Courseiva

CISA Governance and Management of IT Practice Question

An organization's IT department has grown rapidly, and the CIO wants to ensure that employees understand expected behaviors when handling sensitive data and operating critical systems. Which of the following is the MOST appropriate governance mechanism to establish?

⚠ Common exam trap

The trap here is selecting a technical or assurance control when the objective is to establish and reinforce expected workforce behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A documented IT code of conduct, acknowledged by staff, supported by periodic awareness training.

The CIO's objective is behavioral: staff must understand and follow expected practices for sensitive data and critical systems. A code of conduct with acknowledgment and recurring awareness training establishes those expectations, makes them explicit, and refreshes them as the organization grows. Technical restrictions, penetration tests, and vendor agreements address other risk areas and do not create or reinforce employee accountability for conduct.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A service level agreement with the infrastructure hosting provider.

    Why it's wrong here

    A service level agreement defines performance commitments from a vendor and is relevant only where services are outsourced. It does not shape internal employee behavior, communicate expectations for sensitive data handling, or address operation of critical systems by staff. This mechanism governs the supplier relationship, not workforce conduct, so it is misaligned with the stated objective.

  • ✓

    A documented IT code of conduct, acknowledged by staff, supported by periodic awareness training.

    Why this is correct

    A code of conduct translates governance expectations into explicit behavioral requirements, and acknowledgment plus recurring training makes those expectations enforceable and current. This combination addresses both awareness and accountability for sensitive data handling and critical system operations. It is a foundational governance mechanism that scales as the department grows and new staff join, unlike one-off or purely technical measures.

  • ✗

    An annual penetration test of systems that store sensitive data.

    Why it's wrong here

    Penetration testing evaluates technical vulnerabilities from an external or internal attacker perspective. It provides no information about whether employees understand expected behaviors, and it does not establish accountability for handling sensitive data or operating critical systems. While valuable for security assurance, it is a different control category and does not satisfy the governance objective described by the CIO.

  • ✗

    A technical control that blocks access to sensitive data outside business hours.

    Why it's wrong here

    A time-based access restriction is a technical control, not a governance mechanism for shaping employee behavior. It may reduce some risk, but it does not teach staff how to handle sensitive data or operate critical systems correctly, and it can be bypassed by legitimate after-hours work requirements. It also leaves the underlying behavioral risk unaddressed, which is what the CIO asked to govern.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.