CISA Governance and Management of IT Practice Question
A multinational corporation has defined its risk appetite as 'moderate' for IT investments. The IT steering committee is evaluating a new project with potential high returns but also significant cybersecurity risks. The project's risk profile is assessed as 'high' by the risk management team. What should the committee do FIRST?
⚠ Common exam trap
CISA often tests the misconception that any project exceeding risk appetite must be immediately rejected or escalated, when the correct first step is always to evaluate mitigation and residual risk before making a governance decision.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request the project team to identify risk mitigation measures.
When a project's risk profile exceeds the organization's defined risk appetite, the FIRST step is to understand whether the risk can be brought within tolerance through mitigation. The committee cannot make an informed accept/reject/escalate decision until the risk management team and project team have identified possible controls and residual risk. Requesting mitigation measures preserves the opportunity for high returns while aligning the project with the 'moderate' appetite.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Request the project team to identify risk mitigation measures.
Why this is correct
Requesting mitigation measures first addresses the high-risk profile before any acceptance decision, aligning residual risk with the moderate appetite. Identifying controls and their effectiveness gives the committee the information needed to approve, modify or reject the project.
- ✗
Approve the project but increase monitoring.
Why it's wrong here
Approval with added monitoring accepts a high-risk project without first reducing the exposure to align with the moderate appetite. Monitoring detects issues after the fact; risk treatment or acceptance at the proper authority must precede approval.
- ✗
Escalate the decision to the board of directors.
Why it's wrong here
Escalation removes the decision from the body chartered to govern IT risk within its delegated authority. Boards set risk appetite and oversee strategy; steering committees apply that appetite by evaluating, mitigating or accepting individual project risks.
- ✗
Reject the project immediately as it exceeds risk appetite.
Why it's wrong here
Rejection abandons a project whose high returns may justify the exposure, and the committee's role is to weigh risk against return within the stated appetite. Immediate rejection suits projects breaching a mandated threshold with no mitigation path.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.