easyMultiple Choice
CISA Practice Question: According to ISO/IEC 38500, which principle…
According to ISO/IEC 38500, which principle requires that IT investments are made for valid business reasons and with clear business outcomes?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Strategy
The 'Strategy' principle of ISO/IEC 38500 states that IT should be aligned with the business strategy and investments should be made for valid business reasons.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Performance
Why it's wrong here
Performance addresses how well IT services deliver agreed capacity and throughput, not the justification and business case behind investment decisions. It is tempting because performance is a common governance concern, and would be correct when evaluating whether IT meets service-level objectives rather than validating investment rationale.
- ✓
Strategy
Why this is correct
The Strategy principle of ISO/IEC 38500 requires evaluating IT investments against business rationale and expected outcomes, ensuring proposals have valid business reasons. It differs from Acquire, which governs obtaining IT assets, and Conformance, which addresses compliance with rules.
- ✗
Acquisition
Why it's wrong here
Acquisition addresses obtaining IT assets at justified cost, not the ongoing alignment of investment with business outcomes. It is tempting because procurement decisions do involve business cases, and Acquisition would be correct if the question asked who ensures IT purchases are made for valid reasons.
- ✗
Responsibility
Why it's wrong here
Responsibility concerns who is accountable for IT decisions and performance, not whether investments have valid business justification. It tempts because governance accountability underpins investment decisions, and Responsibility would be correct if the question asked who must answer for IT outcomes.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.