hardMultiple ChoiceObjective-mapped
CISA Practice Question: An IS auditor is performing a review of an…
An IS auditor is performing a review of an organization's IT governance framework. Which of the following findings would be of MOST concern?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
No documented IT strategy aligned with business strategy
The absence of a documented IT strategy aligned with the business strategy is the most critical governance finding. Without strategic alignment, IT decisions may not support business objectives, making all other controls less effective. Option B (incomplete project portfolio management) is tactical and can be addressed after strategic alignment. Option C (lack of an IT steering committee) is a structural issue but not as fundamental as lack of strategy. Option D (absence of an enterprise-wide information security policy) is operational and less strategic than the alignment issue.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
No documented IT strategy aligned with business strategy
Why this is correct
Governance requires IT to support business objectives; without alignment, the framework fails.
- ✗
Incomplete IT project portfolio management
Why it's wrong here
Important but secondary to strategic alignment.
- ✗
Lack of an IT steering committee
Why it's wrong here
A steering committee is a mechanism, but governance can exist without it.
- ✗
Absence of an enterprise-wide information security policy
Why it's wrong here
Security is part of governance, but strategic alignment is more fundamental.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 995 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.