CISA Certified Information Systems Auditor – Question2818

Which of the following should an IS auditor review to gain an understanding of the effectiveness of controls over the management of multiple projects?

A.
Project database
B. Policy documents
C. Project portfolio database
D. Program organization

Correct Answer: C

Explanation:

Explanation:
A project portfolio database is the basis for project portfolio management. It includes project data, such as owner, schedules, objectives, project type, status and cost. Project portfolio management requires specific project portfolio reports. A project database may contain the above for one specific project and updates to various parameters pertaining to the current status of that single project. Policy documents on project management set direction for the design, development, implementation and monitoring of the project. Program organization is the team required (steering committee, quality assurance, systems personnel, analyst, programmer, hardware support, etc.) to meet the delivery objective of the project.

CISA Certified Information Systems Auditor – Question2817

Which of the following is a characteristic of timebox management?

A.
Not suitable for prototyping or rapid application development (RAD)
B. Eliminates the need for a quality process
C. Prevents cost overruns and delivery delays
D. Separates system and user acceptance testing

Correct Answer: C

Explanation:

Explanation:
Timebox management, by its nature, sets specific time and cost boundaries. It is very suitable for prototyping and RAD, and integrates system and user acceptance testing, but does not eliminate the need for a quality process.

CISA Certified Information Systems Auditor – Question2816

When planning to add personnel to tasks imposing time constraints on the duration of a project, which of the following should be revalidated FIRST?

A.
The project budget
B. The critical path for the project
C. The length of the remaining tasks
D. The personnel assigned to other tasks

Correct Answer: B

Explanation:

Explanation:
Since adding resources may change the route of the critical path, the critical path must be reevaluated to ensure that additional resources will in fact shorten the project duration. Given that there may be slack time available on some of the other tasks not on the critical path, factors such as the project budget, the length of other tasks and the personnel assigned to them may or may not be affected.

CISA Certified Information Systems Auditor – Question2815

An IS auditor finds that a system under development has 12 linked modules and each item of data can carry up to 10 definable attribute fields. The system handles several million transactions a year. Which of these techniques could an IS auditor use to estimate the size of the development effort?

A.
Program evaluation review technique (PERT)
B. Counting source lines of code (SLOC)
C. Function point analysis
D. White box testing

Correct Answer: C

Explanation:

Explanation:
Function point analysis is an indirect method of measuring the size of an application by considering the number and complexity of its inputs, outputs and files. It is useful for evaluating complex applications. PERT is a project management technique that helps with both planning and control. SLOC gives a direct measure of program size, but does not allow for the complexity that may be caused by having multiple, linked modules and a variety of inputs and outputs. White box testing involves a detailed review of the behavior of program code, and is a quality assurance technique suited to simpler applications during the design and build stage of development.

CISA Certified Information Systems Auditor – Question2814

Change control for business application systems being developed using prototyping could be complicated by the:

A.
iterative nature of prototyping.
B. rapid pace of modifications in requirements and design.
C. emphasis on reports and screens.
D. lack of integrated tools.

Correct Answer: B

Explanation:

Explanation:
Changes in requirements and design happen so quickly that they are seldom documented or approved. Choices A, C and D are characteristics of prototyping, but they do not have an adverse effect on change control.

CISA Certified Information Systems Auditor – Question2813

The reason for establishing a stop or freezing point on the design of a new system is to:

A.
prevent further changes to a project in process.
B. indicate the point at which the design is to be completed.
C. require that changes after that point be evaluated for cost-effectiveness.
D. provide the project management team with more control over the project design.

Correct Answer: C

Explanation:

Explanation:
Projects often have a tendency to expand, especially during the requirements definition phase. This expansion often grows to a point where the originally anticipated cost-benefits are diminished because the cost of the project has increased. When this occurs, it is recommended that the project be stopped or frozen to allow a review of all of the cost- benefits and the payback period.

CISA Certified Information Systems Auditor – Question2812

Many IT projects experience problems because the development time and/or resource requirements are underestimated. Which of the following techniques would provide the GREATEST assistance in developing an estimate of project duration?

A.
Function point analysis
B. PERT chart
C. Rapid application development
D. Object-oriented system development

Correct Answer: B

Explanation:

Explanation:
A PERT chart will help determine project duration once all the activities and the work involved with those activities are known. Function point analysis is a technique for determining the size of a development task based on the number of function points. Function points are factors such as inputs, outputs, inquiries, logical internal files, etc. While this will help determine the size of individual activities, it will not assist in determining project duration since there are many overlapping tasks. Rapid application development is a methodology that enables organizations to develop strategically important systems faster while reducing development costs and maintaining quality, while object-oriented system development is the process of solution specification and modeling.

CISA Certified Information Systems Auditor – Question2811

The most common reason for the failure of information systems to meet the needs of users is that:

A.
user needs are constantly changing.
B. the growth of user requirements was forecast inaccurately.
C. the hardware system limits the number of concurrent users.
D. user participation in defining the system's requirements was inadequate.

Correct Answer: D

Explanation:

Explanation:
Lack of adequate user involvement, especially in the system’s requirements phase, will usually result in a system that does not fully or adequately address the needs of the user. Only users can define what their needs are, and therefore what the system should accomplish.

CISA Certified Information Systems Auditor – Question2810

Which of the following risks could result from inadequate software baselining?

A.
Scope creep
B. Sign-off delays
C. Software integrity violations
D. inadequate controls

Correct Answer: A

Explanation:

Explanation:
A software baseline is the cut-off point in the design and development of a system beyond which additional requirements or modifications to the design do not or cannot occur without undergoing formal strict procedures for approval based on a business costbenefit analysis. Failure to adequately manage the requirements of a system through baselining can result in a number of risks. Foremost among these risks is scope creep, the process through which requirements change during development. Choices, C and D may not always result, but choice A is inevitable.

CISA Certified Information Systems Auditor – Question2809

Documentation of a business case used in an IT development project should be retained until:

A.
the end of the system's life cycle.
B. the project is approved.
C. user acceptance of the system.
D. the system is in production.

Correct Answer: A

Explanation:

Explanation:
A business case can and should be used throughout the life cycle of the product. It serves as an anchor for new (management) personnel, helps to maintain focus and provides valuable information on estimates vs. actuals. Questions like, ‘why do we do that’,
‘What was the original intent’ and ‘how did we perform against the plan’ can be answered, and lessons for developing future business cases can be learned. During the development phase of a project one should always validate the business case, as it is a good management instrument. After finishing a project and entering production, the business case and all the completed research are valuable sources of information that should be kept for further reference