Courseiva
mediumMultiple Select

CISA Practice Question: Which TWO of the following are key benefits of…

Which TWO of the following are key benefits of using a system development life cycle (SDLC) methodology? (Select exactly two.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It provides a structured approach to system development

Option A is correct because an SDLC methodology provides a structured, phased approach (such as requirements, design, development, testing, and deployment) that organizes and governs how a system is built, giving repeatability and control over the process. Option B is correct because SDLC methodologies explicitly include requirements-gathering and validation phases, ensuring user and stakeholder requirements are captured, documented, and confirmed before and during development. Option C is incorrect because SDLC methodologies do not prevent scope changes; they provide change-control mechanisms to manage scope changes, which can and do still occur. Option D is incorrect because security testing remains necessary and is typically integrated into SDLC phases (e.g., during testing or via secure development practices), not eliminated. Option E is incorrect because while an SDLC can improve efficiency and reduce rework costs, it does not guarantee a reduction in overall development cost, so this is not a key guaranteed benefit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    It provides a structured approach to system development

    Why this is correct

    A structured approach directly satisfies the need for control and repeatability across development phases. By defining discrete stages — requirements, design, build, test, deploy — SDLC enforces consistent governance, review gates and documentation, reducing ad hoc decisions and unmanaged scope creep that undermine auditability and security assurance.

  • ✓

    It ensures user requirements are captured and validated

    Why this is correct

    SDLC phases such as requirements definition and user acceptance testing formalise elicitation and sign-off, so stakeholder needs are documented and verified before build. This reduces rework and scope creep, directly satisfying the requirement-capture benefit the question asks for.

  • ✗

    It prevents any scope changes during development

    Why it's wrong here

    An SDLC governs how changes are assessed and approved; it does not forbid scope changes, which remain normal through controlled change management. It is tempting because baselined requirements feel fixed, but the methodology channels change rather than preventing it.

  • ✗

    It eliminates the need for security testing

    Why it's wrong here

    Security testing remains mandatory within an SDLC; the methodology structures when testing occurs, it does not remove the activity. It is tempting because shifting security left can feel like testing becomes automatic, but the phases still require explicit verification before release.

  • ✗

    It reduces the overall cost of development

    Why it's wrong here

    Cost reduction is a genuine SDLC benefit, achieved through earlier defect detection and reduced rework. However, this question asks for two benefits and this option is not among the expected pair, so selecting it displaces a required answer.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.