nerdexam
Isaca

CRISC · Question #357

Which of the following should be of MOST concern to a risk practitioner reviewing the system development life cycle (SDLC)?

The correct answer is D. Testing is completed by IT support users without input from end users.. The absence of end-user involvement in testing during the SDLC is a significant concern for a risk practitioner, as it increases the risk of deploying a system that fails to meet actual business needs or contains undetected usability and functional defects.

Submitted by devops_kid· Apr 18, 2026IT Risk Assessment

Question

Which of the following should be of MOST concern to a risk practitioner reviewing the system development life cycle (SDLC)?

Options

  • ATesting is completed in phases, with user testing scheduled as the final phase.
  • BSegregation of duties controls are overridden during user testing phases.
  • CData anonymization is used during all cycles of end-user testing.
  • DTesting is completed by IT support users without input from end users.

How the community answered

(31 responses)
  • A
    13% (4)
  • B
    6% (2)
  • C
    3% (1)
  • D
    77% (24)

Why each option

The absence of end-user involvement in testing during the SDLC is a significant concern for a risk practitioner, as it increases the risk of deploying a system that fails to meet actual business needs or contains undetected usability and functional defects.

ATesting is completed in phases, with user testing scheduled as the final phase.

Phased testing with user testing as a final phase is a common and acceptable SDLC practice, allowing for incremental validation.

BSegregation of duties controls are overridden during user testing phases.

Temporarily overriding segregation of duties controls during specific, controlled user testing phases might be necessary for practical testing purposes, provided proper oversight and logging are in place, and is less of a concern than lack of user input itself.

CData anonymization is used during all cycles of end-user testing.

Data anonymization in end-user testing is a good practice for privacy and data protection, reducing risk rather than being a concern.

DTesting is completed by IT support users without input from end users.Correct

If testing is solely performed by IT support users without input from end users, there is a high risk that the system will not meet the actual business requirements, contain functional errors, or have usability issues, leading to operational inefficiencies and potential security vulnerabilities that could have been identified by those who use the system daily.

Concept tested: SDLC testing best practices

Source: https://learn.microsoft.com/en-us/azure/cloud-adoption-framework/plan/testing-and-validation

Topics

#SDLC#User Acceptance Testing#IT Risk Assessment#Testing Strategy

Community Discussion

No community discussion yet for this question.

Full CRISC Practice