CISA Governance and Management of IT Practice Question
A financial services company is migrating its core banking system to a public cloud to improve scalability and reduce costs. The project is high-risk due to regulatory compliance requirements (e.g., data residency, audit trails). The IT governance committee has reviewed the project plan and finds that the risk assessment is incomplete – it does not address the potential impact of a cloud provider outage on critical transactions. The committee must approve the project or request changes. The project manager argues that the cloud provider's SLA guarantees 99.99% uptime and that additional controls would delay the project. What should the governance committee do?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request a revised risk assessment that includes contingency plans for provider outages.
The governance committee's role is to ensure that all significant risks are identified and mitigated before approval. The risk assessment is incomplete as it does not address the impact of a cloud provider outage on critical transactions. Requiring a revised risk assessment that includes contingency plans for provider outages is a proper governance response. Option A is wrong because it preemptively rejects the project without considering updated risk information. Option C is wrong because the SLA does not eliminate the need for contingency planning or address other compliance risks. Option D is wrong because a pilot for non-critical systems does not resolve the missing risk assessment for the core banking migration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Reject the project and require the system to remain on-premises.
Why it's wrong here
Rejection is drastic; cloud may still be viable with proper controls.
- ✓
Request a revised risk assessment that includes contingency plans for provider outages.
Why this is correct
The committee must ensure all risks are identified and mitigated.
- ✗
Approve the project based on the provider's strong SLA.
Why it's wrong here
An SLA does not eliminate the need for a full risk assessment.
- ✗
Approve a pilot migration for non-critical systems first.
Why it's wrong here
The committee should address the risk assessment gap before proceeding.
Visual reference
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.