CISA Governance and Management of IT Practice Question
An organization's IT department has recently implemented a new project management methodology. The IS auditor is reviewing the project portfolio and finds that projects are prioritized based on the personal preferences of the IT director rather than strategic alignment. Which of the following is the MOST significant risk arising from this practice?
⚠ Common exam trap
The trap here is focusing on operational symptoms like delays or scope creep rather than the fundamental strategic misalignment that drives those symptoms.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Projects may not align with business strategy, leading to wasted resources and missed opportunities.
When IT projects are prioritized based on personal preferences instead of strategic alignment, the organization risks investing in initiatives that do not support its business goals. This can lead to wasted resources, missed market opportunities, and a failure to achieve expected benefits. The most significant risk is the misalignment between IT and business strategy, which directly impacts the organization's ability to create value and remain competitive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Projects may not align with business strategy, leading to wasted resources and missed opportunities.
Why this is correct
Prioritizing projects based on personal preferences rather than strategic alignment means IT investments may not support the organization's goals. This can result in resources being allocated to low-value projects while critical strategic initiatives are delayed or unfunded. The most significant risk is the misalignment of IT with business strategy, which undermines the value IT delivers and can lead to competitive disadvantage.
- ✗
The IT director may become overburdened with decision-making, causing project delays.
Why it's wrong here
While the IT director's personal involvement in prioritization could create a bottleneck, this is an operational inefficiency rather than the most significant risk. The core issue is that decisions are not based on strategic criteria, which can lead to a portfolio that fails to deliver business value. The risk of delays is secondary to the risk of investing in the wrong projects.
- ✗
The organization may fail to comply with regulatory requirements for project documentation.
Why it's wrong here
Regulatory compliance is important, but the scenario does not indicate any specific regulatory requirement for project prioritization. The primary risk of prioritizing based on personal preferences is strategic misalignment, not documentation non-compliance. While poor documentation could be a consequence, it is not the most significant risk in this context.
- ✗
Project managers may lack clear direction, resulting in scope creep and budget overruns.
Why it's wrong here
Lack of clear direction can contribute to scope creep, but the root cause here is the absence of strategic prioritization. If projects are chosen based on personal preferences, they may not have a solid business case, leading to unclear objectives. However, the most significant risk is not scope creep itself but the underlying misalignment with business strategy, which can render even well-managed projects worthless.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.