Courseiva

CISA Governance and Management of IT Practice Question

An IS auditor is assessing whether an organization's IT steering committee is fulfilling its governance responsibilities. The committee charter states that it oversees IT investment prioritization, monitors IT performance against agreed objectives, and resolves escalated resource conflicts. Which TWO of the following observations would the auditor MOST likely identify as deficiencies in the committee's operation? (Choose two.)

⚠ Common exam trap

The trap here is treating visible committee activity, such as meeting monthly and keeping minutes, as evidence of effective governance even when the substantive oversight responsibilities in the charter are not being exercised.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Performance dashboards report only project schedule and budget, with no measures of realized business outcomes.

The charter obligates the committee to prioritize investments against strategic objectives and to monitor performance against agreed objectives. Business cases are the mechanism that connects funding decisions to strategy, and outcome measures are what allow the committee to judge whether objectives were met. Approving investments without business cases and reporting only schedule and budget leave both obligations unfulfilled. Cross-functional membership, documented conflict resolutions, and regular minuted meetings all support effective operation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Performance dashboards report only project schedule and budget, with no measures of realized business outcomes.

    Why this is correct

    The charter requires monitoring IT performance against agreed objectives, which implies outcome-oriented measurement. Dashboards limited to schedule and budget track delivery activity, not whether investments achieved their intended results. The committee therefore cannot detect value shortfalls, reallocate funding, or hold sponsors accountable. This gap undermines the performance monitoring responsibility and is a substantive operational deficiency.

  • ✗

    Escalated resource conflicts are resolved through a documented decision log with assigned owners.

    Why it's wrong here

    Documented decisions with assigned owners demonstrate that the committee is discharging its resource conflict responsibility in a traceable way. This practice supports accountability and provides audit evidence that escalations are handled rather than deferred. It aligns directly with the charter and represents sound operation. The auditor would view this as a positive observation rather than a deficiency requiring remediation.

  • ✓

    Investment proposals are approved without documented business cases linking them to strategic objectives.

    Why this is correct

    The charter assigns the committee responsibility for overseeing IT investment prioritization. Approving proposals without business cases severs the link between spending and strategic objectives, making prioritization arbitrary and value delivery unmeasurable. This is a direct failure to exercise the oversight responsibility the charter grants, and it leaves the committee unable to demonstrate that funded initiatives align with the organization's direction.

  • ✗

    The committee's membership includes the CIO, the CFO, and several business unit leaders.

    Why it's wrong here

    Cross-functional membership spanning IT, finance, and the business is a strength, not a deficiency. It supports balanced prioritization and ensures that investment decisions reflect both technology and business perspectives. The scenario's charter covers investment, performance, and resource conflict responsibilities, all of which benefit from this composition. This observation is consistent with effective governance and would not be raised as a finding.

  • ✗

    The committee meets monthly and maintains minutes that are distributed to attendees.

    Why it's wrong here

    Regular meetings with distributed minutes indicate an active committee with a basic record of its deliberations. While broader distribution might improve transparency, the practice as described supports the committee's operation and does not contradict any charter responsibility. Meeting cadence and minute-taking are hygiene factors; their presence is evidence of functioning governance, not a deficiency the auditor would report.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.