CISA Practice Question: Information Systems Acquisition, Development, and Implementation
Which TWO of the following are characteristics of the iterative SDLC model?
⚠ Common exam trap
CISA often tests whether candidates can distinguish iterative SDLC characteristics (feedback per iteration, multiple cycles) from waterfall characteristics (upfront requirements, single delivery, initial risk analysis).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
User feedback is incorporated after each iteration
Option B is correct because the iterative SDLC model builds the product in repeated cycles, and after each iteration the working increment is reviewed with users so their feedback can be incorporated into the next iteration. Option D is correct because the defining trait of the iterative model is that the system is developed and refined through multiple cycles, with each cycle producing a progressively more complete version of the product. Options A, C, and E describe characteristics of plan-driven or waterfall-style approaches rather than iterative development: delivering the final product only at the end (A) and freezing detailed requirements at the start (C) reflect a single-pass sequential model, and performing risk analysis only at the beginning (E) contradicts the iterative practice of reassessing risks in each cycle.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The final product is delivered only at the end of the project
Why it's wrong here
Iterative SDLC produces working increments each iteration, so value is delivered progressively rather than once at closure. It is tempting because sequential waterfall does defer delivery to a single final release, making this statement accurate for waterfall but contradicting the iterative model's incremental delivery.
- ✓
User feedback is incorporated after each iteration
Why this is correct
Each iteration ends with a working increment that users evaluate, and their feedback shapes the next cycle's requirements and design. This continuous user involvement is a defining trait of iterative development, satisfying the stem's requirement for a characteristic of that model.
- ✗
Requirements are defined in detail at the start of the project
Why it's wrong here
Iterative development deliberately defers detailed requirements, elaborating them incrementally each cycle, so fixing them upfront contradicts the model's core premise. It is tempting because waterfall does specify requirements fully at project start, and that upfront certainty is genuinely valuable when scope is stable and regulatory sign-off demands it.
- ✓
The system is developed and refined through multiple cycles
Why this is correct
Iterative development repeats the full lifecycle through successive cycles, each producing a refined build. This cyclical repetition is the defining structural trait that distinguishes it from linear waterfall, satisfying the stem's requirement for a characteristic of the iterative SDLC model.
- ✗
Risk analysis is performed only at the beginning
Why it's wrong here
Iterative SDLC revisits risk analysis each cycle as requirements and designs evolve; confining it to inception matches waterfall's phase-gated approach. It is tempting because early risk assessment is genuinely valuable, and front-loading it is correct in a predictive waterfall project with frozen requirements.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.