
CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Information Systems Acquisition, Development and Implementation.
Question
A CISA auditor is evaluating an organization's software development process. Developers occasionally introduce insecure code that is only discovered during release testing, causing delays. Which control would most effectively detect code vulnerabilities early and ensure consistent remediation tracking?
Show the answer and explanation
Correct answer: C. Integrate SAST into the continuous integration (CI) pipeline and block builds for critical or high findings
Integrating SAST into the CI pipeline with build gating for critical/high findings is best because it automates early detection, enforces consistent policy, and creates traceable results within the development workflow so remediation can be tracked. Requiring developers to run local SAST helps but relies on individual compliance and lacks centralized enforcement and audit trails. Quarterly external assessments are periodic and too infrequent to prevent insecure code from entering releases. Manual reviews by the security team before release create a bottleneck, are resource-intensive, and still detect issues late in the lifecycle.
Want more practice?
Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.
