ISACA IT Acquisition, Development, and Implementation 2 — Questions and Answers
Question 1: When auditing application controls, which control type BEST ensures that all data entered into a system has been processed completely?
- Edit checks
- Sequence checks
- Batch totals (Correct answer)
- Hash totals
Correct answer: Batch totals
Batch totals compare the sum of input records to a predetermined control total, ensuring all records in the batch were fully processed.
Question 2: During data conversion from a legacy to a new system, which procedure is MOST important for ensuring data integrity?
- Compressing data to reduce storage requirements
- Performing parallel processing and reconciling results between systems (Correct answer)
- Deleting duplicate records prior to migration
- Converting all data to a single standardized format
Correct answer: Performing parallel processing and reconciling results between systems
Parallel processing runs both systems simultaneously and reconciles outputs to verify the new system produces accurate results consistent with the legacy system.
Question 3: User acceptance testing (UAT) is PRIMARILY performed by which group?
- IS auditors
- Development team members
- End users and business stakeholders (Correct answer)
- Quality assurance specialists
Correct answer: End users and business stakeholders
UAT is performed by end users and business stakeholders to confirm the system meets their operational requirements before go-live approval.
Question 4: Which configuration management practice BEST supports an audit trail for system changes?
- Maintaining a configuration management database (CMDB) (Correct answer)
- Requiring weekly backups of all configurations
- Limiting configuration access to only senior IT staff
- Encrypting all configuration files at rest
Correct answer: Maintaining a configuration management database (CMDB)
A CMDB tracks configuration items, their attributes, and their change history, providing a comprehensive record that supports audit trails and impact analysis.
Question 5: In an Agile development methodology, what is the PRIMARY audit concern compared to a traditional waterfall approach?
- Agile typically produces lower quality code
- Agile introduces more security vulnerabilities by default
- Documentation and formal change control may be less rigorous (Correct answer)
- Agile requires significantly more testing phases
Correct answer: Documentation and formal change control may be less rigorous
Agile's iterative and flexible nature may result in less formal documentation and change control, creating audit challenges around completeness and traceability.
Question 6: When auditing an outsourced software development arrangement, an IS auditor should PRIMARILY review which documentation?
- The vendor's office location and physical size
- Contract terms, SLAs, and right-to-audit clauses (Correct answer)
- The vendor's employee compensation structures
- Marketing materials provided by the vendor
Correct answer: Contract terms, SLAs, and right-to-audit clauses
Contract terms, SLAs, and right-to-audit clauses define vendor obligations and provide the legal basis for the auditor to assess vendor performance and controls.
Question 7: An effective patch management process should ENSURE which of the following practices?
- All patches are applied immediately upon vendor release
- Patches are tested in a non-production environment before deployment (Correct answer)
- Only security patches are required; performance patches are optional
- Patches are applied without management approval to minimize delay
Correct answer: Patches are tested in a non-production environment before deployment
Testing patches in a non-production environment before deployment ensures that untested updates do not disrupt or destabilize production systems.
When auditing application controls, which control type BEST ensures that all data entered into a system has been processed completely?