Courseiva

CISA Governance and Management of IT Practice Question

An IT governance framework has been implemented, but the board is not receiving regular reports on IT performance. Which of the following is the BEST course of action?

⚠ Common exam trap

The trap is choosing a broader or more prestigious-sounding governance initiative (balanced scorecard, CIO reporting line) when the question describes a specific, narrow deficiency — CISA rewards the most direct, proportionate fix to the stated problem.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Develop a dashboard that presents key IT metrics to the board.

The gap identified is that the board is not receiving regular IT performance reports — a communication and reporting deficiency, not a risk identification or organizational design problem. Developing a dashboard that presents key IT metrics to the board (B) directly closes that gap by establishing a repeatable, structured reporting mechanism that gives the board visibility into IT performance. It is the most targeted, proportionate response to the stated deficiency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Conduct an IT risk assessment to identify critical areas.

    Why it's wrong here

    A risk assessment identifies and prioritises threats; it produces no recurring performance reporting to the board. It is tempting because risk assessment underpins governance and would be correct when establishing or refreshing the framework's risk appetite, but here the framework already exists and the gap is reporting, not risk identification.

  • ✓

    Develop a dashboard that presents key IT metrics to the board.

    Why this is correct

    A dashboard directly addresses the missing reporting channel by giving the board recurring visibility of key IT metrics, satisfying the governance requirement for ongoing performance oversight. Unlike one-off reports, it establishes a repeatable mechanism aligned to the framework's monitoring and communication controls, closing the gap between implementation and board-level accountability.

  • ✗

    Implement an IT balanced scorecard that aligns with corporate strategy.

    Why it's wrong here

    An IT balanced scorecard is a measurement and reporting mechanism, not the governance action needed to establish board-level reporting of IT performance. The board's oversight gap requires defining reporting responsibilities and escalation within the governance framework. A scorecard tempts because it produces performance metrics, and would suit an organisation lacking a measurement framework.

  • ✗

    Assign a chief information officer (CIO) to report directly to the board.

    Why it's wrong here

    Reporting lines do not generate performance data; the board needs an established reporting mechanism with defined metrics and cadence. A CIO reporting to the board is tempting because it strengthens oversight and accountability, which suits organisations lacking executive IT representation, but it does not itself deliver the regular IT performance reports the stem requires.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.