Courseiva

CCNA Governance and Management of IT Questions

75 of 109 questions · Page 1/2 · Governance and Management of IT · Answers revealed

1
MCQhard

An IS auditor is reviewing the balanced scorecard for IT. Which of the following metrics BEST aligns with the 'customer perspective'?

A.Average system uptime for critical applications
B.Percentage of IT projects under budget
C.Number of change requests completed on time
D.Percentage of staff with ITIL certification
AnswerA

Uptime reflects customer-facing service levels.

Why this answer

Average system uptime for critical applications directly measures IT service availability from the customer's perspective. In the balanced scorecard framework, the customer perspective focuses on how end users experience IT services. The other options align with different perspectives: B (under budget) is financial, C (change requests on time) is internal processes, and D (ITIL certification) is learning and growth.

2
MCQhard

A multinational manufacturing company with operations in 20 countries has historically allowed each regional division to manage its own IT systems independently. Recently, the company experienced a significant data breach originating from a region with weaker security controls, leading to financial losses and reputational damage. The board has mandated stronger IT governance to prevent future incidents. The CIO proposes implementing a global IT governance framework with centralized policy enforcement. However, regional directors argue that local regulations and business needs require autonomy. The governance committee must decide on a course of action that balances risk and business flexibility. Which of the following approaches is the MOST appropriate?

A.Adopt a federated governance model with global policies and local flexibility within defined tolerances.
B.Allow each region to continue independently but require quarterly reporting to the committee.
C.Implement a fully centralized IT governance model with no regional deviations.
D.Maintain the status quo but enforce minimum security standards across all regions.
AnswerA

Federated governance balances consistency with local adaptation.

Why this answer

The most appropriate approach is the federated governance model (Option A), which establishes global policies and standards centrally while allowing regional divisions to adapt within defined risk tolerances. This balances the board's mandate for stronger IT governance with legitimate local regulatory and business needs. Option B (quarterly reporting) is insufficient because it does not enforce any binding controls, leaving the company vulnerable to future breaches.

Option C (fully centralized) may ignore critical local regulations and hinder business agility, leading to non-compliance and operational friction. Option D (status quo with minimum standards) is too weak; after a significant breach, a more robust framework requiring proactive governance is needed, not just baseline security.

3
MCQmedium

A company has multiple business units with conflicting IT priorities. Which governance body should resolve this?

A.IT steering committee
B.Board of directors
C.IT management
D.Audit committee
AnswerA

This committee is designed to align and prioritize IT investments.

Why this answer

An IT steering committee, comprising business and IT leadership, is responsible for prioritizing IT initiatives and resolving conflicts. IT management may lack authority; board and audit committee have broader oversight roles.

4
Multi-Selecteasy

Which TWO of the following are common objectives of an IT balanced scorecard? (Choose two.)

Select 2 answers
A.Deploying a new ERP system
B.Reducing the number of help desk tickets
C.Enhancing IT staff skills and knowledge
D.Implementing a new firewall
E.Improving customer satisfaction with IT services
AnswersC, E

Learning and growth perspective.

Why this answer

The IT balanced scorecard translates the organization's strategy into objectives across four perspectives: customer, financial, internal process, and learning/growth. Option C (enhancing IT staff skills and knowledge) aligns with the learning and growth perspective, as it focuses on developing human capital. Option E (improving customer satisfaction with IT services) aligns with the customer perspective, measuring how IT meets user needs.

Options A, B, and D are tactical or operational activities rather than strategic objectives spanning the balanced scorecard dimensions.

5
MCQmedium

A large enterprise recently experienced a data breach due to an insider threat. The IT governance committee is reviewing the incident and considering measures to prevent recurrence. Which of the following is the BEST course of action to address the root cause?

A.Implement a privileged access management (PAM) solution to control and monitor elevated access.
B.Increase logging and auditing of all user activities.
C.Deploy a security information and event management (SIEM) tool.
D.Terminate the employment of the insider who caused the breach.
AnswerA

PAM directly prevents and controls unauthorized privileged access, addressing the root cause.

Why this answer

A privileged access management (PAM) solution directly addresses the root cause of an insider threat by controlling, monitoring, and auditing elevated access rights. Since the breach was caused by an insider, limiting and tracking privileged accounts prevents unauthorized or excessive use of administrative credentials, which is the most effective preventive measure against recurrence.

Exam trap

The trap here is that candidates often confuse detective controls (logging, SIEM) with preventive controls (PAM), or they mistakenly view termination as a root-cause fix rather than a reactive measure, failing to recognize that the root cause is the lack of access governance.

How to eliminate wrong answers

Option B is wrong because increasing logging and auditing of all user activities is a detective control, not a preventive one; it helps identify breaches after they occur but does not stop an insider from abusing elevated access. Option C is wrong because deploying a SIEM tool aggregates and correlates logs for detection and analysis, but it does not prevent an insider from using privileged access to cause a breach. Option D is wrong because terminating the insider is a reactive disciplinary action that addresses the specific individual but does not fix the underlying lack of access controls, leaving the enterprise vulnerable to future insider threats.

6
Multi-Selectmedium

Which TWO of the following are key components of an IT governance framework?

Select 2 answers
A.Resource management
B.Strategic alignment
C.Performance measurement
D.Risk management
E.Value delivery
AnswersB, E

Strategic alignment ensures IT goals are in line with business goals, a core governance component.

Why this answer

Strategic alignment (B) is a key component of an IT governance framework because it ensures that IT strategies, investments, and operations are directly linked to business goals and objectives. This alignment is achieved through mechanisms such as balanced scorecards, IT steering committees, and portfolio management, which translate business strategy into IT priorities. Without strategic alignment, IT may operate in a silo, leading to wasted resources and missed opportunities for business value.

Exam trap

The trap here is that candidates often confuse the five focus areas of COBIT (strategic alignment, value delivery, risk management, resource management, performance measurement) with the two core components of an IT governance framework, leading them to select all five or pick risk management as a core component.

7
Multi-Selecteasy

Which TWO of the following are key components of an IT governance framework? (Choose two.)

Select 2 answers
A.Network topology diagram
B.Help desk procedures
C.Hardware inventory
D.IT strategy
E.IT steering committee
AnswersD, E

Correct. Defines alignment with business goals.

Why this answer

D and E are correct. An IT strategy (D) and an IT steering committee (E) are key components of an IT governance framework. A (network topology diagram) is a technical document, B (help desk procedures) is operational, and C (hardware inventory) is operational, so they are not governance components.

8
Multi-Selectmedium

An organization is implementing COBIT 2019. Which TWO of the following are governance enablers? (Choose two.)

Select 2 answers
A.Hardware configuration
B.Project schedule
C.Organizational structures
D.Network performance
E.Culture, ethics and behavior
AnswersC, E

Correct. A COBIT enabler for governance.

Why this answer

Options C and E are correct because organizational structures and culture, ethics, and behavior are governance enablers in COBIT 2019. Option A (Hardware configuration) is incorrect as it is an implementation detail, not a governance enabler. Option B (Project schedule) is incorrect as it is a project management artifact.

Option D (Network performance) is incorrect as it is operational.

9
MCQmedium

A financial institution is evaluating its IT governance structure. Which of the following roles is BEST suited to ensure independent oversight of IT investments?

A.Chief Information Officer (CIO)
B.Project Management Office (PMO) director
C.IT Audit Committee
D.Chief Information Security Officer (CISO)
AnswerC

An independent audit committee provides objective oversight.

Why this answer

The IT Audit Committee is the correct answer because it provides independent oversight of IT investments by operating outside of management's direct reporting structure. Unlike the CIO, PMO director, or CISO, who are all part of management and may have vested interests in project approvals or resource allocation, the IT Audit Committee reports to the board of directors and ensures that IT investments align with enterprise strategy, risk appetite, and regulatory requirements without bias.

Exam trap

The trap here is that candidates often confuse operational management roles (CIO, PMO director, CISO) with governance roles, mistakenly believing that a senior IT manager can provide independent oversight when they are actually part of the management chain being overseen.

How to eliminate wrong answers

Option A is wrong because the Chief Information Officer (CIO) is a senior management role responsible for the day-to-day operation and strategic planning of IT, which inherently lacks the independence required for oversight of IT investments. Option B is wrong because the Project Management Office (PMO) director is focused on project execution, resource management, and delivery metrics, not on independent governance or strategic alignment of IT investments. Option D is wrong because the Chief Information Security Officer (CISO) is primarily concerned with information security risk management and compliance, not with the broader financial and strategic oversight of IT investments.

10
MCQeasy

An organization wants to ensure that IT performance is measured against strategic goals. Which tool is BEST suited?

A.Balanced scorecard
B.Pareto chart
C.SWOT analysis
D.Gantt chart
AnswerA

BSC aligns IT metrics with strategic goals.

Why this answer

A balanced scorecard translates strategic goals into performance metrics across financial, customer, internal process, and learning perspectives. Gantt charts, SWOT analysis, and Pareto charts are not designed for this purpose.

11
MCQhard

An organization's IT governance committee is reviewing a proposal to use a public cloud provider that does not meet the organization's data encryption standards. The board has set a low risk appetite for data privacy. What is the BEST action?

A.Accept the proposal with additional monitoring
B.Delegate the decision to the security team
C.Accept the proposal but require the provider to sign a waiver
D.Reject the proposal until encryption requirements are met
AnswerD

Correct. The proposal does not align with risk appetite.

Why this answer

Rejecting the proposal aligns with the board's low risk appetite for data privacy and ensures encryption standards are met before acceptance. Option A is incorrect because additional monitoring does not resolve the encryption gap. Option B is incorrect because delegation to the security team bypasses the governance committee's responsibility to enforce risk appetite.

Option C is incorrect because waivers do not mitigate the fundamental encryption non-compliance.

Exam trap

The trap is assuming that risk can be mitigated through monitoring or waivers, when the core issue is non-compliance with encryption standards that directly contradicts the board's risk appetite.

12
MCQhard

An auditor finds that access reviews have not been completed for two quarters. What is the MOST significant risk?

A.Data integrity may be compromised
B.Unauthorized access may be granted and persist
C.System performance may degrade
D.Audit findings may be reported to management
AnswerB

Correct. Incomplete reviews allow inappropriate access to continue.

Why this answer

Access reviews are essential for detecting and revoking unauthorized or excessive permissions. Without them, unauthorized access may go undetected and persist, leading to potential security breaches. Option A is incorrect because while data integrity could be compromised as a secondary effect, the most direct risk is unauthorized access.

Option C is incorrect: system performance is unrelated to access reviews. Option D is incorrect because reporting audit findings is a consequence, not the primary risk.

13
Multi-Selecthard

Which THREE of the following are components of the COBIT 2019 governance system?

Select 3 answers
A.Organizational structures
B.Information items
C.Processes
D.Service desk
E.Project management office
AnswersA, B, C

Organizational structures are a governance component.

Why this answer

Options A, B, and C are correct because COBIT 2019 defines governance system components as Organizational Structures, Information Items, and Processes. Option D (Service desk) is an operational process not a governance component. Option E (Project management office) is a management structure, not a governance component as defined in COBIT 2019.

14
MCQmedium

A large financial institution is evaluating the effectiveness of its IT governance framework. The board has requested a review to ensure alignment with business objectives and regulatory requirements. Which of the following is the MOST important factor for the board to consider when assessing the IT governance framework?

A.The framework is integrated with enterprise governance and supports strategic objectives.
B.The framework includes a detailed incident response plan.
C.The framework focuses on achieving high technical efficiency.
D.The framework minimizes overall IT costs.
AnswerA

Integration with enterprise governance ensures IT supports business goals and regulatory compliance.

Why this answer

An effective IT governance framework must be integrated with enterprise governance to ensure alignment with business objectives and regulatory requirements. Option B is incorrect because incident response is an operational process, not a primary board-level governance consideration. Option C is incorrect because technical efficiency is a management concern, not a governance-level factor.

Option D is incorrect because minimizing IT costs is a tactical objective that may conflict with strategic priorities.

15
MCQeasy

Refer to the exhibit. Based on the governance status report, which component should be addressed as a priority?

A.Strategy Alignment
B.Performance Measurement
C.Resource Optimization
D.Risk Management
AnswerC

Red status requires urgent action.

Why this answer

Resource Optimization has a Red status, indicating critical risk or non-compliance, requiring immediate attention. Green and Yellow components are less urgent.

16
MCQeasy

A healthcare organization must comply with HIPAA regulations regarding patient data privacy. The IT department has implemented technical controls, but the compliance officer discovers that some employees are sharing passwords. What is the BEST governance response?

A.Implement multi-factor authentication to prevent password sharing.
B.Enforce the existing policy through disciplinary actions and additional training.
C.Report the incident to the regulatory authority as a data breach.
D.Revise the password policy to require more complex passwords.
AnswerB

Enforcement and training are key governance controls.

Why this answer

The best governance response is to enforce the existing policy through disciplinary actions and additional training (option B). This addresses the root cause of non-compliance—employee behavior—by reinforcing the policy and educating staff. Option A (implementing MFA) is a technical control that may reduce password sharing but does not address the governance aspect; it could be a supporting measure but not the primary governance response.

Option C (reporting to regulatory authority) is premature because password sharing does not necessarily constitute a data breach; there is no evidence of actual exposure. Option D (revising the password policy to require more complex passwords) does not prevent sharing and may even increase it if passwords are harder to remember. Therefore, governance should focus on policy enforcement and training.

17
MCQeasy

A medium-sized manufacturing company has recently deployed an ERP system to integrate its financial, supply chain, and HR processes. The IT department is small (5 staff) and reports to the CFO. The company has no formal IT governance committee; IT decisions are made by the CFO and CEO informally. During a recent audit, it was found that several critical security patches for the ERP system have not been applied, and there are no documented procedures for change management. The IT manager states that patches are applied when time permits, and changes are discussed via email. The CFO argues that the ERP is running fine and the audit findings are low risk. The IS auditor needs to recommend a course of action to improve IT governance. Which of the following is the MOST appropriate initial step?

A.Elevate the issue to the board of directors with a recommendation to outsource IT management
B.Recommend the formation of an IT steering committee comprising key business stakeholders to oversee IT strategy, risk, and resource allocation
C.Develop a comprehensive patch management policy and present it to the CFO for approval
D.Insist that the IT manager immediately apply all missing patches within one week
AnswerB

Correct. This addresses the root cause of lack of governance and oversight.

Why this answer

The root cause is the absence of any formal governance structure. Establishing an IT steering committee with key business stakeholders (e.g., from finance, supply chain, HR) provides oversight, ensures that IT decisions align with business strategy, and creates a forum for prioritizing risks such as missing patches. This addresses the governance gap holistically.

Option A is not appropriate because outsourcing does not fix the lack of internal governance and is an extreme measure. Option C focuses only on patching, not on the underlying governance deficiency. Option D is an operational quick fix that bypasses the need for sustainable governance processes.

Exam trap

The trap is to pick a procedural fix (patch policy or immediate patching) or an extreme measure (outsourcing) instead of recognizing the fundamental governance deficiency.

18
Matchingmedium

Match each COBIT 5 domain to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Evaluate, Direct, and Monitor

Align, Plan, and Organize

Build, Acquire, and Implement

Deliver, Service, and Support

Monitor, Evaluate, and Assess

Why these pairings

COBIT 5 has five process domains: EDM (governance), APO (planning), BAI (acquisition/implementation), DSS (delivery/support), and MEA (monitoring). Correct matches are as above; common confusions involve swapping APO/MEA or DSS/APO.

19
MCQmedium

An organization's IT governance framework includes a policy that all system access must be reviewed quarterly. The internal audit finds that reviews are incomplete. What is the BEST action?

A.Implement an automated access review tool
B.Reinforce accountability with managers
C.Disable all non-compliant accounts
D.Update the policy to require monthly reviews
AnswerB

Correct. Holding managers responsible ensures reviews are completed.

Why this answer

Reinforcing accountability with managers directly addresses the root cause of incomplete reviews—lack of responsibility and follow-through. Option A is incorrect because implementing an automated access review tool may improve efficiency but does not address the underlying accountability issue. Option C is incorrect because disabling all non-compliant accounts could disrupt business operations without solving the process failure.

Option D is incorrect because updating the policy to require monthly reviews increases frequency but does not ensure reviews are completed.

20
MCQmedium

Based on the exhibit, what is the MOST likely security risk?

A.The web server is fully protected
B.Traffic to port 80 is not encrypted
C.Unrestricted traffic is allowed after the specific deny
D.The host 192.168.1.100 is exposed to denial-of-service attacks
AnswerC

This option accurately highlights a common security misconfiguration in sequential rule processing, typical of firewalls or Access Control Lists. If an exhibit demonstrates a specific deny rule that is subsequently followed by a broader, less restrictive allow rule (e.g., an implicit or explicit 'allow any any'), any traffic not explicitly matched and denied by the preceding specific rule will be permitted. This circumvents the intended denial, creating a significant vulnerability by failing to enforce the principle of least privilege.

Why this answer

The 'permit ip any any' at the end allows all traffic, bypassing earlier specific denials. Option A is not correct because the deny line only blocks other traffic, but the permit any any overrides it. Option B is not directly indicated.

Option D is a risk but less direct than the rule order issue.

21
MCQhard

Scenario: A mid-sized manufacturing company has recently experienced a significant IT outage that halted production for 8 hours. The root cause was a failed firmware update on a core switch that was performed outside the change management process by a senior network engineer who claimed the update was urgent to patch a critical vulnerability. The company has a well-documented change management policy that requires all changes to be reviewed by the change advisory board (CAB) before implementation, except for emergency changes which require post-implementation review within 48 hours. The engineer did not follow the emergency change process; he implemented the update directly. The IT director wants to prevent such incidents in the future. Which of the following is the BEST action?

A.Implement automatic firmware updates to eliminate human error.
B.Increase the frequency of CAB meetings to weekly to expedite change approvals.
C.Enforce the change management policy by implementing stricter controls and disciplinary measures for non-compliance.
D.Remove the network engineer's administrative access to all network devices.
AnswerC

Enforcing existing policy with consequences ensures adherence.

Why this answer

The root cause was a deliberate bypass of the existing change management policy, not a flaw in the policy itself. Enforcing stricter controls and disciplinary measures directly addresses the human factor by reinforcing accountability and deterring unauthorized changes, which is the most effective way to prevent recurrence when a well-documented process is already in place but ignored.

Exam trap

The trap here is that candidates often choose technical controls (like automatic updates or removing access) instead of recognizing that the fundamental issue is a governance failure—the policy exists but was not enforced, so the best action is to strengthen enforcement and accountability, not to add or remove technical capabilities.

How to eliminate wrong answers

Option A is wrong because implementing automatic firmware updates would remove human oversight entirely, potentially causing widespread outages if a faulty update is pushed without testing or CAB review, and it does not address the policy violation. Option B is wrong because increasing CAB meeting frequency does not solve the core issue of an engineer bypassing the process; the emergency change process already exists for urgent patches, so the problem is non-compliance, not approval speed. Option D is wrong because removing the network engineer's administrative access is an overly punitive and impractical measure that could hinder legitimate emergency responses; it does not enforce the existing change management process and may violate the principle of least privilege by eliminating necessary access for a qualified engineer.

22
MCQmedium

An IT governance framework has been implemented, but the board is not receiving regular reports on IT performance. Which of the following is the BEST course of action?

A.Conduct an IT risk assessment to identify critical areas.
B.Develop a dashboard that presents key IT metrics to the board.
C.Implement an IT balanced scorecard that aligns with corporate strategy.
D.Assign a chief information officer (CIO) to report directly to the board.
AnswerB

Developing a dashboard presents key IT metrics to the board, directly addressing the need for regular reports.

Why this answer

The best course of action because a dashboard provides a regular, concise view of key IT metrics for the board, directly addressing the lack of reporting. Option A (risk assessment) focuses on risk rather than reporting. Option C (balanced scorecard) is a broader strategic alignment tool.

Option D (assigning a CIO) changes reporting structure but does not ensure regular reports.

23
MCQeasy

An organization has implemented a balanced scorecard (BSC) for IT performance measurement. Which of the following is the PRIMARY benefit of using a BSC?

A.It simplifies the IT budgeting process.
B.It ensures IT metrics are aligned with business strategy.
C.It automates data collection for IT metrics.
D.It provides a single financial metric for IT performance.
AnswerB

This is correct because BSC aligns IT metrics with business strategy across multiple perspectives.

Why this answer

The primary benefit of a balanced scorecard (BSC) is to align IT metrics with business strategy across multiple perspectives (financial, customer, internal processes, learning and growth). Option A is incorrect because BSC does not simplify budgeting; it includes both financial and non-financial metrics. Option C is incorrect because BSC does not automate data collection; it is a framework for measurement, not automation.

Option D is incorrect because BSC does not provide a single financial metric; it uses a balanced set of metrics from multiple perspectives.

24
Multi-Selectmedium

Which TWO of the following are key components of an IT governance framework? (Choose two.)

Select 2 answers
A.Configuration management database
B.Performance measurement
C.Vulnerability assessment results
D.Strategic alignment of IT with business
E.Firewall rules
AnswersB, D

Measuring IT performance is essential for governance.

Why this answer

The correct answers are B (Performance measurement) and D (Strategic alignment of IT with business). Both are key components of an IT governance framework as defined by COBIT and similar frameworks. Performance measurement enables monitoring of IT's contribution to business goals, while strategic alignment ensures IT initiatives support business objectives.

Option A (Configuration management database) is an operational tool, not a governance component. Option C (Vulnerability assessment results) is a security control output. Option E (Firewall rules) is an operational security measure, not a governance framework element.

25
MCQhard

A company is implementing IT governance based on COBIT 2019. Which of the following design factors would have the GREATEST impact on the governance system design?

A.The IT infrastructure complexity.
B.The size of the organization.
C.The number of IT staff.
D.The industry and regulatory environment.
AnswerD

Industry and regulations impose compliance requirements that shape governance.

Why this answer

According to COBIT 2019, the industry and regulatory environment is a key design factor that significantly influences the governance system design, as it dictates compliance and risk management requirements. Options A, B, and C are factors but have a lesser impact compared to industry and regulatory considerations.

26
Multi-Selecthard

Which THREE of the following are responsibilities of the board of directors regarding IT governance? (Choose three.)

Select 3 answers
A.Implementing IT security controls
B.Approving the IT strategy
C.Reviewing and approving IT policies
D.Monitoring daily IT operations
E.Ensuring that IT risks are managed within acceptable levels
AnswersB, C, E

Board approves strategic direction.

Why this answer

Correct answers: B, C, E. The board is responsible for approving the IT strategy (B), reviewing and approving IT policies (C), and ensuring that IT risks are managed within acceptable levels (E). Implementing IT security controls (A) is a management duty, and monitoring daily IT operations (D) is an operational responsibility.

27
Multi-Selecthard

A large enterprise is assessing its IT governance maturity. Which THREE of the following are indicators of a mature governance process? (Select exactly three.)

Select 3 answers
A.IT decisions are made in silos
B.IT budget is allocated based on historical spending
C.There is a formal IT governance committee
D.IT performance metrics are linked to business outcomes
E.IT strategy is reviewed quarterly by the board
AnswersC, D, E

Formal committee is a hallmark of maturity.

Why this answer

Mature governance involves board-level review of IT strategy, linking IT metrics to business outcomes, and having a formal governance committee. Decisions in silos and historical budget allocation are signs of low maturity.

28
Multi-Selecteasy

An IT governance framework should include which TWO key components? (Select exactly two.)

Select 2 answers
A.User training
B.Vendor lock-in
C.Strategic alignment
D.Network firewall rules
E.Performance measurement
AnswersC, E

Aligns IT with business objectives.

Why this answer

Strategic alignment ensures IT supports business goals; performance measurement tracks achievement. Network firewall rules, user training, and vendor lock-in are operational or tactical, not core governance components.

29
MCQeasy

An organization has a policy requiring all employees to complete annual information security awareness training. Which of the following is the BEST way to verify compliance with this policy?

A.Conduct phishing simulation tests
B.Survey employees about their satisfaction with training
C.Interview HR about training content
D.Review training completion records from the learning management system
AnswerD

Records provide direct evidence of completion.

Why this answer

Reviewing training completion records directly confirms that employees have completed the required annual information security awareness training. Option A (phishing simulation tests) evaluates susceptibility to phishing but does not verify training completion. Option B (surveying satisfaction) measures perception, not compliance.

Option C (interviewing HR about content) does not provide evidence of individual completion.

30
Multi-Selecteasy

Which TWO of the following are benefits of implementing an IT governance framework?

Select 2 answers
A.Improved risk management and mitigation
B.Reduction in IT staff headcount
C.Enhanced regulatory compliance
D.Reduced IT operational costs
E.Elimination of all IT project failures
AnswersA, C

Frameworks like COBIT emphasize risk management.

Why this answer

Implementing an IT governance framework, such as COBIT or ISO/IEC 38500, establishes structured policies, procedures, and controls that directly improve risk management and mitigation. By defining clear roles, accountability, and risk appetite, the framework ensures that risks are systematically identified, assessed, and treated, rather than being managed ad hoc. This aligns IT strategy with business objectives and embeds risk management into daily operations.

Exam trap

The trap here is that candidates often confuse the benefits of an IT governance framework with operational cost-cutting or headcount reduction, when in fact the framework's core value is in aligning IT with business goals, improving risk management, and ensuring compliance, not in directly reducing expenses or eliminating failures.

31
MCQeasy

A company is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?

A.Simplifies IT architecture
B.Improves IT staff morale
C.Ensures IT investments support business objectives
D.Reduces IT costs
AnswerC

This is the core purpose of alignment: IT enables business goals.

Why this answer

Aligning IT strategy with business strategy ensures that IT investments support business objectives, delivering value and reducing waste. Reducing costs, improving morale, or simplifying architecture are secondary benefits.

32
Multi-Selectmedium

Which TWO of the following are recommended practices for aligning IT strategy with business goals, according to COBIT 2019?

Select 2 answers
A.Implementing a continuous monitoring system for IT operational metrics
B.Conducting monthly IT steering committee meetings to review project status
C.Adopting a governance framework that covers all IT-related activities and stakeholder needs
D.Defining IT investment portfolios based on business value contribution
E.Using agile development methodologies for all IT projects
AnswersC, D

Correct. A holistic governance framework like COBIT 2019 ensures alignment.

Why this answer

COBIT 2019 explicitly requires a governance framework that covers all IT-related activities and stakeholder needs to ensure alignment with business goals. This framework integrates enterprise governance principles, such as the Governance System and Governance Framework components, to bridge IT and business strategy through policies, structures, and processes.

Exam trap

The trap here is that candidates confuse operational or tactical activities (like monitoring metrics or project reviews) with strategic governance practices, which COBIT 2019 defines as framework-level alignment, not day-to-day management tasks.

33
MCQeasy

An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?

A.Increased technical efficiency
B.Improved resource allocation
C.Reduced IT costs
D.Enhanced security posture
AnswerB

Correct. Alignment ensures IT resources are focused on business priorities.

Why this answer

The primary benefit of aligning IT strategy with business strategy is improved resource allocation (Option B). This alignment ensures that IT investments and projects are directed toward activities that directly support business goals, maximizing value and minimizing waste. While increased technical efficiency (Option A), reduced IT costs (Option C), and enhanced security posture (Option D) are possible outcomes, they are not the primary benefit; they are secondary benefits that may result from proper alignment.

34
MCQeasy

Based on the exhibit, what is the default retention period for data?

A.365 days
B.30 days for Legal role only
C.The policy does not specify a default period
D.30 days
AnswerA

Correct. The default retention period is 365 days.

Why this answer

The JSON exhibit shows a default retention period of 365 days. Option B is incorrect; 30 days is the extension applied only to the Legal role, not the default. Option C is incorrect as the policy explicitly specifies a default period.

Option D is incorrect because 365 days, not 30 days, is the default retention period.

35
MCQmedium

A company plans to outsource its data center operations to a cloud service provider. What is the MOST important governance consideration for the board before finalizing the contract?

A.Select a provider with the lowest cost per transaction.
B.Negotiate the transfer of existing IT staff to the provider.
C.Ensure the contract includes clauses for regulatory compliance and audit rights.
D.Define a detailed exit strategy for transitioning to another provider.
AnswerC

Compliance and audit rights are critical for governance and oversight.

Why this answer

The most important governance consideration because the board must ensure that the contract enforces regulatory compliance and provides audit rights to meet legal and regulatory obligations. Option A is wrong because cost reduction is secondary to compliance and governance. Option B is wrong because transferring staff is an HR/operational issue, not a board-level governance priority.

Option D is wrong while an exit strategy is important, contractually securing compliance and audit rights is more critical for governance oversight.

36
MCQhard

What is the MOST significant weakness in the planned remediation?

A.The remediation only addresses a subset of projects.
B.The remediation may not eliminate the segregation of duties issue.
C.The remediation relies on technology rather than process.
D.The remediation does not include a compensating control.
AnswerB

An automated tool does not prevent the same developer from performing both coding and review if they run the tool.

Why this answer

The planned remediation (e.g., an automated code review tool) does not ensure that the developer who writes the code is different from the person who reviews it. This fails to address the root cause of segregation of duties, making it the most significant weakness. Options A, C, and D are either less critical or not as directly related to the core issue.

37
MCQhard

Based on the exhibit, which control deficiency is most critical for the IS auditor to address?

A.SSH is configured to allow root login
B.The admin user logged in successfully with a password
C.Public key authentication is not being used
D.The system lacks a policy to lock accounts after repeated failed login attempts
AnswerD

Correct. Multiple failed attempts for root from the same IP indicate a brute-force attack, and no lockout is evident.

Why this answer

The most critical deficiency because without an account lockout policy, the system is vulnerable to brute-force password guessing attacks. Even if other controls like SSH key authentication are missing, a lockout policy is a fundamental defense that directly mitigates repeated login attempts, which is a primary attack vector for gaining unauthorized access.

Exam trap

The trap here is that candidates often focus on technical misconfigurations like root login or missing public key authentication, overlooking the foundational security control of account lockout, which is a direct defense against brute-force attacks and is frequently tested as a critical deficiency in CISA exams.

How to eliminate wrong answers

Option A is wrong because while allowing root login via SSH is a security risk, it is less critical than the absence of a lockout policy; root login can be mitigated with other controls like key-based authentication and sudo restrictions. Option B is wrong because a successful password login by the admin user is expected behavior and not a control deficiency; the issue is the lack of stronger authentication methods, not the act of logging in. Option C is wrong because although public key authentication is more secure than password authentication, its absence is a weakness but not as immediately critical as the lack of a lockout policy, which leaves the system exposed to brute-force attacks regardless of authentication method.

38
MCQhard

A multinational corporation is implementing a global IT governance framework. Which of the following challenges is MOST likely to arise?

A.Conflicting regulatory requirements
B.Standardizing hardware across regions
C.Training users on new procedures
D.Software licensing costs
AnswerA

Correct. Different legal environments require careful navigation.

Why this answer

A multinational corporation implementing a global IT governance framework will most likely face conflicting regulatory requirements across different countries (option A). These legal and compliance issues are complex and vary significantly by jurisdiction (e.g., GDPR, data sovereignty), making them the primary challenge. Standardizing hardware (B) is a technical issue that can be addressed through procurement policies.

Training users (C) is an operational challenge that can be managed with change management processes. Software licensing costs (D) are a financial concern but not as fundamental as legal compliance. Therefore, option A is the most likely challenge.

39
MCQeasy

Based on the log, what is the MOST likely root cause of the backup failure?

A.Network connectivity issues
B.Incorrect backup schedule
C.Backup software corruption
D.Insufficient storage capacity
AnswerD

The target directory is full, causing the failure.

Why this answer

The log clearly indicates the target directory is full. Options A, B, C are not indicated in the log.

40
MCQeasy

A medium-sized e-commerce company recently suffered a ransomware attack that encrypted critical databases. The IT team restored systems from backups, but the incident exposed a lack of clear roles and responsibilities for incident response. The board has asked the IT governance committee to review and improve the incident response governance. The committee notes that while there is an incident response policy, it is not regularly tested, and staff are unsure of their roles. The company also lacks a formal communication protocol for notifying stakeholders. What should the committee prioritize to strengthen governance over incident response?

A.Invest in advanced endpoint detection and response tools.
B.Outsource incident response to a managed security service provider.
C.Define and communicate clear roles and responsibilities for incident response, and establish accountability.
D.Conduct a tabletop exercise to test the current plan.
AnswerC

Clear governance structure is foundational.

Why this answer

The root cause is a lack of clear roles, responsibilities, and accountability, which must be addressed first to strengthen governance. Option A is wrong because investing in technology alone does not fix governance gaps. Option B is wrong because outsourcing does not address internal governance deficiencies.

Option D is wrong, while testing is valuable, it should follow role definition and communication.

41
MCQhard

A multinational corporation is evaluating its IT governance structure. The board wants to ensure that IT investments are prioritized based on risk and value. Which framework component is MOST critical?

A.Service level agreements
B.Balanced scorecard
C.IT steering committee
D.Portfolio management process
AnswerD

This process evaluates and ranks investments by risk and value.

Why this answer

A portfolio management process systematically evaluates and prioritizes investments based on risk and value, aligning with board objectives. Steering committee provides oversight, but portfolio management is the mechanism for prioritization.

42
MCQeasy

A mid-sized company is implementing a new IT service management (ITSM) tool to improve incident management. The IT manager wants to ensure that the tool aligns with ITIL best practices. The company has a dedicated service desk team that handles about 200 incidents per week. The IT manager is considering whether to implement a self-service portal for users to submit incidents and check status, or to continue using email-based incident reporting. The service desk team is concerned that a self-service portal might reduce their direct interaction with users and potentially lead to less personalized support. However, the IT manager believes that a portal could improve efficiency and tracking. The company's IT governance framework requires that any major IT investment be approved by the steering committee and that there be a clear business case. The IT manager has prepared a business case but the steering committee wants to ensure that the solution is aligned with ITIL and that it addresses key incident management processes. Which of the following is the most appropriate next step for the IT manager?

A.Implement the self-service portal immediately to improve efficiency, then present the business case later.
B.Conduct a process review with stakeholders to define requirements based on ITIL guidelines before selecting a tool.
C.Proceed with the self-service portal without further review because it is clearly beneficial.
D.Abandon the self-service portal idea and continue with email-based reporting.
AnswerB

This ensures alignment with ITIL and addresses concerns through stakeholder involvement.

Why this answer

ITIL best practices emphasize that process design should precede tool selection. Conducting a process review with stakeholders ensures the self-service portal aligns with defined incident management workflows, such as categorization, prioritization, and escalation, before committing to a specific tool. This step also satisfies the IT governance requirement for a clear business case by validating requirements against ITIL guidelines.

Exam trap

The trap here is that candidates may assume any self-service portal automatically improves efficiency and aligns with ITIL, but CISA tests the principle that process definition must precede tool selection to ensure governance and best practice alignment.

How to eliminate wrong answers

Option A is wrong because implementing the portal immediately without presenting the business case violates the IT governance framework requiring steering committee approval for major IT investments, and it risks deploying a tool that does not align with ITIL-defined incident management processes. Option C is wrong because proceeding without further review ignores the service desk team's concerns about reduced personalization and fails to ensure the portal supports ITIL processes like incident categorization and SLA tracking, which could lead to inefficiencies. Option D is wrong because abandoning the portal idea outright dismisses the potential efficiency gains and tracking improvements that a properly designed self-service portal can provide, and it does not address the need to align with ITIL best practices.

43
MCQhard

A multinational corporation has defined its risk appetite as 'moderate' for IT investments. The IT steering committee is evaluating a new project with potential high returns but also significant cybersecurity risks. The project's risk profile is assessed as 'high' by the risk management team. What should the committee do FIRST?

A.Request the project team to identify risk mitigation measures.
B.Approve the project but increase monitoring.
C.Escalate the decision to the board of directors.
D.Reject the project immediately as it exceeds risk appetite.
AnswerA

Correct. The first step is to request the project team to identify risk mitigation measures that could bring the risk down to a moderate level, aligning with the risk appetite.

Why this answer

The correct first step. When a project's risk profile exceeds the defined risk appetite, the committee should not immediately reject or approve it. Instead, they should first explore whether risk mitigation measures can reduce the risk to an acceptable level.

This aligns with governance best practices to balance risk and reward. Option B is premature without assessing mitigation. Option C escalates too early before considering mitigations.

Option D rejects the opportunity without considering potential mitigation, which may discard valuable projects.

44
MCQhard

Refer to the exhibit. Which perspective shows the greatest deviation from target?

A.Customer
B.Learning & Growth
C.Financial
D.Internal Process
AnswerB

20% below target, the largest deviation.

Why this answer

Learning & Growth is 30 hours short of 150 (20% deficit), while Financial is 10% short, Internal Process is 4% short, and Customer exceeds target. Thus, Learning & Growth has the largest negative gap.

45
MCQmedium

Refer to the exhibit. The organization is planning to achieve the target level. What is the MOST appropriate action?

A.Assign a process owner
B.Implement process metrics and statistical controls
C.Conduct awareness training
D.Increase process documentation
AnswerB

Level 4 requires quantitative management.

Why this answer

To move from Level 3 (Established) to Level 4 (Predictable), the process must be measured and controlled using statistical techniques. Implementing metrics and statistical controls directly addresses the gap. Documentation, ownership, and training are earlier-level activities.

46
Drag & Dropmedium

Order the steps for performing a data backup in the correct sequence.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Backup process: identify data, choose method, schedule, execute/verify, and store offsite.

47
MCQmedium

Scenario: A healthcare organization is implementing a new electronic health records (EHR) system. The project has been delayed due to scope creep and resource constraints. The project sponsor is pressuring the project manager to accelerate the timeline by skipping user acceptance testing (UAT) and going live immediately. The organization has a governance policy that requires all IT projects to complete UAT before deployment. The project manager is concerned about quality and patient safety. Which of the following is the BEST course of action?

A.Compromise by conducting a limited UAT on only critical functionalities.
B.Resign from the project due to ethical concerns.
C.Accept the sponsor's request and skip UAT to meet the deadline.
D.Adhere to the governance policy and escalate the risk to the steering committee for a decision.
AnswerD

Follows policy and involves proper governance body.

Why this answer

The governance policy mandates UAT before deployment, and skipping it could compromise patient safety and data integrity in the EHR system. By escalating the risk to the steering committee, the project manager ensures that the decision is made at the appropriate governance level, balancing project pressures with compliance and quality. This approach aligns with the CISA domain of Governance and Management of IT, where adherence to policies and risk escalation are key controls.

Exam trap

The trap here is that candidates may choose a compromise (Option A) thinking it balances speed and quality, but it still violates the governance policy and fails to address the root cause of scope creep and resource constraints through proper escalation.

How to eliminate wrong answers

Option A is wrong because conducting a limited UAT on only critical functionalities still violates the governance policy and may miss integration or workflow defects that affect patient safety across non-critical modules. Option B is wrong because resigning is an extreme measure that abdicates professional responsibility; the project manager should first use escalation channels and governance processes to address the conflict. Option C is wrong because skipping UAT entirely disregards the governance policy and introduces unacceptable risks to patient safety and regulatory compliance, which could lead to severe consequences for the organization.

48
MCQhard

An IT department uses a balanced scorecard (BSC) to measure performance. The financial perspective shows that IT costs are within budget, but customer satisfaction scores are declining. The learning and growth perspective indicates low employee engagement. Which action should the IT governance committee prioritize?

A.Reduce IT costs further to reallocate savings to customer service.
B.Invest in training and development programs for IT staff.
C.Increase the IT budget to hire more staff.
D.Outsource customer-facing IT support to a third party.
AnswerB

Training improves skills and engagement, leading to better customer satisfaction.

Why this answer

Investing in training and development programs improves employee engagement (learning & growth perspective), which likely leads to better service and increased customer satisfaction. Option A is wrong because reducing costs further may harm service quality and not address the root cause of low engagement. Option C is wrong because simply hiring more staff does not necessarily improve engagement or customer satisfaction without proper training.

Option D is wrong because outsourcing may provide short-term relief but does not address the underlying employee engagement issue and could lead to loss of control.

49
MCQhard

An organization's IT strategy is developed by the IT department without input from business stakeholders. Which of the following is the MOST significant risk?

A.Technology may become obsolete quickly.
B.IT projects may exceed budget.
C.IT staff may lack required skills.
D.IT strategy may not support business objectives.
AnswerD

Lack of business input leads to misalignment, the most significant risk.

Why this answer

Without business input, the strategy may not support business objectives, leading to misalignment. Option A is a possible outcome. Options B and C are less directly related.

50
MCQeasy

A medium-sized manufacturing company has a decentralized IT structure where each business unit manages its own IT budget and projects. The CEO is concerned that IT investments are not aligned with corporate strategy and that there is duplication of effort. The IT department lacks a formal project portfolio management process. The company has experienced several project failures due to poor prioritization. The CEO has asked the newly hired IT auditor to recommend an initial step to improve IT governance. The auditor should recommend:

A.Establishing an IT steering committee with representatives from business units and IT
B.Implementing a project portfolio management software tool immediately to track all projects
C.Conducting a security risk assessment of all IT systems
D.Outsourcing IT management to a third-party provider
AnswerA

A steering committee provides strategic direction, prioritization, and governance over IT investments.

Why this answer

An IT steering committee provides governance oversight, ensures alignment with corporate strategy, and helps prioritize projects to avoid duplication. This foundational step addresses the root cause of poor alignment and project failures before implementing tools or processes. Option B is premature because a tool without governance oversight may not improve prioritization.

Option C focuses on security, not overall strategic alignment. Option D is drastic and does not address internal governance issues.

51
MCQhard

An organization has implemented a new IT service management (ITSM) tool. The IT manager wants to measure the effectiveness of incident management. Which metric is MOST appropriate?

A.Mean time to resolve (MTTR) incidents
B.Percentage of incidents resolved on first call
C.Number of incidents reported per month
D.Percentage of system uptime
AnswerA

MTTR directly measures how quickly incidents are resolved.

Why this answer

Mean time to resolve (MTTR) is the most appropriate metric for measuring the effectiveness of incident management because it directly reflects how quickly the IT team can restore normal service operation after an incident. In ITIL-based ITSM tools, MTTR tracks the elapsed time from incident logging to resolution, providing a clear indicator of process efficiency and team responsiveness.

Exam trap

The trap here is that candidates often confuse incident management metrics with service desk or availability metrics, picking 'percentage of incidents resolved on first call' because it sounds like a measure of effectiveness, but it actually measures first-contact resolution efficiency, not the end-to-end incident management process.

How to eliminate wrong answers

Option B is wrong because the percentage of incidents resolved on first call measures first-level support efficiency, not the overall effectiveness of the incident management process, which includes escalation and resolution workflows. Option C is wrong because the number of incidents reported per month is a volume metric that indicates incident frequency, not the quality or speed of resolution. Option D is wrong because system uptime is a metric for availability management, not incident management; it measures service reliability rather than how incidents are handled.

52
MCQeasy

An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of using a framework like COBIT?

A.Reducing IT operational costs.
B.Aligning IT strategy with business goals.
C.Eliminating all IT-related risks.
D.Ensuring compliance with all regulatory requirements.
AnswerB

COBIT and similar frameworks focus on creating value by aligning IT with business objectives.

Why this answer

COBIT is designed to bridge the gap between business objectives and IT operations by providing a framework that maps IT processes to business goals. The primary benefit is ensuring that IT strategy directly supports and enables business strategy, rather than focusing on cost reduction or risk elimination.

Exam trap

The trap here is that candidates often confuse the primary benefit of a governance framework (strategic alignment) with secondary benefits like cost reduction or compliance, leading them to pick a plausible but incorrect answer that addresses a tactical outcome rather than the core strategic purpose.

How to eliminate wrong answers

Option A is wrong because reducing IT operational costs is a possible outcome of good governance but not the primary purpose of COBIT; cost reduction is more directly addressed by frameworks like ITIL or specific cost-optimization practices. Option C is wrong because no framework can eliminate all IT-related risks; risk management aims to reduce risk to an acceptable level, not achieve zero risk. Option D is wrong because ensuring compliance with all regulatory requirements is an objective of governance but not the primary benefit of COBIT; compliance is one component of a broader alignment goal, and no framework can guarantee compliance with every regulation.

53
MCQhard

A government agency has an IT governance framework that includes an IT strategy committee, an IT steering committee, and a project management office. Despite this, there is a lack of transparency regarding IT spending and resource allocation. The agency's annual audit found that several IT initiatives were not approved by the steering committee and were funded out of operational budgets. The CFO is frustrated because IT costs are unpredictable. The agency's chief information officer (CIO) reports to the CFO but the IT steering committee is chaired by the CIO. The auditor's best recommendation to improve governance is to:

A.Establish a chargeback system to allocate IT costs to business units
B.Require all IT projects to submit a business case to the steering committee for approval
C.Change the steering committee chair to a senior business executive independent of IT
D.Implement a policy that prohibits funding IT projects from operational budgets without steering committee approval
AnswerC

Independence strengthens oversight and reduces the ability of the CIO to bypass governance.

Why this answer

Having an independent steering committee chair (e.g., a senior business executive) eliminates the conflict of interest where the CIO chairs the committee and can bypass governance. Option A (chargeback) addresses cost allocation but not the root cause of unauthorized spending. Option B (business case) is a good practice but can still be ignored if the committee chair is the CIO.

Option D (policy) can be overridden or ignored without structural change in governance.

54
MCQhard

You are the IT governance lead at a multinational corporation with a complex IT environment spanning multiple business units. The company has recently experienced a series of minor security incidents where unauthorized access was gained through unused user accounts that were not disabled after employees left the organization. Additionally, there have been delays in provisioning access for new hires, leading to productivity losses. The IT department currently uses a manual process for access management, with each business unit maintaining its own user lists. The company has a policy that requires access reviews every quarter, but these are often missed or performed superficially. The CIO has asked you to recommend a solution that addresses these issues while ensuring compliance with regulations such as GDPR and SOX. Which of the following is the BEST course of action?

A.Require each business unit to submit monthly reports of active users to IT, which will then manually disable accounts not on the list.
B.Develop a new policy that mandates quarterly access reviews and disciplinary action for non-compliance.
C.Increase the frequency of access reviews to monthly and assign a dedicated team to perform them.
D.Implement an identity governance and administration (IGA) tool that automates user provisioning and de-provisioning, integrates with HR systems, and enforces access reviews.
AnswerD

Automation addresses the root causes: timely de-provisioning, consistent reviews, and compliance.

Why this answer

Implementing an Identity Governance and Administration (IGA) tool directly addresses the root causes: manual, decentralized access management and lack of automated de-provisioning. IGA integrates with HR systems (e.g., Workday, SAP SuccessFactors) to trigger automatic account creation for new hires and immediate deactivation upon termination, eliminating orphaned accounts. It also enforces scheduled, auditable access reviews with certification workflows, ensuring compliance with GDPR (right to erasure, data minimization) and SOX (segregation of duties, access controls).

This automated approach resolves both the security incidents from unused accounts and the productivity losses from delayed provisioning.

Exam trap

The trap here is that candidates often choose options that increase manual oversight (like monthly reports or dedicated teams) because they seem practical, but the CISA exam emphasizes automated, integrated solutions (IGA) as the only sustainable way to achieve compliance and security at scale in complex, multi-unit environments.

How to eliminate wrong answers

Option A is wrong because it perpetuates the manual, error-prone process by relying on business units to submit reports and IT to manually disable accounts, which does not scale, introduces latency, and fails to prevent orphaned accounts between reporting cycles. Option B is wrong because developing a new policy without automated enforcement tools does not address the root cause of missed or superficial reviews; it merely adds another layer of documentation that is likely to be ignored without technical controls. Option C is wrong because increasing review frequency and assigning a dedicated team still relies on manual processes, which are costly, prone to human error, and cannot guarantee timely de-provisioning or integration with HR lifecycle events.

55
MCQmedium

An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. What is the committee's MOST important role?

A.Approving technical specifications
B.Selecting the vendor
C.Ensuring alignment with business objectives
D.Managing the project budget
AnswerC

Correct. The committee provides strategic oversight.

Why this answer

The IT steering committee's most important role is to ensure that proposed IT projects align with the organization's business objectives. Option A is incorrect as technical specifications are typically reviewed by technical architects or engineering teams. Option B is incorrect because vendor selection is often a procurement or business decision, and while the committee may provide input, it is not their primary role.

Option D is incorrect because managing the project budget is the responsibility of the project manager and project team, not the steering committee.

56
Matchingmedium

Match each log type to its typical content.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

System and application events

User login attempts and access

Changes to sensitive data

System errors and failures

Why these pairings

Logs are essential for monitoring and forensics. Correct matches: Audit Log tracks user activities and compliance, Security Log tracks security events, System Log tracks OS events, Application Log tracks application events. Common confusions include mixing system events with audit logs and application errors with security logs.

57
MCQeasy

An IT manager needs to ensure that the organization's IT resources are used efficiently. Which of the following is the BEST metric to measure IT resource utilization?

A.System uptime percentage
B.Average server CPU utilization
C.Number of help desk tickets resolved per day
D.Percentage of projects completed on time
AnswerB

Directly measures how efficiently computing resources are used.

Why this answer

Average server CPU utilization directly measures how much of the computing capacity is being consumed over time, making it the most relevant metric for assessing whether IT resources are being used efficiently. High or low CPU utilization can indicate over-provisioning, under-utilization, or potential performance bottlenecks, enabling the IT manager to optimize resource allocation.

Exam trap

The trap here is that candidates often confuse availability metrics (uptime) with utilization metrics, or they mistakenly equate operational outputs (tickets resolved, project completion) with resource efficiency, leading them to pick a superficially plausible but incorrect answer.

How to eliminate wrong answers

Option A is wrong because system uptime percentage measures availability, not utilization; a server can be up 99.999% of the time but idle, wasting resources. Option C is wrong because the number of help desk tickets resolved per day measures service desk productivity and incident handling efficiency, not the utilization of IT resources like servers or storage. Option D is wrong because the percentage of projects completed on time measures project management performance and schedule adherence, not the operational efficiency of IT resource usage.

58
MCQeasy

An organization has a policy requiring annual information security awareness training for all employees. During a recent audit, it was found that 20% of employees had not completed the training. What is the BEST course of action for the IT governance committee?

A.Reduce the training frequency to biennial.
B.Require managers to ensure their teams complete training and escalate non-compliance to HR.
C.Extend the training deadline by three months.
D.Make the training optional for employees with high performance ratings.
AnswerB

Manager accountability and HR escalation enforce policy.

Why this answer

Enforcing compliance through HR and management reinforces the policy. Option A is wrong because reducing training frequency weakens security. Option C is wrong because extending the deadline does not address non-compliance.

Option D is wrong because training is a mandatory policy, not optional.

59
MCQmedium

A company outsources its data center operations to a third-party provider. Which of the following is the MOST important control to include in the outsourcing contract?

A.Detailed escalation procedures for incidents
B.Service level agreements with financial penalties
C.Requirements for encryption of data at rest
D.Right to audit the provider's facilities and processes
AnswerD

Audit rights enable independent verification of controls.

Why this answer

The right to audit allows the company to verify the provider's compliance. Option A is important but less critical than audit rights. Option B is operational.

Option C is a security control but not the most important contractual safeguard.

60
Multi-Selectmedium

Which TWO of the following are key responsibilities of an IT steering committee?

Select 2 answers
A.Approving the annual IT budget and major capital expenditures
B.Performing daily system monitoring and incident response
C.Defining IT policies and standards
D.Writing application code for new software features
E.Configuring firewall rules and network access controls
AnswersA, C

The steering committee typically approves the IT budget and major expenditures to ensure alignment with business strategy.

Why this answer

The IT steering committee is a senior-level governance body responsible for aligning IT strategy with business objectives. Approving the annual IT budget and major capital expenditures (A) is a core fiduciary duty, ensuring resources are allocated to approved projects and initiatives. Defining IT policies and standards (C) establishes the governance framework for security, compliance, and operational consistency across the enterprise.

Exam trap

The trap here is confusing strategic governance roles (steering committee) with operational or technical roles (system administrators, developers, or network engineers), leading candidates to select hands-on tasks like monitoring, coding, or firewall configuration.

61
MCQmedium

A financial services company is migrating its core banking system to a public cloud to improve scalability and reduce costs. The project is high-risk due to regulatory compliance requirements (e.g., data residency, audit trails). The IT governance committee has reviewed the project plan and finds that the risk assessment is incomplete – it does not address the potential impact of a cloud provider outage on critical transactions. The committee must approve the project or request changes. The project manager argues that the cloud provider's SLA guarantees 99.99% uptime and that additional controls would delay the project. What should the governance committee do?

A.Reject the project and require the system to remain on-premises.
B.Request a revised risk assessment that includes contingency plans for provider outages.
C.Approve the project based on the provider's strong SLA.
D.Approve a pilot migration for non-critical systems first.
AnswerB

The committee must ensure all risks are identified and mitigated.

Why this answer

The governance committee's role is to ensure that all significant risks are identified and mitigated before approval. The risk assessment is incomplete as it does not address the impact of a cloud provider outage on critical transactions. Requiring a revised risk assessment that includes contingency plans for provider outages is a proper governance response.

Option A is wrong because it preemptively rejects the project without considering updated risk information. Option C is wrong because the SLA does not eliminate the need for contingency planning or address other compliance risks. Option D is wrong because a pilot for non-critical systems does not resolve the missing risk assessment for the core banking migration.

62
MCQhard

Based on the exhibit, which control is most likely missing to prevent this type of event?

A.Applying the latest security patches to the SSH service
B.Implementing account lockout after three failed attempts
C.Disabling direct root login via SSH
D.Enforcing strong password complexity
AnswerB

Account lockout directly mitigates brute-force attacks by blocking further attempts.

Why this answer

The exhibit describes a brute-force attack against an SSH service, where an attacker repeatedly attempts to guess credentials. Implementing account lockout after three failed attempts is the most direct control to prevent this type of event, as it halts further login attempts after a threshold, stopping the attack in its tracks regardless of password strength or patching.

Exam trap

The trap here is that candidates often choose 'Disabling direct root login via SSH' (Option C) because it is a well-known security best practice, but it does not prevent brute-force attacks against other user accounts, whereas account lockout directly stops the attack mechanism.

How to eliminate wrong answers

Option A is wrong because applying the latest security patches to the SSH service addresses vulnerabilities in the SSH protocol or implementation, but does not prevent brute-force attacks that exploit weak or guessed credentials. Option C is wrong because disabling direct root login via SSH reduces the attack surface by requiring a non-root account first, but it does not prevent brute-force attacks against any user account; the attacker can still target other usernames. Option D is wrong because enforcing strong password complexity makes passwords harder to guess, but it does not stop an attacker from making unlimited attempts; a brute-force attack can still succeed over time if no lockout mechanism is in place.

63
MCQeasy

Based on the exhibit, what is the MOST appropriate action for IT management?

A.Investigate the reasons for the shortfall and implement corrective actions.
B.Ignore the variance as it is within acceptable range.
C.Adjust the target to 80% to match actual performance.
D.Replace the survey with a different measurement tool.
AnswerA

A gap between actual and target should be analyzed and addressed.

Why this answer

The actual score (82%) is below the target (85%), so IT management should investigate the reasons for the shortfall and implement corrective actions to close the gap. Option B (ignoring the variance) is not acceptable because the performance is below target and not within the acceptable range. Option C (adjusting the target to 80%) is premature without first understanding the root cause.

Option D (replacing the survey) is an overreaction without evidence that the measurement tool is flawed.

64
MCQhard

An organization's IT strategy is not aligned with business strategy due to lack of communication. Which of the following would BEST improve alignment?

A.Business-IT strategy mapping workshops
B.Weekly IT status reports
C.Outsourcing non-core IT functions
D.IT budget increase
AnswerA

Workshops enable joint development of aligned strategies.

Why this answer

Business-IT strategy mapping workshops facilitate direct communication and collaboration, ensuring both sides understand and agree on priorities. Status reports, budget increases, or outsourcing do not address the communication gap.

65
MCQhard

A multinational corporation operates in a highly regulated industry. The IT governance framework includes a risk appetite statement approved by the board. Recently, the company suffered a significant data breach due to an unpatched vulnerability that had been identified three months earlier. The IT audit found that the vulnerability was reported to the IT department but was not prioritized for remediation because it was deemed low risk by the IT operations team. The incident response plan was not activated because the breach was not initially detected. The board wants to strengthen governance to prevent recurrence. The most effective course of action for the auditor to recommend is:

A.Deploying an intrusion detection system to identify breaches sooner
B.Establishing a formal vulnerability management policy that requires risk-based prioritization in accordance with the risk appetite and escalation to the IT risk committee for decisions outside tolerance
C.Disciplining the IT operations team for not escalating the vulnerability
D.Implementing a more robust patch management system with automated patching
AnswerB

This embeds risk governance into the vulnerability management process, ensuring alignment with board-approved risk appetite.

Why this answer

The most effective because it ties vulnerability remediation directly to the board-approved risk appetite and ensures that decisions outside tolerance are escalated to the IT risk committee. This addresses the root cause: the IT operations team made a risk decision (deeming the vulnerability low risk) without governance oversight. Option A (deploying intrusion detection) focuses on detection, not prevention of the governance gap.

Option C (disciplining the team) is reactive and does not fix the process. Option D (automated patching) may help with patching speed but does not ensure risk-based prioritization according to the risk appetite.

66
MCQeasy

An IT manager submits a request to change the firewall configuration during business hours. According to best practices for change management, what should be done FIRST?

A.Obtain approval from the change advisory board
B.Notify all users of the planned change
C.Assess the impact and risk of the proposed change
D.Implement the change immediately to address an urgent threat
AnswerC

Risk assessment is required before approval.

Why this answer

The first step in any change management process is to assess the impact and risk of the proposed change. This assessment informs subsequent steps such as approval, notification, and implementation. Option A (CAB approval) should occur after the impact and risk assessment is completed.

Option B (notifying users) is typically done after the change is approved and scheduled. Option D (immediate implementation) bypasses the necessary assessment and approval steps, which is not best practice even for urgent threats—a risk assessment should still be conducted.

67
MCQmedium

An organization's IT department implemented a new change management process that requires all changes to be approved by a change advisory board (CAB). A critical security patch needs to be deployed within 2 hours to address an active zero-day vulnerability. The change request was submitted but the CAB is not scheduled to meet for another 24 hours. What is the BEST course of action?

A.Deploy the patch and inform the CAB after the fact during the next meeting.
B.Wait for the next scheduled CAB meeting to approve the change.
C.Deploy the patch immediately without any approval as it is a critical security fix.
D.Use the emergency change process to obtain expedited approval from a designated CAB member.
AnswerD

An emergency change process allows swift approval for critical patches, balancing security and control.

Why this answer

It aligns with the ITIL-based emergency change process, which allows for expedited approval from a designated CAB member or emergency authority when a critical security patch must be deployed within hours to mitigate an active zero-day vulnerability. This ensures the change is authorized without waiting for the full CAB meeting, maintaining security while preserving governance and audit trails.

Exam trap

The trap here is that candidates may assume any critical security patch can be deployed immediately without approval (Option C) or that informing the CAB after the fact (Option A) is acceptable, but CISA emphasizes that even emergency changes must follow a defined process with expedited approval to maintain control and accountability.

How to eliminate wrong answers

Option A is wrong because deploying the patch without prior approval violates the change management policy and could lead to unauthorized changes, lack of audit trail, and potential conflicts with other changes. Option B is wrong because waiting 24 hours for the next CAB meeting would leave the system exposed to the active zero-day vulnerability, increasing risk of exploitation. Option C is wrong because deploying without any approval bypasses all governance controls, ignoring the need for documented authorization even for emergency fixes, and could cause operational disruptions without coordination.

68
MCQeasy

Which of the following is the PRIMARY purpose of an IT governance framework?

A.To ensure IT aligns with and supports business strategy
B.To ensure compliance with laws and regulations
C.To protect IT assets from cyber threats
D.To reduce IT operational costs
AnswerA

Governance frameworks focus on alignment and value delivery.

Why this answer

The primary purpose of an IT governance framework is to ensure that IT investments, strategies, and operations are aligned with and support the overall business strategy, enabling the organization to achieve its goals. This alignment is achieved through mechanisms such as strategic planning, portfolio management, and performance measurement, which are core to frameworks like COBIT 2019. Without this alignment, IT may operate in isolation, leading to wasted resources and missed business opportunities.

Exam trap

The trap here is that candidates often confuse the primary purpose of IT governance with operational or security objectives, such as compliance or cost reduction, because those are more tangible and frequently tested in other domains, but the CISA exam emphasizes that governance is fundamentally about strategic alignment and value delivery.

How to eliminate wrong answers

Option B is wrong because ensuring compliance with laws and regulations is a secondary objective of IT governance, not the primary purpose; compliance is typically addressed through specific controls and policies within the framework, but the framework's overarching goal is strategic alignment. Option C is wrong because protecting IT assets from cyber threats is a function of information security management and risk management, which are components of governance but not its primary purpose; governance focuses on direction and oversight, not operational security. Option D is wrong because reducing IT operational costs is a potential outcome of effective governance, but it is not the primary purpose; cost reduction is a tactical benefit, whereas governance is fundamentally about value creation and strategic alignment.

69
MCQmedium

Which of the following is a potential risk in this RACI matrix?

A.The IT Director is accountable but not informed of all changes.
B.IT Operations is informed, but should be responsible for implementation.
C.The Business Process Owner is consulted, which may delay approvals.
D.The Change Manager is responsible but lacks authority to approve.
AnswerD

If the Change Manager is responsible but not accountable, they may not have approval authority, leading to bypassed controls.

Why this answer

The Change Manager is responsible but lacks authority to approve. In a RACI matrix, the Responsible (R) party performs the work, while the Accountable (A) party is ultimately answerable and has approval authority. If the Change Manager is marked as Responsible for change approval without being Accountable, there is a risk that they may not have the proper authority to approve changes, leading to potential unauthorized changes.

Option A is not necessarily a risk because being Accountable does not require being informed of all changes. Option B: IT Operations being informed is appropriate; they do not need to be Responsible for implementation. Option C: The Business Process Owner being consulted is normal and may cause delays but is not as critical as the authority issue.

Thus, D is the most significant risk.

70
MCQeasy

Which of the following is the PRIMARY purpose of an IT strategy committee?

A.To monitor IT project timelines
B.To manage IT vendor contracts
C.To approve IT project budgets
D.To ensure IT investments support business objectives
AnswerD

Strategic alignment is the primary goal.

Why this answer

The primary purpose of an IT strategy committee is to ensure that IT investments align with and support business objectives, providing strategic direction and governance. Option A is incorrect as monitoring project timelines is an operational task, not a strategic committee responsibility. Option B is incorrect because managing vendor contracts is typically handled by procurement or IT operations.

Option C is incorrect because approving specific project budgets is a project-level decision, not the committee's primary focus.

71
MCQmedium

A retail company is merging with a competitor. The IT departments of both organizations have different IT governance structures: Company A uses a centralized model with strict change management, while Company B uses a decentralized model with autonomous business unit IT. The CIO has been tasked with integrating the IT functions post-merger. The board expects cost synergies and improved service levels. The integration team is facing resistance from Company B's business heads who fear loss of agility. The CIO needs to propose a governance model for the merged entity. Which approach would BEST meet the board's expectations while addressing resistance?

A.Keep both models separate and allow business units to choose their preferred model.
B.Adopt Company B's decentralized model to preserve agility.
C.Immediately impose Company A's centralized model across the merged entity.
D.Implement a phased integration with a transitional governance structure that includes representatives from both sides.
AnswerD

Phased integration respects both cultures and reduces resistance.

Why this answer

A phased integration with a transitional governance structure that includes representatives from both sides allows the merged entity to gradually converge governance models, manage change and resistance, and work toward cost synergies and improved service levels without immediately disrupting business operations. Option A is incorrect because keeping both models separate permanently fails to achieve the desired integration and synergies. Option B is incorrect because fully adopting the decentralized model may not deliver the cost synergies and centralized control expected by the board.

Option C is incorrect because immediately imposing a centralized model would likely cause strong resistance from Company B's business heads and disrupt agility, undermining the merger's success.

72
MCQhard

An organization has decentralized IT management with each business unit making its own technology decisions. Which of the following is the BEST way to maintain enterprise-wide governance?

A.Deploy a single enterprise resource planning (ERP) system across all units.
B.Require all IT projects to be approved by the corporate IT department.
C.Create a central IT budget that allocates funds to business units.
D.Establish an enterprise architecture review board with representatives from all business units.
AnswerD

This provides governance without removing unit autonomy.

Why this answer

An enterprise architecture review board with representatives from all business units ensures alignment with enterprise-wide standards and governance while respecting decentralized decision-making. Option A is too prescriptive and may not fit all units. Option B centralizes approval, which undermines decentralization.

Option C addresses budgeting, not governance of IT decisions.

73
Multi-Selecthard

Which THREE of the following are responsibilities of the board of directors regarding IT governance? (Choose three.)

Select 3 answers
A.Designing network security architecture
B.Setting IT risk appetite
C.Reviewing IT performance
D.Implementing IT controls
E.Approving IT strategy
AnswersB, C, E

Correct. Board defines risk tolerance.

Why this answer

Options B, C, and E are correct because setting IT risk appetite, reviewing IT performance, and approving IT strategy are board-level responsibilities under IT governance. Option A is incorrect as designing network security architecture is an operational task typically handled by management or technical staff. Option D is incorrect because implementing IT controls is also a management function, not a board responsibility.

74
MCQeasy

A small business lacks formal IT governance. What is the FIRST step to establish governance?

A.Assign an IT manager
B.Define IT policies
C.Conduct a risk assessment
D.Implement COBIT
AnswerC

Risk assessment reveals the starting point for governance.

Why this answer

Conducting a risk assessment identifies the most critical issues and guides the development of governance policies and structure. Defining policies or assigning roles without understanding risks may be premature.

75
MCQmedium

An organization is implementing a new IT governance framework. Which of the following is the BEST approach to ensure alignment between IT strategy and business goals?

A.Align IT budget with the previous year's business plan
B.Conduct annual IT strategy reviews independent of business cycles
C.Establish an IT steering committee with business representation
D.Delegate IT strategy to the CIO without business input
AnswerC

A steering committee with business leaders ensures ongoing alignment.

Why this answer

An IT steering committee with both IT and business leaders ensures continuous strategic alignment by involving business stakeholders in IT decision-making. Option A is incorrect because aligning the IT budget with a previous year's business plan uses outdated information and does not guarantee alignment with current goals. Option B is incorrect because annual IT strategy reviews independent of business cycles create a disconnect between IT and business priorities.

Option D is incorrect because delegating IT strategy solely to the CIO without business input can lead to misalignment with organizational objectives.

Page 1 of 2 · 109 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Governance and Management of IT questions.