Courseiva

CISA Governance and Management of IT Practice Question

An IS auditor is reviewing an organization's IT governance framework and notes that the board of directors has established an IT strategy committee. Which TWO of the following are the MOST appropriate responsibilities for this committee? (Choose two.)

⚠ Common exam trap

Many exam-takers confuse governance with management, leading to the selection of operational tasks that are not appropriate for a board-level committee.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Monitoring the performance of IT investments and ensuring benefits realization.

The IT strategy committee, as a board-level body, should focus on strategic oversight: approving the IT strategic plan and ensuring alignment with business objectives, and monitoring IT investment performance and benefits realization. These responsibilities ensure that IT supports the organization's goals and delivers value. Operational tasks such as managing daily operations, designing controls, or conducting technical tests are management responsibilities and fall outside the committee's governance mandate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Designing and implementing IT internal controls over financial reporting.

    Why it's wrong here

    Designing and implementing IT internal controls over financial reporting is a management responsibility, often executed by the IT and finance functions. The board's IT strategy committee provides oversight of the control environment but does not design or implement controls. Its role is to ensure that management has established effective controls and that they are operating as intended.

  • ✗

    Managing day-to-day IT operations and resolving technical issues.

    Why it's wrong here

    Day-to-day IT operations and technical issue resolution are management responsibilities, not board committee responsibilities. The IT strategy committee focuses on strategic oversight, not operational execution. Involving the committee in operational matters would blur the line between governance and management and reduce its effectiveness in providing strategic direction.

  • ✓

    Monitoring the performance of IT investments and ensuring benefits realization.

    Why this is correct

    Monitoring IT investment performance and benefits realization is a key governance responsibility of the IT strategy committee. By overseeing whether IT projects deliver expected value, the committee ensures accountability and supports continuous improvement. This oversight helps prevent wasteful spending and ensures that IT contributes to business success.

  • ✓

    Approving the IT strategic plan and ensuring alignment with business objectives.

    Why this is correct

    The IT strategy committee, as a board-level committee, is responsible for approving the IT strategic plan and ensuring it aligns with the organization's business objectives. This oversight ensures that IT investments support strategic goals and that IT risks are managed at the highest level. It is a core governance responsibility that cannot be delegated to management alone.

  • ✗

    Conducting technical vulnerability assessments and penetration testing.

    Why it's wrong here

    Technical vulnerability assessments and penetration testing are operational security activities performed by IT security teams or external specialists. The IT strategy committee's role is to oversee that such activities are performed and that risks are managed, not to conduct them. Direct involvement in technical testing is outside the scope of board-level governance.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.