Inspirational journeys

Follow the stories of academics and their research expeditions

CISA—Certified Information Systems Auditor - Part 227

Mary Smith

Sat, 18 Apr 2026

CISA—Certified Information Systems Auditor - Part 227

1. During which of the following phases in system development would user acceptance test plans normally be prepared?

A) Feasibility study
B) Requirements definition
C) implementation planning
D) Postimplementation review



2. The use of object-oriented design and development techniques would MOST likely:

A) facilitate the ability to reuse modules.
B) improve system performance.
C) enhance control effectiveness.
D) speed up the system development life cycle.



3. Which of the following should be included in a feasibility study for a project to implement an EDI process?

A) The encryption algorithm format
B) The detailed internal control procedures
C) The necessary communication protocols
D) The proposed trusted third-party agreement



4. When a new system is to be implemented within a short time frame, it is MOST important to:

A) finish writing user manuals.
B) perform user acceptance testing.
C) add last-minute enhancements to functionalities.
D) ensure that the code has been documented and reviewed.



5. An organization has contracted with a vendor for a turnkey solution for their electronic toll collection system (ETCS). The vendor has provided its proprietary application software as part of the solution. The contract should require that:

A) a backup server be available to run ETCS operations with up-to-date data.
B) a backup server be loaded with all the relevant software and data.
C) the systems staff of the organization be trained to handle any event.
D) source code of the ETCS application be placed in escrow.



1. Right Answer: B
Explanation: During requirements definition, the project team will be working with the users to define their precise objectives and functional needs. At this time, the users should be working with the team to consider and document hot the system functionality can be tested ensure it meets their stated needs. The feasibility study is too early for such detailed user involvement, and the implementation planning and postimplementation review phases are too late. An IS auditor should know at what point user testing should be planned to ensure it is most effective and efficient.

2. Right Answer: A
Explanation: One of the major benefits of object-oriented design and development is the ability to reuse modules. The other options do not normally benefit from the object- oriented technique.

3. Right Answer: C
Explanation: Encryption algorithms, third-party agreements and internal control procedures are too detailed for this phase. They would only be outlined and any cost or performance implications shown. The communications protocols must be included, as there may be significant cost implications if new hardware and software are involved, and risk implications if the technology is new to the organization.

4. Right Answer: B
Explanation: It would be most important to complete the user acceptance testing to ensure that the system to be implemented is working correctly. The completion of the user manuals is similar to the performance of code reviews. If time is tight, the last thing one would want to do is add another enhancement, as it would be necessary to freeze the code and complete the testing, then make any other changes as future enhancements. It would be appropriate to have the code documented and reviewed, but unless the acceptance testing is completed, there is no guarantee that the system will work correctly and meet user requirement.

5. Right Answer: D
Explanation: Whenever proprietary application software is purchased, the contract should provide for a source code agreement. This will ensure that the purchasing company will have the opportunity to modify the software should the vendor cease to be in business. Having a backup server with current data and staff training is critical but not as critical as ensuring the availability of the source code.

0 Comments

Leave a comment