Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

Which TWO of the following are characteristics of the iterative SDLC model?

⚠ Common exam trap

CISA often tests whether candidates can distinguish iterative SDLC characteristics (feedback per iteration, multiple cycles) from waterfall characteristics (upfront requirements, single delivery, initial risk analysis).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

User feedback is incorporated after each iteration

Option B is correct because the iterative SDLC model builds the product in repeated cycles, and after each iteration the working increment is reviewed with users so their feedback can be incorporated into the next iteration. Option D is correct because the defining trait of the iterative model is that the system is developed and refined through multiple cycles, with each cycle producing a progressively more complete version of the product. Options A, C, and E describe characteristics of plan-driven or waterfall-style approaches rather than iterative development: delivering the final product only at the end (A) and freezing detailed requirements at the start (C) reflect a single-pass sequential model, and performing risk analysis only at the beginning (E) contradicts the iterative practice of reassessing risks in each cycle.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The final product is delivered only at the end of the project

    Why it's wrong here

    Iterative SDLC produces working increments each iteration, so value is delivered progressively rather than once at closure. It is tempting because sequential waterfall does defer delivery to a single final release, making this statement accurate for waterfall but contradicting the iterative model's incremental delivery.

  • ✓

    User feedback is incorporated after each iteration

    Why this is correct

    Each iteration ends with a working increment that users evaluate, and their feedback shapes the next cycle's requirements and design. This continuous user involvement is a defining trait of iterative development, satisfying the stem's requirement for a characteristic of that model.

  • ✗

    Requirements are defined in detail at the start of the project

    Why it's wrong here

    Iterative development deliberately defers detailed requirements, elaborating them incrementally each cycle, so fixing them upfront contradicts the model's core premise. It is tempting because waterfall does specify requirements fully at project start, and that upfront certainty is genuinely valuable when scope is stable and regulatory sign-off demands it.

  • ✓

    The system is developed and refined through multiple cycles

    Why this is correct

    Iterative development repeats the full lifecycle through successive cycles, each producing a refined build. This cyclical repetition is the defining structural trait that distinguishes it from linear waterfall, satisfying the stem's requirement for a characteristic of the iterative SDLC model.

  • ✗

    Risk analysis is performed only at the beginning

    Why it's wrong here

    Iterative SDLC revisits risk analysis each cycle as requirements and designs evolve; confining it to inception matches waterfall's phase-gated approach. It is tempting because early risk assessment is genuinely valuable, and front-loading it is correct in a predictive waterfall project with frozen requirements.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.