nerdexam
Isaca

CRISC · Question #2

An organization has made a decision to purchase a new IT system. During when phase of the system development life cycle (SDLC) will identified risk MOST likely lead to architecture and design trade- o

The correct answer is C. Initiation. During the Initiation phase of the SDLC, identified risks are most likely to lead to architecture and design trade-offs because fundamental system requirements and feasibility are still being defined.

Submitted by kavita_s· Apr 18, 2026IT Risk Assessment

Question

An organization has made a decision to purchase a new IT system. During when phase of the system development life cycle (SDLC) will identified risk MOST likely lead to architecture and design trade- offs?

Options

  • AAcquisition
  • BImplementation
  • CInitiation
  • DOperation and maintenance

How the community answered

(41 responses)
  • A
    5% (2)
  • B
    7% (3)
  • C
    85% (35)
  • D
    2% (1)

Why each option

During the Initiation phase of the SDLC, identified risks are most likely to lead to architecture and design trade-offs because fundamental system requirements and feasibility are still being defined.

AAcquisition

The Acquisition phase involves purchasing decisions, which typically occur after architecture and design choices have largely been solidified, making trade-offs at this point more costly.

BImplementation

The Implementation phase involves building or configuring the system based on established designs; making fundamental architecture changes at this stage is highly disruptive and expensive.

CInitiationCorrect

The Initiation phase is where high-level requirements are defined and feasibility is assessed; identifying risks at this early stage allows for fundamental architectural and design adjustments or trade-offs to be made without incurring significant rework costs associated with later phases.

DOperation and maintenance

The Operation and maintenance phase is post-deployment, where major architecture and design modifications due to newly identified risks are extremely costly and can significantly impact ongoing business operations.

Concept tested: SDLC risk integration

Source: https://learn.microsoft.com/en-us/compliance/regulatory/offering-fedramp-nist-800-53-security-assessment-framework#system-development-life-cycle-sdlc-security

Topics

#SDLC Phases#Risk Integration#System Architecture#Design Trade-offs

Community Discussion

No community discussion yet for this question.

Full CRISC Practice