โ† All CISA Flashcard Decks

System Development and Implementation Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 System Development and Implementation flashcards as text
  1. An IS auditor reviewing software procurement should FIRST verify that the vendor's product:

    Answer: Meets the organization's defined functional and security requirements

    Alignment with documented requirements is the foundational criterion before evaluating cost, market share, or technology features.

  2. Which of the following BEST describes the purpose of a program change log?

    Answer: To provide an audit trail of all modifications made to production programs

    A program change log maintains a chronological record of who changed what and when, forming the audit trail for production program modifications.

  3. During a SDLC audit, an IS auditor notices that requirements sign-off was obtained from IT management only, excluding business users. This represents a weakness in:

    Answer: Requirements validation and stakeholder engagement

    Requirements must be approved by business stakeholders who will use the system, not just IT, to ensure the solution meets actual business needs.

  4. A software development team uses an iterative methodology where working software is delivered in short cycles. This BEST describes:

    Answer: Agile/Scrum development

    Agile/Scrum delivers working software in short, time-boxed sprints with frequent stakeholder feedback and iterative refinement.

  5. When auditing a data conversion during system migration, the IS auditor should PRIMARILY verify that:

    Answer: All data was accurately and completely transferred to the new system

    Data integrity and completeness during conversion is critical; any data loss or corruption directly impacts business continuity and reliability of the new system.

  6. An IS auditor finds that developers have direct access to the production environment. The MOST significant risk is:

    Answer: Unauthorized or untested changes could be made directly to production

    Direct developer access to production breaks segregation of duties and enables unauthorized modifications that bypass change control processes.

  7. In software project management, a critical path PRIMARILY helps an IS auditor assess:

    Answer: Which tasks, if delayed, will directly extend the project completion date

    The critical path identifies the sequence of dependent tasks with zero float, meaning any delay on these tasks delays the entire project.