Domain 3: Information Systems Acquisition, Development, and Implementation - PART 3B Flashcards

1
Q

An advantage in using a bottom-up vs. a top-down approach to software testing is that:

A

errors in critical modules are detected earlier.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

An advantage of using sanitized live transactions in test data is that:

A

test transactions are representative of live processing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

At the completion of a system development project, a post-project review should include which of the following?

A

Identifying lessons learned that may be applicable to future projects

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

At the end of the testing phase of software development, an IS auditor observes that an intermittent software error has NOT been corrected. No action has been taken to resolve the error. The IS auditor should:

A

recommend that problem resolution be escalated.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Change control for business application systems being developed using prototyping could be complicated by the:

A

rapid pace of modifications in requirements and design.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A company has contracted with an external consulting firm to implement a commercial financial system to replace its existing system developed in-house. In reviewing the proposed development approach, which of the following would be of GREATEST concern?

A

A quality plan is not part of the contracted deliverables.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

During a post-implementation review of an enterprise resource management system, an IS auditor would MOST likely:

A

review access control configuration.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

During a postimplementation review, which of the following activities should be performed?

A

Return on investment analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

During the development of an application, quality assurance testing and user acceptance testing were combined. The MAJOR concern for an IS auditor reviewing the project is that there will be:

A

improper acceptance of a program.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

During the requirements definition stage of a proposed enterprise resource planning system, the project sponsor requests that the procurement and accounts payable modules be linked. Which of the following test methods would be the BEST to perform?

A

Integration testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

During the system testing phase of an application development project the IS auditor should review the:

A

error reports.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

During which of the following phases in system development would user acceptance test plans normally be prepared?

A

Requirements definition

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

During which phase of software application testing should an organization perform the testing of architectural design?

A

Integration testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

An enterprise is developing a new procurement system, and things are behind schedule. As a result, it is proposed that the time originally planned for the test phase be shortened. The project manager asks the IS auditor for recommendations to mitigate the risk associated with reduced testing. Which of the following is a suitable risk mitigation strategy?

A

Test and release a pilot with reduced functionality.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

A failure discovered in which of the following testing stages would have the GREATEST impact on the implementation of new application software?

A

Acceptance testing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

From a risk management point of view, the BEST approach when implementing a large and complex IT infrastructure is:

A

a deployment plan based on sequenced phases.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Functionality is a characteristic associated with evaluating the quality of software products throughout their life cycle, and is BEST described as the set of attributes that bear on the:

A

existence of a set of functions and their specified properties.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

The GREATEST advantage of rapid application development over the traditional system development life cycle is that it:

A

shortens the development time frame.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Ideally, stress testing should be carried out in a:

A

test environment using live workloads.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

An IS audit group has been involved in the integration of an automated audit tool kit with an existing enterprise resource planning system. Due to performance issues, the audit tool kit is not permitted to go live. What should the IS auditor’s BEST recommendation be?

A

Review the results of stress tests during user acceptance testing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

An IS auditor finds that a system under development has 12 linked modules and each item of data can carry up to 10 definable attribute fields. The system handles several million transactions a year. Which of these techniques could an IS auditor use to estimate the size of the development effort?

A

Function point analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
22
Q

An IS auditor finds that user acceptance testing of a new system is being repeatedly interrupted by defect fixes from the developers. Which of the following would be the BEST recommendation for an IS auditor to make?

A

Consider the feasibility of a separate user acceptance environment.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
23
Q

An IS auditor has been asked to review the implementation of a customer relationship management system for a large organization. The IS auditor discovered the project incurred significant over-budget expenses and scope creep caused the project to miss key dates. Which of the following should the IS auditor recommend for future projects?

A

A software baseline

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
24
Q

An IS auditor is involved in the reengineering process that aims to optimize IT infrastructure. Which of the following will BEST identify the issues to be resolved?

A

Gap analysis

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
25
Q

An IS auditor is reviewing an enterprise’s system development testing policy. Which of the following statements concerning use of production data for testing would the IS auditor consider to be MOST appropriate?

A

Senior IS and business management must approve use before production data can be used for testing.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
26
Q

An IS auditor is reviewing a project for the implementation of a mission-critical system and notes that, instead of parallel implementation, the team opted for an immediate cutover to the new system. Which of the following is the GREATEST concern?

A

The implementation phase of the project has no back out plan.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
27
Q

An IS auditor is reviewing a project that is using an agile software development approach. Which of the following should the IS auditor expect to find?

A

Post iteration reviews that identify lessons learned for future use in the project

28
Q

The IS auditor is reviewing a recently completed conversion to a new enterprise resource planning system. In the final stage of the conversion process, the organization ran the old and new systems in parallel for 30 days before allowing the new system to run on its own. What is the MOST significant advantage to the organization by using this strategy?

A

Assurance that the new system meets functional requirements

29
Q

An IS auditor is reviewing system development for a health care organization with two application environments—production and test. During an interview, the auditor notes that production data are used in the test environment to test program changes. What is the MOST significant potential risk from this situation?

A

The test environment may not have adequate access controls implemented to ensure data confidentiality.

30
Q

An IS auditor is reviewing the software development process for an organization. Which of the following functions are appropriate for the end users to perform?

A

Program output testing

31
Q

An IS auditor’s PRIMARY concern when application developers wish to use a copy of yesterday’s production transaction file for volume tests is that:

A

unauthorized access to sensitive data may result.

32
Q

The knowledge base of an expert system that uses questionnaires to lead the user through a series of choices before a conclusion is reached is known as:

A

decision trees.

33
Q

A legacy payroll application is migrated to a new application. Which of the following stakeholders should be PRIMARILY responsible for reviewing and signing-off on the accuracy and completeness of the data before going live?

A

Data owner

34
Q

An organization is implementing a new system to replace a legacy system. Which of the following conversion practices creates the GREATEST risk?

A

Direct cutover

35
Q

An organization is migrating from a legacy system to an enterprise resource planning system. While reviewing the data migration activity, the MOST important concern for the IS auditor is to determine that there is a:

A

correlation of semantic characteristics of the data migrated between the two systems.

36
Q

An organization is replacing a payroll program that it developed in-house, with the relevant subsystem of a commercial enterprise resource planning (ERP) system. Which of the following would represent the HIGHEST potential risk?

A

Faulty migration of historical data from the old system to the new system

37
Q

An organization recently deployed a customer relationship management application that was developed in-house. Which of the following is the BEST option to ensure that the application operates as designed?

A

Post- implementation review

38
Q

The PRIMARY objective of conducting a post-implementation review for a business process automation project is to:

A

ensure that the project meets the intended business requirements.

39
Q

The PRIMARY objective of performing a postincident review is that it presents an opportunity to:

A

improve internal control procedures.

40
Q

The PRIMARY purpose of a post- implementation review is to ascertain that:

A

project objectives have been met.

41
Q

A project development team is considering using production data for its test deck. The team removed sensitive data elements from the bed before loading it into the test environment. Which of the following additional concerns should an IS auditor have with this practice?

A

Not all functionality will be tested.

42
Q

Regression testing is undertaken PRIMARILY to ensure that:

A

applied changes have not introduced new errors.

43
Q

Results of a post-implementation review indicate that only 75 percent of the users can log in to the application concurrently. Which of the following could have BEST discovered the identified weakness of the application?

A

Load testing

44
Q

A small company cannot segregate duties between its development processes and its change control function. What is the BEST way to ensure that the tested code that is moved into production is the same?

A

Release management software

45
Q

The specific advantage of white box testing is that it:

A

determines procedural accuracy or conditions of a program’s specific logic paths.

46
Q

What is the BEST method to facilitate successful user testing and acceptance of a new enterprise resource planning payroll system that is replacing an existing legacy system?

A

Parallel testing

47
Q

What is the PRIMARY reason that an IS auditor would verify that the process of post-implementation review of an application was completed after a release?

A

To check that the project meets expectations

48
Q

What kind of software application testing is considered the final stage of testing and typically includes users outside of the development team?

A

Beta testing

49
Q

When a new system is to be implemented within a short time frame, it is MOST important to:

A

perform user acceptance testing.

50
Q

When reviewing input controls, an IS auditor observes that, in accordance with corporate policy, procedures allow supervisory override of data validation edits. The IS auditor should:

A

ensure that overrides are automatically logged and subject to review.

51
Q

When two or more systems are integrated, the IS auditor must review input/output controls in the:

A

systems sending and receiving data.

52
Q

Which of the following BEST helps an IS auditor assess and measure the value of a newly implemented system?

A

Post- implementation review

53
Q

Which of the following carries the LOWEST risk when managing failures while transitioning from legacy applications to new applications?

A

Parallel changeover

54
Q

Which of the following has the MOST significant impact on the success of an application systems implementation?

A

The overall organizational environment

55
Q

Which of the following helps an IS auditor evaluate the quality of new software that is developed and implemented?

A

The first report of the mean time between failures

56
Q

Which of the following is an advantage of an integrated test facility (ITF)?

A

Periodic testing does not require separate test processes.

57
Q

Which of the following is an advantage of the top-down approach to software testing?

A

Interface errors are identified early.

58
Q

Which of the following is MOST critical when creating data for testing the logic in a new or modified application system?

A

Data representing conditions that are expected in actual processing

59
Q

Which of the following is of GREATEST concern to an IS auditor when performing an audit of a client relationship management (CRM) system migration project?

A

A single implementation is planned, immediately decommissioning the legacy system.

60
Q

Which of the following is the BEST approach to ensure that sufficient test coverage will be achieved for a project with a strict end date and a fixed time to perform testing?

A

Requirements should be tested in terms of importance and frequency of use.

61
Q

Which of the following is the BEST indicator that a newly developed system will be used after it is in production?

A

User acceptance testing

62
Q

Which of the following is the PRIMARY purpose for conducting parallel testing?

A

To ensure the new system meets user requirements

63
Q

Which of the following software testing methods provides the BEST feedback on how software will perform in the live environment?

A

Beta testing

64
Q

Which of the following system and data conversion strategies provides the GREATEST redundancy?

A

Parallel run

65
Q

Which of the following test techniques would the IS auditor use to identify specific program logic that has not been tested?

A

Mapping

66
Q

Which of the following types of testing would determine whether a new or modified system can operate in its target environment without adversely impacting other existing systems?

A

Sociability testing

67
Q

Which testing approach is MOST appropriate to ensure that internal application interface errors are identified as soon as possible?

A

Top-down testing