Courseiva

CISA Governance and Management of IT Practice Question

An IS auditor is assessing the effectiveness of an organization's IT governance implementation. Which TWO of the following are the MOST important indicators that IT governance is effectively implemented? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse operational efficiency metrics like project timeliness or meeting frequency with true indicators of governance effectiveness, which focus on alignment and accountability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IT performance is regularly monitored and reported to the board.

Effective IT governance is demonstrated when IT decisions align with business strategy and when IT performance is regularly monitored and reported to the board. These indicators show that governance mechanisms are actively guiding IT to deliver value and manage risks, and that there is accountability at the highest level. Other options are either operational metrics or structural elements that do not directly prove governance effectiveness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    IT performance is regularly monitored and reported to the board.

    Why this is correct

    Regular monitoring and reporting to the board ensure accountability and transparency. It indicates that governance processes are in place to track IT performance against strategic goals and that the board is engaged in oversight. This is a critical indicator because without reporting, governance cannot be effective; the board must have visibility to make informed decisions and hold management accountable.

  • ✗

    All IT projects are completed on time and within budget.

    Why it's wrong here

    On-time and on-budget project completion is a project management metric, not a governance indicator. Projects can be completed on time and within budget but still fail to deliver business value or align with strategy. Effective governance focuses on benefits realization and strategic alignment, not just project execution efficiency. Therefore, this is not a reliable indicator of governance effectiveness.

  • ✗

    The IT department has a low employee turnover rate.

    Why it's wrong here

    Low turnover may indicate a stable work environment, but it is not a direct indicator of effective IT governance. Governance effectiveness is measured by alignment, value delivery, risk management, and resource optimization. Turnover could be low due to various reasons unrelated to governance, such as competitive pay or economic conditions. It does not provide insight into whether IT is governed effectively.

  • ✗

    The IT steering committee meets at least quarterly.

    Why it's wrong here

    Meeting frequency alone does not indicate effective governance. A committee can meet regularly but fail to make impactful decisions or enforce accountability. The effectiveness of governance depends on the quality of decisions, alignment with business, and monitoring of outcomes. Frequency is a structural element, but it is not sufficient to demonstrate that governance is working.

  • ✓

    IT decisions are made in alignment with business strategy and priorities.

    Why this is correct

    Alignment between IT decisions and business strategy is a core objective of IT governance. When IT investments and initiatives consistently support business goals, it indicates that governance mechanisms are working. This is a key indicator because it demonstrates that IT is not operating in isolation but is integrated with enterprise objectives, leading to value creation and risk optimization.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.