Inspirational journeys

Follow the stories of academics and their research expeditions

CISA—Certified Information Systems Auditor - Part 233

Mary Smith

Sat, 18 Apr 2026

CISA—Certified Information Systems Auditor - Part 233

1. Which of the following is an implementation risk within the process of decision support systems?

A) Management control
B) Semistructured dimensions
C) inability to specify purpose and usage patterns
D) Changes in decision processes



2. An organization is implementing a new system to replace a legacy system. Which of the following conversion practices creates the GREATEST risk?

A) Pilot
B) Parallel
C) Direct cutover
D) Phased



3. Which of the following system and data conversion strategies provides the GREATEST redundancy?

A) Direct cutover
B) Pilot study
C) Phased approach
D) Parallel run



4. Which of the following would impair the independence of a quality assurance team?

A) Ensuring compliance with development methods
B) Checking the testing assumptions
C) Correcting coding errors during the testing process
D) Checking the code to ensure proper documentation



5. From a risk management point of view, the BEST approach when implementing a large and complex IT infrastructure is:

A) a big bang deployment after proof of concept.
B) prototyping and a one-phase deployment.
C) a deployment plan based on sequenced phases.
D) to simulate the new infrastructure before deployment.



1. Right Answer: C
Explanation: The inability to specify purpose and usage patterns is a risk that developers need to anticipate while implementing a decision support system (DSS). Choices A, B and D are not risks, but characteristics of a DDS.

2. Right Answer: C
Explanation: Direct cutover implies switching to the new system immediately, usually without the ability to revert to the old system in the event of problems. All other alternatives are done gradually and thus provide greater recoverability and are therefore less risky.

3. Right Answer: D
Explanation: Parallel runs are the safest-though the most expensive-approach, because both the old and new systems are run, thus incurring what might appear to be double costs. Direct cutover is actually quite risky, since it does not provide for a 'shake down period' nor does it provide an easy fallback option. Both a pilot study and a phased approach are performed incrementally, making rollback procedures difficult to execute.

4. Right Answer: C
Explanation: Correction of code should not be a responsibility of the quality assurance team as it would not ensure segregation of duties and would impair the team's independence. The other choices are valid quality assurance functions.

5. Right Answer: C
Explanation: When developing a large and complex IT infrastructure, the best practice is to use a phased approach to fitting the entire system together. This will provide greater assurance of quality results. The other choices are riskier approaches.

0 Comments

Leave a comment