Need for End-User Testing in Packaged Software?

System Development & IT Procurement
Answer Correct answer: B — Acquiring packaged software reduces end-user testing requirements compared to in-house development because vendors perform foundational quality assurance upfront.

Compared to developing a system in-house, acquiring a software package means that the need for testing by end users is:

  1. increased.
  2. reduced. Correct Answer
  3. eliminated.
  4. unchanged.

Community Votes

B
50%
D
50%

50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests your understanding of procurement trade-offs, with the common trap being the confusion between vendor quality assurance and the complete elimination of end-user validation.

Acquiring packaged software reduces the end-user testing burden compared to custom development, as vendors handle foundational quality assurance before delivery. Community consensus aligns with option B, recognizing that outsourcing shifts but does not erase acceptance testing obligations.

Option D (unchanged) is frequently selected under the assumption that User Acceptance Testing scales identically across both sourcing models, overlooking the significant reduction in core functionality validation provided by the vendor.

Community Discussion (3 comments)

veli_117 👍 1 Selected: D
Although acquired systems are tested by the vendor prior to distribution, these systems and any subsequent changes should be tested thoroughly by the end user and the system maintenance staff.
MJORGER 👍 1 Selected: B
B. reduced When a business acquires a software package, it’s typically already been tested extensively by the vendor, so the need for end-user testing is generally reduced.
Sibsankar 👍 1
A is right

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Acquiring packaged software significantly reduces the end-user testing burden because the vendor has already conducted extensive unit and system testing. ISACA guidelines emphasize that outsourcing development shifts foundational validation responsibilities away from internal teams, allowing end users to focus solely on business-fit verification rather than rebuilding test cases from scratch.

Why the Other Options Are Wrong

Option A is incorrect because purchasing software eliminates custom coding phases, which inherently lowers total testing volume rather than increasing it. Option C fails because acceptance testing remains mandatory to verify integration, security configurations, and workflow alignment. Option D is a frequent trap, assuming User Acceptance Testing scales identically across both models, while ignoring the substantial baseline testing already completed by the vendor.

Community Comment Notes

The voting split between options B and D reflects ongoing debate among candidates regarding audit standards. Comment [1] argues for option D by emphasizing that thorough end-user validation is still required post-acquisition. Conversely, comment [2] correctly identifies that vendor-pretested functionality naturally reduces the overall testing scope, aligning with official CISA review material expectations.

Exam Strategy

When evaluating IT procurement scenarios, always distinguish between vendor-provided quality assurance and mandatory business acceptance testing. Remember that while packaged solutions streamline development, your audit checklist must still account for configuration validation and integration testing before go-live.

Frequently Asked Questions

Why isn't end-user testing completely eliminated?

Vendors only test standard functionality. You must still validate integration, workflows, and business-specific requirements through acceptance testing.

Is testing effort truly unchanged for packaged software?

No. While User Acceptance Testing remains mandatory, overall testing volume drops significantly since core code and bug fixes are handled by the vendor.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide