Courseiva
Governance and Management of ITmediumMultiple SelectObjective-mapped

CISA Governance and Management of IT Practice Question

An organization is implementing an IT governance framework to align IT with business objectives. Which TWO of the following are primary responsibilities of the IT steering committee?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Approving IT project budgets and priorities

Options C and E are correct. The IT steering committee is responsible for approving IT project budgets and priorities (C) and ensuring IT investments deliver value (E). Performing daily IT operations (A) is an operational management task. Defining IT security policies (B) is typically the responsibility of the security function. Conducting technical vulnerability assessments (D) is a technical operational activity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Performing daily IT operations

    Why it's wrong here

    Daily IT operations are managed by IT operations teams, not the steering committee.

  • Defining IT security policies

    Why it's wrong here

    Security policies are typically defined by the information security function and approved by the board or risk committee.

  • Approving IT project budgets and priorities

    Why this is correct

    The IT steering committee provides oversight and approval for major IT investments and priorities.

  • Conducting technical vulnerability assessments

    Why it's wrong here

    Vulnerability assessments are technical activities performed by security operations teams.

  • Ensuring IT investments deliver value

    Why this is correct

    The steering committee monitors the value delivery of IT projects and ensures alignment with business goals.

About these practice questions

One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization is implementing a new IT governance framework. Which of the following is the BEST approach to ensure alignment between IT strategy and business goals?

medium
  • A.Align IT budget with the previous year's business plan
  • B.Conduct annual IT strategy reviews independent of business cycles
  • C.Establish an IT steering committee with business representation
  • D.Delegate IT strategy to the CIO without business input

Why C: An IT steering committee with both IT and business leaders ensures continuous strategic alignment by involving business stakeholders in IT decision-making. Option A is incorrect because aligning the IT budget with a previous year's business plan uses outdated information and does not guarantee alignment with current goals. Option B is incorrect because annual IT strategy reviews independent of business cycles create a disconnect between IT and business priorities. Option D is incorrect because delegating IT strategy solely to the CIO without business input can lead to misalignment with organizational objectives.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.