Courseiva

CISA · domain

Governance and Management of IT

This domain covers IT governance, risk management, and control frameworks for the CISA exam. It tests your ability to align IT with business strategy, evaluate risk, and ensure compliance. Expect scenario-based questions on policies, roles, and the audit of governance structures, not just definitions.

121 questions35 easy45 medium41 hard

Focused practice

Practice Governance and Management of IT questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Governance and Management of IT

You must be able to evaluate IT governance structures, order risk and backup steps, and apply change management controls. The single most important thing is knowing that governance is a board responsibility, not an IT function.

IT governance frameworks like COBIT and their components

Risk assessment steps and risk treatment options

Change management processes including CAB and emergency changes

Data backup procedures and recovery point objectives

Watch out for

Common Governance and Management of IT exam traps

  • ▸Assuming IT owns governance decisions when the board and executives are ultimately accountable.
  • ▸Confusing risk assessment order: identification, analysis, evaluation, and treatment must be sequential.
  • ▸Forgetting that emergency changes still require post-implementation review and documentation.

Question index

All Governance and Management of IT questions (121)

Click any question to see the full explanation, or start a practice session above.

1

A multinational manufacturing company with operations in 20 countries has historically allowed each regional division to manage its own IT systems independently. Recently, the company experienced a significant data breach originating from a region with weaker security controls, leading to financial losses and reputational damage. The board has mandated stronger IT governance to prevent future incidents. The CIO proposes implementing a global IT governance framework with centralized policy enforcement. However, regional directors argue that local regulations and business needs require autonomy. The governance committee must decide on a course of action that balances risk and business flexibility. Which of the following approaches is the MOST appropriate?

Hard
2

A company has multiple business units with conflicting IT priorities. Which governance body should resolve this?

Medium
3

Which TWO of the following are common objectives of an IT balanced scorecard? (Choose two.)

Easy
4

A large enterprise recently experienced a data breach due to an insider threat. The IT governance committee is reviewing the incident and considering measures to prevent recurrence. Which of the following is the BEST course of action to address the root cause?

Medium
5

Which TWO of the following are key components of an IT governance framework? (Choose two.)

Easy
6

An organization is implementing COBIT 2019. Which TWO of the following are governance enablers? (Choose two.)

Medium
7

A financial institution is evaluating its IT governance structure. Which of the following roles is BEST suited to ensure independent oversight of IT investments?

Medium
8

An organization wants to ensure that IT performance is measured against strategic goals. Which tool is BEST suited?

Easy
9

An organization's IT governance committee is reviewing a proposal to use a public cloud provider that does not meet the organization's data encryption standards. The board has set a low risk appetite for data privacy. What is the BEST action?

Hard
10

An auditor finds that access reviews have not been completed for two quarters. What is the MOST significant risk?

Hard
11

Which THREE of the following are components of the COBIT 2019 governance system?

Hard
12

A large financial institution is evaluating the effectiveness of its IT governance framework. The board has requested a review to ensure alignment with business objectives and regulatory requirements. Which of the following is the MOST important factor for the board to consider when assessing the IT governance framework?

Medium
13

A healthcare organization must comply with HIPAA regulations regarding patient data privacy. The IT department has implemented technical controls, but the compliance officer discovers that some employees are sharing passwords. What is the BEST governance response?

Easy
14

An IS auditor is evaluating an organization's IT governance maturity using COBIT 2019. The auditor finds that IT processes are largely ad hoc, with no formal documentation or consistent monitoring. However, the organization has recently implemented a tool to automate some IT service management tasks. Management believes this tool elevates their maturity to a managed level. The auditor should:

Hard
15

A medium-sized manufacturing company has recently deployed an ERP system to integrate its financial, supply chain, and HR processes. The IT department is small (5 staff) and reports to the CFO. The company has no formal IT governance committee; IT decisions are made by the CFO and CEO informally. During a recent audit, it was found that several critical security patches for the ERP system have not been applied, and there are no documented procedures for change management. The IT manager states that patches are applied when time permits, and changes are discussed via email. The CFO argues that the ERP is running fine and the audit findings are low risk. The IS auditor needs to recommend a course of action to improve IT governance. Which of the following is the MOST appropriate initial step?

Easy
16

An organization's IT governance framework includes a policy that all system access must be reviewed quarterly. The internal audit finds that reviews are incomplete. What is the BEST action?

Medium
17

An IS auditor is reviewing the IT governance of a financial services firm. The auditor discovers that the IT steering committee has approved a major core banking system upgrade, but the project lacks a formal business case and no post-implementation review is planned. Which of the following is the MOST significant risk arising from this situation?

Hard
18

A business continuity plan (BCP) includes a tabletop exercise once a year. An IS auditor finds that the exercise only involves IT staff. Which of the following is the BEST recommendation?

Medium
19

Based on the exhibit, what is the MOST likely security risk?

Medium
20

An IS auditor is reviewing an organization's IT governance framework and notices that the IT steering committee, chaired by the CIO, approves all IT investments and also monitors their benefits realization. The board has delegated full IT decision-making authority to this committee. The auditor is MOST likely to conclude that:

Medium
21

Scenario: A mid-sized manufacturing company has recently experienced a significant IT outage that halted production for 8 hours. The root cause was a failed firmware update on a core switch that was performed outside the change management process by a senior network engineer who claimed the update was urgent to patch a critical vulnerability. The company has a well-documented change management policy that requires all changes to be reviewed by the change advisory board (CAB) before implementation, except for emergency changes which require post-implementation review within 48 hours. The engineer did not follow the emergency change process; he implemented the update directly. The IT director wants to prevent such incidents in the future. Which of the following is the BEST action?

Hard
22

An IT governance framework has been implemented, but the board is not receiving regular reports on IT performance. Which of the following is the BEST course of action?

Medium
23

A hospital's IT department has implemented a new electronic health record (EHR) system. The IS auditor is reviewing the IT governance over the project and finds that the project sponsor is the CIO, who also chairs the IT steering committee that approved the project. Which of the following is the MOST significant governance risk?

Easy
24

An organization has implemented a balanced scorecard (BSC) for IT performance measurement. Which of the following is the PRIMARY benefit of using a BSC?

Easy
25

A company is implementing IT governance based on COBIT 2019. Which of the following design factors would have the GREATEST impact on the governance system design?

Hard
26

An IS auditor is assessing the IT governance framework of a retail company. The auditor finds that the company has a formal IT strategy, an IT steering committee, and a defined IT organizational structure. However, the auditor notes that there is no process to ensure that IT investments are justified and prioritized. Which of the following are the MOST appropriate recommendations to address this deficiency? (Choose two.)

Hard
27

A large enterprise is assessing its IT governance maturity. Which THREE of the following are indicators of a mature governance process? (Select exactly three.)

Hard
28

An IT governance framework should include which TWO key components? (Select exactly two.)

Easy
29

An organization has a policy requiring all employees to complete annual information security awareness training. Which of the following is the BEST way to verify compliance with this policy?

Easy
30

Which TWO of the following are benefits of implementing an IT governance framework?

Easy
31

A company is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?

Easy
32

Which TWO of the following are recommended practices for aligning IT strategy with business goals, according to COBIT 2019?

Medium
33

Midway through a multi-year ERP implementation, the CIO asks the IS auditor to review how the organization is realizing the intended business benefits. The project is on schedule and within budget, but business unit managers report that key process changes have not been adopted. Which of the following is the MOST appropriate action for the IS auditor to recommend?

Medium
34

An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?

Easy
35

A company plans to outsource its data center operations to a cloud service provider. What is the MOST important governance consideration for the board before finalizing the contract?

Medium
36

An organization's IT department has a policy that all new hires must sign an acceptable use policy (AUP) before gaining access to systems. During an audit, the IS auditor finds that several contractors were granted access without signing the AUP. Which of the following is the auditor's BEST recommendation?

Easy
37

A multinational corporation is implementing a global IT governance framework. Which of the following challenges is MOST likely to arise?

Hard
38

An IS auditor is reviewing an organization's IT governance framework and notes that the board of directors has established an IT strategy committee. Which TWO of the following are the MOST appropriate responsibilities for this committee? (Choose two.)

Medium
39

An IS auditor is reviewing an organization's IT governance structure. The board of directors has delegated all IT oversight to the CIO, who reports to the CFO. The auditor finds that the board receives only annual summaries of IT performance and never reviews IT risks. Which of the following is the MOST significant governance concern?

Medium
40

A medium-sized e-commerce company recently suffered a ransomware attack that encrypted critical databases. The IT team restored systems from backups, but the incident exposed a lack of clear roles and responsibilities for incident response. The board has asked the IT governance committee to review and improve the incident response governance. The committee notes that while there is an incident response policy, it is not regularly tested, and staff are unsure of their roles. The company also lacks a formal communication protocol for notifying stakeholders. What should the committee prioritize to strengthen governance over incident response?

Easy
41

An IS auditor is reviewing the IT organizational structure of a mid-sized manufacturing company. The auditor finds that the IT department reports to the CFO, and there is no separate IT strategy committee. The CEO believes that IT is a support function and does not need board-level representation. Which of the following is the MOST appropriate recommendation for the auditor?

Easy
42

A multinational corporation is evaluating its IT governance structure. The board wants to ensure that IT investments are prioritized based on risk and value. Which framework component is MOST critical?

Hard
43

A mid-sized company is implementing a new IT service management (ITSM) tool to improve incident management. The IT manager wants to ensure that the tool aligns with ITIL best practices. The company has a dedicated service desk team that handles about 200 incidents per week. The IT manager is considering whether to implement a self-service portal for users to submit incidents and check status, or to continue using email-based incident reporting. The service desk team is concerned that a self-service portal might reduce their direct interaction with users and potentially lead to less personalized support. However, the IT manager believes that a portal could improve efficiency and tracking. The company's IT governance framework requires that any major IT investment be approved by the steering committee and that there be a clear business case. The IT manager has prepared a business case but the steering committee wants to ensure that the solution is aligned with ITIL and that it addresses key incident management processes. Which of the following is the most appropriate next step for the IT manager?

Easy
44

A multinational corporation has defined its risk appetite as 'moderate' for IT investments. The IT steering committee is evaluating a new project with potential high returns but also significant cybersecurity risks. The project's risk profile is assessed as 'high' by the risk management team. What should the committee do FIRST?

Hard
45

A global retail company is implementing an IT governance framework. The board of directors has asked the IS auditor to identify the KEY components that should be included in the framework to ensure effective governance. Which TWO of the following are essential components of an IT governance framework? (Choose two.)

Hard
46

Order the steps for performing a data backup in the correct sequence.

Medium
47

An IS auditor is reviewing the IT governance framework of a small organization. The auditor finds that the IT manager reports directly to the CFO, and there is no separate IT steering committee. Which of the following is the MOST appropriate conclusion?

Easy
48

Scenario: A healthcare organization is implementing a new electronic health records (EHR) system. The project has been delayed due to scope creep and resource constraints. The project sponsor is pressuring the project manager to accelerate the timeline by skipping user acceptance testing (UAT) and going live immediately. The organization has a governance policy that requires all IT projects to complete UAT before deployment. The project manager is concerned about quality and patient safety. Which of the following is the BEST course of action?

Medium
49

An IT department uses a balanced scorecard (BSC) to measure performance. The financial perspective shows that IT costs are within budget, but customer satisfaction scores are declining. The learning and growth perspective indicates low employee engagement. Which action should the IT governance committee prioritize?

Hard
50

An organization's IT strategy is developed by the IT department without input from business stakeholders. Which of the following is the MOST significant risk?

Hard
51

A medium-sized manufacturing company has a decentralized IT structure where each business unit manages its own IT budget and projects. The CEO is concerned that IT investments are not aligned with corporate strategy and that there is duplication of effort. The IT department lacks a formal project portfolio management process. The company has experienced several project failures due to poor prioritization. The CEO has asked the newly hired IT auditor to recommend an initial step to improve IT governance. The auditor should recommend:

Easy
52

An organization has implemented a new IT service management (ITSM) tool. The IT manager wants to measure the effectiveness of incident management. Which metric is MOST appropriate?

Hard
53

A financial services firm has a mature IT governance framework. The IS auditor is reviewing the IT governance structure and notices that the IT steering committee meets quarterly and focuses primarily on project approvals. Which of the following is the MOST significant concern regarding this committee's effectiveness?

Medium
54

An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of using a framework like COBIT?

Easy
55

You are the IT governance lead at a multinational corporation with a complex IT environment spanning multiple business units. The company has recently experienced a series of minor security incidents where unauthorized access was gained through unused user accounts that were not disabled after employees left the organization. Additionally, there have been delays in provisioning access for new hires, leading to productivity losses. The IT department currently uses a manual process for access management, with each business unit maintaining its own user lists. The company has a policy that requires access reviews every quarter, but these are often missed or performed superficially. The CIO has asked you to recommend a solution that addresses these issues while ensuring compliance with regulations such as GDPR and SOX. Which of the following is the BEST course of action?

Hard
56

An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. What is the committee's MOST important role?

Medium
57

An IT manager needs to ensure that the organization's IT resources are used efficiently. Which of the following is the BEST metric to measure IT resource utilization?

Easy
58

An organization has a policy requiring annual information security awareness training for all employees. During a recent audit, it was found that 20% of employees had not completed the training. What is the BEST course of action for the IT governance committee?

Easy
59

A company outsources its data center operations to a third-party provider. Which of the following is the MOST important control to include in the outsourcing contract?

Medium
60

A financial services company is migrating its core banking system to a public cloud to improve scalability and reduce costs. The project is high-risk due to regulatory compliance requirements (e.g., data residency, audit trails). The IT governance committee has reviewed the project plan and finds that the risk assessment is incomplete – it does not address the potential impact of a cloud provider outage on critical transactions. The committee must approve the project or request changes. The project manager argues that the cloud provider's SLA guarantees 99.99% uptime and that additional controls would delay the project. What should the governance committee do?

Medium
61

Based on the exhibit, which control is most likely missing to prevent this type of event?

Hard
62

Based on the exhibit, what is the MOST appropriate action for IT management?

Easy
63

An organization's IT department has grown rapidly, and the CIO wants to ensure that employees understand expected behaviors when handling sensitive data and operating critical systems. Which of the following is the MOST appropriate governance mechanism to establish?

Easy
64

An organization's IT strategy is not aligned with business strategy due to lack of communication. Which of the following would BEST improve alignment?

Hard
65

An organization has decided to adopt a formal IT governance framework to improve alignment between IT and business objectives. Management asks the IS auditor to advise on the FIRST step in the adoption process. Which of the following should the IS auditor recommend?

Medium
66

A multinational corporation operates in a highly regulated industry. The IT governance framework includes a risk appetite statement approved by the board. Recently, the company suffered a significant data breach due to an unpatched vulnerability that had been identified three months earlier. The IT audit found that the vulnerability was reported to the IT department but was not prioritized for remediation because it was deemed low risk by the IT operations team. The incident response plan was not activated because the breach was not initially detected. The board wants to strengthen governance to prevent recurrence. The most effective course of action for the auditor to recommend is:

Hard
67

An IT manager submits a request to change the firewall configuration during business hours. According to best practices for change management, what should be done FIRST?

Easy
68

An organization's IT department implemented a new change management process that requires all changes to be approved by a change advisory board (CAB). A critical security patch needs to be deployed within 2 hours to address an active zero-day vulnerability. The change request was submitted but the CAB is not scheduled to meet for another 24 hours. What is the BEST course of action?

Medium
69

Which of the following is the PRIMARY purpose of an IT governance framework?

Easy
70

An IS auditor is reviewing the IT governance framework of a financial services firm. The auditor notes that the IT strategy is updated annually, but there is no process to monitor whether IT initiatives are aligned with the strategy. Which of the following is the BEST recommendation?

Medium
71

An IS auditor is assessing the effectiveness of an organization's IT governance implementation. Which TWO of the following are the MOST important indicators that IT governance is effectively implemented? (Choose two.)

Hard
72

Which of the following is the PRIMARY purpose of an IT strategy committee?

Easy
73

An IS auditor is reviewing an organization's IT governance structure and finds that the IT steering committee meets quarterly but has no defined charter or decision-making authority. Which of the following is the MOST significant risk arising from this situation?

Medium
74

A retail company is merging with a competitor. The IT departments of both organizations have different IT governance structures: Company A uses a centralized model with strict change management, while Company B uses a decentralized model with autonomous business unit IT. The CIO has been tasked with integrating the IT functions post-merger. The board expects cost synergies and improved service levels. The integration team is facing resistance from Company B's business heads who fear loss of agility. The CIO needs to propose a governance model for the merged entity. Which approach would BEST meet the board's expectations while addressing resistance?

Medium
75

An organization has decentralized IT management with each business unit making its own technology decisions. Which of the following is the BEST way to maintain enterprise-wide governance?

Hard
76

An IS auditor is evaluating an organization's IT risk management process. The auditor finds that risk assessments are performed annually by the IT department alone, without input from business units. Which of the following is the MOST significant concern?

Hard
77

An organization outsources its data center operations. What is the BEST way to ensure the service provider's controls are effective?

Hard
78

Which THREE of the following are responsibilities of the board of directors regarding IT governance? (Choose three.)

Hard
79

An IS auditor is reviewing the governance structure of a large retail company. The board has delegated all IT oversight to the IT steering committee, which meets quarterly and focuses primarily on project prioritization. The auditor notes that the board receives no IT-related reports and does not review IT risks. Which of the following is the MOST significant governance concern?

Medium
80

An organization is implementing a new IT governance framework. Which of the following is the BEST approach to ensure alignment between IT strategy and business goals?

Medium
81

A multinational corporation is adopting a hybrid cloud strategy. The IT governance board must decide on a framework to ensure alignment with business objectives and regulatory compliance. Which framework is MOST appropriate?

Hard
82

An IS auditor is evaluating an organization's IT governance framework. The auditor finds that IT decisions are made ad hoc by various business units without alignment to corporate strategy. Which TWO of the following are the MOST important governance mechanisms the auditor should recommend to address this issue? (Choose two.)

Hard
83

During an IT audit, the auditor discovers that the IT department has not conducted a business impact analysis (BIA) for three years. The organization's disaster recovery plan (DRP) is based on the previous BIA. The IT manager argues that the DRP is still valid because no major changes have occurred. What should the auditor recommend?

Hard
84

A multinational corporation has adopted a decentralized IT governance model where business units have significant autonomy over IT decisions. The IS auditor is assessing the effectiveness of this model. Which of the following is the MOST critical factor for the auditor to evaluate?

Medium
85

An organization's IT department has recently implemented a new project management methodology. The IS auditor is reviewing the project portfolio and finds that projects are prioritized based on the personal preferences of the IT director rather than strategic alignment. Which of the following is the MOST significant risk arising from this practice?

Easy
86

An organization is implementing an IT governance framework to align IT with business objectives. Which TWO of the following are primary responsibilities of the IT steering committee?

Medium
87

A large financial institution has a well-defined IT governance framework with a clear organizational structure, policies, and processes. However, the internal audit department has identified that several IT projects are over budget and behind schedule. The project managers blame unclear requirements and scope creep. The IT governance committee meets monthly but reviews projects only at a high level. The auditor's best recommendation to improve project governance is to:

Medium
88

During a risk assessment, an IS auditor identifies that the IT department has not performed a business impact analysis (BIA) for critical systems. Which of the following is the MOST significant risk?

Hard
89

An IS auditor is evaluating an organization's IT governance maturity using COBIT 2019. The auditor finds that IT processes are largely ad hoc, with no formal documentation, and success depends on individual heroics. Which of the following maturity levels BEST describes this situation?

Hard
90

An IS auditor is evaluating the IT governance structure of a multinational corporation. The auditor finds that IT decisions are made independently by regional business units, with no central oversight. The corporate IT strategy exists but is not enforced. Which of the following is the MOST likely consequence of this governance approach?

Hard
91

A retail organization's board has approved an IT governance framework that delegates decision rights for infrastructure standards to a central architecture board, while reserving funding decisions above a threshold for the board's technology committee. Business units must comply with the standards but may request exceptions. Which of the following is the MOST important control for the IS auditor to verify when assessing the effectiveness of this framework?

Hard
92

An IT department uses a balanced scorecard to measure performance. Which metric would BEST reflect the 'customer perspective'?

Easy
93

An IT manager is reviewing the service level agreements (SLAs) for a cloud-based email service. The SLA guarantees 99.9% uptime per month. The service experienced an outage of 45 minutes in a 30-day month. Did the service meet the SLA?

Medium
94

An IT audit revealed that the organization's IT steering committee has not met in the past six months. Which of the following is the MOST likely consequence of this situation?

Medium
95

A mid-sized insurance company has decided to adopt a formal IT governance framework because its board is concerned about unmanaged IT risk. The CIO asks the IS auditor to recommend the FIRST step in establishing the governance framework. Which of the following should the IS auditor recommend?

Medium
96

Which TWO of the following are benefits of establishing an IT steering committee?

Easy
97

An organization is planning to outsource its data center operations. Which of the following governance practices should be implemented to ensure proper oversight?

Medium
98

An IS auditor is reviewing the organization's IT governance framework. The board has delegated oversight of IT to an IT steering committee. The auditor finds that the committee meets quarterly, but its charter does not define decision rights or escalation procedures. Which of the following is the MOST significant concern?

Medium
99

An IS auditor is assessing an organization's IT governance implementation. The auditor finds that IT policies are outdated, roles and responsibilities are unclear, and there is no regular reporting on IT performance to the board. Which TWO of the following are the MOST critical actions to improve IT governance? (Choose two.)

Hard
100

Which THREE of the following are commonly recognized benefits of implementing a formal IT service management (ITSM) framework such as ITIL?

Hard
101

An IT manager is developing a governance policy for change management. Which element is MOST important to include?

Easy
102

Which THREE of the following are components of a typical IT governance framework?

Hard
103

An IS auditor is assessing an organization's IT governance. The auditor finds that the IT balanced scorecard is used to measure IT performance, but the metrics are heavily focused on internal IT processes and do not include business or customer perspectives. Which of the following is the MOST likely consequence of this imbalance?

Medium
104

An IS auditor is reviewing an organization's IT governance policies and finds that the IT strategy is updated annually, but there is no process to monitor external factors such as regulatory changes or emerging technologies. Which of the following is the MOST significant risk of this deficiency?

Medium
105

An organization's IT strategy must be aligned with business strategy. Which of the following is the PRIMARY benefit of this alignment?

Easy
106

An organization is implementing a new ERP system. The project sponsor requests a change that will significantly increase project scope without additional budget. Which of the following is the BEST action for the project manager?

Hard
107

An organization's data classification policy defines 'Confidential' data as requiring encryption at rest. An IS auditor discovers that a database containing customer personal information is not encrypted. What is the auditor's BEST course of action?

Hard
108

During an IT audit, the auditor discovers that the IT strategy is not formally documented. Which of the following is the MOST significant risk associated with this finding?

Easy
109

An organization has a policy that requires all IT projects to have a business case approved by the IT steering committee. The IS auditor discovers that a major infrastructure upgrade was initiated without an approved business case. Which of the following is the auditor's PRIMARY concern?

Medium
110

Which TWO of the following are key responsibilities of an IT steering committee?

Medium
111

An organization is establishing an IT governance committee. The committee's charter includes overseeing IT investments, monitoring IT performance, and ensuring compliance with regulations. Which of the following should the IS auditor recommend as the MOST important characteristic of the committee's membership?

Easy
112

An IS auditor is assessing whether an organization's IT steering committee is fulfilling its governance responsibilities. The committee charter states that it oversees IT investment prioritization, monitors IT performance against agreed objectives, and resolves escalated resource conflicts. Which TWO of the following observations would the auditor MOST likely identify as deficiencies in the committee's operation? (Choose two.)

Hard
113

Which THREE of the following are indicators of mature IT governance?

Hard
114

An IT department is struggling with project delays and budget overruns. Which governance practice would be MOST effective?

Medium
115

Arrange the steps to perform a risk assessment in the correct order.

Medium
116

An IS auditor is assessing the effectiveness of an organization's IT governance framework. Which TWO of the following are essential components that the auditor should verify are in place? (Choose two.)

Medium
117

An IS auditor is assessing an organization's IT governance framework and finds that the IT balanced scorecard includes metrics such as system uptime, number of help desk tickets resolved, and average response time. The auditor notes that these are all internal IT operational metrics. The MOST significant concern is that:

Hard
118

An organization is developing its IT strategy to align with the overall business strategy. The business strategy emphasizes rapid market expansion through digital products. Which of the following IT strategies would BEST support this business goal?

Easy
119

A company is considering restructuring its IT department from a centralized to a decentralized model to give business units more autonomy. What is a PRIMARY governance risk associated with this move?

Medium
120

An organization has experienced several security incidents due to unauthorized changes to production systems. Which governance mechanism should be strengthened?

Medium
121

An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. Which of the following BEST demonstrates that the proposal aligns with the organization's strategic goals?

Easy

Frequently asked questions

What does the Governance and Management of IT domain cover on the CISA exam?
You must be able to evaluate IT governance structures, order risk and backup steps, and apply change management controls. The single most important thing is knowing that governance is a board responsibility, not an IT function.
How many questions are in this domain?
This page lists all 121 Governance and Management of IT questions in the CISA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Governance and Management of IT questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
isaca-cisa ISACA-CISA it governance mgmt Practice Questions