20+ practice questions focused on Governance and Management of IT — one of the most tested topics on the Certified Information Systems Auditor CISA exam. Each question includes a detailed explanation so you learn why the right answer is correct.
Start Governance and Management of IT PracticeA company's IT governance policy requires that all critical systems have a documented business continuity plan (BCP). During an audit, an IT auditor finds that the BCP for a critical financial system has not been updated in three years. Which of the following is the BEST recommendation?
Explanation: IT governance policies require that BCPs remain current to reflect actual operational processes. An outdated BCP (three years stale) may contain obsolete recovery procedures, contact information, or dependencies, rendering it ineffective during a real incident. Updating the BCP and then testing it validates that the documented steps align with the current system architecture and can be executed successfully, which is a core requirement of the BCP lifecycle per ISACA guidelines.
Which TWO of the following are key components of an IT governance framework?
Explanation: Strategic alignment (B) is a key component of an IT governance framework because it ensures that IT strategies, investments, and operations are directly linked to business goals and objectives. This alignment is achieved through mechanisms such as balanced scorecards, IT steering committees, and portfolio management, which translate business strategy into IT priorities. Without strategic alignment, IT may operate in a silo, leading to wasted resources and missed opportunities for business value.
Which TWO of the following are key responsibilities of an IT steering committee?
Explanation: An IT steering committee is a governance body that provides strategic direction and oversight, so option A (approving the annual IT budget and major capital expenditures) is correct because allocating and authorizing funding for IT investments is a core governance responsibility that ensures projects align with business strategy. Option C (defining IT policies and standards) is also correct because the steering committee sets the high-level rules, standards, and priorities that guide the IT organization and ensure consistency, compliance, and risk management. The remaining options are operational or hands-on technical tasks: B (daily system monitoring and incident response) belongs to IT operations or a SOC, D (writing application code) belongs to software developers, and E (configuring firewall rules and network access controls) belongs to network or security engineers, none of which are steering-committee responsibilities.
Match each COBIT 5 domain to its description.
Explanation: COBIT 5 has five process domains: EDM (governance), APO (planning), BAI (acquisition/implementation), DSS (delivery/support), and MEA (monitoring). Correct matches are as above; common confusions involve swapping APO/MEA or DSS/APO.
Match each log type to its typical content.
Explanation: Logs are essential for monitoring and forensics. Correct matches: Audit Log tracks user activities and compliance, Security Log tracks security events, System Log tracks OS events, Application Log tracks application events. Common confusions include mixing system events with audit logs and application errors with security logs.
+15 more Governance and Management of IT questions available
Practice all Governance and Management of IT questions1. Baseline your knowledge
Start with 10 questions to gauge your current understanding of Governance and Management of IT. This tells you whether you need a concept refresher or just practice.
2. Review every explanation
For each question — right or wrong — read the full explanation. Understanding why an answer is correct is more valuable than knowing the answer itself.
3. Focus on exam traps
Governance and Management of IT questions on the CISA frequently use trap wording. Look for subtle differences in answers that test your precision, not just general knowledge.
4. Reach 80% consistently
Do repeated sessions until you score 80%+ three times in a row. Then move to mixed-mode practice to test cross-topic recall under realistic conditions.
The exact number varies per candidate. Governance and Management of IT is tested as part of the Certified Information Systems Auditor CISA blueprint. Practicing with targeted Governance and Management of IT questions ensures you can handle any format or difficulty that appears.
Yes. Courseiva provides free CISA practice questions across all exam topics and domains. The platform includes topic-based practice, mock exams, missed-question review, bookmarked questions, and readiness tracking — no account required.
Difficulty is subjective, but Governance and Management of IT is a high-priority exam concept tested in multiple ways — direct recall, scenario analysis, and command-output interpretation. Consistent practice is the best way to build confidence.
Launch a full Governance and Management of IT practice session with instant scoring and detailed explanations.
Start Governance and Management of IT Practice →