Courseiva

CISA Governance and Management of IT Practice Question

An organization is implementing an IT governance framework to align IT with business objectives. Which TWO of the following are primary responsibilities of the IT steering committee?

⚠ Common exam trap

CISA often tests the distinction between governance (setting direction, approving budgets, ensuring value) and management (executing operations, writing policies, running scans) — candidates who pick operational-sounding options confuse the two layers.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Approving IT project budgets and priorities

Option C is correct because an IT steering committee is a governance body that reviews and approves IT project budgets and sets project priorities, ensuring that funding and sequencing decisions align with business strategy rather than being left to operational teams. Option E is correct because a core governance responsibility is ensuring IT investments deliver value, which the committee accomplishes by monitoring benefits realization, tracking ROI, and holding IT accountable for outcomes tied to business objectives. Options A, B, and D do not belong: performing daily IT operations (A) is an operational/IT operations function, defining IT security policies (B) is typically delegated to a security governance or CISO function (the steering committee may endorse them but does not author them), and conducting technical vulnerability assessments (D) is a hands-on technical security task performed by security engineers or analysts, not a governance committee.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Performing daily IT operations

    Why it's wrong here

    Daily operational execution belongs to IT operations staff and service management processes, not a strategic governance body. It is tempting because the committee oversees IT, yet oversight means direction-setting and investment decisions; hands-on task execution would consume the meeting time governance requires for alignment.

  • ✗

    Defining IT security policies

    Why it's wrong here

    Policy definition sits with security leadership, which drafts and maintains standards before steering committee endorsement; the committee sets strategic direction and prioritisation instead. It is tempting because the committee does approve policies, but that approval role differs from authoring them, which is the security function's remit.

  • ✓

    Approving IT project budgets and priorities

    Why this is correct

    Approving IT project budgets and priorities is a primary steering committee duty, since the committee allocates resources and sequences projects to match business objectives. This governance decision keeps investment aligned with strategy rather than departmental preference.

  • ✗

    Conducting technical vulnerability assessments

    Why it's wrong here

    Vulnerability scanning is a hands-on technical control performed by security engineers using scanning tools. It is tempting because the committee cares about risk posture, but it consumes assessment output rather than producing it; governance bodies review aggregated risk reporting, leaving testing to operational security teams.

  • ✓

    Ensuring IT investments deliver value

    Why this is correct

    The IT steering committee prioritises and approves IT initiatives, then monitors whether each investment returns expected business value and aligns with strategic objectives. Ensuring IT investments deliver value is therefore a primary governance responsibility, satisfying the stem's alignment goal.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CISA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization is implementing a new IT governance framework. Which of the following is the BEST approach to ensure alignment between IT strategy and business goals?

medium
  • A.Align IT budget with the previous year's business plan
  • B.Conduct annual IT strategy reviews independent of business cycles
  • ✓ C.Establish an IT steering committee with business representation
  • D.Delegate IT strategy to the CIO without business input

Why C: An IT steering committee with business representation is the best approach because it creates a formal, ongoing governance mechanism where business and IT leaders jointly prioritize investments, review performance, and make strategic decisions. This ensures IT strategy is continuously aligned with business goals rather than being set in isolation. COBIT and ISO/IEC 38500 both emphasize such cross-functional governance bodies as the primary vehicle for strategic alignment.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.