CISA Governance and Management of IT Practice Question
A multinational corporation is implementing a global IT governance framework. Which of the following challenges is MOST likely to arise?
⚠ Common exam trap
The trap is selecting an operational or financial issue (hardware, training, licensing) when the question asks about governance — CISA expects you to recognize that governance challenges are regulatory and strategic, not tactical.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Conflicting regulatory requirements
A global IT governance framework must reconcile laws, regulations, and industry standards across many jurisdictions. Multinationals face conflicting requirements — for example, GDPR data residency in the EU versus data localization laws in other countries, or differing breach-notification timelines. These conflicts directly shape governance policies, controls, and reporting, making them the most likely and most impactful challenge.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Conflicting regulatory requirements
Why this is correct
Differing data protection, privacy, and financial reporting rules across jurisdictions force the framework to reconcile incompatible mandates, which is the central governance obstacle. A single global policy cannot satisfy every regulator simultaneously, so conflicting requirements are the most likely challenge.
- ✗
Standardizing hardware across regions
Why it's wrong here
Hardware standardisation is a procurement and logistics concern, not a governance framework challenge. It would be the answer if the stem asked about consolidating infrastructure vendors across sites, but governance frameworks address decision rights, policy and control alignment, which differing regional regulations and business cultures directly obstruct.
- ✗
Training users on new procedures
Why it's wrong here
User training is a change-management task, not the governance challenge itself; it arises after policies are defined. Training would be the answer where the stem concerns adoption of new procedures post-implementation, but here the multinational scope makes reconciling divergent legal, regulatory and cultural requirements across regions the primary obstacle.
- ✗
Software licensing costs
Why it's wrong here
Software licensing costs are a budgetary matter, not a governance implementation challenge. Licensing would be the answer if the stem concerned cost optimisation or vendor negotiation, but a governance framework's difficulty lies in harmonising decision-making, accountability and regulatory compliance across jurisdictions with conflicting requirements.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.