Courseiva
Governance and Management of ITmediumMultiple ChoiceObjective-mapped

CISA Governance and Management of IT Practice Question

A company plans to outsource its data center operations to a cloud service provider. What is the MOST important governance consideration for the board before finalizing the contract?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Ensure the contract includes clauses for regulatory compliance and audit rights.

The most important governance consideration because the board must ensure that the contract enforces regulatory compliance and provides audit rights to meet legal and regulatory obligations. Option A is wrong because cost reduction is secondary to compliance and governance. Option B is wrong because transferring staff is an HR/operational issue, not a board-level governance priority. Option D is wrong while an exit strategy is important, contractually securing compliance and audit rights is more critical for governance oversight.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Select a provider with the lowest cost per transaction.

    Why it's wrong here

    Cost is not the primary governance concern.

  • Negotiate the transfer of existing IT staff to the provider.

    Why it's wrong here

    Staff transfer is an HR issue, not board-level governance.

  • Ensure the contract includes clauses for regulatory compliance and audit rights.

    Why this is correct

    Compliance and audit rights are critical for governance and oversight.

  • Define a detailed exit strategy for transitioning to another provider.

    Why it's wrong here

    Exit strategy is important but secondary to initial compliance.

About these practice questions

Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on CISA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company outsources its data center operations to a third-party provider. Which of the following is the MOST important control to include in the outsourcing contract?

medium
  • A.Detailed escalation procedures for incidents
  • B.Service level agreements with financial penalties
  • C.Requirements for encryption of data at rest
  • D.Right to audit the provider's facilities and processes

Why D: The right to audit allows the company to verify the provider's compliance. Option A is important but less critical than audit rights. Option B is operational. Option C is a security control but not the most important contractual safeguard.

Variation 2. An organization is planning to outsource its data center operations. Which of the following governance practices should be implemented to ensure proper oversight?

medium
  • A.Conduct annual financial audits of the outsourcer.
  • B.Require the outsourcer to obtain ISO 27001 certification.
  • C.Establish a service level agreement (SLA) with key performance indicators (KPIs).
  • D.Allow the outsourcer to manage all security controls independently.

Why C: Establishing a service level agreement (SLA) with key performance indicators (KPIs) provides measurable performance targets and accountability, ensuring proper oversight of outsourced data center operations. Option A (annual financial audits) addresses financial compliance but not operational oversight. Option B (ISO 27001 certification) is a certification, not an ongoing governance practice. Option D (allowing the outsourcer to manage all security controls independently) abdicates the organization's responsibility for oversight.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.