hardMultiple Choice
CISA Practice Question: A company outsources its data center operations
A company outsources its data center operations. Which IT governance practice is MOST critical to ensure the outsourcing arrangement meets business requirements?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Establishing a service level agreement (SLA) with key performance indicators
Service level management ensures that the outsourcer's performance is monitored against agreed-upon metrics.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Establishing a service level agreement (SLA) with key performance indicators
Why this is correct
An SLA translates business requirements into measurable key performance indicators, giving the company an enforceable basis to monitor the outsourcer's delivery. Without defined metrics and remedies, governance over the arrangement lacks objective evidence of compliance.
- ✗
Performing a total cost of ownership analysis
Why it's wrong here
Total cost of ownership quantifies the financial comparison of the arrangement; it does not verify that service levels, controls and obligations meet business requirements. It is tempting because cost analysis is a genuine part of outsourcing decisions, and would be the right choice if the question asked how to evaluate the arrangement's value for money.
- ✗
Creating a RACI matrix for the outsourced processes
Why it's wrong here
A RACI matrix only assigns roles and responsibilities across outsourced processes; it does not enforce contractual performance or service delivery. It is tempting because RACI clarifies accountability, and it would be the right choice when the governance gap is unclear ownership of tasks rather than ensuring the outsourcer meets business requirements.
- ✗
Conducting background checks on outsourcer employees
Why it's wrong here
Background checks on outsourcer employees address personnel security risk, not whether the outsourcing arrangement delivers against business requirements. It is tempting because vetting staff is a genuine control, and it would be correct where the concern is insider threat or screening of third-party personnel rather than governance of service performance.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.