Courseiva

CISA Governance and Management of IT Practice Question

An IS auditor is assessing an organization's IT governance framework and finds that the IT balanced scorecard includes metrics such as system uptime, number of help desk tickets resolved, and average response time. The auditor notes that these are all internal IT operational metrics. The MOST significant concern is that:

⚠ Common exam trap

The trap here is focusing on the technical nature or lack of benchmarking of the metrics rather than the fundamental imbalance in the scorecard's perspectives.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The scorecard lacks metrics that measure the contribution of IT to business strategy and customer value.

An IT balanced scorecard should provide a balanced view of IT performance across multiple perspectives, including business contribution, customer orientation, operational excellence, and future orientation. The scenario describes only internal operational metrics, which means the scorecard does not measure IT's contribution to business strategy or customer value. This imbalance is the most significant concern because it prevents the board and management from assessing whether IT is delivering strategic value.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The scorecard does not include financial metrics such as IT cost per employee or return on IT investment.

    Why it's wrong here

    Financial metrics are important, but the balanced scorecard concept requires a balance of financial and non-financial measures across four perspectives: financial, customer, internal processes, and learning and growth. The scenario already includes internal process metrics. The most critical gap is the absence of customer and business contribution perspectives, not just financial metrics.

  • ✗

    The metrics are too technical for the board to understand and may lead to misinterpretation.

    Why it's wrong here

    While technical metrics can be difficult for non-technical board members, the more fundamental issue is the absence of strategic and customer-focused metrics. Even if the metrics were simplified, the scorecard would still be incomplete. The auditor's primary concern should be the lack of balance across perspectives, not the technical nature of the existing metrics.

  • ✓

    The scorecard lacks metrics that measure the contribution of IT to business strategy and customer value.

    Why this is correct

    A balanced scorecard should include metrics from multiple perspectives, including business contribution and customer orientation. Focusing solely on internal operational metrics like uptime and ticket resolution provides an incomplete view of IT performance. The most significant concern is that the scorecard does not measure how IT contributes to business strategy or delivers value to customers, which is essential for effective IT governance and alignment.

  • ✗

    The metrics are not benchmarked against industry standards, making them less useful for comparison.

    Why it's wrong here

    Benchmarking can add value, but it is not a core requirement of a balanced scorecard. The primary purpose of the scorecard is to provide a balanced view of performance across strategic objectives. The lack of benchmarking is secondary to the lack of balance. The auditor should focus on whether the scorecard includes measures that reflect the organization's strategy and stakeholder needs.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.