Courseiva

CISA Governance and Management of IT Practice Question

An IT governance framework should include which TWO key components? (Select exactly two.)

⚠ Common exam trap

It's easy for candidates to confuse operational IT controls (training, firewalls) with governance framework components — CISA candidates often pick 'user training' because it sounds foundational, but governance is about direction and oversight, not execution.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Strategic alignment

Strategic alignment (C) is a core component of any IT governance framework because governance must ensure that IT investments, priorities, and initiatives directly support the organization's business goals and objectives. Performance measurement (E) is equally essential, as governance requires metrics, KPIs, and monitoring mechanisms (such as balanced scorecards or COBIT goals) to verify that IT delivers value, manages risk, and meets agreed service levels. Together, these two components reflect the dual governance mandate of directing IT toward business strategy while measuring whether it actually delivers. The other options do not belong: user training (A) is an operational capability rather than a governance component, vendor lock-in (B) is a risk to be avoided, not a framework element, and network firewall rules (D) are technical security controls, not governance-level components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    User training

    Why it's wrong here

    User training is an awareness activity, not a governance component; frameworks define decision rights, accountability and oversight structures. Training supports governance outcomes but does not establish direction, monitoring or resource alignment. It would be correct if the question asked about controls mitigating human error rather than framework components.

  • ✗

    Vendor lock-in

    Why it's wrong here

    Vendor lock-in is a risk governance seeks to avoid, not a component it includes. Frameworks comprise structures such as decision rights, accountability, strategy alignment and performance measurement. Lock-in would be relevant if the question asked which risk a poorly governed sourcing strategy creates.

  • ✓

    Strategic alignment

    Why this is correct

    Strategic alignment ensures IT investments and initiatives directly support organisational objectives, satisfying the governance requirement to link technology decisions with business strategy. COBIT and ISO/IEC 38500 both identify this linkage as a core governance component, distinct from operational execution, because governance must direct where IT resources are deployed rather than merely manage their day-to-day running.

  • ✗

    Network firewall rules

    Why it's wrong here

    Firewall rules are a technical security control, not a governance component. Governance frameworks address decision rights, accountability, strategic alignment and performance monitoring rather than device configuration. Firewall rules would be the right answer if the question asked which control enforces network segmentation.

  • ✓

    Performance measurement

    Why this is correct

    Performance measurement provides the metrics that let governance bodies verify whether IT delivers against strategic objectives and manages risk within tolerance. Without it, the framework cannot demonstrate accountability or drive corrective action, leaving the governance structure unmeasurable and effectively unenforceable.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.