CISA Practice Question: Information Systems Acquisition, Development, and Implementation
Which TWO of the following are typical controls in the testing phase of the SDLC? (Select two.)
⚠ Common exam trap
CISA often tests the confusion between design-phase controls (threat modeling), development-phase controls (code reviews), and testing-phase controls (DAST, UAT), so candidates must map each control to the correct SDLC phase.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Security testing (DAST/pen test)
Security testing such as DAST and penetration testing (C) is a typical testing-phase control because it validates the running application against vulnerabilities after code is built, exercising the deployed system rather than the design. User acceptance testing (E) is also a testing-phase control, as it verifies the completed system meets business requirements and is fit for release before go-live. Rollback plan testing (A) belongs to change/release management or deployment readiness, not the SDLC testing phase. Code reviews (B) are a build/development-phase control performed on source code before or during integration. Threat modeling (D) is a design-phase activity that identifies threats and mitigations before code is written.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rollback plan testing
Why it's wrong here
Rollback plan testing belongs to implementation and post-implementation review, where recovery procedures are rehearsed before go-live. It is tempting because rollback readiness genuinely matters, but it is validated during deployment preparation, not within the testing phase's verification of code against requirements.
- ✗
Code reviews
Why it's wrong here
Code reviews are a construction-phase control, performed on source before the build is released to testers. They are tempting because they detect defects early, yet the testing phase verifies executed software against requirements, so static inspection of code sits outside its scope.
- ✓
Security testing (DAST/pen test)
Why this is correct
Security testing such as dynamic application security testing and penetration testing probes the running application for exploitable weaknesses during the testing phase. It verifies that security requirements are implemented before go-live, satisfying the testing-phase control criterion rather than development or operations.
- ✗
Threat modeling
Why it's wrong here
Threat modelling is a design-phase activity, identifying threats against architecture before code exists. It is tempting because it improves security assurance, but the testing phase executes the built system; threat modelling precedes development rather than validating the completed artefact.
- ✓
User acceptance testing (UAT)
Why this is correct
User acceptance testing validates that the built system meets business requirements and is fit for purpose before release. Conducted by end users against realistic scenarios, UAT is a testing-phase control confirming functional suitability, distinct from design, development or post-implementation review activities.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.