Inspirational journeys

Follow the stories of academics and their research expeditions

CISA—Certified Information Systems Auditor - Part 217

Mary Smith

Sat, 18 Apr 2026

CISA—Certified Information Systems Auditor - Part 217

1. Which of the following is a characteristic of timebox management?

A) Not suitable for prototyping or rapid application development (RAD)
B) Eliminates the need for a quality process
C) Prevents cost overruns and delivery delays
D) Separates system and user acceptance testing



2. Which of the following should an IS auditor review to gain an understanding of the effectiveness of controls over the management of multiple projects?

A) Project database
B) Policy documents
C) Project portfolio database
D) Program organization



3. To minimize the cost of a software project, quality management techniques should be applied:

A) as close to their writing (i.e., point of origination) as possible.
B) primarily at project start-up to ensure that the project is established in accordance with organizational governance standards.
C) continuously throughout the project with an emphasis on finding and fixing defects primarily during testing to maximize the defect detection rate.
D) mainly at project close-down to capture lessons learned that can be applied to future projects.



4. When identifying an earlier project completion time, which is to be obtained by paying a premium for early completion, the activities that should be selected are those:

A) whose sum of activity time is the shortest.
B) that have zero slack time.
C) that give the longest possible completion time.
D) whose sum of slack time is the shortest.



5. At the completion of a system development project, a post project review should include which of the following?

A) Assessing risks that may lead to downtime after the production release
B) Identifying lessons learned that may be applicable to future projects
C) Verifying the controls in the delivered system are working
D) Ensuring that test data are deleted



1. Right Answer: C
Explanation: Timebox management, by its nature, sets specific time and cost boundaries. It is very suitable for prototyping and RAD, and integrates system and user acceptance testing, but does not eliminate the need for a quality process.

2. Right Answer: C
Explanation: A project portfolio database is the basis for project portfolio management. It includes project data, such as owner, schedules, objectives, project type, status and cost. Project portfolio management requires specific project portfolio reports. A project database may contain the above for one specific project and updates to various parameters pertaining to the current status of that single project. Policy documents on project management set direction for the design, development, implementation and monitoring of the project. Program organization is the team required (steering committee, quality assurance, systems personnel, analyst, programmer, hardware support, etc.) to meet the delivery objective of the project.

3. Right Answer: C
Explanation: While it is important to properly establish a software development project, quality management should be effectively practiced throughout the project. The major source of unexpected costs on most software projects is rework. The general rule is that the earlier in the development life cycle that a defect occurs, and the longer it takes to find and fix that defect, the more effort will be needed to correct it. A well-written quality management plan is a good start, but it must also be actively applied. Simply relying on testing to identify defects is a relatively costly and less effective way of achieving software quality. For example, an error in requirements discovered in the testing phase can result in scrapping significant amounts of work. Capturing lessons learned will be too late for the current project.Additionally, applying quality management techniques throughout a project is likely to yield its own insights into the causes of quality problems and assist in staff development.

4. Right Answer: B
Explanation: A critical path's activity time is longer than that for any other path through the network. This path is important because if everything goes as scheduled, its length gives the shortest possible completion time for the overall project. Activities on the critical path become candidates for crashing, i.e., for reduction in their time by payment of a premium for early completion. Activities on the critical path have zero slack time and conversely, activities with zero slack time are on a critical path.By successively relaxing activities on a critical path, a curve showing total project costs vs. time can be obtained.

5. Right Answer: B
Explanation: A project team has something to learn from each and every project. As risk assessment is a key issue for project management, it is important for the organization to accumulate lessons learned and integrate them into future projects. An assessment of potential downtime should be made with the operations group and other specialists before implementing a system. Verifying that controls are working should be covered during the acceptance test phase and possibly, again, in the post implementation review. Test data should be retained for future regression testing.

0 Comments

Leave a comment