hardMultiple Choice
CISA Practice Question: In the context of IT governance, what is the…
In the context of IT governance, what is the PRIMARY purpose of an exception management process for IT policies?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To allow temporary deviations from policy under controlled conditions with appropriate approvals
Exception management allows controlled deviations from policy when required, while ensuring accountability and documentation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To automatically update policies based on changing business needs
Why it's wrong here
Exception management handles individual, time-limited deviations from existing policy; it does not rewrite or automatically update the policies themselves, which is the remit of policy owners and change governance. Automatic updating is tempting because policies must evolve with business needs, but that is policy lifecycle management, not exception handling.
- ✗
To provide a mechanism for employees to bypass security controls
Why it's wrong here
Exception management records, risk-assesses and time-limits approved deviations from a policy, retaining oversight and compensating controls; it does not grant employees a route to bypass security controls at will. That framing is tempting because exceptions do permit defined non-compliance, but only through documented, authorised approval.
- ✗
To eliminate the need for policy compliance monitoring
Why it's wrong here
Exceptions are logged, tracked and reported, which feeds compliance monitoring rather than removing it; the process exists to keep deviations visible and time-bound. Eliminating monitoring is tempting because approved exceptions reduce enforcement effort, but governance requires ongoing oversight of every granted exception and its expiry.
- ✓
To allow temporary deviations from policy under controlled conditions with appropriate approvals
Why this is correct
Temporary, approved deviations satisfy the governance requirement to balance control with operational reality. Exceptions are time-bound, documented and authorised at the right level, so risk is accepted knowingly rather than ignored. This preserves policy integrity while allowing legitimate business needs, which is precisely the primary purpose of exception management.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.