
Certified Information Systems Auditor
Domain 3Objective 6
Implementation Configuration and Release Management CISA Practice Questions (Page 5)
Part of the Information Systems Acquisition, Development and Implementation domain, which accounts for 12% of the CISA exam.
32questions here
7free pages
8concepts
12%of the exam
Questions 21–25
- 21
When should a post-implementation review typically be conducted?
Select an answer first - 22
A development team is using a version control system to manage a critical application. The team has a policy that all changes must be reviewed before merging into the main branch. However, a developer accidentally merges a change without review. The change introduces a security vulnerability. What is the MOST appropriate action?
Select an answer first - 23
What is the primary purpose of a post-implementation review?
Select an answer first - 24
An organization is implementing a new financial system. The project team has been making changes to the system configuration without going through the change management process. The internal audit team has identified this as a risk. What is the MOST appropriate control to address this risk?
Select an answer first - 25
In the configuration management process, which activity involves defining and documenting the characteristics of each configuration item, such as its name, version, and owner?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by ISACA. “CISA” is a trademark of its owner, used for identification only.