System Development and Implementation Flashcards
7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 System Development and Implementation flashcards as text
Which of the following is the PRIMARY objective of a structured walkthrough during system development?
Answer: Peer review of code or design to identify defects early
Structured walkthroughs are formal peer review sessions designed to detect errors in design, code, or documentation before they propagate to later phases.
An IS auditor reviewing system documentation finds that no operations manual exists for a newly implemented system. The PRIMARY concern is:
Answer: Operations staff may be unable to maintain or recover the system properly
Without an operations manual, staff lack the guidance needed for routine operations, troubleshooting, and disaster recovery, increasing operational risk.
During application testing, what is the MAIN purpose of boundary value analysis?
Answer: Testing input values at the edges of valid ranges where defects are most likely
Boundary value analysis tests values at, just below, and just above defined input limits, where programming errors are most commonly found.
A company outsources its application development to a third-party vendor. Which control is MOST important for the IS auditor to verify?
Answer: Contractual rights to audit the vendor and review deliverables
Contractual audit rights ensure the organization retains oversight of vendor activities, code quality, and security practices throughout the engagement.
The MOST effective control to prevent SQL injection vulnerabilities in a newly developed web application is:
Answer: Using parameterized queries and input validation in application code
Parameterized queries separate SQL logic from user-supplied data, preventing malicious input from being interpreted as SQL commands.
When reviewing an Agile development project, an IS auditor should be MOST concerned if:
Answer: Security and compliance requirements are consistently deferred to later sprints
Continuously deferring security and compliance work creates technical debt and may result in a system that fails regulatory requirements at launch.
An IS auditor evaluating a software quality assurance program should expect to find metrics that track:
Answer: Defect density, test coverage, and open defect aging
Defect density, test coverage, and defect aging are key quality indicators that reflect the reliability and completeness of testing efforts.