Courseiva

CISA · topic practice

Governance and Management of IT practice questions

This domain covers IT governance, risk management, and control frameworks for the CISA exam. It tests your ability to align IT with business strategy, evaluate risk, and ensure compliance. Expect scenario-based questions on policies, roles, and the audit of governance structures, not just definitions.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Governance and Management of IT

What the exam tests

What to know about Governance and Management of IT

You must be able to evaluate IT governance structures, order risk and backup steps, and apply change management controls. The single most important thing is knowing that governance is a board responsibility, not an IT function.

IT governance frameworks like COBIT and their components

Risk assessment steps and risk treatment options

Change management processes including CAB and emergency changes

Data backup procedures and recovery point objectives

Watch out for

Common Governance and Management of IT exam traps

  • ▸Assuming IT owns governance decisions when the board and executives are ultimately accountable.
  • ▸Confusing risk assessment order: identification, analysis, evaluation, and treatment must be sequential.
  • ▸Forgetting that emergency changes still require post-implementation review and documentation.

Practice set

Governance and Management of IT questions

20 questions · select your answer, then reveal the explanation

A company's IT governance policy requires that all critical systems have a documented business continuity plan (BCP). During an audit, an IT auditor finds that the BCP for a critical financial system has not been updated in three years. Which of the following is the BEST recommendation?

Which TWO of the following are key components of an IT governance framework?

Which TWO of the following are key responsibilities of an IT steering committee?

Match each COBIT 5 domain to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Evaluate, Direct, and Monitor

Align, Plan, and Organize

Build, Acquire, and Implement

Deliver, Service, and Support

Monitor, Evaluate, and Assess

Match each log type to its typical content.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

System and application events

User login attempts and access

Changes to sensitive data

System errors and failures

A small business lacks formal IT governance. What is the FIRST step to establish governance?

A financial institution is required by regulators to demonstrate that IT controls are effective. Which of the following provides the BEST evidence?

An organization is implementing IT governance based on COBIT. Which THREE of the following are enablers? (Select exactly three.)

Refer to the exhibit. Based on the governance status report, which component should be addressed as a priority?

Network Topology
|> show governance-status| Component | Status |

Refer to the exhibit. The organization is planning to achieve the target level. What is the MOST appropriate action?

Exhibit

> cobit process-capability EDM01
Process: EDM01 - Ensure Governance Framework Setting and Maintenance
Current Level: 3 (Established Process)
Target Level: 4 (Predictable Process)
Gap: 1

Refer to the exhibit. Which perspective shows the greatest deviation from target?

Exhibit

IT BSC Report Q1 2025:
- Financial: Actual 80% of plan (Target 90%)
- Customer: Satisfaction score 4.2/5 (Target 4.0)
- Internal Process: SLA compliance 95% (Target 99%)
- Learning & Growth: Training hours 120 (Target 150)

Which TWO of the following are key components of an IT governance framework?

An organization is adopting COBIT 2019. Which TWO of the following are components of the governance system?

Which of the following is a potential risk in this RACI matrix?

Exhibit

Refer to the exhibit.
The following is a RACI matrix for the change management process:
Activity: Change request approval
Responsible: Change Manager (R)
Accountable: IT Director (A)
Consulted: Business Process Owner (C)
Informed: IT Operations (I)

What is the MOST significant weakness in the planned remediation?

Exhibit

Refer to the exhibit.
The following is an excerpt from an IT control self-assessment report:
Control: Segregation of duties in system development
Finding: In 3 out of 10 projects, the same developer who wrote code also performed code review.
Risk: High
Planned Remediation: Implement automated code review tool by Q3.

According to COBIT 2019, which design factor is MOST critical for tailoring a governance system?

Based on the exhibit, which metric would be LEAST relevant to the 'Customer' perspective?

Exhibit

Refer to the exhibit.

IT Balanced Scorecard – Customer Perspective:
- Objective: Improve customer satisfaction
- Metrics:
  - Satisfaction Survey Score (target: >90%)
  - Complaint Resolution Time (target: <24 hours)
- Other perspectives: Internal Process, Learning & Growth, Financial

Based on the exhibit, what is the default retention period for data?

Exhibit

Refer to the exhibit.

{
  "policyName": "Data Retention",
  "retentionPeriodDays": 365,
  "enforcement": "automatic",
  "exceptions": [
    {
      "role": "Legal",
      "extendDays": 30
    }
  ]
}

An IS auditor is reviewing the balanced scorecard for IT. Which of the following metrics BEST aligns with the 'customer perspective'?

Which TWO of the following are key components of an IT governance framework? (Choose two.)

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Governance and Management of IT sessions

Start a Governance and Management of IT only practice session

Every question in these sessions is drawn from the Governance and Management of IT domain — nothing else.

Related practice questions

Related CISA topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CISA exam test about Governance and Management of IT?
You must be able to evaluate IT governance structures, order risk and backup steps, and apply change management controls. The single most important thing is knowing that governance is a board responsibility, not an IT function.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Governance and Management of IT questions in a focused session?
Yes — the session launcher on this page draws every question from the Governance and Management of IT domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CISA topics?
Use the topic links above to move to related areas, or go back to the CISA question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CISA exam covers. They are not copied from any real exam or dump site.