Need for End-User Testing in Packaged Software?
Compared to developing a system in-house, acquiring a software package means that the need for testing by end users is:
Community Votes
50% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests your understanding of procurement trade-offs, with the common trap being the confusion between vendor quality assurance and the complete elimination of end-user validation.
Acquiring packaged software reduces the end-user testing burden compared to custom development, as vendors handle foundational quality assurance before delivery. Community consensus aligns with option B, recognizing that outsourcing shifts but does not erase acceptance testing obligations.
Option D (unchanged) is frequently selected under the assumption that User Acceptance Testing scales identically across both sourcing models, overlooking the significant reduction in core functionality validation provided by the vendor.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Acquiring packaged software significantly reduces the end-user testing burden because the vendor has already conducted extensive unit and system testing. ISACA guidelines emphasize that outsourcing development shifts foundational validation responsibilities away from internal teams, allowing end users to focus solely on business-fit verification rather than rebuilding test cases from scratch.Why the Other Options Are Wrong
Option A is incorrect because purchasing software eliminates custom coding phases, which inherently lowers total testing volume rather than increasing it. Option C fails because acceptance testing remains mandatory to verify integration, security configurations, and workflow alignment. Option D is a frequent trap, assuming User Acceptance Testing scales identically across both models, while ignoring the substantial baseline testing already completed by the vendor.Community Comment Notes
The voting split between options B and D reflects ongoing debate among candidates regarding audit standards. Comment [1] argues for option D by emphasizing that thorough end-user validation is still required post-acquisition. Conversely, comment [2] correctly identifies that vendor-pretested functionality naturally reduces the overall testing scope, aligning with official CISA review material expectations.Exam Strategy
When evaluating IT procurement scenarios, always distinguish between vendor-provided quality assurance and mandatory business acceptance testing. Remember that while packaged solutions streamline development, your audit checklist must still account for configuration validation and integration testing before go-live.
Frequently Asked Questions
Why isn't end-user testing completely eliminated?
Vendors only test standard functionality. You must still validate integration, workflows, and business-specific requirements through acceptance testing.
Is testing effort truly unchanged for packaged software?
No. While User Acceptance Testing remains mandatory, overall testing volume drops significantly since core code and bug fixes are handled by the vendor.
Related Analysis
Practice All CISA Questions
Access 400 questions with complete answers and detailed explanations.
View Full CISA Practice Test →