What this quiz covers
This quiz focuses on Evaluate System Acquisition And Implementation Controls, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
Which of the following is the most significant risk of implementing a new financial system without adequate parallel processing?
CPA Isc Quiz
Practice Evaluate System Acquisition And Implementation Controls in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.
This quiz focuses on Evaluate System Acquisition And Implementation Controls, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.
Which of the following is the most significant risk of implementing a new financial system without adequate parallel processing?
Explanation: Parallel processing runs both systems simultaneously, allowing comparison of outputs to detect discrepancies in the new system before fully committing to it. Without parallel processing, errors in the new system may not be identified until they affect financial reporting. Answer D is correct. License expiry (A), training (B), and vendor support (C) are operational concerns.
During an audit of a recent system implementation, the auditor finds no documented test plans, test scripts, or test results. The system is now in production processing live financial transactions. This finding indicates:
Explanation: Absence of test documentation means there is no evidence that the system was validated - the system may contain errors that will affect financial data integrity, and the risk cannot be assessed retroactively. Answer C is correct. Informal testing (A) leaves no evidence. It is not minor when the system is processing live transactions (B). System scope does not eliminate testing requirements (D).
Which of the following represents an effective control over interface testing during a system implementation?
Explanation: Interface testing requires actually transmitting test data through each interface and verifying end-to-end correctness - confirming that connected systems receive and process data accurately. Answer C is correct. Shared databases (A) are a design choice, not a testing control. Documentation (B, D) addresses design but not operational correctness.
Which of the following system conversion strategies carries the highest operational risk during a system implementation?
Explanation: Direct cutover is highest risk because there is no fallback - if the new system has problems, the organization cannot revert to the old system without significant disruption. Answer D is correct. Parallel (A) is lowest risk. Phased (B) and pilot (C) both provide controlled testing before full deployment.
During a system implementation, the project team discovers that a key interface between the new financial system and the bank reconciliation module cannot be completed before the planned go-live date. Which of the following is the most appropriate action?
Explanation: Incomplete critical interfaces require a formal risk decision - delay, workaround, or formal risk acceptance with compensating controls - not ad hoc deployment or elimination of testing. Answer A is correct. Deploying without resolving the issue (B) creates unacceptable operational risk. Cancellation (C) is an extreme measure. Eliminating testing (D) introduces additional uncontrolled risk.
An organization upgrades its financial system. The old chart of accounts has 500 accounts and the new system has a revised structure with 450 accounts. Which of the following migration controls is most important?
Explanation: An account mapping document ensures every historical account is correctly mapped to the new structure - preventing transaction history from being lost or misclassified. Testing validates the mapping before migration. Answer D is correct. Direct migration without mapping (A) risks misclassification. Random sampling (B) without a complete map doesn't validate coverage. Deleting the old data (C) before successful migration is premature.
An organization implements a new fixed asset system. The data migration brings over 5,000 asset records from the legacy system. An auditor tests the migration by comparing a sample of 50 records across key fields between the source and target systems. The auditor finds that 8 records have incorrect depreciation start dates in the new system. This finding indicates:
Explanation: A 16% error rate on a critical field (depreciation start dates directly affect depreciation calculations and financial reporting) in a sample suggests a systemic problem that likely affects many more records across the full population. Answer D is correct. 8/50 is a significant rate (A). Depreciation dates are critical for accurate expense reporting (B). Targeted remediation may be more efficient than full reversal (C).
During an IT audit, an auditor is evaluating controls over a system implementation completed six months ago. Which of the following audit procedures would most directly assess whether the implementation controls were effective?
Explanation: Project documentation review provides direct evidence of whether key implementation controls were applied - testing, migration validation, authorization, and lessons learned. Answer A is correct. Current access lists (B) reflect post-implementation state. Transaction testing (C) reflects current accuracy but not implementation controls specifically. SLA review (D) addresses ongoing operations.
Which of the following best describes the primary purpose of controls over system acquisition and implementation?
Explanation: System acquisition and implementation controls govern the entire lifecycle from selection through go-live, ensuring systems are authorized, tested, configured correctly, and deployed safely. Answer A is correct. Cost reduction (B), training (C), and licensing (D) are important considerations but not the primary control objective.
User acceptance testing (UAT) is performed during system implementation primarily to:
Explanation: UAT validates that the system does what the business needs it to do - verifying business requirements are met through user-led testing before the system is deployed to production. Answer C is correct. Technical benchmarks (A) are IT performance testing. Contract fulfillment (B) is a vendor management activity. Security testing (D) is a separate test phase.
A company is evaluating three ERP systems from different vendors. Which of the following represents a key control in the vendor selection process?
Explanation: A formal RFP with documented evaluation criteria ensures selection decisions are objective, risk-aware, and aligned to both business and technical requirements. Answer A is correct. Lowest cost (B) ignores TCO and risk. Competitor usage (C) may not fit the organization's specific needs. IT-only selection (D) lacks business alignment.
Which of the following system implementation controls most directly addresses the risk that configuration errors in a new financial system will produce incorrect transaction processing?
Explanation: Configuration testing with sample transactions directly validates that the system's setup produces correct outputs - the most targeted control for detecting configuration errors that could affect transaction accuracy. Answer C is correct. Confidentiality agreements (A) and penetration testing (B) address different risks. Legacy backup (D) is a data protection control, not a configuration validation control.
Which of the following represents a significant control weakness in a system implementation project?
Explanation: Having developers approve their own work and deploy to production without independent review eliminates segregation of duties - creating risk of undetected errors and unauthorized changes making it to production. Answer B is correct. Cross-functional teams (A), agile methodology (C), and mixed control types (D) are all appropriate practices.
An organization is implementing a new payroll system. Which of the following tests should be completed before go-live to specifically address the risk of incorrect payroll calculations?
Explanation: Parallel payroll calculation testing - running the new system with known test data and comparing outputs to manually computed expectations - directly validates calculation accuracy before production use. Answer A is correct. Security certifications (B), performance testing (C), and backup verification (D) are important but don't specifically test calculation accuracy.
Which of the following implementation controls specifically addresses the risk that historical financial data transferred from a legacy system contains errors that affect comparative period reporting?
Explanation: Reconciling migrated historical data to audited financial statements ensures comparative period data is accurate - directly addressing the risk of historical data errors in the new system. Answer B is correct. Training (A) addresses operational readiness. Encryption (C) addresses security. Archiving (D) addresses retention.
Which of the following best describes the purpose of regression testing during a system upgrade or enhancement?
Explanation: Regression testing ensures that changes introduced in an upgrade or enhancement did not inadvertently break existing functionality - a critical safeguard for complex systems where changes can have unintended consequences. Answer B is correct. Security testing (A) and new feature testing (D) are separate test types. Load testing (C) is performance testing.
During a system implementation project, which of the following represents a key control over data migration from the legacy system to the new system?
Explanation: Data migration reconciliation - comparing counts and totals between source and target - directly verifies that all data was transferred completely and accurately, the most critical migration control. Answer B is correct. Broad access (A) increases risk. Immediate deletion (C) eliminates the ability to verify and remediate. Untested migration (D) dramatically increases error risk.
An organization is implementing a cloud-based financial system as a SaaS solution. Which of the following implementation controls is uniquely important in a SaaS context?
Explanation: In a SaaS model, the organization cannot control infrastructure but is fully responsible for configuring application-level security, access controls, and data settings - a critical implementation control in cloud deployments. Answer B is correct. On-premises database configuration (A) is not applicable to SaaS. Local installation (C) is not how SaaS works. Physical server location (D) may be relevant for data residency but is not the most critical implementation control.
Which of the following represents a key control during the post-implementation phase of a system deployment?
Explanation: A PIR after go-live evaluates whether the system delivered its intended benefits, identifies post-production issues, and captures process improvements for future projects - closing the implementation lifecycle. Answer C is correct. Contract negotiations (A) and UAT (B) occur before go-live. Architecture documentation (D) should be completed during, not after, implementation.
Which of the following is a key control to prevent scope creep from compromising a system implementation project's integrity?
Explanation: A formal change control process for project scope ensures that any additions are evaluated for impact on timeline, budget, and quality - preventing uncontrolled expansion that can compromise implementation quality and budget. Answer B is correct. Unrestricted changes (A) cause scope creep. Complete rigidity (C) may prevent necessary refinements. IT-only decisions (D) lack business alignment.