Courseiva
mediumMultiple Choice

CISA Practice Question: Is adopting a decentralized IT structure to…

An organization is adopting a decentralized IT structure to better meet the needs of its business units. Which of the following is a potential risk of this approach?

⚠ Common exam trap

CISA often tests the trade-off between centralization and decentralization, and candidates frequently confuse the risks of one with the benefits of the other—picking 'slower response' as a risk of decentralization when it is actually a risk of centralization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Increased duplication of IT resources and inconsistent standards

Decentralized IT structures push decision-making authority and resources down to individual business units, which naturally leads to each unit acquiring its own hardware, software, and support staff. This fragmentation creates redundant systems and divergent technical standards across the organization, increasing cost and complexity. The correct answer captures this classic trade-off: while decentralization improves responsiveness, it sacrifices economies of scale and standardization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Increased duplication of IT resources and inconsistent standards

    Why this is correct

    Decentralised IT lets each business unit procure and configure independently, so overlapping systems and divergent configurations emerge across units. This directly satisfies the stem's risk: duplicated IT resources alongside inconsistent standards, raising cost and complicating governance, integration and security enforcement.

  • ✗

    Slower response to business unit needs

    Why it's wrong here

    Decentralisation places IT decision-making and resources within business units, which typically shortens response times by removing central approval queues. It is tempting because centralised structures genuinely can respond slowly, but the stem asks for a risk of decentralising, and this describes the problem decentralisation is adopted to solve.

  • ✗

    Higher initial setup costs for central services

    Why it's wrong here

    Decentralisation shifts spend toward business-unit systems and duplicated local infrastructure, so central service setup costs do not rise as a consequence. It is tempting because centralising shared services does carry significant initial build costs, but that describes the centralised model, not the risk introduced by moving away from it.

  • ✗

    Reduced alignment with corporate strategy

    Why it's wrong here

    Decentralised structures typically improve business-unit responsiveness but weaken enterprise-wide governance and standardisation, not corporate strategy alignment directly. It is tempting because decentralisation does dilute central control, yet the concrete risk is duplicated resources and inconsistent standards rather than strategic misalignment.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.