Courseiva

CCNA It Governance Mgmt Questions

75 of 121 questions · Page 1/2 · It Governance Mgmt topic · Answers revealed

1
MCQhard

A multinational manufacturing company with operations in 20 countries has historically allowed each regional division to manage its own IT systems independently. Recently, the company experienced a significant data breach originating from a region with weaker security controls, leading to financial losses and reputational damage. The board has mandated stronger IT governance to prevent future incidents. The CIO proposes implementing a global IT governance framework with centralized policy enforcement. However, regional directors argue that local regulations and business needs require autonomy. The governance committee must decide on a course of action that balances risk and business flexibility. Which of the following approaches is the MOST appropriate?

A.Adopt a federated governance model with global policies and local flexibility within defined tolerances.
B.Allow each region to continue independently but require quarterly reporting to the committee.
C.Implement a fully centralized IT governance model with no regional deviations.
D.Maintain the status quo but enforce minimum security standards across all regions.
AnswerA

A federated model sets mandatory global policies, such as security baselines, while permitting regional deviations within defined tolerances. This directly addresses the breach caused by weak local controls without stripping the autonomy regional directors require for local regulations.

Why this answer

A federated governance model with global policies and local flexibility within defined tolerances is the most appropriate because it balances the board's mandate for stronger, centralized governance with the regional directors' need for autonomy to meet local regulations and business requirements. It establishes global minimum standards while allowing regions to adapt within approved boundaries, directly addressing the risk of weak regional controls without eliminating necessary flexibility.

Exam trap

The trap is choosing extreme options (full centralization or full autonomy) when the scenario explicitly demands a balance between global risk control and local flexibility.

How to eliminate wrong answers

Option B is wrong because allowing each region to continue independently with only quarterly reporting does not provide the centralized enforcement needed to prevent a repeat of the breach; reporting is reactive and does not ensure consistent controls. Option C is wrong because a fully centralized model with no regional deviations ignores local regulatory and business needs, which can cause compliance violations and operational friction, making it impractical for a multinational. Option D is wrong because maintaining the status quo while enforcing minimum standards is essentially what already failed; without a governance framework to enforce and monitor those standards, the same weaknesses persist.

2
MCQmedium

A company has multiple business units with conflicting IT priorities. Which governance body should resolve this?

A.IT steering committee
B.Board of directors
C.IT management
D.Audit committee
AnswerA

An IT steering committee provides cross-functional executive oversight, arbitrating competing priorities between business units and aligning IT investment with enterprise strategy. It holds the authority to allocate resources and settle conflicts that individual unit managers cannot resolve, directly satisfying the stem's requirement for a governance body to mediate conflicting IT priorities.

Why this answer

An IT steering committee is the governance body composed of senior business and IT leaders that prioritizes IT investments and resolves conflicts between business units' competing IT priorities. It exists precisely to arbitrate cross-functional prioritization and align IT initiatives with business strategy, making it the correct forum for resolving conflicting priorities among business units.

Exam trap

CISA often tests the distinction between governance and management — candidates must remember that the IT steering committee is the governance body that resolves cross-business-unit IT priority conflicts, not IT management or the board.

How to eliminate wrong answers

Option B is wrong because the board of directors focuses on overall corporate strategy, fiduciary oversight, and shareholder interests — it does not typically get involved in operational IT prioritization conflicts between business units. Option C is wrong because IT management executes and delivers IT services but does not have the cross-business authority to arbitrate conflicting priorities between business units. Option D is wrong because the audit committee oversees financial reporting, internal controls, and compliance — not IT project prioritization.

3
Multi-Selecteasy

Which TWO of the following are common objectives of an IT balanced scorecard? (Choose two.)

Select 2 answers
A.Deploying a new ERP system
B.Reducing the number of help desk tickets
C.Enhancing IT staff skills and knowledge
D.Implementing a new firewall
E.Improving customer satisfaction with IT services
AnswersC, E

The IT balanced scorecard includes a learning and growth perspective, which covers developing IT staff competencies. Enhancing staff skills and knowledge therefore aligns with that objective, supporting the stem's requirement for common balanced scorecard goals.

Why this answer

The IT balanced scorecard adapts the four-perspective Kaplan-Norton framework to IT, so its objectives are outcome-oriented goals rather than one-off projects. Option C, enhancing IT staff skills and knowledge, is correct because it maps to the learning and growth (innovation) perspective, which drives the internal process and customer perspectives through continuous capability development. Option E, improving customer satisfaction with IT services, is correct because it maps to the customer perspective, measuring how well IT delivers value and meets service expectations.

Options A (deploying a new ERP system) and D (implementing a new firewall) are specific tactical projects or deliverables, not strategic scorecard objectives, and option B (reducing the number of help desk tickets) is a narrow operational metric that may even conflict with service quality rather than a balanced scorecard objective.

Exam trap

CISA often tests the difference between strategic objectives (like improving satisfaction or skills) and tactical initiatives (like deploying a system or reducing tickets).

4
MCQmedium

A large enterprise recently experienced a data breach due to an insider threat. The IT governance committee is reviewing the incident and considering measures to prevent recurrence. Which of the following is the BEST course of action to address the root cause?

A.Implement a privileged access management (PAM) solution to control and monitor elevated access.
B.Increase logging and auditing of all user activities.
C.Deploy a security information and event management (SIEM) tool.
D.Terminate the employment of the insider who caused the breach.
AnswerA

Privileged access management directly addresses insider misuse by vaulting, brokering and session-recording elevated accounts, enforcing least privilege and just-in-time elevation. This targets the root cause — uncontrolled privileged credentials — rather than merely detecting activity after the breach has already occurred.

Why this answer

A privileged access management (PAM) solution directly addresses the root cause of an insider threat by controlling, monitoring, and auditing elevated access rights. Since the breach was caused by an insider, limiting and tracking privileged accounts prevents unauthorized or excessive use of administrative credentials, which is the most effective preventive measure against recurrence.

Exam trap

The trap here is that candidates often confuse detective controls (logging, SIEM) with preventive controls (PAM), or they mistakenly view termination as a root-cause fix rather than a reactive measure, failing to recognize that the root cause is the lack of access governance.

How to eliminate wrong answers

Option B is wrong because increasing logging and auditing of all user activities is a detective control, not a preventive one; it helps identify breaches after they occur but does not stop an insider from abusing elevated access. Option C is wrong because deploying a SIEM tool aggregates and correlates logs for detection and analysis, but it does not prevent an insider from using privileged access to cause a breach. Option D is wrong because terminating the insider is a reactive disciplinary action that addresses the specific individual but does not fix the underlying lack of access controls, leaving the enterprise vulnerable to future insider threats.

5
Multi-Selecteasy

Which TWO of the following are key components of an IT governance framework? (Choose two.)

Select 2 answers
A.Network topology diagram
B.Help desk procedures
C.Hardware inventory
D.IT strategy
E.IT steering committee
AnswersD, E

IT strategy aligns technology investment and delivery with enterprise objectives, giving the governance framework its direction-setting component. It ensures decisions about resources, risk and priorities trace back to business goals rather than isolated technical preferences.

Why this answer

Option D (IT strategy) is correct because an IT governance framework must define how IT is aligned with and supports the organization's business objectives, and the IT strategy is the core document that establishes this direction, priorities, and value delivery. Option E (IT steering committee) is correct because governance requires a decision-making body with assigned authority and accountability; the IT steering committee provides oversight, prioritization, and resource-allocation decisions across IT initiatives. The remaining options do not belong: a network topology diagram (A) and a hardware inventory (C) are operational/technical artifacts describing infrastructure, not governance mechanisms, and help desk procedures (B) are tactical service-management documentation rather than a governance component.

Exam trap

CISA often tests the distinction between governance artifacts (strategy, steering committees, policies, oversight bodies) and operational/technical artifacts (topology diagrams, help desk procedures, inventories) — candidates frequently pick the technical-sounding option because it feels concrete.

6
Multi-Selectmedium

An organization is implementing COBIT 2019. Which TWO of the following are governance enablers? (Choose two.)

Select 2 answers
A.Hardware configuration
B.Project schedule
C.Organizational structures
D.Network performance
E.Culture, ethics and behavior
AnswersC, E

Organizational structures are a COBIT 2019 governance enabler, defining decision rights, roles and reporting lines that determine how governance is implemented. They satisfy the enabler category covering the formal entities and relationships through which IT governance decisions are made and executed.

Why this answer

In COBIT 2019, governance enablers are the components that make governance and management of enterprise IT possible, and the framework defines seven enabler categories: principles/policies/frameworks, processes, organizational structures, culture/ethics/behavior, information, services/infrastructure/applications, and people/skills/competencies. Option C (Organizational structures) is correct because it is one of these seven enabler categories, covering the decision-making roles, boards, and committees that define accountability for I&T governance. Option E (Culture, ethics and behavior) is also correct because it is explicitly listed as an enabler category, capturing the values and behaviors of individuals and the enterprise that influence governance outcomes.

Options A (Hardware configuration), B (Project schedule), and D (Network performance) are not governance enablers; they are specific technical or project-level artifacts that fall under other domains (e.g., services/infrastructure or management processes) rather than being one of COBIT's defined enabler categories.

Exam trap

CISA often tests whether candidates confuse operational artifacts (schedules, hardware, performance metrics) with the seven formal COBIT governance enabler categories.

7
MCQmedium

A financial institution is evaluating its IT governance structure. Which of the following roles is BEST suited to ensure independent oversight of IT investments?

A.Chief Information Officer (CIO)
B.Project Management Office (PMO) director
C.IT Audit Committee
D.Chief Information Security Officer (CISO)
AnswerC

An independent audit committee provides objective oversight.

Why this answer

The IT Audit Committee is the correct answer because it provides independent oversight of IT investments by operating outside of management's direct reporting structure. Unlike the CIO, PMO director, or CISO, who are all part of management and may have vested interests in project approvals or resource allocation, the IT Audit Committee reports to the board of directors and ensures that IT investments align with enterprise strategy, risk appetite, and regulatory requirements without bias.

Exam trap

The trap here is that candidates often confuse operational management roles (CIO, PMO director, CISO) with governance roles, mistakenly believing that a senior IT manager can provide independent oversight when they are actually part of the management chain being overseen.

How to eliminate wrong answers

Option A is wrong because the Chief Information Officer (CIO) is a senior management role responsible for the day-to-day operation and strategic planning of IT, which inherently lacks the independence required for oversight of IT investments. Option B is wrong because the Project Management Office (PMO) director is focused on project execution, resource management, and delivery metrics, not on independent governance or strategic alignment of IT investments. Option D is wrong because the Chief Information Security Officer (CISO) is primarily concerned with information security risk management and compliance, not with the broader financial and strategic oversight of IT investments.

8
MCQeasy

An organization wants to ensure that IT performance is measured against strategic goals. Which tool is BEST suited?

A.Balanced scorecard
B.Pareto chart
C.SWOT analysis
D.Gantt chart
AnswerA

The balanced scorecard translates strategic objectives into measurable perspectives — financial, customer, internal process, and learning and growth — and cascades them into IT metrics. This directly links IT performance measurement to strategic goals, which financial or operational metrics alone cannot achieve.

Why this answer

A balanced scorecard measures organizational performance across four perspectives — financial, customer, internal business processes, and learning and growth — and explicitly links operational metrics to strategic objectives. This makes it the best tool for ensuring IT performance is measured against strategic goals, since it translates strategy into measurable KPIs.

Exam trap

CISA often tests the difference between strategic alignment tools and general quality/planning tools — candidates pick SWOT because it sounds strategic, but SWOT assesses position, not performance against goals.

How to eliminate wrong answers

Option B is wrong because a Pareto chart is a quality tool that prioritizes problems by frequency (the 80/20 rule); it does not link performance to strategy. Option C is wrong because SWOT analysis is a strategic planning technique for assessing internal and external factors, not a performance measurement framework. Option D is wrong because a Gantt chart is a project scheduling tool showing tasks over time, not a strategic performance measurement system.

9
MCQhard

An organization's IT governance committee is reviewing a proposal to use a public cloud provider that does not meet the organization's data encryption standards. The board has set a low risk appetite for data privacy. What is the BEST action?

A.Accept the proposal with additional monitoring
B.Delegate the decision to the security team
C.Accept the proposal but require the provider to sign a waiver
D.Reject the proposal until encryption requirements are met
AnswerD

Rejecting the proposal directly enforces the board's low risk appetite for data privacy, since the provider's encryption controls fall short of the organisation's mandated standards. Accepting residual privacy risk would exceed that appetite. Governance committees must align procurement decisions with stated risk tolerance rather than accept unmitigated control gaps.

Why this answer

The board has set a low risk appetite for data privacy, meaning the organization is willing to accept only minimal risk in this area. A cloud provider that does not meet the organization's data encryption standards introduces a risk that exceeds this appetite. Therefore, the proposal must be rejected until the provider can comply with the encryption requirements.

This aligns with governance principles where risk decisions must be made in accordance with the organization's risk appetite.

Exam trap

CISA often tests the misconception that additional monitoring or waivers can compensate for a control gap when the risk appetite is low, but the correct answer is to reject non-compliant proposals outright.

How to eliminate wrong answers

Option A is wrong because accepting the proposal with additional monitoring does not mitigate the risk to an acceptable level given the low risk appetite; monitoring is a detective control, not a preventive one, and the encryption gap remains. Option B is wrong because delegating the decision to the security team abdicates the governance committee's responsibility to align decisions with the board's risk appetite; the security team may not have the authority to accept risks on behalf of the board. Option C is wrong because a waiver signed by the provider does not reduce the risk; it merely acknowledges it, and the organization would still be accepting a risk that exceeds its stated appetite.

10
MCQhard

An auditor finds that access reviews have not been completed for two quarters. What is the MOST significant risk?

A.Data integrity may be compromised
B.Unauthorized access may be granted and persist
C.System performance may degrade
D.Audit findings may be reported to management
AnswerB

Missed quarterly reviews mean accumulated entitlement drift goes undetected, so accounts retain access after role changes or termination. The stem's two-quarter gap directly enables unauthorised access to be granted and to persist unchallenged, which is the most significant consequence.

Why this answer

The most significant risk of missed access reviews is that unauthorized or excessive access rights remain in place undetected, allowing users to retain privileges they should no longer have (e.g., after role changes or terminations). This directly enables insider threats and privilege creep, which is the core control objective of periodic access reviews.

Exam trap

CISA often tests the difference between the risk itself (unauthorized access persisting) and the consequence (audit findings) — candidates pick the reporting outcome instead of the underlying security exposure.

How to eliminate wrong answers

Option A is wrong because data integrity is a broader concern affected by many controls; missed access reviews primarily affect authorization, not integrity directly. Option C is wrong because system performance is unrelated to access review cadence. Option D is wrong because audit findings being reported is a consequence of the gap, not the risk itself — the question asks for the most significant risk, which is the security exposure, not the reporting outcome.

11
Multi-Selecthard

Which THREE of the following are components of the COBIT 2019 governance system?

Select 3 answers
A.Organizational structures
B.Information items
C.Processes
D.Service desk
E.Project management office
AnswersA, B, C

Organisational structures are one of COBIT 2019's governance system components, alongside processes, policies and procedures, information, culture and behaviour, people skills and competencies, services, infrastructure and applications. They define decision rights and accountability, satisfying the stem's requirement for governance system components.

Why this answer

COBIT 2019 defines a governance system as comprising several distinct types of components, and among the listed choices the three that belong are A (Organizational structures), B (Information items), and C (Processes). Organizational structures are correct because COBIT 2019 explicitly names them as a component type, covering the various decision-making bodies and roles (such as boards, committees, and executive management) that carry out governance and management activities. Information items are correct because COBIT 2019 lists them as a component, referring to the information produced and used by the governance system to enable informed decision-making and effective operation.

Processes are correct because COBIT 2019 identifies processes as a core component type, encompassing the organized sets of practices and activities (the governance and management objectives) used to achieve enterprise goals. The unmarked options do not belong: a service desk (D) is a specific IT service management function rather than a COBIT 2019 governance system component type, and a project management office (E) is a particular organizational entity or function, not one of the defined component categories in the COBIT 2019 governance system.

Exam trap

The trap here is confusing COBIT governance components with ITIL operational functions (service desk, PMO) — candidates who have ITIL fresh in mind often select service desk or PMO because they sound 'governance-adjacent' but are not COBIT 2019 components.

12
MCQmedium

A large financial institution is evaluating the effectiveness of its IT governance framework. The board has requested a review to ensure alignment with business objectives and regulatory requirements. Which of the following is the MOST important factor for the board to consider when assessing the IT governance framework?

A.The framework is integrated with enterprise governance and supports strategic objectives.
B.The framework includes a detailed incident response plan.
C.The framework focuses on achieving high technical efficiency.
D.The framework minimizes overall IT costs.
AnswerA

Integration with enterprise governance directly satisfies the stem's alignment constraint: it ensures IT decisions cascade from and report into overall corporate strategy, so the board can trace IT investment to business objectives and regulatory obligations rather than assessing IT in isolation.

Why this answer

An effective IT governance framework must be integrated with enterprise governance to ensure alignment with business objectives and regulatory requirements. Option B is incorrect because incident response is an operational process, not a primary board-level governance consideration. Option C is incorrect because technical efficiency is a management concern, not a governance-level factor.

Option D is incorrect because minimizing IT costs is a tactical objective that may conflict with strategic priorities.

13
MCQeasy

A healthcare organization must comply with HIPAA regulations regarding patient data privacy. The IT department has implemented technical controls, but the compliance officer discovers that some employees are sharing passwords. What is the BEST governance response?

A.Implement multi-factor authentication to prevent password sharing.
B.Enforce the existing policy through disciplinary actions and additional training.
C.Report the incident to the regulatory authority as a data breach.
D.Revise the password policy to require more complex passwords.
AnswerB

Password sharing breaches the existing policy, so governance demands enforcing that policy through disciplinary action plus further training. Technical controls alone cannot compel behaviour; accountability and awareness address the human factor HIPAA privacy compliance requires.

Why this answer

Password sharing is a policy violation, not a technical control failure. The best governance response is to enforce the existing policy through disciplinary action and reinforce awareness via training, addressing the human/behavioral root cause while maintaining a documented compliance posture.

Exam trap

CISA often tests the distinction between technical controls and governance/administrative responses — candidates gravitate toward technical fixes (MFA, complexity) when the scenario calls for policy enforcement and training.

How to eliminate wrong answers

Option A is wrong because MFA is a technical control that reduces risk but does not directly address the governance issue of employees violating policy, and it does not remediate the existing violation. Option C is wrong because password sharing is an internal policy violation, not necessarily a reportable data breach under HIPAA unless actual unauthorized disclosure occurred. Option D is wrong because stronger password complexity does not prevent sharing and misdiagnoses the root cause as weak passwords rather than policy non-compliance.

14
MCQhard

An IS auditor is evaluating an organization's IT governance maturity using COBIT 2019. The auditor finds that IT processes are largely ad hoc, with no formal documentation or consistent monitoring. However, the organization has recently implemented a tool to automate some IT service management tasks. Management believes this tool elevates their maturity to a managed level. The auditor should:

A.Assess the actual process maturity against COBIT criteria, noting that tool implementation without process definition does not raise maturity.
B.Recommend immediate reclassification to the managed level to reflect management's commitment to improvement.
C.Conclude that the organization is at an initial level because the tool is not fully integrated with all IT processes.
D.Agree that the tool implementation demonstrates a managed level because automation implies repeatable processes.
AnswerA

COBIT 2019 maturity levels are based on the capability of processes, not on the tools used. Implementing a tool without defining, documenting, and consistently executing processes does not move the organization beyond the initial or ad hoc level. The auditor should evaluate the processes against the COBIT criteria for each maturity level, recognizing that automation can support but not substitute for process management.

Why this answer

COBIT 2019 maturity levels assess process capability, not the presence of tools. The organization's processes are ad hoc and undocumented, which aligns with the initial level. Implementing an automation tool does not automatically elevate maturity because the underlying processes are not defined, managed, or measured.

The IS auditor should evaluate the processes against COBIT criteria and conclude that the tool alone does not raise maturity to the managed level.

Exam trap

The trap here is equating the implementation of a tool with process maturity, overlooking that COBIT maturity is about process capability, not technology adoption.

15
MCQeasy

A medium-sized manufacturing company has recently deployed an ERP system to integrate its financial, supply chain, and HR processes. The IT department is small (5 staff) and reports to the CFO. The company has no formal IT governance committee; IT decisions are made by the CFO and CEO informally. During a recent audit, it was found that several critical security patches for the ERP system have not been applied, and there are no documented procedures for change management. The IT manager states that patches are applied when time permits, and changes are discussed via email. The CFO argues that the ERP is running fine and the audit findings are low risk. The IS auditor needs to recommend a course of action to improve IT governance. Which of the following is the MOST appropriate initial step?

A.Elevate the issue to the board of directors with a recommendation to outsource IT management
B.Recommend the formation of an IT steering committee comprising key business stakeholders to oversee IT strategy, risk, and resource allocation
C.Develop a comprehensive patch management policy and present it to the CFO for approval
D.Insist that the IT manager immediately apply all missing patches within one week
AnswerB

An IT steering committee gives the five-person IT function formal governance oversight, addressing the absent decision-making structure the audit flagged. It routes patch and change-management accountability through business stakeholders rather than the CFO's informal judgement, satisfying the need for documented, risk-based governance.

Why this answer

The root cause of the audit findings is the absence of IT governance, not the missing patches themselves. Forming an IT steering committee establishes a governance structure that aligns IT strategy with business objectives, assigns accountability for risk, and provides oversight for change and patch management. This addresses the underlying governance gap rather than a symptom, making it the most appropriate initial step for the IS auditor to recommend.

Exam trap

CISA often tests the distinction between addressing a symptom (missing patches) and addressing the root cause (lack of governance); candidates frequently choose the technical fix because it feels more actionable.

How to eliminate wrong answers

Option A is wrong because escalating to the board with an outsourcing recommendation is a disproportionate leap that skips the foundational governance step and presumes outsourcing is the solution before governance is even established. Option C is wrong because developing a patch management policy treats a symptom; without a governance body to approve, enforce, and fund it, the policy will likely be ignored, as evidenced by the CFO's dismissive attitude. Option D is wrong because insisting on immediate patching is an operational directive, not a governance recommendation, and it ignores the change management risk of applying untested patches to a production ERP without a formal process.

16
MCQmedium

An organization's IT governance framework includes a policy that all system access must be reviewed quarterly. The internal audit finds that reviews are incomplete. What is the BEST action?

A.Implement an automated access review tool
B.Reinforce accountability with managers
C.Disable all non-compliant accounts
D.Update the policy to require monthly reviews
AnswerB

Accountability sits with line managers who own the access reviews; reinforcing it makes them enforce the quarterly policy rather than audit merely re-testing. This addresses the root cause of incomplete reviews, restoring the control the framework requires.

Why this answer

When access reviews are incomplete, the root cause is often lack of accountability among managers who are responsible for conducting the reviews. Reinforcing accountability with managers—through clear expectations, consequences, and escalation—addresses the behavioral gap and ensures the control operates effectively. This is the best action because it directly targets the cause of non-compliance without weakening the control or introducing unnecessary risk.

Exam trap

CISA often tests the difference between treating the symptom (automation, disabling accounts) and addressing the root cause (accountability); candidates may pick a technical fix when the issue is a management/process failure.

How to eliminate wrong answers

Option A is wrong because implementing an automated tool may improve efficiency but does not address the underlying accountability issue; managers could still ignore the reviews. Option C is wrong because disabling all non-compliant accounts is a drastic, disruptive action that could lock out legitimate users and does not fix the process. Option D is wrong because updating the policy to require monthly reviews increases the burden without addressing why quarterly reviews are incomplete, likely worsening non-compliance.

17
MCQhard

An IS auditor is reviewing the IT governance of a financial services firm. The auditor discovers that the IT steering committee has approved a major core banking system upgrade, but the project lacks a formal business case and no post-implementation review is planned. Which of the following is the MOST significant risk arising from this situation?

A.The IT steering committee may not have the authority to approve such a project.
B.IT resources may be misallocated to projects that do not support business strategy.
C.The project may exceed its budget without proper justification.
D.The project may fail to meet technical specifications.
AnswerB

The absence of a formal business case means the project's strategic alignment and expected benefits are not evaluated. Without a post-implementation review, there is no verification that benefits were realized. This creates a significant risk that IT resources are invested in initiatives that do not deliver value or support business goals, leading to wasted resources and missed opportunities. This is the most critical governance risk.

Why this answer

The most significant risk is that without a formal business case, the project's alignment with business strategy and expected benefits are not established, and without a post-implementation review, there is no accountability for realizing those benefits. This can lead to misallocation of IT resources and failure to deliver value, which is a fundamental governance concern. Other risks, such as budget overruns or technical failures, are secondary to the strategic misalignment.

Exam trap

The trap here is focusing on tactical project risks like budget or technical issues, while overlooking the strategic governance risk of investing in initiatives without a business case or benefits realization review.

18
MCQmedium

A business continuity plan (BCP) includes a tabletop exercise once a year. An IS auditor finds that the exercise only involves IT staff. Which of the following is the BEST recommendation?

A.Perform a failover test of the production environment
B.Increase the frequency of IT-only exercises
C.Invite business process owners to participate in future exercises
D.Include a data restoration test in the exercise
AnswerC

Involving business process owners directly addresses the stem's constraint: the exercise excludes non-IT stakeholders. Business continuity depends on process recovery, not just infrastructure restoration, so owners validate recovery time objectives and interdependencies that IT staff cannot assess alone. Their participation tests cross-functional coordination, which is the exercise's core purpose.

Why this answer

The best recommendation is to invite business process owners to participate in future exercises because BCP is a business-wide initiative, not just IT. Their involvement ensures that business impact, recovery priorities, and cross-functional dependencies are properly tested. This addresses the auditor's finding that the exercise only involves IT staff.

Exam trap

CISA often tests the auditor's ability to recommend the most appropriate improvement, and candidates may choose technical fixes (like failover tests) instead of addressing the governance and business involvement gap.

How to eliminate wrong answers

Option A is wrong because a failover test of production is a technical recovery test, not a BCP tabletop exercise improvement, and it may be too disruptive. Option B is wrong because increasing frequency of IT-only exercises does not address the lack of business involvement, which is the core issue. Option D is wrong because including a data restoration test is a technical component and does not resolve the missing business representation.

19
MCQmedium

Based on the exhibit, what is the MOST likely security risk?

A.The web server is fully protected
B.Traffic to port 80 is not encrypted
C.Unrestricted traffic is allowed after the specific deny
D.The host 192.168.1.100 is exposed to denial-of-service attacks
AnswerC

This option accurately highlights a common security misconfiguration in sequential rule processing, typical of firewalls or Access Control Lists. If an exhibit demonstrates a specific deny rule that is subsequently followed by a broader, less restrictive allow rule (e.g., an implicit or explicit 'allow any any'), any traffic not explicitly matched and denied by the preceding specific rule will be permitted. This circumvents the intended denial, creating a significant vulnerability by failing to enforce the principle of least privilege.

Why this answer

The 'permit ip any any' at the end allows all traffic, bypassing earlier specific denials. Option A is not correct because the deny line only blocks other traffic, but the permit any any overrides it. Option B is not directly indicated.

Option D is a risk but less direct than the rule order issue.

20
MCQmedium

An IS auditor is reviewing an organization's IT governance framework and notices that the IT steering committee, chaired by the CIO, approves all IT investments and also monitors their benefits realization. The board has delegated full IT decision-making authority to this committee. The auditor is MOST likely to conclude that:

A.The arrangement is appropriate as long as the committee reports regularly to the board on its decisions and outcomes.
B.The committee structure provides adequate oversight because the CIO has the technical expertise to evaluate IT investments.
C.The board's delegation of full authority to the committee is acceptable because IT governance is an operational responsibility, not a board responsibility.
D.The committee's dual role of approving investments and monitoring benefits creates a self-review risk that weakens independent oversight.
AnswerD

The IT steering committee, chaired by the CIO, both approves investments and monitors their benefits realization. This self-review creates a conflict of interest because the same group evaluates the success of its own decisions. Effective governance requires independent oversight, typically by the board or a separate audit function, to ensure objective assessment. The auditor should flag this as a governance weakness.

Why this answer

The IT steering committee, led by the CIO, both approves IT investments and monitors their benefits, which is a self-review conflict. The board has delegated full authority, meaning it lacks independent oversight. Effective IT governance requires separation between those who make investment decisions and those who evaluate their outcomes.

The auditor should conclude that this structure weakens independent oversight and may lead to biased benefits assessments.

Exam trap

The trap here is assuming that regular reporting to the board or the CIO's technical expertise can compensate for the lack of independent oversight in a self-review situation.

21
MCQhard

Scenario: A mid-sized manufacturing company has recently experienced a significant IT outage that halted production for 8 hours. The root cause was a failed firmware update on a core switch that was performed outside the change management process by a senior network engineer who claimed the update was urgent to patch a critical vulnerability. The company has a well-documented change management policy that requires all changes to be reviewed by the change advisory board (CAB) before implementation, except for emergency changes which require post-implementation review within 48 hours. The engineer did not follow the emergency change process; he implemented the update directly. The IT director wants to prevent such incidents in the future. Which of the following is the BEST action?

A.Implement automatic firmware updates to eliminate human error.
B.Increase the frequency of CAB meetings to weekly to expedite change approvals.
C.Enforce the change management policy by implementing stricter controls and disciplinary measures for non-compliance.
D.Remove the network engineer's administrative access to all network devices.
AnswerC

The outage stemmed from an engineer bypassing the documented CAB and emergency-change routes. Enforcing the existing policy with stricter preventive controls and consequences directly addresses that non-compliance, closing the gap that allowed the unapproved firmware update.

Why this answer

The root cause was a deliberate bypass of the existing change management policy, not a flaw in the policy itself. Enforcing stricter controls and disciplinary measures directly addresses the human factor by reinforcing accountability and deterring unauthorized changes, which is the most effective way to prevent recurrence when a well-documented process is already in place but ignored.

Exam trap

The trap here is that candidates often choose technical controls (like automatic updates or removing access) instead of recognizing that the fundamental issue is a governance failure—the policy exists but was not enforced, so the best action is to strengthen enforcement and accountability, not to add or remove technical capabilities.

How to eliminate wrong answers

Option A is wrong because implementing automatic firmware updates would remove human oversight entirely, potentially causing widespread outages if a faulty update is pushed without testing or CAB review, and it does not address the policy violation. Option B is wrong because increasing CAB meeting frequency does not solve the core issue of an engineer bypassing the process; the emergency change process already exists for urgent patches, so the problem is non-compliance, not approval speed. Option D is wrong because removing the network engineer's administrative access is an overly punitive and impractical measure that could hinder legitimate emergency responses; it does not enforce the existing change management process and may violate the principle of least privilege by eliminating necessary access for a qualified engineer.

22
MCQmedium

An IT governance framework has been implemented, but the board is not receiving regular reports on IT performance. Which of the following is the BEST course of action?

A.Conduct an IT risk assessment to identify critical areas.
B.Develop a dashboard that presents key IT metrics to the board.
C.Implement an IT balanced scorecard that aligns with corporate strategy.
D.Assign a chief information officer (CIO) to report directly to the board.
AnswerB

A dashboard directly addresses the missing reporting channel by giving the board recurring visibility of key IT metrics, satisfying the governance requirement for ongoing performance oversight. Unlike one-off reports, it establishes a repeatable mechanism aligned to the framework's monitoring and communication controls, closing the gap between implementation and board-level accountability.

Why this answer

The gap identified is that the board is not receiving regular IT performance reports — a communication and reporting deficiency, not a risk identification or organizational design problem. Developing a dashboard that presents key IT metrics to the board (B) directly closes that gap by establishing a repeatable, structured reporting mechanism that gives the board visibility into IT performance. It is the most targeted, proportionate response to the stated deficiency.

Exam trap

The trap is choosing a broader or more prestigious-sounding governance initiative (balanced scorecard, CIO reporting line) when the question describes a specific, narrow deficiency — CISA rewards the most direct, proportionate fix to the stated problem.

How to eliminate wrong answers

Option A is wrong because conducting an IT risk assessment addresses risk identification, not the reporting gap — it does not create a mechanism for the board to receive ongoing performance information. Option C is wrong because implementing an IT balanced scorecard is a broader strategic alignment initiative; while valuable, it is heavier than needed and does not directly solve the immediate reporting deficiency (and a scorecard still needs a delivery mechanism to the board). Option D is wrong because assigning a CIO to report directly to the board changes reporting lines but does not guarantee regular IT performance reporting — it addresses structure, not the missing reporting content and cadence.

23
MCQeasy

A hospital's IT department has implemented a new electronic health record (EHR) system. The IS auditor is reviewing the IT governance over the project and finds that the project sponsor is the CIO, who also chairs the IT steering committee that approved the project. Which of the following is the MOST significant governance risk?

A.Lack of segregation of duties between project sponsorship and project approval.
B.The project sponsor should be a clinical leader rather than the CIO.
C.The IT steering committee may not have the authority to approve large projects.
D.The CIO may not have sufficient technical knowledge to sponsor an EHR project.
AnswerA

Having the CIO serve as both project sponsor and chair of the committee that approves the project creates a conflict of interest and a lack of segregation of duties. The sponsor is responsible for advocating for the project, while the approval body should provide independent oversight. This combination can lead to biased decisions, insufficient challenge, and inadequate risk assessment. It undermines the governance principle of independent review and can result in projects proceeding without proper scrutiny.

Why this answer

The most significant governance risk is the lack of segregation of duties between project sponsorship and project approval. When the CIO sponsors the project and also chairs the committee that approves it, independent oversight is compromised. This can lead to inadequate challenge, biased decision-making, and insufficient risk assessment.

Proper governance requires that project approval be made by a body that can objectively evaluate the project's merits and risks, separate from those advocating for it.

Exam trap

The trap here is focusing on the CIO's technical knowledge or the sponsor's role, rather than recognizing the conflict of interest created by combining sponsorship and approval responsibilities.

24
MCQeasy

An organization has implemented a balanced scorecard (BSC) for IT performance measurement. Which of the following is the PRIMARY benefit of using a BSC?

A.It simplifies the IT budgeting process.
B.It ensures IT metrics are aligned with business strategy.
C.It automates data collection for IT metrics.
D.It provides a single financial metric for IT performance.
AnswerB

A balanced scorecard links IT measures across financial, customer, internal process and learning perspectives to organisational objectives, so IT performance is judged by strategic contribution rather than isolated technical metrics. That strategic alignment is its primary benefit.

Why this answer

A balanced scorecard (BSC) translates an organization's mission and strategy into a comprehensive set of performance measures across four perspectives: financial, customer, internal business processes, and learning and growth. Its primary benefit in an IT context is ensuring that IT metrics and activities are directly linked to and driven by business strategy, rather than being measured in isolation. This strategic alignment is the defining purpose of the BSC framework as developed by Kaplan and Norton.

Exam trap

CISA often tests whether candidates confuse the BSC's strategic alignment purpose with operational tooling benefits like budgeting, automation, or single-metric reporting — the trap is picking a tactically appealing but strategically incorrect benefit.

How to eliminate wrong answers

Option A is wrong because the BSC is a strategic performance measurement and management framework, not a budgeting tool; it does not simplify or automate the budgeting process. Option C is wrong because the BSC does not automate data collection — it defines what should be measured, while data collection automation is handled by separate BI or monitoring tools. Option D is wrong because the BSC deliberately uses multiple perspectives (financial, customer, internal process, learning and growth), not a single financial metric, which would defeat its purpose.

25
MCQhard

A company is implementing IT governance based on COBIT 2019. Which of the following design factors would have the GREATEST impact on the governance system design?

A.The IT infrastructure complexity.
B.The size of the organization.
C.The number of IT staff.
D.The industry and regulatory environment.
AnswerD

Industry and regulatory environment design factors shape mandatory compliance obligations and risk appetite, so they most strongly determine governance system design. They drive which COBIT components and focus areas are tailored, outweighing enterprise-specific factors such as size or threat landscape.

Why this answer

According to COBIT 2019, the industry and regulatory environment is a key design factor that significantly influences the governance system design, as it dictates compliance and risk management requirements. Options A, B, and C are factors but have a lesser impact compared to industry and regulatory considerations.

26
Multi-Selecthard

An IS auditor is assessing the IT governance framework of a retail company. The auditor finds that the company has a formal IT strategy, an IT steering committee, and a defined IT organizational structure. However, the auditor notes that there is no process to ensure that IT investments are justified and prioritized. Which of the following are the MOST appropriate recommendations to address this deficiency? (Choose two.)

Select 2 answers
A.Conduct a post-implementation review of all IT projects.
B.Increase the frequency of IT steering committee meetings to monthly.
C.Implement a formal IT investment approval process with defined criteria.
D.Establish an IT portfolio management function to oversee investment prioritization.
E.Delegate investment decisions to individual business units to speed up approvals.
AnswersC, D

A formal IT investment approval process with defined criteria (e.g., ROI, strategic alignment, risk) ensures that investments are justified and prioritized consistently. This directly addresses the deficiency of no process to justify and prioritize IT investments. It provides a structured mechanism for decision-making and accountability, which is essential for effective IT governance.

Why this answer

The most appropriate recommendations are to implement a formal IT investment approval process with defined criteria and to establish an IT portfolio management function. These two measures directly address the absence of a process to justify and prioritize IT investments. The approval process ensures that each investment is evaluated against consistent criteria, while portfolio management provides ongoing oversight and prioritization across all investments, aligning them with strategic objectives.

Exam trap

The trap here is selecting actions that improve oversight frequency or delegate decisions, which do not establish a structured process for justifying and prioritizing investments.

27
Multi-Selecthard

A large enterprise is assessing its IT governance maturity. Which THREE of the following are indicators of a mature governance process? (Select exactly three.)

Select 3 answers
A.IT decisions are made in silos
B.IT budget is allocated based on historical spending
C.There is a formal IT governance committee
D.IT performance metrics are linked to business outcomes
E.IT strategy is reviewed quarterly by the board
AnswersC, D, E

A formal IT governance committee provides the standing oversight structure through which decisions, accountability and resource direction are exercised. Its existence demonstrates that governance is institutionalised rather than ad hoc, which is a recognised indicator of a mature governance process.

Why this answer

Option C is correct because a formal IT governance committee establishes clear accountability, decision rights, and oversight structures, which are hallmarks of a mature governance process rather than ad hoc or siloed decision-making. Option D is correct because linking IT performance metrics to business outcomes demonstrates that governance is aligned with enterprise strategy and value delivery, a key maturity indicator in frameworks such as COBIT. Option E is correct because regular board-level review of IT strategy, such as quarterly, shows sustained executive engagement, strategic alignment, and proactive oversight rather than reactive or infrequent attention.

Options A and B do not belong because siloed IT decision-making and budget allocation based solely on historical spending reflect immature, reactive governance practices that lack integration, strategic alignment, and value-based prioritization.

Exam trap

CISA often tests whether candidates can distinguish mature governance indicators (formal committees, business-linked metrics, board review) from immature practices (silos, historical budgeting) that are sometimes mistaken for stability.

28
Multi-Selecteasy

An IT governance framework should include which TWO key components? (Select exactly two.)

Select 2 answers
A.User training
B.Vendor lock-in
C.Strategic alignment
D.Network firewall rules
E.Performance measurement
AnswersC, E

Strategic alignment ensures IT investments and initiatives directly support organisational objectives, satisfying the governance requirement to link technology decisions with business strategy. COBIT and ISO/IEC 38500 both identify this linkage as a core governance component, distinct from operational execution, because governance must direct where IT resources are deployed rather than merely manage their day-to-day running.

Why this answer

Strategic alignment (C) is a core component of any IT governance framework because governance must ensure that IT investments, priorities, and initiatives directly support the organization's business goals and objectives. Performance measurement (E) is equally essential, as governance requires metrics, KPIs, and monitoring mechanisms (such as balanced scorecards or COBIT goals) to verify that IT delivers value, manages risk, and meets agreed service levels. Together, these two components reflect the dual governance mandate of directing IT toward business strategy while measuring whether it actually delivers.

The other options do not belong: user training (A) is an operational capability rather than a governance component, vendor lock-in (B) is a risk to be avoided, not a framework element, and network firewall rules (D) are technical security controls, not governance-level components.

Exam trap

The trap here is confusing operational IT controls (training, firewalls) with governance framework components — CISA candidates often pick 'user training' because it sounds foundational, but governance is about direction and oversight, not execution.

29
MCQeasy

An organization has a policy requiring all employees to complete annual information security awareness training. Which of the following is the BEST way to verify compliance with this policy?

A.Conduct phishing simulation tests
B.Survey employees about their satisfaction with training
C.Interview HR about training content
D.Review training completion records from the learning management system
AnswerD

Reviewing learning management system completion records provides direct, timestamped evidence that each employee finished the annual training, satisfying the policy's compliance verification requirement. Unlike interviews or observation, which sample behaviour, the LMS record is authoritative and auditable per employee, enabling exception reporting for those overdue.

Why this answer

The policy specifically requires employees to complete annual information security awareness training. The most direct and objective way to verify compliance is to examine the training completion records maintained by the learning management system (LMS). These records provide evidence of who has completed the training and when, directly confirming adherence to the policy.

Other methods may assess effectiveness or satisfaction but do not verify completion.

Exam trap

CISA often tests the distinction between verifying compliance (checking if requirements are met) and assessing effectiveness (evaluating impact or quality), so candidates may incorrectly choose phishing simulations or surveys, which measure effectiveness rather than compliance.

How to eliminate wrong answers

Option A is wrong because phishing simulation tests measure employee behavior and susceptibility to phishing, not whether they have completed the required training. Option B is wrong because surveying employee satisfaction with training assesses quality and perception, not compliance with the completion requirement. Option C is wrong because interviewing HR about training content provides information about the training material itself, not evidence that employees have completed it.

30
Multi-Selecteasy

Which TWO of the following are benefits of implementing an IT governance framework?

Select 2 answers
A.Improved risk management and mitigation
B.Reduction in IT staff headcount
C.Enhanced regulatory compliance
D.Reduced IT operational costs
E.Elimination of all IT project failures
AnswersA, C

Frameworks like COBIT emphasize risk management.

Why this answer

Implementing an IT governance framework, such as COBIT or ISO/IEC 38500, establishes structured policies, procedures, and controls that directly improve risk management and mitigation. By defining clear roles, accountability, and risk appetite, the framework ensures that risks are systematically identified, assessed, and treated, rather than being managed ad hoc. This aligns IT strategy with business objectives and embeds risk management into daily operations.

Exam trap

The trap here is that candidates often confuse the benefits of an IT governance framework with operational cost-cutting or headcount reduction, when in fact the framework's core value is in aligning IT with business goals, improving risk management, and ensuring compliance, not in directly reducing expenses or eliminating failures.

31
MCQeasy

A company is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?

A.Simplifies IT architecture
B.Improves IT staff morale
C.Ensures IT investments support business objectives
D.Reduces IT costs
AnswerC

Alignment directs funding and resources toward initiatives that deliver measurable business value, so IT spend directly supports strategic goals. This satisfies the stem's requirement for the primary benefit of linking IT strategy to business strategy.

Why this answer

Aligning IT strategy with business strategy ensures that technology investments, projects, and resources are directed toward achieving the organization's business goals, which is the fundamental purpose of IT governance frameworks like COBIT. This alignment translates business objectives into IT priorities so that every dollar and hour spent on IT delivers measurable business value.

Exam trap

CISA often tests the difference between primary governance benefits and secondary operational outcomes, tempting candidates to pick cost reduction or architecture simplification instead of business objective support.

How to eliminate wrong answers

Option A is wrong because simplifying IT architecture is a possible byproduct, not the primary benefit of strategic alignment. Option B is wrong because IT staff morale is an internal HR outcome and not the governance objective. Option D is wrong because cost reduction may or may not result from alignment; the primary benefit is value delivery and objective support, not cost cutting.

32
Multi-Selectmedium

Which TWO of the following are recommended practices for aligning IT strategy with business goals, according to COBIT 2019?

Select 2 answers
A.Implementing a continuous monitoring system for IT operational metrics
B.Conducting monthly IT steering committee meetings to review project status
C.Adopting a governance framework that covers all IT-related activities and stakeholder needs
D.Defining IT investment portfolios based on business value contribution
E.Using agile development methodologies for all IT projects
AnswersC, D

Adopting a governance framework spanning all IT-related activities and stakeholder needs directly satisfies COBIT 2019's alignment principle, since the framework cascades enterprise goals into IT objectives and defines decision rights, accountability and performance measurement across every domain, ensuring IT strategy remains traceable to business intent rather than isolated departmental priorities.

Why this answer

Option C is correct because COBIT 2019's governance system is explicitly built on a governance framework that spans the whole enterprise—covering all IT-related activities through the governance and management objectives and addressing the needs of internal and external stakeholders, which is exactly what aligning IT strategy with business goals requires. Option D is correct because COBIT 2019's BA (Build, Acquire and Implement) and APO (Align, Plan and Organise) domains, particularly APO05 Managed Portfolio, call for managing IT investments as a portfolio prioritised by business value and strategic contribution, directly tying IT spending to business goals. Option A is not marked correct because continuous monitoring of operational metrics is a performance/operations practice rather than a strategic alignment practice in COBIT 2019.

Option B is not marked correct because, while steering committees are useful, COBIT 2019 does not prescribe monthly IT steering committee meetings as a recommended alignment practice. Option E is not marked correct because COBIT 2019 is methodology-agnostic and does not mandate agile for all IT projects as a means of strategic alignment.

Exam trap

The trap here is that candidates confuse operational or tactical activities (like monitoring metrics or project reviews) with strategic governance practices, which COBIT 2019 defines as framework-level alignment, not day-to-day management tasks.

33
MCQmedium

Midway through a multi-year ERP implementation, the CIO asks the IS auditor to review how the organization is realizing the intended business benefits. The project is on schedule and within budget, but business unit managers report that key process changes have not been adopted. Which of the following is the MOST appropriate action for the IS auditor to recommend?

A.Implement a formal benefits realization plan with defined ownership and periodic measurement of outcome metrics.
B.Escalate the schedule and budget variances to the audit committee for immediate action.
C.Perform a post-implementation review immediately to determine whether the project should be cancelled.
D.Recommend that the project steering committee increase the frequency of status reporting to weekly.
AnswerA

Because the project is on time and on budget yet benefits are not materializing, the gap is in benefits management, not delivery. A formal benefits realization plan assigns accountability for outcome metrics and establishes periodic measurement so deviations trigger corrective action. This directly addresses the governance objective of ensuring IT investments deliver value, which is exactly what the CIO asked the auditor to assess.

Why this answer

The scenario deliberately separates delivery success from benefit realization: the project is on time and within budget, yet process changes are not adopted, meaning the investment's intended value is at risk. The governance response is to establish benefits ownership and outcome measurement through a benefits realization plan. Escalating false variances, increasing reporting cadence, or prematurely conducting a post-implementation review all fail to create accountability for outcomes.

Exam trap

The trap here is assuming that on-time, on-budget delivery equates to successful benefits realization, when the two are governed by separate mechanisms.

34
MCQeasy

An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of aligning IT strategy with business strategy?

A.Increased technical efficiency
B.Improved resource allocation
C.Reduced IT costs
D.Enhanced security posture
AnswerB

Aligning IT strategy with business strategy ensures IT investments, staffing and budgets target the organisation's actual priorities. This directly produces improved resource allocation, since resources flow to initiatives that demonstrably support business objectives rather than isolated technical goals.

Why this answer

Aligning IT strategy with business strategy ensures that IT investments and initiatives directly support business objectives, leading to more effective prioritization and allocation of resources (budget, personnel, technology) to areas that deliver the most value. This alignment is a core goal of IT governance frameworks like COBIT, which emphasize value delivery and resource optimization.

Exam trap

The trap is choosing a tangible, operational benefit like reduced costs or increased efficiency, which are outcomes of good IT management but not the primary benefit of strategic alignment; the exam expects you to recognize that alignment drives resource allocation toward business value.

How to eliminate wrong answers

Option A is wrong because increased technical efficiency is an operational outcome, not the primary benefit of strategic alignment; efficiency can be achieved without alignment. Option C is wrong because reduced IT costs may result from alignment but is not the primary benefit—alignment is about value creation, not just cost cutting. Option D is wrong because enhanced security posture is a component of IT governance but not the primary benefit of aligning IT with business strategy; security is one of many domains.

35
MCQmedium

A company plans to outsource its data center operations to a cloud service provider. What is the MOST important governance consideration for the board before finalizing the contract?

A.Select a provider with the lowest cost per transaction.
B.Negotiate the transfer of existing IT staff to the provider.
C.Ensure the contract includes clauses for regulatory compliance and audit rights.
D.Define a detailed exit strategy for transitioning to another provider.
AnswerC

Outsourcing data centre operations transfers processing to a third party, so the board must secure contractual regulatory compliance and audit rights. These clauses preserve oversight and evidence-gathering ability, satisfying the governance obligation for accountability over outsourced services.

Why this answer

The board's primary governance responsibility is to ensure the organization remains compliant with all applicable laws and regulations, even when operations are outsourced. Without explicit contractual clauses for regulatory compliance and audit rights, the company loses visibility and control over how its data is handled, creating legal and reputational risk. This is the most critical governance consideration because it directly addresses accountability and oversight.

Exam trap

CISA often tests the distinction between governance and management. Candidates may choose an operational or tactical answer (like exit strategy or cost) instead of the governance-level answer that focuses on compliance and audit rights.

How to eliminate wrong answers

Option A is wrong because selecting a provider based solely on lowest cost ignores risk, compliance, and service quality, which are core governance concerns. Option B is wrong because transferring IT staff is an operational HR matter, not a governance imperative. Option D is wrong because while an exit strategy is important for business continuity, it is secondary to ensuring compliance and auditability during the contract term.

36
MCQeasy

An organization's IT department has a policy that all new hires must sign an acceptable use policy (AUP) before gaining access to systems. During an audit, the IS auditor finds that several contractors were granted access without signing the AUP. Which of the following is the auditor's BEST recommendation?

A.Require the IT manager to manually verify AUP signatures before granting access.
B.Update the AUP to include contractors and re-communicate the policy.
C.Conduct additional security awareness training for all contractors.
D.Implement automated enforcement to block access until the AUP is signed.
AnswerD

Automated enforcement ensures compliance by preventing access until the AUP is acknowledged. This is the best recommendation because it addresses the root cause—human error or process bypass—and provides a preventive control. Manual reminders or training alone are less effective. Automated enforcement is a standard practice for ensuring policy compliance at scale.

Why this answer

The most effective recommendation is to implement automated enforcement that blocks system access until the AUP is signed. This preventive control ensures consistent compliance and eliminates the risk of human error. Other options are either detective or corrective and do not prevent unauthorized access in the first place.

Exam trap

The trap here is assuming that training or manual checks are sufficient when the issue is a lack of enforcement, not awareness.

37
MCQhard

A multinational corporation is implementing a global IT governance framework. Which of the following challenges is MOST likely to arise?

A.Conflicting regulatory requirements
B.Standardizing hardware across regions
C.Training users on new procedures
D.Software licensing costs
AnswerA

Differing data protection, privacy, and financial reporting rules across jurisdictions force the framework to reconcile incompatible mandates, which is the central governance obstacle. A single global policy cannot satisfy every regulator simultaneously, so conflicting requirements are the most likely challenge.

Why this answer

A global IT governance framework must reconcile laws, regulations, and industry standards across many jurisdictions. Multinationals face conflicting requirements — for example, GDPR data residency in the EU versus data localization laws in other countries, or differing breach-notification timelines. These conflicts directly shape governance policies, controls, and reporting, making them the most likely and most impactful challenge.

Exam trap

The trap is selecting an operational or financial issue (hardware, training, licensing) when the question asks about governance — CISA expects you to recognize that governance challenges are regulatory and strategic, not tactical.

How to eliminate wrong answers

Option B is wrong because hardware standardization is an operational/engineering task, not a governance challenge, and it is usually solvable with procurement standards. Option C is wrong because user training is a routine change-management activity, not a structural governance conflict. Option D is wrong because software licensing costs are a financial/procurement concern, not a governance framework challenge.

38
Multi-Selectmedium

An IS auditor is reviewing an organization's IT governance framework and notes that the board of directors has established an IT strategy committee. Which TWO of the following are the MOST appropriate responsibilities for this committee? (Choose two.)

Select 2 answers
A.Designing and implementing IT internal controls over financial reporting.
B.Managing day-to-day IT operations and resolving technical issues.
C.Monitoring the performance of IT investments and ensuring benefits realization.
D.Approving the IT strategic plan and ensuring alignment with business objectives.
E.Conducting technical vulnerability assessments and penetration testing.
AnswersC, D

Monitoring IT investment performance and benefits realization is a key governance responsibility of the IT strategy committee. By overseeing whether IT projects deliver expected value, the committee ensures accountability and supports continuous improvement. This oversight helps prevent wasteful spending and ensures that IT contributes to business success.

Why this answer

The IT strategy committee, as a board-level body, should focus on strategic oversight: approving the IT strategic plan and ensuring alignment with business objectives, and monitoring IT investment performance and benefits realization. These responsibilities ensure that IT supports the organization's goals and delivers value. Operational tasks such as managing daily operations, designing controls, or conducting technical tests are management responsibilities and fall outside the committee's governance mandate.

Exam trap

The trap here is confusing governance with management, leading to the selection of operational tasks that are not appropriate for a board-level committee.

39
MCQmedium

An IS auditor is reviewing an organization's IT governance structure. The board of directors has delegated all IT oversight to the CIO, who reports to the CFO. The auditor finds that the board receives only annual summaries of IT performance and never reviews IT risks. Which of the following is the MOST significant governance concern?

A.The board has not retained ultimate responsibility for IT oversight.
B.The CFO should not have IT reporting to them because it creates a conflict of interest.
C.IT performance is not measured using balanced scorecard metrics.
D.The CIO lacks the authority to implement IT strategies.
AnswerA

The board is ultimately responsible for IT governance, including risk oversight. By delegating all oversight to the CIO and only receiving annual summaries, the board has effectively abdicated its responsibility. This creates a governance gap where IT risks may not be adequately addressed at the highest level. The auditor should flag this as a significant deficiency because it undermines the principles of effective IT governance.

Why this answer

The board of directors holds ultimate accountability for IT governance, including oversight of IT risks and alignment with business strategy. Delegating all oversight to the CIO without active board involvement and only receiving annual summaries means the board is not fulfilling its fiduciary duty. This creates a significant governance risk because IT decisions may not be aligned with stakeholder interests and risks may go unaddressed.

The auditor should highlight this as a critical concern.

Exam trap

The trap here is assuming that delegating IT oversight to a capable CIO absolves the board of its governance responsibilities, when in fact the board must retain ultimate accountability.

40
MCQeasy

A medium-sized e-commerce company recently suffered a ransomware attack that encrypted critical databases. The IT team restored systems from backups, but the incident exposed a lack of clear roles and responsibilities for incident response. The board has asked the IT governance committee to review and improve the incident response governance. The committee notes that while there is an incident response policy, it is not regularly tested, and staff are unsure of their roles. The company also lacks a formal communication protocol for notifying stakeholders. What should the committee prioritize to strengthen governance over incident response?

A.Invest in advanced endpoint detection and response tools.
B.Outsource incident response to a managed security service provider.
C.Define and communicate clear roles and responsibilities for incident response, and establish accountability.
D.Conduct a tabletop exercise to test the current plan.
AnswerC

Assigning and communicating explicit incident response roles, with named accountability, removes the confusion staff reported and gives the untested policy operational substance. This directly satisfies the governance gap the board identified, enabling escalation and stakeholder notification to function during future incidents.

Why this answer

The committee should prioritize defining and communicating clear roles and responsibilities for incident response and establishing accountability. The incident exposed a lack of clarity in roles, which is a governance issue. Without clear roles, even the best tools or outsourced services may not be effective.

This directly addresses the governance gap identified.

Exam trap

CISA often tests the distinction between governance (roles, accountability) and technical controls or testing, tempting candidates to choose a tactical solution like tabletop exercises or tools when the root cause is unclear roles.

How to eliminate wrong answers

Option A is wrong because investing in advanced endpoint detection and response tools is a technical control, not a governance improvement; it does not address the lack of clear roles and responsibilities. Option B is wrong because outsourcing incident response may provide expertise but does not fix the internal governance issue of unclear roles and accountability; it could even exacerbate the problem if not managed properly. Option D is wrong because conducting a tabletop exercise is a testing activity that can help validate roles, but it is not the first priority when roles are not defined; you cannot test what does not exist.

The priority should be to define roles first.

41
MCQeasy

An IS auditor is reviewing the IT organizational structure of a mid-sized manufacturing company. The auditor finds that the IT department reports to the CFO, and there is no separate IT strategy committee. The CEO believes that IT is a support function and does not need board-level representation. Which of the following is the MOST appropriate recommendation for the auditor?

A.The CFO should be given additional training on IT governance.
B.The organization should establish an IT governance framework with board involvement.
C.The IT department should report to the CEO to ensure strategic alignment.
D.The IT department should be outsourced to reduce costs and improve efficiency.
AnswerB

Establishing a formal IT governance framework ensures that IT is aligned with business strategy and that the board provides oversight. This addresses the root cause: the CEO's view that IT is merely support and does not need board representation. A governance framework defines roles, responsibilities, and processes for IT decision-making, ensuring IT is managed as a strategic asset.

Why this answer

The CEO's perception of IT as a support function and the absence of board-level oversight indicate a governance gap. Establishing an IT governance framework with board involvement ensures IT is strategically managed and aligned with business goals. This is the most comprehensive and appropriate recommendation, addressing the root cause rather than symptoms.

Exam trap

The trap here is recommending structural changes like reporting line adjustments or outsourcing, which do not address the fundamental need for board-level IT governance and strategic alignment.

42
MCQhard

A multinational corporation is evaluating its IT governance structure. The board wants to ensure that IT investments are prioritized based on risk and value. Which framework component is MOST critical?

A.Service level agreements
B.Balanced scorecard
C.IT steering committee
D.Portfolio management process
AnswerD

Portfolio management processes let the board prioritise and monitor IT investments against risk and value criteria, directly satisfying the stem's requirement. It provides the governance mechanism for balancing investment mix, whereas other components address resource, performance or compliance concerns.

Why this answer

A portfolio management process systematically evaluates and prioritizes investments based on risk and value, aligning with board objectives. Steering committee provides oversight, but portfolio management is the mechanism for prioritization.

43
MCQeasy

A mid-sized company is implementing a new IT service management (ITSM) tool to improve incident management. The IT manager wants to ensure that the tool aligns with ITIL best practices. The company has a dedicated service desk team that handles about 200 incidents per week. The IT manager is considering whether to implement a self-service portal for users to submit incidents and check status, or to continue using email-based incident reporting. The service desk team is concerned that a self-service portal might reduce their direct interaction with users and potentially lead to less personalized support. However, the IT manager believes that a portal could improve efficiency and tracking. The company's IT governance framework requires that any major IT investment be approved by the steering committee and that there be a clear business case. The IT manager has prepared a business case but the steering committee wants to ensure that the solution is aligned with ITIL and that it addresses key incident management processes. Which of the following is the most appropriate next step for the IT manager?

A.Implement the self-service portal immediately to improve efficiency, then present the business case later.
B.Conduct a process review with stakeholders to define requirements based on ITIL guidelines before selecting a tool.
C.Proceed with the self-service portal without further review because it is clearly beneficial.
D.Abandon the self-service portal idea and continue with email-based reporting.
AnswerB

ITIL-aligned requirements must be defined before tool selection, ensuring the ITSM solution supports incident management processes rather than forcing process change. A stakeholder process review establishes the business case the steering committee requires, addressing governance and alignment constraints.

Why this answer

ITIL best practices emphasize that process design should precede tool selection. Conducting a process review with stakeholders ensures the self-service portal aligns with defined incident management workflows, such as categorization, prioritization, and escalation, before committing to a specific tool. This step also satisfies the IT governance requirement for a clear business case by validating requirements against ITIL guidelines.

Exam trap

The trap here is that candidates may assume any self-service portal automatically improves efficiency and aligns with ITIL, but CISA tests the principle that process definition must precede tool selection to ensure governance and best practice alignment.

How to eliminate wrong answers

Option A is wrong because implementing the portal immediately without presenting the business case violates the IT governance framework requiring steering committee approval for major IT investments, and it risks deploying a tool that does not align with ITIL-defined incident management processes. Option C is wrong because proceeding without further review ignores the service desk team's concerns about reduced personalization and fails to ensure the portal supports ITIL processes like incident categorization and SLA tracking, which could lead to inefficiencies. Option D is wrong because abandoning the portal idea outright dismisses the potential efficiency gains and tracking improvements that a properly designed self-service portal can provide, and it does not address the need to align with ITIL best practices.

44
MCQhard

A multinational corporation has defined its risk appetite as 'moderate' for IT investments. The IT steering committee is evaluating a new project with potential high returns but also significant cybersecurity risks. The project's risk profile is assessed as 'high' by the risk management team. What should the committee do FIRST?

A.Request the project team to identify risk mitigation measures.
B.Approve the project but increase monitoring.
C.Escalate the decision to the board of directors.
D.Reject the project immediately as it exceeds risk appetite.
AnswerA

Requesting mitigation measures first addresses the high-risk profile before any acceptance decision, aligning residual risk with the moderate appetite. Identifying controls and their effectiveness gives the committee the information needed to approve, modify or reject the project.

Why this answer

When a project's risk profile exceeds the organization's defined risk appetite, the FIRST step is to understand whether the risk can be brought within tolerance through mitigation. The committee cannot make an informed accept/reject/escalate decision until the risk management team and project team have identified possible controls and residual risk. Requesting mitigation measures preserves the opportunity for high returns while aligning the project with the 'moderate' appetite.

Exam trap

CISA often tests the misconception that any project exceeding risk appetite must be immediately rejected or escalated, when the correct first step is always to evaluate mitigation and residual risk before making a governance decision.

How to eliminate wrong answers

Option B is wrong because approving a high-risk project that exceeds the stated risk appetite without first evaluating mitigation bypasses governance and effectively ignores the risk appetite framework. Option C is wrong because escalation to the board is premature—the board should only be involved if risk cannot be reduced to an acceptable level or if the decision exceeds the committee's delegated authority. Option D is wrong because immediate rejection is a knee-jerk response that discards potential high returns without first determining whether controls can reduce risk to an acceptable level.

45
Multi-Selecthard

A global retail company is implementing an IT governance framework. The board of directors has asked the IS auditor to identify the KEY components that should be included in the framework to ensure effective governance. Which TWO of the following are essential components of an IT governance framework? (Choose two.)

Select 2 answers
A.Outsourcing of all IT functions to a third party
B.Detailed technical training for all IT staff
C.Performance measurement and monitoring
D.Use of a specific software development methodology
E.IT strategic alignment with business objectives
AnswersC, E

Performance measurement and monitoring are essential to IT governance because they provide the means to assess whether IT is delivering value, managing risks, and using resources efficiently. Without metrics and monitoring, the board and management cannot make informed decisions or hold IT accountable. This component enables continuous improvement and ensures that governance objectives are being met. It is a recognized pillar of effective governance frameworks.

Why this answer

IT strategic alignment and performance measurement are core components of an IT governance framework. Alignment ensures IT supports business goals, while performance measurement provides the feedback loop to assess effectiveness and drive accountability. Other options, such as training, development methodologies, and outsourcing, are operational or strategic choices that may be governed but are not fundamental building blocks of the framework itself.

Exam trap

The trap here is confusing operational activities like technical training or specific development methodologies with the strategic components of IT governance, which focus on direction, alignment, and oversight.

46
Drag & Dropmedium

Order the steps for performing a data backup in the correct sequence.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Backup process: identify data, choose method, schedule, execute/verify, and store offsite.

47
MCQeasy

An IS auditor is reviewing the IT governance framework of a small organization. The auditor finds that the IT manager reports directly to the CFO, and there is no separate IT steering committee. Which of the following is the MOST appropriate conclusion?

A.The IT manager should report to the COO to ensure operational alignment.
B.The governance structure is inadequate because IT should report to the CEO.
C.The lack of an IT steering committee is a critical deficiency that must be remediated immediately.
D.The governance structure may be appropriate for the organization's size, provided IT decisions are aligned with business strategy.
AnswerD

In smaller organizations, formal IT steering committees may not be necessary if there is effective communication and alignment between IT and business leadership. The key is whether IT decisions support business objectives. The reporting line to the CFO can be effective if it ensures IT is integrated with financial and strategic planning. This conclusion is balanced and recognizes that governance structures should fit the organization's context.

Why this answer

The most appropriate conclusion is that the governance structure may be appropriate for the organization's size, provided IT decisions are aligned with business strategy. Smaller organizations often rely on informal governance mechanisms rather than formal committees. The reporting line to the CFO can be effective if it facilitates strategic alignment and oversight.

The auditor should focus on whether the structure achieves governance objectives, not on prescriptive best practices that may not fit the context.

Exam trap

The trap here is assuming that a formal IT steering committee and a specific reporting line are mandatory for all organizations, regardless of size or context.

48
MCQmedium

Scenario: A healthcare organization is implementing a new electronic health records (EHR) system. The project has been delayed due to scope creep and resource constraints. The project sponsor is pressuring the project manager to accelerate the timeline by skipping user acceptance testing (UAT) and going live immediately. The organization has a governance policy that requires all IT projects to complete UAT before deployment. The project manager is concerned about quality and patient safety. Which of the following is the BEST course of action?

A.Compromise by conducting a limited UAT on only critical functionalities.
B.Resign from the project due to ethical concerns.
C.Accept the sponsor's request and skip UAT to meet the deadline.
D.Adhere to the governance policy and escalate the risk to the steering committee for a decision.
AnswerD

Escalation preserves the mandatory UAT control while transferring the timeline risk decision to the steering committee, which owns governance exceptions. Skipping UAT would breach policy and expose patient safety, so the project manager must not accept that risk unilaterally.

Why this answer

The governance policy mandates UAT before deployment, and skipping it could compromise patient safety and data integrity in the EHR system. By escalating the risk to the steering committee, the project manager ensures that the decision is made at the appropriate governance level, balancing project pressures with compliance and quality. This approach aligns with the CISA domain of Governance and Management of IT, where adherence to policies and risk escalation are key controls.

Exam trap

The trap here is that candidates may choose a compromise (Option A) thinking it balances speed and quality, but it still violates the governance policy and fails to address the root cause of scope creep and resource constraints through proper escalation.

How to eliminate wrong answers

Option A is wrong because conducting a limited UAT on only critical functionalities still violates the governance policy and may miss integration or workflow defects that affect patient safety across non-critical modules. Option B is wrong because resigning is an extreme measure that abdicates professional responsibility; the project manager should first use escalation channels and governance processes to address the conflict. Option C is wrong because skipping UAT entirely disregards the governance policy and introduces unacceptable risks to patient safety and regulatory compliance, which could lead to severe consequences for the organization.

49
MCQhard

An IT department uses a balanced scorecard (BSC) to measure performance. The financial perspective shows that IT costs are within budget, but customer satisfaction scores are declining. The learning and growth perspective indicates low employee engagement. Which action should the IT governance committee prioritize?

A.Reduce IT costs further to reallocate savings to customer service.
B.Invest in training and development programs for IT staff.
C.Increase the IT budget to hire more staff.
D.Outsource customer-facing IT support to a third party.
AnswerB

Low employee engagement drives the customer satisfaction decline, so training and development addresses the learning and growth weakness that ultimately feeds the customer perspective. Fixing the root cause is preferable to treating the lagging satisfaction symptom.

Why this answer

The BSC's learning and growth perspective is the foundational driver of the other three perspectives — low employee engagement directly undermines process quality, customer satisfaction, and ultimately financial outcomes. Since customer satisfaction is already declining and the root cause traces to employee engagement, the governance committee should prioritize investing in training and development to fix the upstream cause. This aligns with the BSC's cause-and-effect logic where learning and growth improvements cascade into customer and financial results.

Exam trap

CISA often tests whether candidates chase the symptom (customer satisfaction) with a direct fix rather than addressing the upstream BSC perspective (learning and growth) that the data identifies as the root cause — the trap is picking the option that 'sounds responsive' instead of the one the scorecard logic dictates.

How to eliminate wrong answers

Option A is wrong because cutting costs further ignores the identified root cause (low engagement) and risks worsening customer satisfaction by starving the IT function of resources. Option C is wrong because simply increasing budget to hire more staff does not address the engagement problem — more disengaged staff does not improve customer outcomes and may increase costs without benefit. Option D is wrong because outsourcing customer-facing support is a tactical workaround that does not fix the internal learning and growth deficiency and often degrades customer satisfaction further due to loss of institutional knowledge.

50
MCQhard

An organization's IT strategy is developed by the IT department without input from business stakeholders. Which of the following is the MOST significant risk?

A.Technology may become obsolete quickly.
B.IT projects may exceed budget.
C.IT staff may lack required skills.
D.IT strategy may not support business objectives.
AnswerD

Without business stakeholder input, the IT strategy is shaped by technical priorities alone, so it can diverge from what the organisation actually needs to achieve. The stem's constraint — strategy developed in isolation — directly produces misalignment with business objectives, the most significant enterprise-wide risk.

Why this answer

An IT strategy developed in isolation from business stakeholders risks being misaligned with organizational goals, meaning IT investments may not deliver business value or support strategic objectives. This is the most significant risk because it undermines the entire purpose of IT governance—ensuring IT enables and extends business strategy. Other risks like obsolescence, budget overruns, or skill gaps are secondary symptoms that may result from misalignment.

Exam trap

CISA often tests the distinction between strategic risks (misalignment with business objectives) and operational risks (budget, skills, obsolescence); candidates frequently pick a tangible operational issue when the question asks for the MOST significant strategic risk.

How to eliminate wrong answers

Option A is wrong because technology obsolescence is a tactical/technical risk that can be managed through lifecycle planning and is not the primary consequence of excluding business stakeholders. Option B is wrong because budget overruns are a project management concern that can occur even with perfect business alignment and is not the most significant strategic risk. Option C is wrong because skill gaps are an operational HR/training issue that does not directly stem from the lack of business input in strategy development.

51
MCQeasy

A medium-sized manufacturing company has a decentralized IT structure where each business unit manages its own IT budget and projects. The CEO is concerned that IT investments are not aligned with corporate strategy and that there is duplication of effort. The IT department lacks a formal project portfolio management process. The company has experienced several project failures due to poor prioritization. The CEO has asked the newly hired IT auditor to recommend an initial step to improve IT governance. The auditor should recommend:

A.Establishing an IT steering committee with representatives from business units and IT
B.Implementing a project portfolio management software tool immediately to track all projects
C.Conducting a security risk assessment of all IT systems
D.Outsourcing IT management to a third-party provider
AnswerA

A steering committee directly addresses the stem's constraint: no formal portfolio process across decentralised units. It creates a cross-functional forum that prioritises and aligns IT investments with corporate strategy, resolving duplication and poor prioritisation before any tooling or policy is introduced.

Why this answer

An IT steering committee provides governance oversight, ensures alignment with corporate strategy, and helps prioritize projects to avoid duplication. This foundational step addresses the root cause of poor alignment and project failures before implementing tools or processes. Option B is premature because a tool without governance oversight may not improve prioritization.

Option C focuses on security, not overall strategic alignment. Option D is drastic and does not address internal governance issues.

52
MCQhard

An organization has implemented a new IT service management (ITSM) tool. The IT manager wants to measure the effectiveness of incident management. Which metric is MOST appropriate?

A.Mean time to resolve (MTTR) incidents
B.Percentage of incidents resolved on first call
C.Number of incidents reported per month
D.Percentage of system uptime
AnswerA

MTTR directly quantifies how quickly incidents are resolved, which is the core effectiveness measure for incident management. It satisfies the stem's requirement to gauge the ITSM process's performance by tracking elapsed time from incident logging to restoration of normal service.

Why this answer

Mean time to resolve (MTTR) is the most appropriate metric for measuring the effectiveness of incident management because it directly reflects how quickly the IT team can restore normal service operation after an incident. In ITIL-based ITSM tools, MTTR tracks the elapsed time from incident logging to resolution, providing a clear indicator of process efficiency and team responsiveness.

Exam trap

The trap here is that candidates often confuse incident management metrics with service desk or availability metrics, picking 'percentage of incidents resolved on first call' because it sounds like a measure of effectiveness, but it actually measures first-contact resolution efficiency, not the end-to-end incident management process.

How to eliminate wrong answers

Option B is wrong because the percentage of incidents resolved on first call measures first-level support efficiency, not the overall effectiveness of the incident management process, which includes escalation and resolution workflows. Option C is wrong because the number of incidents reported per month is a volume metric that indicates incident frequency, not the quality or speed of resolution. Option D is wrong because system uptime is a metric for availability management, not incident management; it measures service reliability rather than how incidents are handled.

53
MCQmedium

A financial services firm has a mature IT governance framework. The IS auditor is reviewing the IT governance structure and notices that the IT steering committee meets quarterly and focuses primarily on project approvals. Which of the following is the MOST significant concern regarding this committee's effectiveness?

A.The committee's scope is too narrow to provide comprehensive IT governance oversight.
B.Project approvals should be delegated to the project management office.
C.Quarterly meetings are too infrequent to approve projects in a timely manner.
D.The committee lacks representation from business unit leaders.
AnswerA

An IT steering committee should oversee a broad range of IT governance matters, including strategic alignment, risk management, resource allocation, and performance monitoring. Focusing primarily on project approvals limits its ability to address other critical governance areas. This narrow scope can lead to unmanaged risks, misalignment with business strategy, and missed opportunities for value creation. The committee's effectiveness is significantly compromised if it does not cover the full spectrum of IT governance responsibilities.

Why this answer

The most significant concern is that the IT steering committee's scope is too narrow, focusing only on project approvals. Effective IT governance requires oversight of strategic alignment, risk management, resource allocation, and performance. A committee that limits itself to project approvals fails to address these critical areas, leaving the organization exposed to unmanaged risks and misaligned IT investments.

Broadening the committee's mandate is essential for effective governance.

Exam trap

The trap here is focusing on meeting frequency or representation as the primary issue, when the real problem is the committee's limited scope of responsibilities.

54
MCQeasy

An organization is implementing a new IT governance framework. Which of the following is the PRIMARY benefit of using a framework like COBIT?

A.Reducing IT operational costs.
B.Aligning IT strategy with business goals.
C.Eliminating all IT-related risks.
D.Ensuring compliance with all regulatory requirements.
AnswerB

COBIT provides a structured governance model linking IT activities, resources and performance measurement directly to enterprise objectives. This alignment ensures IT investments and controls demonstrably support business strategy, which is the framework's primary governance benefit rather than mere compliance or cost reduction.

Why this answer

COBIT is designed to bridge the gap between business objectives and IT operations by providing a framework that maps IT processes to business goals. The primary benefit is ensuring that IT strategy directly supports and enables business strategy, rather than focusing on cost reduction or risk elimination.

Exam trap

The trap here is that candidates often confuse the primary benefit of a governance framework (strategic alignment) with secondary benefits like cost reduction or compliance, leading them to pick a plausible but incorrect answer that addresses a tactical outcome rather than the core strategic purpose.

How to eliminate wrong answers

Option A is wrong because reducing IT operational costs is a possible outcome of good governance but not the primary purpose of COBIT; cost reduction is more directly addressed by frameworks like ITIL or specific cost-optimization practices. Option C is wrong because no framework can eliminate all IT-related risks; risk management aims to reduce risk to an acceptable level, not achieve zero risk. Option D is wrong because ensuring compliance with all regulatory requirements is an objective of governance but not the primary benefit of COBIT; compliance is one component of a broader alignment goal, and no framework can guarantee compliance with every regulation.

55
MCQhard

You are the IT governance lead at a multinational corporation with a complex IT environment spanning multiple business units. The company has recently experienced a series of minor security incidents where unauthorized access was gained through unused user accounts that were not disabled after employees left the organization. Additionally, there have been delays in provisioning access for new hires, leading to productivity losses. The IT department currently uses a manual process for access management, with each business unit maintaining its own user lists. The company has a policy that requires access reviews every quarter, but these are often missed or performed superficially. The CIO has asked you to recommend a solution that addresses these issues while ensuring compliance with regulations such as GDPR and SOX. Which of the following is the BEST course of action?

A.Require each business unit to submit monthly reports of active users to IT, which will then manually disable accounts not on the list.
B.Develop a new policy that mandates quarterly access reviews and disciplinary action for non-compliance.
C.Increase the frequency of access reviews to monthly and assign a dedicated team to perform them.
D.Implement an identity governance and administration (IGA) tool that automates user provisioning and de-provisioning, integrates with HR systems, and enforces access reviews.
AnswerD

Automated provisioning and de-provisioning tied to HR system feeds directly eliminates the orphaned accounts and provisioning delays described, while scheduled access reviews enforce the quarterly policy and produce the audit evidence GDPR and SOX demand.

Why this answer

Implementing an Identity Governance and Administration (IGA) tool directly addresses the root causes: manual, decentralized access management and lack of automated de-provisioning. IGA integrates with HR systems (e.g., Workday, SAP SuccessFactors) to trigger automatic account creation for new hires and immediate deactivation upon termination, eliminating orphaned accounts. It also enforces scheduled, auditable access reviews with certification workflows, ensuring compliance with GDPR (right to erasure, data minimization) and SOX (segregation of duties, access controls).

This automated approach resolves both the security incidents from unused accounts and the productivity losses from delayed provisioning.

Exam trap

The trap here is that candidates often choose options that increase manual oversight (like monthly reports or dedicated teams) because they seem practical, but the CISA exam emphasizes automated, integrated solutions (IGA) as the only sustainable way to achieve compliance and security at scale in complex, multi-unit environments.

How to eliminate wrong answers

Option A is wrong because it perpetuates the manual, error-prone process by relying on business units to submit reports and IT to manually disable accounts, which does not scale, introduces latency, and fails to prevent orphaned accounts between reporting cycles. Option B is wrong because developing a new policy without automated enforcement tools does not address the root cause of missed or superficial reviews; it merely adds another layer of documentation that is likely to be ignored without technical controls. Option C is wrong because increasing review frequency and assigning a dedicated team still relies on manual processes, which are costly, prone to human error, and cannot guarantee timely de-provisioning or integration with HR lifecycle events.

56
MCQmedium

An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. What is the committee's MOST important role?

A.Approving technical specifications
B.Selecting the vendor
C.Ensuring alignment with business objectives
D.Managing the project budget
AnswerC

The steering committee's primary function is to ensure proposed IT investments align with and support business objectives, prioritising them accordingly. Confirming that the CRM system delivers strategic business value, rather than assessing technical detail, is its most important role.

Why this answer

An IT steering committee is a governance body whose primary function is to ensure that IT investments and projects align with the organization's strategic business objectives. It prioritizes, funds, and monitors initiatives at a portfolio level, so its most important role is strategic alignment rather than tactical execution. Technical specifications, vendor selection, and day-to-day budget management are delegated to project teams and IT management.

Exam trap

CISA often tests the confusion between governance and management roles — candidates pick a hands-on activity like vendor selection or budget management when the question asks about the steering committee's strategic purpose.

How to eliminate wrong answers

Option A is wrong because approving technical specifications is an architecture or engineering responsibility, not a governance committee's role — the committee sets direction, not design. Option B is wrong because vendor selection is typically delegated to procurement and the project team against criteria the committee approves, not performed by the committee itself. Option D is wrong because managing the project budget is the project manager's operational responsibility; the committee approves funding and monitors outcomes, but does not manage the budget line by line.

57
MCQeasy

An IT manager needs to ensure that the organization's IT resources are used efficiently. Which of the following is the BEST metric to measure IT resource utilization?

A.System uptime percentage
B.Average server CPU utilization
C.Number of help desk tickets resolved per day
D.Percentage of projects completed on time
AnswerB

Average server CPU utilisation directly quantifies how much processing capacity is consumed versus available, giving a concrete efficiency measure of IT resource usage. It satisfies the manager's need to measure utilisation, unlike metrics such as incident counts or uptime that reflect availability rather than efficiency.

Why this answer

Average server CPU utilization directly measures how much of the computing capacity is being consumed over time, making it the most relevant metric for assessing whether IT resources are being used efficiently. High or low CPU utilization can indicate over-provisioning, under-utilization, or potential performance bottlenecks, enabling the IT manager to optimize resource allocation.

Exam trap

The trap here is that candidates often confuse availability metrics (uptime) with utilization metrics, or they mistakenly equate operational outputs (tickets resolved, project completion) with resource efficiency, leading them to pick a superficially plausible but incorrect answer.

How to eliminate wrong answers

Option A is wrong because system uptime percentage measures availability, not utilization; a server can be up 99.999% of the time but idle, wasting resources. Option C is wrong because the number of help desk tickets resolved per day measures service desk productivity and incident handling efficiency, not the utilization of IT resources like servers or storage. Option D is wrong because the percentage of projects completed on time measures project management performance and schedule adherence, not the operational efficiency of IT resource usage.

58
MCQeasy

An organization has a policy requiring annual information security awareness training for all employees. During a recent audit, it was found that 20% of employees had not completed the training. What is the BEST course of action for the IT governance committee?

A.Reduce the training frequency to biennial.
B.Require managers to ensure their teams complete training and escalate non-compliance to HR.
C.Extend the training deadline by three months.
D.Make the training optional for employees with high performance ratings.
AnswerB

Line managers own their teams' compliance, so requiring them to enforce completion and escalating persistent non-compliance to HR applies accountability and consequence. This addresses the 20% gap through existing governance structures rather than ad hoc reminders or policy rewrites.

Why this answer

The governance committee's role is to ensure policy compliance through accountability mechanisms. Requiring managers to enforce completion and escalating non-compliance to HR reinforces the policy's mandatory nature and creates consequences for non-compliance, which is the most effective way to achieve sustained compliance. This addresses the root cause—lack of enforcement—rather than weakening the policy.

Exam trap

CISA often tests the difference between treating the symptom (extending deadlines, reducing frequency) and addressing the root cause (lack of accountability); candidates may pick a lenient option that weakens the control instead of enforcing it.

How to eliminate wrong answers

Option A is wrong because reducing training frequency weakens the security posture and does not address the non-compliance; it simply lowers the bar to make numbers look better. Option C is wrong because extending the deadline is a temporary fix that does not create accountability and may result in continued non-compliance. Option D is wrong because making training optional for high performers creates a double standard, undermines the policy, and leaves the organization exposed to insider threats regardless of performance ratings.

59
MCQmedium

A company outsources its data center operations to a third-party provider. Which of the following is the MOST important control to include in the outsourcing contract?

A.Detailed escalation procedures for incidents
B.Service level agreements with financial penalties
C.Requirements for encryption of data at rest
D.Right to audit the provider's facilities and processes
AnswerD

The right to audit gives the company contractual authority to inspect the provider's facilities and processes, verifying that outsourced controls operate effectively. Without it, the organisation cannot independently confirm compliance or security, so this clause is the most critical control to embed in the outsourcing contract.

Why this answer

The right to audit the provider's facilities and processes is the most important control because it ensures the outsourcing company can verify that the provider is complying with security, regulatory, and contractual requirements. Without audit rights, the company has no independent means to confirm that controls are effective, leaving it exposed to undetected risks.

Exam trap

CISA often tests the difference between assurance and operational controls. Candidates might choose SLAs or encryption because they sound important, but the right to audit is the governance mechanism that provides ongoing assurance.

How to eliminate wrong answers

Option A is wrong because escalation procedures are operational and do not provide assurance over the provider's controls. Option B is wrong because SLAs with penalties address performance but not compliance or security verification. Option C is wrong because encryption is a specific technical control, but it is only one aspect and does not guarantee overall compliance; audit rights are broader and more fundamental.

60
MCQmedium

A financial services company is migrating its core banking system to a public cloud to improve scalability and reduce costs. The project is high-risk due to regulatory compliance requirements (e.g., data residency, audit trails). The IT governance committee has reviewed the project plan and finds that the risk assessment is incomplete – it does not address the potential impact of a cloud provider outage on critical transactions. The committee must approve the project or request changes. The project manager argues that the cloud provider's SLA guarantees 99.99% uptime and that additional controls would delay the project. What should the governance committee do?

A.Reject the project and require the system to remain on-premises.
B.Request a revised risk assessment that includes contingency plans for provider outages.
C.Approve the project based on the provider's strong SLA.
D.Approve a pilot migration for non-critical systems first.
AnswerB

The SLA covers provider uptime, not the bank's regulatory obligation to plan for outage impact on critical transactions. Requesting contingency planning in the risk assessment satisfies the incomplete-assessment constraint before approval, rather than accepting the SLA as sufficient mitigation.

Why this answer

The governance committee's role is to ensure that risks are identified, assessed, and mitigated before approving a high-risk project. An incomplete risk assessment that ignores the impact of a cloud provider outage on critical banking transactions is a material gap. Requesting a revised risk assessment with contingency plans directly addresses this gap while allowing the project to proceed responsibly.

This aligns with CISA's emphasis on risk-based decision-making and IT governance.

Exam trap

CISA often tests the misconception that a strong SLA eliminates the need for contingency planning, but governance requires assessing residual risk and ensuring business continuity even with contractual guarantees.

How to eliminate wrong answers

Option A is wrong because rejecting the project outright is an overreaction; the committee should first ensure risks are properly assessed and mitigated, not abandon the cloud strategy. Option C is wrong because an SLA is a contractual commitment, not a guarantee of uninterrupted service; it does not eliminate the need for contingency planning, and 99.99% uptime still allows for downtime that could impact critical transactions. Option D is wrong because a pilot for non-critical systems does not address the core deficiency—the lack of a risk assessment for critical transactions—and could delay necessary risk mitigation for the full migration.

61
MCQhard

Based on the exhibit, which control is most likely missing to prevent this type of event?

A.Applying the latest security patches to the SSH service
B.Implementing account lockout after three failed attempts
C.Disabling direct root login via SSH
D.Enforcing strong password complexity
AnswerB

Account lockout after three failed attempts blocks continued password guessing against the same account, directly preventing the brute-force authentication event shown. This satisfies the control gap by throttling repeated failures rather than merely logging or alerting on them.

Why this answer

The exhibit describes a brute-force attack against an SSH service, where an attacker repeatedly attempts to guess credentials. Implementing account lockout after three failed attempts is the most direct control to prevent this type of event, as it halts further login attempts after a threshold, stopping the attack in its tracks regardless of password strength or patching.

Exam trap

The trap here is that candidates often choose 'Disabling direct root login via SSH' (Option C) because it is a well-known security best practice, but it does not prevent brute-force attacks against other user accounts, whereas account lockout directly stops the attack mechanism.

How to eliminate wrong answers

Option A is wrong because applying the latest security patches to the SSH service addresses vulnerabilities in the SSH protocol or implementation, but does not prevent brute-force attacks that exploit weak or guessed credentials. Option C is wrong because disabling direct root login via SSH reduces the attack surface by requiring a non-root account first, but it does not prevent brute-force attacks against any user account; the attacker can still target other usernames. Option D is wrong because enforcing strong password complexity makes passwords harder to guess, but it does not stop an attacker from making unlimited attempts; a brute-force attack can still succeed over time if no lockout mechanism is in place.

62
MCQeasy

Based on the exhibit, what is the MOST appropriate action for IT management?

A.Investigate the reasons for the shortfall and implement corrective actions.
B.Ignore the variance as it is within acceptable range.
C.Adjust the target to 80% to match actual performance.
D.Replace the survey with a different measurement tool.
AnswerA

A shortfall against the exhibit's planned targets signals a control or performance gap, so management must first establish root cause before committing resources. Investigating the reasons and implementing corrective actions satisfies the stem's demand for the most appropriate management response, closing the gap rather than merely reporting it.

Why this answer

When a performance metric shows a significant shortfall against its target, IT management's most appropriate action is to investigate the root cause and implement corrective actions. This aligns with continuous improvement and governance principles rather than adjusting targets or ignoring the gap.

Exam trap

CISA often tests whether candidates choose the 'investigate and correct' answer over 'adjust the target' — the latter sounds pragmatic but is a classic governance anti-pattern that auditors flag as metric manipulation.

How to eliminate wrong answers

Option B is wrong because ignoring the variance assumes it is acceptable without evidence; a shortfall against target should be investigated, not dismissed. Option C is wrong because lowering the target to match actual performance is 'gaming the metric' and undermines the purpose of the measurement — it hides the problem instead of fixing it. Option D is wrong because replacing the measurement tool is premature and does not address the underlying performance gap; the tool may be perfectly valid.

63
MCQeasy

An organization's IT department has grown rapidly, and the CIO wants to ensure that employees understand expected behaviors when handling sensitive data and operating critical systems. Which of the following is the MOST appropriate governance mechanism to establish?

A.A service level agreement with the infrastructure hosting provider.
B.A documented IT code of conduct, acknowledged by staff, supported by periodic awareness training.
C.An annual penetration test of systems that store sensitive data.
D.A technical control that blocks access to sensitive data outside business hours.
AnswerB

A code of conduct translates governance expectations into explicit behavioral requirements, and acknowledgment plus recurring training makes those expectations enforceable and current. This combination addresses both awareness and accountability for sensitive data handling and critical system operations. It is a foundational governance mechanism that scales as the department grows and new staff join, unlike one-off or purely technical measures.

Why this answer

The CIO's objective is behavioral: staff must understand and follow expected practices for sensitive data and critical systems. A code of conduct with acknowledgment and recurring awareness training establishes those expectations, makes them explicit, and refreshes them as the organization grows. Technical restrictions, penetration tests, and vendor agreements address other risk areas and do not create or reinforce employee accountability for conduct.

Exam trap

The trap here is selecting a technical or assurance control when the objective is to establish and reinforce expected workforce behavior.

64
MCQhard

An organization's IT strategy is not aligned with business strategy due to lack of communication. Which of the following would BEST improve alignment?

A.Business-IT strategy mapping workshops
B.Weekly IT status reports
C.Outsourcing non-core IT functions
D.IT budget increase
AnswerA

Misalignment stems from business and IT holding different assumptions, so structured mapping workshops force both groups to articulate objectives, capabilities and dependencies in one forum. That shared translation of business goals into IT services directly repairs the communication gap the stem identifies.

Why this answer

Business-IT strategy mapping workshops bring business and IT stakeholders together to explicitly map IT initiatives to business goals, which directly addresses the lack of communication and misalignment. This collaborative exercise creates shared understanding and a documented linkage between IT investments and business outcomes, which is the most effective way to improve alignment. It is a governance and communication mechanism, not just a reporting or budgeting action.

Exam trap

CISA often tests the difference between communication (reports) and alignment (joint strategy mapping) — candidates who pick 'weekly status reports' mistake information flow for strategic alignment.

How to eliminate wrong answers

Option B is wrong because weekly IT status reports are one-way communication that informs but does not create alignment — they do not involve business stakeholders in strategy mapping. Option C is wrong because outsourcing non-core IT functions may reduce cost or focus but does not improve strategic alignment between IT and business. Option D is wrong because increasing the IT budget without addressing communication and governance does not align IT with business strategy — it may even increase misalignment if spent on the wrong priorities.

65
MCQmedium

An organization has decided to adopt a formal IT governance framework to improve alignment between IT and business objectives. Management asks the IS auditor to advise on the FIRST step in the adoption process. Which of the following should the IS auditor recommend?

A.Perform a gap assessment comparing current IT governance practices with the framework's control objectives.
B.Purchase and deploy a governance, risk, and compliance tool to automate control monitoring.
C.Benchmark the organization's IT spending ratio against industry peers.
D.Appoint a chief information security officer to own the governance initiative.
AnswerA

Adopting a framework begins with understanding the current state so that implementation effort is directed where it is needed. A gap assessment maps existing practices against the framework's control objectives and identifies what is missing, redundant, or misaligned. This evidence-based starting point prevents the organization from implementing controls it already has or overlooking critical deficiencies, and it produces the baseline needed for prioritization and later progress measurement.

Why this answer

Framework adoption follows a logical sequence: understand the current state, identify gaps against the target control objectives, prioritize remediation, then implement and monitor. A gap assessment produces the baseline that makes every later decision informed, from tool selection to ownership to investment prioritization. Tooling, role appointments, and peer benchmarking are either premature or too narrow to serve as the starting point.

Exam trap

The trap here is equating the start of governance adoption with acquiring a tool or naming an owner, rather than establishing an evidence-based current-state baseline.

66
MCQhard

A multinational corporation operates in a highly regulated industry. The IT governance framework includes a risk appetite statement approved by the board. Recently, the company suffered a significant data breach due to an unpatched vulnerability that had been identified three months earlier. The IT audit found that the vulnerability was reported to the IT department but was not prioritized for remediation because it was deemed low risk by the IT operations team. The incident response plan was not activated because the breach was not initially detected. The board wants to strengthen governance to prevent recurrence. The most effective course of action for the auditor to recommend is:

A.Deploying an intrusion detection system to identify breaches sooner
B.Establishing a formal vulnerability management policy that requires risk-based prioritization in accordance with the risk appetite and escalation to the IT risk committee for decisions outside tolerance
C.Disciplining the IT operations team for not escalating the vulnerability
D.Implementing a more robust patch management system with automated patching
AnswerB

A risk-based vulnerability management policy directly ties remediation priority to the board-approved risk appetite, closing the gap where IT operations unilaterally downgraded a known vulnerability. Mandatory escalation to the IT risk committee for items exceeding tolerance ensures governance oversight, preventing recurrence of undetected, unactioned exposures.

Why this answer

The root cause is a governance failure: the IT operations team made a risk-acceptance decision that exceeded its authority, without a formal process tying vulnerability prioritization to the board-approved risk appetite. A vulnerability management policy that mandates risk-based prioritization aligned with the risk appetite and requires escalation to the IT risk committee when findings fall outside tolerance directly addresses this governance gap. This is the most effective recommendation because it fixes the decision-making framework, not just the symptom.

Exam trap

CISA often tests the distinction between technical controls (patching, IDS) and governance controls (policy, escalation, risk appetite alignment); candidates frequently pick the technical fix when the scenario describes a governance failure.

How to eliminate wrong answers

Option A is wrong because an IDS improves detection but does not fix the prioritization and escalation failure that allowed the unpatched vulnerability to remain unaddressed. Option C is wrong because disciplining staff is a reactive, punitive measure that does not establish the governance controls needed to prevent recurrence. Option D is wrong because automated patching is a technical control that still requires a policy defining what gets patched, when, and by whose authority — without that policy, the same misprioritization can recur.

67
MCQeasy

An IT manager submits a request to change the firewall configuration during business hours. According to best practices for change management, what should be done FIRST?

A.Obtain approval from the change advisory board
B.Notify all users of the planned change
C.Assess the impact and risk of the proposed change
D.Implement the change immediately to address an urgent threat
AnswerC

Assessing impact and risk first determines the change's potential disruption, security implications and dependencies before any decision or scheduling occurs. This satisfies change management best practise by ensuring informed approval, rather than proceeding directly to implementation during business hours.

Why this answer

Best-practice change management requires assessing the impact and risk of a proposed change before seeking approval or implementation. This assessment informs the change advisory board (CAB) decision and determines the appropriate approval path, rollback plan, and testing requirements. Without a risk assessment, approval would be uninformed and potentially unsafe.

Exam trap

CISA often tests the sequencing of change management steps — the trap is selecting 'obtain CAB approval' first, when the correct first step is assessing impact and risk to inform that approval.

How to eliminate wrong answers

Option A is wrong because CAB approval should follow the risk assessment — approving before assessing risk inverts the process and leads to uninformed decisions. Option B is wrong because user notification comes after approval and scheduling, not as the first step; notifying users before the change is even assessed or approved is premature. Option D is wrong because implementing immediately bypasses change management controls entirely, even for urgent threats; emergency changes still require expedited assessment and approval (e.g., emergency CAB).

68
MCQmedium

An organization's IT department implemented a new change management process that requires all changes to be approved by a change advisory board (CAB). A critical security patch needs to be deployed within 2 hours to address an active zero-day vulnerability. The change request was submitted but the CAB is not scheduled to meet for another 24 hours. What is the BEST course of action?

A.Deploy the patch and inform the CAB after the fact during the next meeting.
B.Wait for the next scheduled CAB meeting to approve the change.
C.Deploy the patch immediately without any approval as it is a critical security fix.
D.Use the emergency change process to obtain expedited approval from a designated CAB member.
AnswerD

The emergency change process exists precisely for time-critical situations such as an active zero-day, allowing a designated CAB member to grant expedited approval without convening the full board. This satisfies the two-hour deployment constraint while preserving change governance and auditability, unlike bypassing approval entirely or waiting 24 hours for the scheduled CAB meeting.

Why this answer

It aligns with the ITIL-based emergency change process, which allows for expedited approval from a designated CAB member or emergency authority when a critical security patch must be deployed within hours to mitigate an active zero-day vulnerability. This ensures the change is authorized without waiting for the full CAB meeting, maintaining security while preserving governance and audit trails.

Exam trap

The trap here is that candidates may assume any critical security patch can be deployed immediately without approval (Option C) or that informing the CAB after the fact (Option A) is acceptable, but CISA emphasizes that even emergency changes must follow a defined process with expedited approval to maintain control and accountability.

How to eliminate wrong answers

Option A is wrong because deploying the patch without prior approval violates the change management policy and could lead to unauthorized changes, lack of audit trail, and potential conflicts with other changes. Option B is wrong because waiting 24 hours for the next CAB meeting would leave the system exposed to the active zero-day vulnerability, increasing risk of exploitation. Option C is wrong because deploying without any approval bypasses all governance controls, ignoring the need for documented authorization even for emergency fixes, and could cause operational disruptions without coordination.

69
MCQeasy

Which of the following is the PRIMARY purpose of an IT governance framework?

A.To ensure IT aligns with and supports business strategy
B.To ensure compliance with laws and regulations
C.To protect IT assets from cyber threats
D.To reduce IT operational costs
AnswerA

An IT governance framework directs decision rights and accountability so technology investments, risk appetite and resource allocation all serve organisational objectives. This satisfies the stem's demand for the primary purpose: alignment of IT with business strategy, rather than operational controls, cost reduction or compliance reporting, which are secondary outcomes.

Why this answer

The primary purpose of an IT governance framework is to ensure that IT investments, strategies, and operations are aligned with and support the overall business strategy, enabling the organization to achieve its goals. This alignment is achieved through mechanisms such as strategic planning, portfolio management, and performance measurement, which are core to frameworks like COBIT 2019. Without this alignment, IT may operate in isolation, leading to wasted resources and missed business opportunities.

Exam trap

The trap here is that candidates often confuse the primary purpose of IT governance with operational or security objectives, such as compliance or cost reduction, because those are more tangible and frequently tested in other domains, but the CISA exam emphasizes that governance is fundamentally about strategic alignment and value delivery.

How to eliminate wrong answers

Option B is wrong because ensuring compliance with laws and regulations is a secondary objective of IT governance, not the primary purpose; compliance is typically addressed through specific controls and policies within the framework, but the framework's overarching goal is strategic alignment. Option C is wrong because protecting IT assets from cyber threats is a function of information security management and risk management, which are components of governance but not its primary purpose; governance focuses on direction and oversight, not operational security. Option D is wrong because reducing IT operational costs is a potential outcome of effective governance, but it is not the primary purpose; cost reduction is a tactical benefit, whereas governance is fundamentally about value creation and strategic alignment.

70
MCQmedium

An IS auditor is reviewing the IT governance framework of a financial services firm. The auditor notes that the IT strategy is updated annually, but there is no process to monitor whether IT initiatives are aligned with the strategy. Which of the following is the BEST recommendation?

A.Delegate IT strategy oversight to the IT steering committee.
B.Increase the frequency of IT strategy updates to quarterly.
C.Conduct an annual external audit of IT projects.
D.Implement a balanced scorecard to track IT performance against strategic objectives.
AnswerD

A balanced scorecard translates strategic objectives into measurable metrics across financial, customer, internal process, and learning perspectives. It provides a mechanism to monitor alignment of IT initiatives with the strategy on an ongoing basis. This directly addresses the gap of no monitoring process. Other options may be useful but do not provide the comprehensive, strategic alignment focus that a balanced scorecard offers.

Why this answer

The best recommendation is to implement a balanced scorecard to track IT performance against strategic objectives. This provides a structured, ongoing method to monitor whether IT initiatives are aligned with the IT strategy. It enables management to measure progress, identify deviations, and take corrective action.

The other options either address symptoms, provide only periodic assurance, or lack a specific monitoring mechanism, making them less effective in closing the governance gap.

Exam trap

The trap here is assuming that more frequent strategy updates or delegation alone will ensure alignment, when the real need is a systematic monitoring process.

71
Multi-Selecthard

An IS auditor is assessing the effectiveness of an organization's IT governance implementation. Which TWO of the following are the MOST important indicators that IT governance is effectively implemented? (Choose two.)

Select 2 answers
A.IT performance is regularly monitored and reported to the board.
B.All IT projects are completed on time and within budget.
C.The IT department has a low employee turnover rate.
D.The IT steering committee meets at least quarterly.
E.IT decisions are made in alignment with business strategy and priorities.
AnswersA, E

Regular monitoring and reporting to the board ensure accountability and transparency. It indicates that governance processes are in place to track IT performance against strategic goals and that the board is engaged in oversight. This is a critical indicator because without reporting, governance cannot be effective; the board must have visibility to make informed decisions and hold management accountable.

Why this answer

Effective IT governance is demonstrated when IT decisions align with business strategy and when IT performance is regularly monitored and reported to the board. These indicators show that governance mechanisms are actively guiding IT to deliver value and manage risks, and that there is accountability at the highest level. Other options are either operational metrics or structural elements that do not directly prove governance effectiveness.

Exam trap

The trap here is confusing operational efficiency metrics like project timeliness or meeting frequency with true indicators of governance effectiveness, which focus on alignment and accountability.

72
MCQeasy

Which of the following is the PRIMARY purpose of an IT strategy committee?

A.To monitor IT project timelines
B.To manage IT vendor contracts
C.To approve IT project budgets
D.To ensure IT investments support business objectives
AnswerD

The IT strategy committee exists to align technology direction with enterprise goals, reviewing and directing IT investments so they deliver business value. The stem asks for its primary purpose, which is ensuring those investments support business objectives rather than merely overseeing technical operations.

Why this answer

The primary purpose of an IT strategy committee is to ensure that IT investments and initiatives are aligned with and support the organization's business objectives. This governance body provides strategic direction, prioritizes IT investments, and ensures IT delivers business value rather than just managing operational tasks.

Exam trap

CISA often tests the confusion between strategic governance (business-IT alignment) and tactical/operational responsibilities (timelines, contracts, budgets), so candidates pick a concrete-sounding operational task over the strategic purpose.

How to eliminate wrong answers

Option A is wrong because monitoring project timelines is a tactical project management function, not the strategic purpose of an IT strategy committee. Option B is wrong because managing vendor contracts is a procurement/operational responsibility, not the committee's primary strategic role. Option C is wrong because approving individual project budgets is a financial control activity that supports, but is not the primary purpose of, the strategy committee — the committee focuses on alignment with business strategy.

73
MCQmedium

An IS auditor is reviewing an organization's IT governance structure and finds that the IT steering committee meets quarterly but has no defined charter or decision-making authority. Which of the following is the MOST significant risk arising from this situation?

A.The committee may lack the technical expertise to evaluate IT projects.
B.IT projects may experience delays due to infrequent meetings.
C.IT initiatives may not be aligned with business strategy due to unclear governance mandate.
D.The committee may exceed its budget due to lack of financial oversight.
AnswerC

Without a charter and authority, the committee cannot enforce alignment between IT investments and business goals. This is the most significant risk because governance structures exist to provide direction and oversight; their absence undermines strategic alignment, resource prioritization, and accountability. Other risks, while possible, are secondary to the fundamental failure of governance.

Why this answer

A steering committee without a formal charter and decision-making authority cannot fulfill its governance role. The most critical risk is that IT initiatives will not be aligned with business strategy because the committee lacks the mandate to prioritize and enforce alignment. This undermines the entire purpose of IT governance, making other operational risks secondary.

Exam trap

The trap here is focusing on operational symptoms like delays or budget overruns rather than the foundational governance deficiency of an undefined mandate.

74
MCQmedium

A retail company is merging with a competitor. The IT departments of both organizations have different IT governance structures: Company A uses a centralized model with strict change management, while Company B uses a decentralized model with autonomous business unit IT. The CIO has been tasked with integrating the IT functions post-merger. The board expects cost synergies and improved service levels. The integration team is facing resistance from Company B's business heads who fear loss of agility. The CIO needs to propose a governance model for the merged entity. Which approach would BEST meet the board's expectations while addressing resistance?

A.Keep both models separate and allow business units to choose their preferred model.
B.Adopt Company B's decentralized model to preserve agility.
C.Immediately impose Company A's centralized model across the merged entity.
D.Implement a phased integration with a transitional governance structure that includes representatives from both sides.
AnswerD

A phased transition with joint governance representatives balances the board's cost-synergy and service-level goals against Company B's agility concerns, giving business heads a voice during integration. This incremental approach reduces resistance while moving toward a unified, standardised governance model.

Why this answer

A phased integration with a transitional governance structure that includes representatives from both sides allows the merged entity to gradually converge governance models, manage change and resistance, and work toward cost synergies and improved service levels without immediately disrupting business operations. Option A is incorrect because keeping both models separate permanently fails to achieve the desired integration and synergies. Option B is incorrect because fully adopting the decentralized model may not deliver the cost synergies and centralized control expected by the board.

Option C is incorrect because immediately imposing a centralized model would likely cause strong resistance from Company B's business heads and disrupt agility, undermining the merger's success.

75
MCQhard

An organization has decentralized IT management with each business unit making its own technology decisions. Which of the following is the BEST way to maintain enterprise-wide governance?

A.Deploy a single enterprise resource planning (ERP) system across all units.
B.Require all IT projects to be approved by the corporate IT department.
C.Create a central IT budget that allocates funds to business units.
D.Establish an enterprise architecture review board with representatives from all business units.
AnswerD

An enterprise architecture review board with representatives from every business unit provides a cross-unit forum that reviews technology decisions against shared standards. This preserves enterprise-wide governance without removing the decentralised autonomy each unit currently exercises.

Why this answer

Establishing an enterprise architecture review board with representatives from all business units is the best way to maintain enterprise-wide governance in a decentralized IT management structure. This board provides a collaborative forum where business units can align their technology decisions with enterprise-wide standards and strategic goals, ensuring consistency and compliance without centralizing decision-making. It balances autonomy with governance by involving stakeholders from all units in the review and approval of architectural decisions.

Exam trap

CISA often tests governance models, and candidates may choose centralized approval or budgeting as the best way to maintain governance, but in a decentralized structure, a collaborative review board is more effective because it respects autonomy while ensuring alignment.

How to eliminate wrong answers

Option A is wrong because deploying a single ERP system across all units is a tactical solution that may not be feasible or desirable for all business units and does not address overall IT governance. Option B is wrong because requiring all IT projects to be approved by corporate IT centralizes decision-making, which contradicts the decentralized structure and may create bottlenecks. Option C is wrong because creating a central IT budget that allocates funds to business units gives corporate IT financial control but does not ensure architectural alignment or governance of technology decisions.

Page 1 of 2 · 121 questions totalNext →

Ready to test yourself?

Try a timed practice session using only It Governance Mgmt questions.