ISACA CISA — Certified Information Systems Auditor · Domain 3 · 12% of exam

Information Systems Acquisition, Development and Implementation

Drill 18 practice questions focused entirely on Information Systems Acquisition, Development and Implementation for the ISACA CISA exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer18 questions
Question 1 of 18

An organization is replacing its core inventory management system. Project management has selected an abrupt (direct) changeover on a weekend, decommissioning the legacy system immediately once the new system goes live. As the IS auditor reviewing the implementation plan, which aspect should raise the GREATEST concern?

Reviewed for accuracy · Report an issue
Question 2 of 18

An IS auditor is reviewing an agile software development project. The development team completes sprints every two weeks and demonstrates working features to stakeholders. However, the auditor notices that several completed user stories lacked documented acceptance criteria before development began, and defects related to these stories are frequently found only after release to production. Which of the following is the auditor's BEST recommendation to address the root cause?

Reviewed for accuracy · Report an issue
Question 3 of 18

An IS auditor is reviewing the initiation phase of a proposed customer relationship management (CRM) system replacement. The project charter has been drafted and a preliminary budget approved, but the auditor notes that the organization proceeded directly to vendor selection. Which of the following, if MISSING, would represent the MOST significant control weakness in the project initiation process?

Reviewed for accuracy · Report an issue
Question 4 of 18

During the implementation of a new customer billing system, historical account balances are being migrated from the legacy system. Which control provides the BEST assurance that the converted data in the new system is complete and accurate?

Reviewed for accuracy · Report an issue
Question 5 of 18

During the implementation phase of a new order-management system, an IS auditor observes that the project team has completed unit testing of individual modules and is preparing for the next testing stage. The team wants to verify that data passed between the newly coded order-entry module and the inventory module behaves correctly when the modules operate together. Which type of testing should the team perform NEXT to address this concern?

Reviewed for accuracy · Report an issue
Question 6 of 18

During the planning phase of a large in-house application development project, the project manager needs to estimate the development effort before design specifications are finalized. Management wants an estimation approach that is based on the functionality delivered to the user rather than on the volume of code, so that estimates remain independent of the programming language and technology chosen. Which technique BEST meets this requirement?

Reviewed for accuracy · Report an issue
Question 7 of 18

An IS auditor is reviewing a large system development project managed with a predictive (waterfall) methodology. The project manager reports that a non-critical task on the network diagram has slipped by three days but insists the overall delivery date is unaffected. Which of the following is the MOST important factor for the auditor to verify before accepting this assertion?

Reviewed for accuracy · Report an issue
Question 8 of 18

An organization is replacing its legacy payroll system with a new cloud-based solution. The payroll director insists that no employee should ever receive an incorrect or delayed paycheck during the transition, and management is willing to accept higher operational cost and effort to guarantee this. Which changeover technique should the IS auditor expect the project team to recommend?

Reviewed for accuracy · Report an issue
Question 9 of 18

An organization is replacing its legacy order-management system with a new platform. Due to limited resources and a desire to reduce operational risk, management decides to migrate one regional business unit at a time over several months, keeping the legacy system running for units not yet cut over. During the audit of this implementation, which control is MOST important for the IS auditor to verify is in place?

Reviewed for accuracy · Report an issue
Question 10 of 18

A new customer relationship management (CRM) system went live six weeks ago and has been running smoothly. Management asks the IS auditor when a post-implementation review (PIR) should be conducted to be most effective. What is the BEST advice?

Reviewed for accuracy · Report an issue
Question 11 of 18

An organization has chosen a prototyping approach to develop a new customer-facing web application because business requirements are not yet fully defined. During the audit, the IS auditor is asked to identify the GREATEST risk associated with using this development methodology in this situation.

Reviewed for accuracy · Report an issue
Question 12 of 18

An IS auditor is reviewing a large predictive (waterfall) software development project nearing the testing phase. The auditor wants to verify that every approved business requirement has been correctly addressed by the design, built into the code, and validated during testing. Which artifact would BEST enable the auditor to confirm this?

Reviewed for accuracy · Report an issue
Question 13 of 18

During the development of a new customer portal, the project team decides to integrate with a 20-year-old core banking system using screen-scraping because the legacy system has no documented APIs. An IS auditor reviewing the design should be MOST concerned that this approach:

Reviewed for accuracy · Report an issue
Question 14 of 18

An IS auditor is invited to participate in a large system development project that is using a predictive (waterfall) methodology. The auditor wants the involvement to be most effective at ensuring that appropriate application controls are built into the system. At which point should the auditor's review have the GREATEST impact on control design?

Reviewed for accuracy · Report an issue
Question 15 of 18

During a review of a large predictive software development project, an IS auditor finds that developers can move their code changes directly into the test and production libraries without any formal review or tracking of what was moved. Which control weakness represents the GREATEST concern to the auditor?

Reviewed for accuracy · Report an issue
Question 16 of 18

During implementation of a new order-management system, the project team applied an emergency patch to fix a defect discovered in the pricing module just before go-live. The IS auditor is reviewing the test approach used before deploying the patch. Which testing activity is MOST important for the team to perform before releasing the patched system to production?

Reviewed for accuracy · Report an issue
Question 17 of 18

An IS auditor is reviewing a large in-house software development project that follows a predictive (waterfall) methodology. Management asks the auditor when application controls (such as input validation and reconciliation routines) should be identified and designed to be most cost-effective and to reduce rework. What should the auditor advise as the most appropriate point in the lifecycle?

Reviewed for accuracy · Report an issue
Question 18 of 18

A new customer billing system has completed system and integration testing performed by the development team. The project manager wants to proceed directly to production deployment to meet the go-live deadline. As the IS auditor reviewing the implementation controls, which activity is the MOST important control that should occur before deployment?

Reviewed for accuracy · Report an issue

More CISA practice

Keep going with the other ISACA CISA — Certified Information Systems Auditor domains, or take a full timed mock exam.

← Back to CISA overview