CISA Governance and Management of IT Practice Question
An organization has experienced several security incidents due to unauthorized changes to production systems. Which governance mechanism should be strengthened?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change management process
A change management process ensures that all changes are authorized, tested, and approved, directly addressing unauthorized changes. Asset management, CMDB, and incident response are supportive but not the primary control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IT asset management
Why it's wrong here
Asset management tracks assets but does not control change authorization.
- ✗
Configuration management database
Why it's wrong here
CMDB records configurations but does not enforce change control.
- ✗
Incident response plan
Why it's wrong here
Incident response deals with after-the-fact reaction, not prevention.
- ✓
Change management process
Why this is correct
This controls the approval and implementation of changes.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An IT manager is developing a governance policy for change management. Which element is MOST important to include?
easy- A.Project management methodology
- B.Detailed technical procedures
- C.List of all applications
- ✓ D.Roles and responsibilities
Why D: Clearly defined roles and responsibilities ensure accountability in the change process. Option A is incorrect because project management methodology is separate from governance policy. Option B is incorrect as detailed technical procedures are part of implementation, not governance. Option C is incorrect because a list of all applications is operational, not a governance element.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.