CISA Governance and Management of IT Practice Question
An organization has experienced several security incidents due to unauthorized changes to production systems. Which governance mechanism should be strengthened?
⚠ Common exam trap
CISA often tests the confusion between change management and configuration management; candidates must remember that change management controls modifications, while configuration management tracks the state of assets.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change management process
Unauthorized changes to production systems indicate a failure in the change management process, which is designed to control and authorize modifications. Strengthening change management ensures that all changes are reviewed, approved, and documented, reducing the risk of unauthorized alterations. The other mechanisms address asset inventory, configuration data, or incident response, but do not directly prevent unauthorized changes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
IT asset management
Why it's wrong here
IT asset management tracks hardware and software inventory, not who may alter production systems or under what approval. It is tempting because unknown assets complicate control, and it would be correct when incidents stem from unmanaged or undiscovered assets rather than from changes made without authorisation.
- ✗
Configuration management database
Why it's wrong here
A configuration management database records intended configuration baselines but does not enforce approval or prevent unauthorised production changes. It is tempting because it underpins change control, and it would be correct when the goal is reconciling documented configuration items against discovered state rather than gating changes.
- ✗
Incident response plan
Why it's wrong here
An incident response plan governs detection, containment and recovery after an event, not the authorisation of production changes beforehand. It is tempting because incidents prompted the review, and it would be correct when the weakness lies in how the organisation responds to and contains security incidents.
- ✓
Change management process
Why this is correct
Unauthorised changes to production systems indicate that changes are not being requested, assessed, approved and tracked before implementation. Strengthening change management enforces authorisation, testing and rollback controls, directly preventing the uncontrolled modifications that caused the incidents.
Go deeper
Related to this question
About these practice questions
This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An IT manager is developing a governance policy for change management. Which element is MOST important to include?
easy- A.Project management methodology
- B.Detailed technical procedures
- C.List of all applications
- ✓ D.Roles and responsibilities
Why D: Roles and responsibilities are the cornerstone of any governance policy because they establish accountability and authority for change approval, implementation, and review. Without clearly defined roles (e.g., change manager, change advisory board, implementer), even well-documented procedures lack ownership and enforcement. Governance is about decision rights and accountability, not operational details. Thus, defining who is responsible for what is the most critical element to include.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.