โ† All CISA Flashcard Decks

System Development and Implementation Flashcards

7 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 System Development and Implementation flashcards as text
  1. An IS auditor is assessing a project that used prototyping as its development approach. The PRIMARY risk of this methodology is:

    Answer: Insufficient technical documentation and scope creep

    Prototyping can lead to inadequate formal documentation and uncontrolled scope expansion as stakeholders continually request enhancements to the prototype.

  2. Which of the following BEST describes the role of configuration management in system development?

    Answer: Controlling and tracking changes to software components and their versions

    Configuration management ensures that software components are versioned, tracked, and controlled so that any version can be reproduced and changes are auditable.

  3. An organization implements a new payroll system in parallel with the legacy system for two pay cycles. The PRIMARY purpose of parallel operations is to:

    Answer: Validate that the new system produces correct results by comparing outputs

    Parallel operations allow organizations to compare outputs from both systems, confirming the new system's accuracy before full cutover.

  4. During a CISA audit of the testing phase, an auditor discovers that developers performed their own integration testing with no independent review. This violates the principle of:

    Answer: Segregation of duties

    Segregation of duties requires that testing be performed or reviewed independently from development to ensure objectivity and catch biases.

  5. A key output of the feasibility study phase in SDLC is:

    Answer: A business case assessing technical, economic, and operational viability

    The feasibility study produces a business case that evaluates whether a proposed system is technically achievable, economically justified, and operationally suitable.

  6. An IS auditor reviewing system retirement (decommissioning) should PRIMARILY confirm that:

    Answer: Data retention requirements are met and data is migrated or archived per policy

    Compliance with data retention policies and proper archiving or migration of historical data is the primary risk when retiring a system.

  7. When auditing a DevOps environment, which control is MOST critical to verify regarding the deployment pipeline?

    Answer: That automated security scans and approval gates are embedded in the CI/CD pipeline

    Embedding automated security scans and approval gates in the CI/CD pipeline ensures every deployment is vetted for vulnerabilities and authorized before reaching production.