access control models before any code is written. Option B (Architecture review) is correct because reviewing the proposed system architecture during design ensures that structural weaknesses, trust boundaries, and integration points are evaluated and corrected early, when changes are cheapest. Option D (Threat modeling) is correct because threat modeling is a design-phase activity that systematically identifies threats, attack vectors, and mitigations against the planned architecture and data flows. Option C (Code review) does not belong because it occurs during the implementation or development phase, after code exists to inspect. Option E (User acceptance testing) does not belong because UAT is a testing/validation activity performed late in the SDLC, after the system is built, to confirm it meets business requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Designing security controls

    Why this is correct

    The design phase translates requirements into technical specifications, so designing security controls here embeds confidentiality, integrity and availability measures into the solution before coding begins. Addressing security at design prevents costly retrofitting and satisfies the SDLC control objective of proactive risk mitigation.

  • ✓

    Architecture review

    Why this is correct

    Architecture review during design validates that the proposed structure aligns with enterprise standards, integrates with existing systems and supports scalability and resilience. Conducting it before construction begins satisfies the design phase's control objective of confirming the solution's technical soundness prior to costly development.

  • ✗

    Code review

    Why it's wrong here

    Code review examines implemented source code during development or testing, after design artefacts are produced. It is tempting because secure design principles influence what reviewers check, but review is a build-phase control; design-phase controls include requirements traceability, design walkthroughs and threat modelling.

  • ✓

    Threat modeling

    Why this is correct

    Threat modelling during design systematically identifies potential attack vectors and weaknesses in the proposed architecture, allowing mitigations to be built in rather than patched later. This satisfies the design phase's control objective of anticipating security risks before code is written.

  • ✗

    User acceptance testing

    Why it's wrong here

    User acceptance testing validates the finished system against business requirements during testing or implementation, after design is baselined. It is tempting because acceptance criteria are defined during design, but executing UAT is a later-phase control, not a design-phase control such as design reviews or security architecture sign-off.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.