What is the greatest concern when key UAT scenarios are untested?

Information Systems Acquisition, Development, and Implementation
Answer Correct answer: B — Untested UAT scenarios mean system functions may not meet business requirements, the direct purpose UAT is meant to confirm.

Shortly after a system was deployed into production, it was identified that some key scenarios were not tested during user acceptance testing (UAT). Which of the following is the GREATEST concern with this situation?

  1. The system may have gone into production with defects.
  2. System functions may not meet business requirements. Correct Answer
  3. Significant security risks may not have been assessed.
  4. Extra funding may be required to complete the testing.

Community Votes

B
67%
C
33%

67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the fundamental objective of UAT — validating that system functions meet business requirements — while the trap is treating UAT as if it existed primarily for security or defect finding.

What is the greatest concern when UAT scenarios are skipped before production? This CISA practice question walks through the answer choices and confirms that the system may not meet business requirements (B) because UAT is a business-acceptance validation.

Choosing C and focusing on security risk is common, but UAT is not the primary vehicle for security risk assessment; its purpose is to confirm that business and functional requirements are satisfied.

Community Discussion (4 comments)

blehbleh 👍 1 Selected: B
This is B.
RS66 👍 1 Selected: B
B. System functions may not meet business requirements.
Binagr8 👍 1
It is B. A. Defects: While defects are a concern, UAT primarily focuses on ensuring the system fulfills its intended purpose according to user needs. Unforeseen defects might still exist, but untested functionalities related to business requirements are a bigger risk. The core purpose of UAT is to validate if the system fulfills the needs of the users and aligns with the business goals. Untested key scenarios raise the biggest concern that the system might not be meeting those expectations.
joehong 👍 1 Selected: C
C. Significant security risks may not have been assessed.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The greatest concern is that key user acceptance scenarios were never executed, so the organization cannot confirm that the system actually satisfies the agreed business requirements. UAT is the formal checkpoint designed precisely to determine whether a system meets users' needs; when critical areas are omitted, a positive acceptance decision was never genuinely established. This makes B the strongest answer because "System functions may not meet business requirements" is not a downstream inference but the direct purpose UAT exists to serve.

Why the Other Options Are Wrong

A ("The system may have gone into production with defects") describes a possible consequence, but defects are not the primary purpose of UAT nor the first thing an auditor concludes from missing UAT scenarios. C ("Significant security risks may not have been assessed") is an important consideration, but security risk assessment is normally performed through dedicated security testing and a risk assessment process, not UAT; UAT is centered on business functionality and requirements. D ("Extra funding may be required to complete the testing") is a project management consequence, not the greatest control concern. The phrase "greatest concern" directs candidates to the purpose that UAT, by its nature, is intended to protect.

Community Comment Notes

Several learners selected B, and Binagr8 emphasized that the core purpose of UAT is to validate whether the system fulfils user needs and aligns with business goals; that comment captures the rationale for B. A smaller group selected C, and joehong's choice shows the common trap of broadening UAT to include full security assurance. The comment thread does not provide evidence that changes the conclusion; UAT remains a business-requirements acceptance checkpoint.

Official Reference

Exam Strategy

When a CISA question asks about the greatest concern in acquisition or implementation, anchor to the phase's objective: UAT exists to confirm that business requirements are fulfilled. Map omitted UAT scenarios straight to option B instead of tracing secondary consequences such as defects, security, or funding.

Frequently Asked Questions

Why is 'security risks may not have been assessed' not the best answer?

Security is normally validated through dedicated security testing and risk assessments, while UAT specifically validates business requirements and user acceptance. Untested UAT cases point most directly to unmet business requirements.

What should the auditor do when UAT scenarios were skipped?

The auditor should assess the impact of the missing scenarios, especially for critical business processes, and recommend additional testing or compensating controls before allowing full reliance on the system.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide