Courseiva

CISA Practice Question: Information Systems Acquisition, Development, and Implementation

Which TWO of the following are key elements of a change request document?

⚠ Common exam trap

CISA often tests whether candidates confuse supporting documents (contracts, budgets, manuals) with the intrinsic elements of a change request—candidates pick budget because cost impact feels relevant, but the budget itself is not an RFC component.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Justification

Option B (Justification) is correct because a change request must state the business or technical reason the change is needed, so the change advisory board (CAB) can assess its value and priority before approval. Option D (Rollback plan) is correct because every change request must document how to revert the change if it fails or causes an outage, which is essential for risk mitigation and restoring the configuration item to its prior baseline. A vendor contract (A) is a procurement/legal artifact, not a standard component of a change request. A project budget (C) relates to financial planning and cost control, not to the change management process itself. A user manual (E) is end-user documentation and has no role in defining or approving a change.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Vendor contract

    Why it's wrong here

    A vendor contract governs procurement terms and sits outside the change request, which documents the change itself. It is tempting because contracts are referenced when a change alters licensed or supported components, but they belong to procurement records, not the request's scope, justification, risk and rollback details.

  • ✓

    Justification

    Why this is correct

    Justification records the business or technical reason the change is needed, letting the Change Advisory Board weigh benefit against risk and cost. Without it, approvers cannot judge whether the change is warranted, so the document fails its decision-support purpose.

  • ✗

    Project budget

    Why it's wrong here

    Project budget tracks overall funding and sits outside the change request, which documents the specific change. It is tempting because significant changes consume budget, so cost appears relevant, but financial tracking belongs to project accounting, not the request's scope, justification, risk and rollback details.

  • ✓

    Rollback plan

    Why this is correct

    A rollback plan defines how to revert the change if implementation fails or causes disruption, restoring the prior known-good state. It satisfies the change request's requirement for recoverability, limiting downtime and data integrity impact on production services.

  • ✗

    User manual

    Why it's wrong here

    A user manual documents end-user operation after deployment, so it cannot specify the change itself, its justification, impact analysis or approval. It is tempting because manuals are SDLC deliverables, and would be the correct artefact when the change request concerns documentation updates accompanying a release.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.