Courseiva
easyMultiple Select

CISA Practice Question: Which THREE of the following are typical phases…

Which THREE of the following are typical phases in the system development life cycle (SDLC)?

⚠ Common exam trap

Candidates often confuse operational activities like patch management or specific testing techniques with the high-level phases of the SDLC, leading candidates to select activities that occur post-deployment or are sub-steps of a phase.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementation.

The SDLC is commonly modeled as a sequence of phases such as requirements gathering/analysis, design, development, testing, implementation/deployment, and maintenance. Option D (Requirements analysis) is correct because it is the phase where business and functional needs are elicited, documented, and validated, forming the basis for all later work. Option E (Design) is correct because it translates the approved requirements into system architecture, components, interfaces, and detailed specifications before coding begins. Option B (Implementation) is correct because it is the phase in which the designed system is built, coded, tested at the unit level, and deployed into production or a target environment. Option A (Unit testing) is a testing activity performed within the development/implementation phase rather than a distinct top-level SDLC phase, and Option C (Patch management) is an ongoing IT operations/maintenance process for applying vendor fixes, not a standard SDLC phase.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Unit testing.

    Why it's wrong here

    Unit testing is a technique performed within the testing phase, not a phase itself. It is tempting because testing is a recognised SDLC phase and unit testing is a core part of it, but the phases are requirements gathering, design, development, testing, implementation and maintenance; unit testing sits inside testing rather than standing as a separate phase.

  • ✓

    Implementation.

    Why this is correct

    Implementation is a recognised SDLC phase in which the designed system is coded, configured and deployed into the production environment. It follows design and precedes testing and maintenance, forming the build stage of the lifecycle.

  • ✗

    Patch management.

    Why it's wrong here

    Patch management is an ongoing operational activity performed after deployment, not an SDLC phase such as requirements, design, development, testing or implementation. It is tempting because patching does occur during maintenance, but maintenance covers enhancements and fixes, whereas patching is a recurring task within that phase, not a phase itself.

  • ✓

    Requirements analysis.

    Why this is correct

    Requirements analysis is a recognised SDLC phase that elicits, documents and validates business and functional needs before design begins. Its outputs, such as the requirements specification, provide the baseline against which later design, testing and acceptance are measured.

  • ✓

    Design.

    Why this is correct

    Design is a recognised SDLC phase that translates approved requirements into system architecture, data models, interfaces and detailed specifications. It sits between requirements analysis and implementation, giving developers the blueprint they build and test against.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.