Courseiva

CCNA It Governance Mgmt Questions

46 of 121 questions · Page 2/2 · It Governance Mgmt topic · Answers revealed

76
MCQhard

An IS auditor is evaluating an organization's IT risk management process. The auditor finds that risk assessments are performed annually by the IT department alone, without input from business units. Which of the following is the MOST significant concern?

A.Risk assessments should be performed by an independent party to ensure objectivity.
B.The IT department may lack the expertise to assess all risks.
C.Annual risk assessments are insufficient; they should be performed continuously.
D.Risk assessments may not reflect business impact, leading to misaligned risk mitigation.
AnswerD

Without business unit input, risk assessments focus on technical vulnerabilities rather than business impact. This can result in mitigation efforts that do not address the most critical risks to the organization. The most significant concern is that risk management becomes an IT-centric exercise, failing to align with enterprise risk management, which requires a business-driven perspective.

Why this answer

The most significant concern is that risk assessments performed solely by IT may not reflect business impact. Effective IT risk management requires collaboration between IT and business units to ensure that risks are evaluated in terms of their potential effect on business objectives. Without this, mitigation efforts may be misdirected, and critical business risks may be overlooked.

Exam trap

The trap here is focusing on the frequency or independence of risk assessments rather than the critical need for business involvement to assess impact.

77
MCQhard

An organization outsources its data center operations. What is the BEST way to ensure the service provider's controls are effective?

A.Conduct periodic third-party audits
B.Rely on the provider's internal audit reports
C.Monitor service level agreements only
D.Require the provider to implement all organizational controls
AnswerA

Periodic third-party audits provide independent, objective verification that the outsourced provider's controls operate effectively, testing evidence rather than relying on self-reported assurances. This satisfies the stem's requirement to assure control effectiveness across an outsourced data centre.

Why this answer

Periodic third-party audits provide independent, objective assurance that the service provider's controls are designed and operating effectively. Unlike internal audit reports produced by the provider, third-party audits (e.g., SOC 2, ISO 27001 certification) are performed by an independent firm and give the outsourcing organization reliable evidence for governance and compliance purposes. This is the best way to verify control effectiveness because it removes the provider's self-assessment bias.

Exam trap

CISA often tests the misconception that a provider's internal audit reports or SLA monitoring are sufficient assurance; the trap is choosing a self-reported or performance-only measure instead of independent third-party audit evidence.

How to eliminate wrong answers

Option B is wrong because relying solely on the provider's internal audit reports introduces a conflict of interest—the provider audits itself, and the reports may be incomplete or biased. Option C is wrong because monitoring SLAs only measures service performance (uptime, response time) and does not assess the effectiveness of security or operational controls. Option D is wrong because requiring the provider to implement all organizational controls is impractical and may not be feasible given the provider's multi-tenant environment; it also does not verify that controls are working.

78
Multi-Selecthard

Which THREE of the following are responsibilities of the board of directors regarding IT governance? (Choose three.)

Select 3 answers
A.Designing network security architecture
B.Setting IT risk appetite
C.Reviewing IT performance
D.Implementing IT controls
E.Approving IT strategy
AnswersB, C, E

Setting IT risk appetite is a board-level governance duty: it defines how much technology risk the enterprise will accept in pursuit of objectives. Management then operates within that tolerance, giving the board the boundary against which IT risk decisions are escalated and measured.

Why this answer

Option B is correct because setting the IT risk appetite is a core board-level governance responsibility: the board defines how much risk the organization is willing to accept in pursuit of its objectives, which then guides management's risk decisions. Option C is correct because reviewing IT performance is a board oversight duty — the board monitors whether IT is delivering value, meeting objectives, and staying within risk tolerances, typically through metrics and reporting. Option E is correct because approving IT strategy is a fundamental board responsibility, ensuring IT initiatives align with and support the enterprise's overall business strategy and goals.

Options A and D are not board responsibilities: designing network security architecture (A) and implementing IT controls (D) are hands-on operational and technical tasks performed by IT management and staff, not by the board, which focuses on direction, oversight, and accountability rather than execution.

Exam trap

CISA often tests the distinction between governance and management responsibilities; candidates may incorrectly assign operational tasks like implementing controls or designing architecture to the board.

79
MCQmedium

An IS auditor is reviewing the governance structure of a large retail company. The board has delegated all IT oversight to the IT steering committee, which meets quarterly and focuses primarily on project prioritization. The auditor notes that the board receives no IT-related reports and does not review IT risks. Which of the following is the MOST significant governance concern?

A.There is no independent assurance over IT activities reported to the board.
B.The IT steering committee is too focused on project prioritization and ignores other IT domains.
C.The IT steering committee meets only quarterly, which is insufficient to address emerging IT risks.
D.The board has not retained ultimate responsibility for IT governance and oversight.
AnswerD

The board is ultimately accountable for IT governance, even when delegating to committees. By receiving no IT reports and not reviewing IT risks, the board has failed to exercise its oversight role. This is the most significant concern because it undermines the entire governance framework and can lead to unmanaged IT risks and misalignment with business strategy.

Why this answer

The board retains ultimate accountability for IT governance and must ensure oversight, even when delegating to committees. Without board-level reporting and risk review, the governance structure lacks direction and accountability, increasing the risk of IT failures and misalignment with business objectives. Other concerns, such as meeting frequency or committee focus, are secondary to this foundational failure.

Exam trap

The trap here is assuming that delegating IT oversight to a committee absolves the board of responsibility, when in fact the board must still provide direction and monitor IT risks.

80
MCQmedium

An organization is implementing a new IT governance framework. Which of the following is the BEST approach to ensure alignment between IT strategy and business goals?

A.Align IT budget with the previous year's business plan
B.Conduct annual IT strategy reviews independent of business cycles
C.Establish an IT steering committee with business representation
D.Delegate IT strategy to the CIO without business input
AnswerC

An IT steering committee with business representation provides the joint decision-making forum where IT strategy is shaped against business goals, satisfying the alignment requirement directly. It creates shared ownership and prioritisation rather than leaving strategy to IT alone.

Why this answer

An IT steering committee with business representation is the best approach because it creates a formal, ongoing governance mechanism where business and IT leaders jointly prioritize investments, review performance, and make strategic decisions. This ensures IT strategy is continuously aligned with business goals rather than being set in isolation. COBIT and ISO/IEC 38500 both emphasize such cross-functional governance bodies as the primary vehicle for strategic alignment.

Exam trap

CISA often tests the difference between governance structures (steering committees) and operational activities (budgeting, reviews), tempting candidates to pick a tactical-sounding option that lacks ongoing business involvement.

How to eliminate wrong answers

Option A is wrong because aligning the IT budget to the previous year's business plan is backward-looking and static; it does not ensure alignment with current or future business goals. Option B is wrong because conducting IT strategy reviews independently of business cycles disconnects IT planning from business planning cadence, defeating alignment. Option D is wrong because delegating IT strategy solely to the CIO without business input removes the business voice from strategic decisions, which is the opposite of alignment.

81
MCQhard

A multinational corporation is adopting a hybrid cloud strategy. The IT governance board must decide on a framework to ensure alignment with business objectives and regulatory compliance. Which framework is MOST appropriate?

A.ITIL 4 Service Value System
B.COBIT 2019
C.ISO/IEC 27001 Information Security Management
D.PMBOK Guide
AnswerB

COBIT 2019 provides a governance and management framework explicitly linking IT objectives to business goals, with defined processes and control practices for regulatory compliance. This satisfies the board's need for enterprise-wide governance across hybrid cloud rather than technology-specific operational guidance.

Why this answer

COBIT 2019 is the most appropriate framework because it is specifically designed for IT governance, providing a comprehensive set of controls and processes to align IT with business objectives and ensure regulatory compliance. In a hybrid cloud strategy, COBIT 2019's focus on governance objectives, stakeholder needs, and risk management directly addresses the board's need for oversight across on-premises and cloud environments, unlike frameworks that target service management, security, or project management.

Exam trap

The trap here is that candidates often confuse ITIL (service management) with governance, assuming that best practices for service delivery inherently cover board-level alignment and compliance, but ITIL lacks the governance objectives and stakeholder-driven goal cascade that COBIT provides for hybrid cloud strategies.

How to eliminate wrong answers

Option A is wrong because ITIL 4 Service Value System focuses on IT service management (ITSM) best practices, such as incident and change management, but lacks the governance and compliance alignment mechanisms required for board-level decision-making in a hybrid cloud strategy. Option C is wrong because ISO/IEC 27001 is an information security management standard that addresses security controls and risk management, but it does not provide a holistic governance framework for aligning IT with business objectives and regulatory compliance across the entire enterprise. Option D is wrong because PMBOK Guide is a project management framework that covers project lifecycle and processes, but it is not designed for ongoing IT governance or ensuring sustained alignment with business goals and compliance in a hybrid cloud environment.

82
Multi-Selecthard

An IS auditor is evaluating an organization's IT governance framework. The auditor finds that IT decisions are made ad hoc by various business units without alignment to corporate strategy. Which TWO of the following are the MOST important governance mechanisms the auditor should recommend to address this issue? (Choose two.)

Select 2 answers
A.Establish an IT steering committee with representation from key business units and IT.
B.Implement a formal IT project portfolio management process.
C.Increase the IT budget to allow business units more autonomy.
D.Delegate all IT decisions to the CIO to centralize authority.
E.Conduct annual IT audits to identify misalignments.
AnswersA, B

An IT steering committee provides a formal forum for prioritizing IT initiatives, aligning them with business strategy, and ensuring cross-functional input. It directly addresses the lack of coordination and strategic alignment by centralizing decision-making and fostering communication between business and IT. This is a fundamental governance mechanism to prevent ad hoc decisions.

Why this answer

The lack of alignment and ad hoc decision-making indicates a need for governance structures that provide direction and oversight. An IT steering committee and formal portfolio management are proactive mechanisms that ensure IT initiatives are prioritized and aligned with corporate strategy. They establish accountability and cross-functional collaboration, directly addressing the root cause.

Exam trap

The trap here is focusing on reactive or structural changes like increasing budget or centralizing authority, which do not address the need for ongoing strategic alignment and cross-functional governance.

83
MCQhard

During an IT audit, the auditor discovers that the IT department has not conducted a business impact analysis (BIA) for three years. The organization's disaster recovery plan (DRP) is based on the previous BIA. The IT manager argues that the DRP is still valid because no major changes have occurred. What should the auditor recommend?

A.Recommend that a new BIA be conducted to validate and update the DRP.
B.Accept the IT manager's rationale and close the finding.
C.Recommend terminating the current DRP until the BIA is completed.
D.Recommend accepting the risk and documenting the decision.
AnswerA

A DRP derives its recovery priorities and timeframes from BIA output; a three-year-old BIA may no longer reflect current systems or dependencies. Recommending a fresh BIA validates assumptions and updates the DRP, satisfying the need for an accurate, current recovery baseline.

Why this answer

A business impact analysis (BIA) is the foundation of a valid disaster recovery plan (DRP). Without a current BIA, the DRP may not reflect the organization's current critical processes, recovery time objectives (RTOs), or recovery point objectives (RPOs). Even if no major changes are perceived, subtle shifts in dependencies, resource availability, or regulatory requirements can render the DRP ineffective.

Therefore, the auditor should recommend conducting a new BIA to validate and update the DRP.

Exam trap

The trap here is that candidates may assume the IT manager's claim of 'no major changes' is sufficient, but the CISA exam emphasizes that a BIA must be periodically reviewed (typically annually) regardless of perceived stability, because hidden dependencies or gradual changes can still affect recovery requirements.

How to eliminate wrong answers

Option B is wrong because accepting the IT manager's rationale without evidence ignores the risk that the DRP may be outdated; the auditor's role is to verify, not assume, that no changes have impacted recovery requirements. Option C is wrong because terminating the current DRP would leave the organization without any recovery plan until the BIA is completed, increasing operational risk unnecessarily. Option D is wrong because accepting the risk and documenting the decision without further action is premature; the auditor should first recommend a BIA to determine the actual risk level before deciding to accept it.

84
MCQmedium

A multinational corporation has adopted a decentralized IT governance model where business units have significant autonomy over IT decisions. The IS auditor is assessing the effectiveness of this model. Which of the following is the MOST critical factor for the auditor to evaluate?

A.Whether business units have the autonomy to select their own hardware and software vendors.
B.Whether the central IT function has been completely eliminated.
C.Whether a common framework and standards exist to ensure consistency and interoperability.
D.Whether each business unit has its own IT steering committee.
AnswerC

In a decentralized IT governance model, business units make independent decisions, which can lead to fragmentation, duplication, and integration challenges. The existence of a common framework and standards is critical to ensure that IT systems and processes remain consistent, secure, and interoperable across the organization. Without such a framework, the organization may face increased costs, data silos, and difficulty in achieving enterprise-wide objectives. Thus, this is the most critical factor for the auditor to evaluate.

Why this answer

The most critical factor in a decentralized IT governance model is the existence of a common framework and standards to ensure consistency, interoperability, and alignment with enterprise objectives. Without such a framework, business units may make disparate decisions that lead to fragmentation, duplication, and increased risk. The auditor should evaluate whether standards are in place and enforced, and whether they effectively balance autonomy with enterprise-wide needs.

Exam trap

The trap here is assuming that decentralization requires the elimination of central IT or that local steering committees are the key, when the real critical factor is the presence of common standards and frameworks.

85
MCQeasy

An organization's IT department has recently implemented a new project management methodology. The IS auditor is reviewing the project portfolio and finds that projects are prioritized based on the personal preferences of the IT director rather than strategic alignment. Which of the following is the MOST significant risk arising from this practice?

A.Projects may not align with business strategy, leading to wasted resources and missed opportunities.
B.The IT director may become overburdened with decision-making, causing project delays.
C.The organization may fail to comply with regulatory requirements for project documentation.
D.Project managers may lack clear direction, resulting in scope creep and budget overruns.
AnswerA

Prioritizing projects based on personal preferences rather than strategic alignment means IT investments may not support the organization's goals. This can result in resources being allocated to low-value projects while critical strategic initiatives are delayed or unfunded. The most significant risk is the misalignment of IT with business strategy, which undermines the value IT delivers and can lead to competitive disadvantage.

Why this answer

When IT projects are prioritized based on personal preferences instead of strategic alignment, the organization risks investing in initiatives that do not support its business goals. This can lead to wasted resources, missed market opportunities, and a failure to achieve expected benefits. The most significant risk is the misalignment between IT and business strategy, which directly impacts the organization's ability to create value and remain competitive.

Exam trap

The trap here is focusing on operational symptoms like delays or scope creep rather than the fundamental strategic misalignment that drives those symptoms.

86
Multi-Selectmedium

An organization is implementing an IT governance framework to align IT with business objectives. Which TWO of the following are primary responsibilities of the IT steering committee?

Select 2 answers
A.Performing daily IT operations
B.Defining IT security policies
C.Approving IT project budgets and priorities
D.Conducting technical vulnerability assessments
E.Ensuring IT investments deliver value
AnswersC, E

Approving IT project budgets and priorities is a primary steering committee duty, since the committee allocates resources and sequences projects to match business objectives. This governance decision keeps investment aligned with strategy rather than departmental preference.

Why this answer

Option C is correct because an IT steering committee is a governance body that reviews and approves IT project budgets and sets project priorities, ensuring that funding and sequencing decisions align with business strategy rather than being left to operational teams. Option E is correct because a core governance responsibility is ensuring IT investments deliver value, which the committee accomplishes by monitoring benefits realization, tracking ROI, and holding IT accountable for outcomes tied to business objectives. Options A, B, and D do not belong: performing daily IT operations (A) is an operational/IT operations function, defining IT security policies (B) is typically delegated to a security governance or CISO function (the steering committee may endorse them but does not author them), and conducting technical vulnerability assessments (D) is a hands-on technical security task performed by security engineers or analysts, not a governance committee.

Exam trap

CISA often tests the distinction between governance (setting direction, approving budgets, ensuring value) and management (executing operations, writing policies, running scans) — candidates who pick operational-sounding options confuse the two layers.

87
MCQmedium

A large financial institution has a well-defined IT governance framework with a clear organizational structure, policies, and processes. However, the internal audit department has identified that several IT projects are over budget and behind schedule. The project managers blame unclear requirements and scope creep. The IT governance committee meets monthly but reviews projects only at a high level. The auditor's best recommendation to improve project governance is to:

A.Increase the frequency of security reviews for all projects
B.Change the IT steering committee's meeting frequency to weekly with detailed reviews
C.Establish a project management office (PMO) to oversee project governance and reporting
D.Require all projects to use a specific project management software tool
AnswerC

A PMO establishes standardised project governance, oversight and reporting, directly addressing the unclear requirements, scope creep and high-level-only reviews causing overruns. It satisfies the need for project-level governance discipline that the existing framework lacks, rather than merely refining committee structure.

Why this answer

Establishing a project management office (PMO) provides standardized project management practices, oversight, and controls to prevent scope creep and improve delivery. Option A is tactical and focuses on security, not project delivery. Option B changes meeting frequency but does not establish a dedicated project governance function.

Option D mandates a tool but does not address underlying governance processes.

88
MCQhard

During a risk assessment, an IS auditor identifies that the IT department has not performed a business impact analysis (BIA) for critical systems. Which of the following is the MOST significant risk?

A.Non-compliance with software licensing
B.Increased likelihood of security breaches
C.Inability to calculate total cost of ownership
D.Uncertainty regarding recovery time objectives for critical systems
AnswerD

Without a BIA, the organisation cannot determine maximum tolerable downtime or derive recovery time objectives for critical systems. That gap leaves recovery priorities and continuity requirements undefined, making uncertainty over RTOs the most significant risk identified.

Why this answer

A business impact analysis (BIA) is essential for identifying critical business functions and determining recovery time objectives (RTOs) and recovery point objectives (RPOs). Without a BIA, the organization lacks a clear understanding of how long systems can be down and what data loss is acceptable, leading to uncertainty in recovery planning. This is the most significant risk because it directly affects the ability to recover from disruptions.

Exam trap

CISA often tests the misconception that a BIA is primarily about security or compliance, when its core purpose is to determine recovery objectives and business impact.

How to eliminate wrong answers

Option A is wrong because software licensing non-compliance is a legal and financial risk, but it is not directly related to the absence of a BIA. Option B is wrong because while security breaches are a risk, a BIA does not directly prevent them; it focuses on recovery. Option C is wrong because total cost of ownership is a financial metric, not a primary outcome of a BIA, which is more about recovery objectives.

89
MCQhard

An IS auditor is evaluating an organization's IT governance maturity using COBIT 2019. The auditor finds that IT processes are largely ad hoc, with no formal documentation, and success depends on individual heroics. Which of the following maturity levels BEST describes this situation?

A.Level 3 – Defined
B.Level 0 – Incomplete
C.Level 2 – Managed
D.Level 1 – Initial
AnswerD

Level 1 in COBIT 2019 is characterized by ad hoc processes, lack of documentation, and reliance on individual efforts. The scenario describes exactly this: no formal processes and success dependent on heroics. This is the lowest maturity level, indicating that governance is unstructured and unpredictable.

Why this answer

COBIT 2019 defines maturity levels from 0 to 5. Level 1 (Initial) is assigned when processes are ad hoc and undocumented, and success depends on individual competence. This matches the scenario precisely.

Higher levels require increasing degrees of planning, documentation, and standardization, which are not present here.

Exam trap

The trap here is confusing Level 1 with Level 0; Level 0 means processes are not performed at all, while Level 1 means they are performed but informally.

90
MCQhard

An IS auditor is evaluating the IT governance structure of a multinational corporation. The auditor finds that IT decisions are made independently by regional business units, with no central oversight. The corporate IT strategy exists but is not enforced. Which of the following is the MOST likely consequence of this governance approach?

A.Increased agility and faster response to local market needs.
B.Duplication of IT resources and inability to achieve economies of scale.
C.Enhanced innovation from diverse regional approaches.
D.Improved compliance with local regulations due to regional autonomy.
AnswerB

Without central oversight, regional units may independently procure and manage IT resources, leading to redundant systems, duplicated efforts, and lost opportunities for standardization and cost savings. This fragmentation is a classic risk of uncoordinated decentralization. The corporate IT strategy is not enforced, so there is no mechanism to align regional decisions with enterprise goals, making duplication and inefficiency the most likely outcome.

Why this answer

The most likely consequence is duplication of IT resources and inability to achieve economies of scale. When regional units make independent IT decisions without central oversight or enforcement of a corporate strategy, they often procure redundant systems and fail to leverage enterprise-wide contracts or shared services. This fragmentation increases costs, complicates integration, and undermines the ability to achieve strategic alignment, making it the most significant governance risk.

Exam trap

The trap here is focusing on potential benefits of decentralization, such as agility or innovation, while overlooking the governance risk of uncoordinated decision-making that leads to duplication and inefficiency.

91
MCQhard

A retail organization's board has approved an IT governance framework that delegates decision rights for infrastructure standards to a central architecture board, while reserving funding decisions above a threshold for the board's technology committee. Business units must comply with the standards but may request exceptions. Which of the following is the MOST important control for the IS auditor to verify when assessing the effectiveness of this framework?

A.The architecture board meets at least quarterly and maintains minutes of its deliberations.
B.Exception requests are documented, time-bound, and approved at a level commensurate with the risk of noncompliance.
C.The board's technology committee reviews the IT capital budget at each scheduled meeting.
D.Business units are surveyed annually on their satisfaction with the standards and the exception process.
AnswerB

The framework's credibility depends on whether the delegated authority is actually enforced. Exceptions are the primary leak path: if they are undocumented, open-ended, or approved at too low a level, the architecture board's decision rights become nominal. Verifying that exceptions are documented, time-bound, and approved commensurate with risk directly tests whether the governance design operates as intended in practice.

Why this answer

Governance frameworks allocate decision rights, but their effectiveness is determined by how deviations are handled. Because business units can request exceptions to architecture standards, the exception process is where delegated authority is either preserved or eroded. Documented, time-bound exceptions approved at a risk-commensurate level preserve the architecture board's authority while allowing justified flexibility.

Meeting cadence, satisfaction surveys, and budget review do not test whether standards are actually binding.

Exam trap

The trap here is focusing on the visible activity of the governance bodies rather than on the exception mechanism that determines whether their decision rights are real.

92
MCQeasy

An IT department uses a balanced scorecard to measure performance. Which metric would BEST reflect the 'customer perspective'?

A.Training hours per employee
B.System uptime percentage
C.User satisfaction survey results
D.Project completion rate
AnswerC

User satisfaction survey results directly capture how customers perceive IT service quality, matching the balanced scorecard's customer perspective. Other metrics, such as incident resolution or budget variance, reflect internal process or financial perspectives rather than customer outcomes.

Why this answer

The customer perspective focuses on user satisfaction and service responsiveness. Option A is incorrect as training hours relate to learning and growth perspective. Option B is incorrect as system uptime is an internal process metric.

Option D is incorrect as project completion rate is an internal efficiency metric.

93
MCQmedium

An IT manager is reviewing the service level agreements (SLAs) for a cloud-based email service. The SLA guarantees 99.9% uptime per month. The service experienced an outage of 45 minutes in a 30-day month. Did the service meet the SLA?

A.Yes, because 45 minutes is within 0.1% of the total time.
B.Yes, because the SLA is calculated per day, not per month.
C.No, because any downtime exceeding 30 minutes is a violation.
D.No, because the allowed downtime for 99.9% uptime is approximately 43 minutes.
AnswerD

99.9% uptime permits 0.1% downtime; in a 30-day month (43,200 minutes) that equals about 43.2 minutes. The 45-minute outage exceeds this allowance, so the SLA was breached, confirming the service did not meet its monthly commitment.

Why this answer

The SLA guarantees 99.9% uptime per month. For a 30-day month (43,200 minutes), 99.9% uptime allows only 0.1% downtime, which is 43.2 minutes. The actual outage of 45 minutes exceeds this threshold, so the SLA was not met.

Option D correctly identifies the allowed downtime as approximately 43 minutes.

Exam trap

The trap here is that candidates may incorrectly round 43.2 minutes to 43 minutes and then assume 45 minutes is close enough, or they may mistakenly think 0.1% of a month is 30 minutes, leading them to choose option C.

How to eliminate wrong answers

Option A is wrong because 45 minutes is not within 0.1% of the total time; 0.1% of 43,200 minutes is 43.2 minutes, so 45 minutes exceeds the allowed downtime. Option B is wrong because the SLA explicitly states 'per month,' not per day, and calculating per day would allow even less downtime (e.g., 0.1% of 1,440 minutes = 1.44 minutes per day). Option C is wrong because the SLA does not specify a 30-minute threshold; the allowed downtime is derived from the 99.9% uptime calculation, not an arbitrary 30-minute limit.

94
MCQmedium

An IT audit revealed that the organization's IT steering committee has not met in the past six months. Which of the following is the MOST likely consequence of this situation?

A.Higher IT staff turnover.
B.Increased number of security incidents.
C.Inconsistent IT policies across departments.
D.Delayed decision-making on IT investments.
AnswerD

A stalled steering committee removes the governance forum where cross-functional IT investment proposals are prioritised and approved, so funding decisions queue up unresolved. This directly satisfies the stem's six-month gap, making delayed decision-making on IT investments the most likely consequence rather than an operational or security failure.

Why this answer

The IT steering committee is responsible for strategic IT governance, including prioritizing and approving IT investments. If it does not meet, decisions on IT investments are delayed because there is no forum to review, prioritize, and approve them. This directly impacts the organization's ability to align IT with business goals and can stall critical projects.

Exam trap

CISA often tests the distinction between governance and management; candidates may confuse the steering committee's strategic role with operational issues like security incidents or staff turnover, but the most direct consequence of its inactivity is delayed investment decisions.

How to eliminate wrong answers

Option A is wrong because higher IT staff turnover is typically caused by factors like poor management, lack of career development, or low morale, not directly by a steering committee's inactivity. Option B is wrong because increased security incidents are usually the result of weak security controls, not governance meeting frequency. Option C is wrong because inconsistent IT policies across departments result from poor policy management and communication, not solely from a steering committee not meeting; while governance can influence policy, the most direct consequence is delayed investment decisions.

95
MCQmedium

A mid-sized insurance company has decided to adopt a formal IT governance framework because its board is concerned about unmanaged IT risk. The CIO asks the IS auditor to recommend the FIRST step in establishing the governance framework. Which of the following should the IS auditor recommend?

A.Create a RACI matrix for all IT processes to clarify accountability.
B.Define IT governance objectives and align them with enterprise strategic goals.
C.Implement a balanced scorecard to measure IT performance across four perspectives.
D.Establish an IT steering committee to oversee IT investment decisions.
AnswerB

Establishing IT governance must begin by defining clear objectives that are directly linked to the enterprise's strategic goals. Without this alignment, subsequent structures, processes, and metrics lack direction and may not deliver value. This foundational step ensures that governance efforts focus on achieving business outcomes and managing IT-related risks in a way that supports the organization's overall mission and stakeholder expectations.

Why this answer

The first step in establishing IT governance is to define objectives that align IT with enterprise strategy. This ensures that all subsequent governance structures, processes, and metrics are purposeful and support business goals. Without this alignment, other activities such as scorecards, RACI matrices, or steering committees lack a foundation and may not effectively manage IT-related risks or deliver value to the organization.

Exam trap

The trap here is assuming that implementing a governance mechanism such as a steering committee or scorecard is the first step, when actually defining objectives and strategic alignment must come first.

96
Multi-Selecteasy

Which TWO of the following are benefits of establishing an IT steering committee?

Select 2 answers
A.Improved operational efficiency of IT systems
B.Enhanced prioritization of IT investments
C.Better alignment between IT and business strategy
D.Reduction of management overhead
E.Direct control over technical IT decisions
AnswersB, C

An IT steering committee aligns IT spending with business strategy by ranking competing initiatives against agreed criteria, ensuring limited funds target the highest-value projects. This directly satisfies the stem's benefit of enhanced prioritisation of IT investments, since cross-functional oversight resolves competing departmental demands that isolated IT management cannot arbitrate.

Why this answer

Option B is correct because an IT steering committee's core purpose is governance: it evaluates competing IT initiatives against business value, risk, and resource capacity, thereby enhancing prioritization of IT investments so funding goes to the highest-value projects. Option C is correct because the committee is composed of senior business and IT leaders who jointly set direction, which produces better alignment between IT and business strategy and ensures IT delivers on organizational objectives. Option A is not a primary benefit of a steering committee, since operational efficiency of IT systems is achieved through operational management practices such as monitoring, tuning, and incident management rather than governance-level prioritization.

Option D is incorrect because establishing a steering committee adds governance meetings and coordination effort, typically increasing rather than reducing management overhead. Option E is incorrect because steering committees provide strategic direction and oversight, not direct control over technical IT decisions, which remain with IT architects, engineers, and operational teams.

Exam trap

CISA often tests the distinction between governance and management, and candidates may incorrectly assume that a steering committee directly improves operational efficiency or reduces overhead, when its primary benefits are strategic alignment and prioritization.

97
MCQmedium

An organization is planning to outsource its data center operations. Which of the following governance practices should be implemented to ensure proper oversight?

A.Conduct annual financial audits of the outsourcer.
B.Require the outsourcer to obtain ISO 27001 certification.
C.Establish a service level agreement (SLA) with key performance indicators (KPIs).
D.Allow the outsourcer to manage all security controls independently.
AnswerC

An SLA with KPIs defines measurable performance targets and remedies, giving the organisation contractual oversight of the outsourced data centre. It satisfies the governance constraint by establishing enforceable accountability, monitoring and reporting rather than relying on the vendor's internal controls alone.

Why this answer

Establishing an SLA with KPIs is a fundamental governance practice for outsourcing because it defines measurable performance expectations and provides a basis for monitoring and enforcing the provider's obligations. It ensures the outsourcer is accountable for service delivery and aligns with business objectives.

Exam trap

The trap is selecting a specific certification or audit as the primary governance practice, when the broader and more essential practice is establishing measurable SLAs with KPIs for ongoing oversight.

How to eliminate wrong answers

Option A is wrong because annual financial audits alone do not provide comprehensive oversight of operational and security controls. Option B is wrong because requiring ISO 27001 certification is a point-in-time certification and does not guarantee ongoing compliance or performance; it is a useful criterion but not sufficient for oversight. Option D is wrong because allowing the outsourcer to manage all security controls independently abdicates the organization's responsibility for oversight and risk management.

98
MCQmedium

An IS auditor is reviewing the organization's IT governance framework. The board has delegated oversight of IT to an IT steering committee. The auditor finds that the committee meets quarterly, but its charter does not define decision rights or escalation procedures. Which of the following is the MOST significant concern?

A.The board has delegated IT oversight to a committee, which dilutes board accountability.
B.The committee meets too infrequently to govern IT effectively.
C.The committee does not include business unit representatives, limiting its perspective.
D.The committee's charter lacks clear decision rights and escalation procedures, creating ambiguity in IT decision-making.
AnswerD

This is the most significant concern because without defined decision rights and escalation procedures, the committee cannot effectively govern IT. Decision rights clarify who is authorized to make specific IT decisions, while escalation procedures ensure issues are raised to the appropriate level. Their absence can lead to inconsistent decisions, unmanaged risks, and accountability gaps, directly undermining the governance framework.

Why this answer

The most significant concern is the lack of defined decision rights and escalation procedures in the committee's charter. Effective IT governance requires clear authority for decision-making and a defined path for escalating issues. Without these, the committee cannot ensure timely, accountable IT decisions, leading to potential misalignment with business objectives and unmanaged risks.

Meeting frequency and representation are secondary to this structural gap.

Exam trap

The trap here is assuming that meeting frequency or committee composition is the primary governance issue, when the absence of decision rights and escalation procedures is the fundamental flaw.

99
Multi-Selecthard

An IS auditor is assessing an organization's IT governance implementation. The auditor finds that IT policies are outdated, roles and responsibilities are unclear, and there is no regular reporting on IT performance to the board. Which TWO of the following are the MOST critical actions to improve IT governance? (Choose two.)

Select 2 answers
A.Increase the IT budget to allow for more staff training.
B.Update all IT policies annually to ensure they reflect current technology.
C.Implement regular IT performance reporting to the board and executive management.
D.Conduct an annual IT risk assessment to identify vulnerabilities.
E.Establish a formal IT governance framework with defined roles and responsibilities.
AnswersC, E

Regular reporting is essential for transparency and informed decision-making. It enables the board to monitor IT performance, risks, and alignment with strategy. Without reporting, governance is reactive and blind. This action directly addresses the lack of oversight and ensures accountability.

Why this answer

The most critical actions are to establish a formal governance framework and implement regular reporting. These address the root causes: lack of structure and lack of oversight. A framework clarifies roles and responsibilities, while reporting ensures accountability and informed decision-making.

Other actions, such as updating policies or training, are supportive but not sufficient alone.

Exam trap

The trap here is choosing tactical actions like updating policies or training, which are important but do not address the fundamental governance gaps.

100
Multi-Selecthard

Which THREE of the following are commonly recognized benefits of implementing a formal IT service management (ITSM) framework such as ITIL?

Select 3 answers
A.Better alignment between IT services and business needs
B.Guaranteed zero downtime for critical services
C.Elimination of the need for external IT audits
D.Improved service quality and availability
E.Increased efficiency and cost savings through standardized processes
AnswersA, D, E

A formal ITSM framework defines services around business outcomes and agreed service levels, so IT priorities, investment and reporting align with organisational objectives rather than technical silos. This alignment is a widely cited benefit of adopting ITIL practises.

Why this answer

Option A is correct because ITSM frameworks like ITIL are built around service-level alignment, using practices such as Service Level Management and Demand Management to ensure IT services directly support business objectives and outcomes. Option D is correct because ITIL's Service Design and Continual Service Improvement practices, along with Availability Management and Incident Management, are specifically designed to raise service quality and availability through defined SLAs, OLAs, and KPIs. Option E is correct because standardizing processes such as Change Enablement, Incident Management, and Problem Management reduces ad hoc work, eliminates duplication, and lowers cost through repeatable, measurable workflows.

Option B is not correct because no framework can guarantee zero downtime; ITIL only improves availability through resilience and recovery practices, and outages can still occur. Option C is not correct because adopting ITSM does not remove the need for external IT audits; regulatory, statutory, and third-party audit requirements (e.g., SOX, ISO 27001) remain independent of ITIL adoption.

Exam trap

The trap here is that candidates may confuse the risk-reduction benefits of ITSM (like improved availability) with an absolute guarantee, or assume that a framework replaces independent verification, when in reality ITSM improves processes but does not eliminate the need for external audits or guarantee perfect uptime.

101
MCQeasy

An IT manager is developing a governance policy for change management. Which element is MOST important to include?

A.Project management methodology
B.Detailed technical procedures
C.List of all applications
D.Roles and responsibilities
AnswerD

Roles and responsibilities define who may authorise, implement and verify each change, directly satisfying the governance requirement for accountability and segregation of duties. Without assigned ownership, approval controls cannot be enforced or audited, leaving changes unmanaged. This makes it the most important element for a change management governance policy.

Why this answer

Roles and responsibilities are the cornerstone of any governance policy because they establish accountability and authority for change approval, implementation, and review. Without clearly defined roles (e.g., change manager, change advisory board, implementer), even well-documented procedures lack ownership and enforcement. Governance is about decision rights and accountability, not operational details.

Thus, defining who is responsible for what is the most critical element to include.

Exam trap

CISA often tests the distinction between governance (strategic, accountability-focused) and management (tactical, procedure-focused), so candidates may mistakenly choose detailed technical procedures or project management methodology as the most important element, overlooking that governance is fundamentally about roles and responsibilities.

How to eliminate wrong answers

Option A is wrong because project management methodology pertains to how projects are executed, not to the governance of changes; it is a subset of change management but not the most critical governance element. Option B is wrong because detailed technical procedures are operational and belong in work instructions or runbooks, not in a high-level governance policy. Option C is wrong because a list of all applications is an inventory artifact, not a governance component; it does not define authority or accountability.

102
Multi-Selecthard

Which THREE of the following are components of a typical IT governance framework?

Select 3 answers
A.Network troubleshooting procedures
B.Strategic alignment of IT with business
C.Risk management and compliance
D.Performance measurement and reporting
E.Vendor contract management
AnswersB, C, D

Core governance component.

Why this answer

Strategic alignment of IT with business is a core component of an IT governance framework because it ensures that IT initiatives directly support and enable the organization's business objectives and strategies. This alignment is achieved through mechanisms like balanced scorecards and IT steering committees, which prioritize IT investments based on business value. Without this component, IT may operate in a silo, leading to wasted resources and missed opportunities.

Exam trap

The trap here is that candidates often confuse operational IT activities (like troubleshooting or contract management) with the strategic, oversight-oriented components of governance, leading them to select options that describe 'doing IT' rather than 'governing IT'.

103
MCQmedium

An IS auditor is assessing an organization's IT governance. The auditor finds that the IT balanced scorecard is used to measure IT performance, but the metrics are heavily focused on internal IT processes and do not include business or customer perspectives. Which of the following is the MOST likely consequence of this imbalance?

A.IT projects will be delivered on time and within budget.
B.IT staff will require additional training on customer service.
C.The IT budget will be reduced due to lack of business justification.
D.IT may fail to deliver value to the business and meet stakeholder expectations.
AnswerD

The balanced scorecard should include financial, customer, internal process, and learning and growth perspectives. Excluding business and customer perspectives means IT performance is measured without regard to how it supports business goals or satisfies users. This can result in IT initiatives that are technically efficient but do not deliver strategic value or meet stakeholder needs, leading to dissatisfaction and misalignment.

Why this answer

The balanced scorecard is designed to provide a comprehensive view of performance across multiple perspectives. Omitting business and customer perspectives means IT performance is evaluated solely on internal efficiency, which can lead to IT initiatives that do not support business strategy or satisfy users. The most likely consequence is a failure to deliver value and meet stakeholder expectations, undermining IT's contribution to the organization.

Exam trap

The trap here is assuming that internal process efficiency automatically translates to business value, when in fact a balanced scorecard must include external perspectives to ensure alignment with stakeholder needs.

104
MCQmedium

An IS auditor is reviewing an organization's IT governance policies and finds that the IT strategy is updated annually, but there is no process to monitor external factors such as regulatory changes or emerging technologies. Which of the following is the MOST significant risk of this deficiency?

A.IT investments may not deliver expected returns.
B.The organization may fail to comply with new regulations.
C.The IT steering committee may not meet regularly.
D.The IT strategy may become misaligned with business objectives.
AnswerB

Without monitoring regulatory changes, the organization may not be aware of new compliance requirements, leading to legal penalties, fines, and reputational damage. This is a direct and significant risk because regulatory compliance is mandatory. The IT strategy should include processes to scan the external environment for regulatory updates and adjust IT controls accordingly. The auditor should identify this as a critical deficiency because non-compliance can have severe financial and operational consequences, and it undermines the effectiveness of IT governance.

Why this answer

The most significant risk of not monitoring external factors is regulatory non-compliance. Regulations can change rapidly, and failure to detect and respond to them can result in legal penalties, fines, and reputational harm. The IT strategy must include a process for environmental scanning to identify regulatory updates and emerging technologies.

Without this, the organization may inadvertently violate new laws or fall behind competitors. The auditor should recommend implementing a formal external monitoring process as part of IT governance.

Exam trap

The trap here is focusing on internal alignment or investment returns when the scenario explicitly points to external factors, making regulatory compliance the most direct and severe risk.

105
MCQeasy

An organization's IT strategy must be aligned with business strategy. Which of the following is the PRIMARY benefit of this alignment?

A.Faster adoption of new technologies
B.Enhanced security posture
C.Reduced IT operational costs
D.Increased value of IT investments to business objectives
AnswerD

Aligning IT strategy with business strategy directs IT spending and initiatives toward organisational goals, maximising the business value delivered by IT investments. That outcome is the primary benefit, rather than cost reduction, technology standardisation or faster project delivery.

Why this answer

When IT strategy is aligned with business strategy, every IT investment is directly tied to achieving specific business objectives, such as increasing revenue, improving customer experience, or enabling new business models. This alignment ensures that resources are allocated to projects that deliver measurable business value, rather than being spent on technology for its own sake. The primary benefit is therefore the increased value of IT investments to business objectives, as misalignment often leads to wasted expenditure on systems that do not support core business goals.

Exam trap

The trap here is that candidates often confuse operational benefits (like cost reduction or faster tech adoption) with the strategic primary benefit, failing to recognize that alignment is fundamentally about ensuring IT investments deliver value to the business, not about efficiency or security alone.

How to eliminate wrong answers

Option A is wrong because faster adoption of new technologies is a potential operational benefit, but it is not the primary benefit of alignment; rapid adoption without business context can actually lead to misalignment and wasted resources. Option B is wrong because enhanced security posture is a critical outcome of good IT governance, but it is a secondary benefit that results from aligning security controls with business risk appetite, not the primary reason for aligning IT and business strategy. Option C is wrong because reduced IT operational costs can be a byproduct of alignment (e.g., eliminating redundant systems), but cost reduction is not the primary goal; the primary goal is ensuring IT spending directly supports business value creation, which may sometimes require increased investment.

106
MCQhard

An organization is implementing a new ERP system. The project sponsor requests a change that will significantly increase project scope without additional budget. Which of the following is the BEST action for the project manager?

A.Accept the change and adjust the project timeline accordingly.
B.Initiate the formal change control process and escalate to the steering committee.
C.Implement the change and inform the steering committee later.
D.Reject the change because it is outside the original scope.
AnswerB

A scope increase without matching budget requires the formal change control process, since the change board and steering committee hold authority to approve, reject, or re-baseline scope, schedule, and funding. This satisfies the stem's constraint by preventing unilateral scope creep and preserving the approved baseline.

Why this answer

The project manager must follow the formal change control process to evaluate the impact of a scope change that lacks additional budget. Escalating to the steering committee is appropriate because they have the authority to approve or reject changes that affect project constraints, ensuring alignment with organizational governance and IT strategy.

Exam trap

The trap here is that candidates may choose to reject the change outright (Option D) thinking it protects the baseline, but the CISA exam emphasizes following the formal change control process and escalating to the appropriate governance body rather than making unilateral decisions.

How to eliminate wrong answers

Option A is wrong because accepting the change without budget or formal approval violates project governance and may lead to resource overallocation and timeline failure. Option C is wrong because implementing the change before informing the steering committee bypasses the required change control process and risks unauthorized scope creep. Option D is wrong because outright rejection without following the change control process denies the steering committee the opportunity to assess the change's strategic value or reallocate priorities.

107
MCQhard

An organization's data classification policy defines 'Confidential' data as requiring encryption at rest. An IS auditor discovers that a database containing customer personal information is not encrypted. What is the auditor's BEST course of action?

A.Encrypt the database immediately
B.Report the finding to the data owner and IT management
C.Recommend a compensating control
D.Verify the classification of the data
AnswerB

The auditor's role is to report the control gap, not remediate it. Escalating to the data owner and IT management places the finding with those accountable for the Confidential data and able to enforce encryption at rest, satisfying the policy requirement.

Why this answer

The IS auditor's primary responsibility is to report findings to the appropriate stakeholders—the data owner and IT management—so they can take corrective action. Option A is incorrect because implementing controls is management's responsibility, not the auditor's. Option C is premature; compensating controls should be recommended after reporting and discussing the risk.

Option D is unnecessary since the data classification policy already defines 'Confidential' data requiring encryption, and the auditor has identified a violation of that policy.

108
MCQeasy

During an IT audit, the auditor discovers that the IT strategy is not formally documented. Which of the following is the MOST significant risk associated with this finding?

A.Difficulty in recruiting qualified IT staff.
B.Inability to measure the performance of IT systems.
C.Lack of alignment between IT investments and business goals.
D.Increased operational costs due to unplanned IT initiatives.
AnswerC

Without a documented IT strategy, investment decisions lack a formal reference point tying spend to business objectives, so resources drift toward ad hoc technical priorities rather than organisational goals. This directly satisfies the stem's alignment risk, making it the most significant consequence of the missing documentation.

Why this answer

An undocumented IT strategy means there is no formal link between technology investment decisions and business objectives, so IT spending, projects, and priorities can drift away from what the organization is actually trying to achieve. This strategic misalignment is the most significant risk because it undermines value delivery across the entire IT portfolio, not just one operational area. Auditors treat the IT strategy as the governing document that translates business goals into IT direction, so its absence is a governance-level finding.

Exam trap

CISA often tests the difference between a governance-level risk (strategic misalignment) and operational symptoms (cost overruns, poor performance measurement) — candidates who pick the most visible symptom instead of the root governance risk get it wrong.

How to eliminate wrong answers

Option A is wrong because recruiting difficulty is an HR/talent issue driven by market conditions and compensation, not by whether the IT strategy is documented. Option B is wrong because performance measurement depends on metrics, SLAs, and monitoring frameworks — an IT strategy document is not the instrument used to measure system performance. Option D is wrong because unplanned IT initiatives and their cost overruns are a symptom of weak portfolio/project governance; while related, it is a downstream operational consequence, whereas the strategy gap's primary risk is strategic misalignment with business goals.

109
MCQmedium

An organization has a policy that requires all IT projects to have a business case approved by the IT steering committee. The IS auditor discovers that a major infrastructure upgrade was initiated without an approved business case. Which of the following is the auditor's PRIMARY concern?

A.The project may exceed its budget due to lack of financial oversight.
B.The IT steering committee may not be aware of the project's progress.
C.The project may not deliver expected business value or align with strategic goals.
D.The project may not have sufficient technical resources allocated.
AnswerC

The primary purpose of a business case is to justify the investment and ensure alignment with strategic objectives. Without an approved business case, the project lacks formal justification and may not deliver value. This is the most significant concern because it undermines governance and could lead to wasted resources and strategic misalignment.

Why this answer

The primary concern is that without an approved business case, the project may not deliver expected business value or align with strategic goals. The business case is a key governance control that ensures IT investments are justified and prioritized. Its absence indicates a breakdown in project initiation governance, which could result in wasted resources and failure to achieve strategic objectives.

Exam trap

The trap here is focusing on operational issues like budget or resources rather than the governance failure of initiating a project without proper justification and approval.

110
Multi-Selectmedium

Which TWO of the following are key responsibilities of an IT steering committee?

Select 2 answers
A.Monitoring IT performance and value delivery
B.Managing day-to-day IT operations
C.Writing and testing application code
D.Prioritizing IT projects and allocating resources
E.Conducting IT audit engagements
AnswersA, D

Monitoring IT performance and value delivery is a steering committee duty because the committee oversees whether IT investments deliver expected business benefits. It satisfies the governance constraint by providing ongoing oversight and accountability rather than day-to-day operational management.

Why this answer

The IT steering committee is a senior-level governance body responsible for aligning IT strategy with business objectives. Monitoring IT performance and value delivery (A) is a key responsibility because the committee must ensure that IT investments generate the expected business benefits and that service levels meet agreed targets. Prioritizing IT projects and allocating resources (D) is also a core duty, as the committee decides which initiatives receive funding and staffing based on strategic importance and risk, rather than operational urgency.

Exam trap

The trap here is confusing governance responsibilities (steering committee) with management or execution tasks (operations, coding, auditing), leading candidates to select options that sound plausible but belong to lower-level roles.

111
MCQeasy

An organization is establishing an IT governance committee. The committee's charter includes overseeing IT investments, monitoring IT performance, and ensuring compliance with regulations. Which of the following should the IS auditor recommend as the MOST important characteristic of the committee's membership?

A.Exclusive membership of board directors
B.Majority representation by IT managers
C.Inclusion of senior business executives and the CIO
D.Representation primarily from the finance department
AnswerC

Effective IT governance committees require representation from both business and IT leadership to ensure that IT decisions are aligned with business strategy and that IT risks are understood across the organization. Senior business executives provide strategic direction and prioritize investments, while the CIO offers technical insight and operational feasibility. This balanced membership fosters accountability, facilitates communication, and helps the committee make informed decisions that deliver value and manage risks appropriately.

Why this answer

The most important characteristic of an IT governance committee is balanced membership that includes senior business executives and the CIO. This ensures that IT decisions are aligned with business strategy, risks are managed from both business and technical perspectives, and accountability is shared. Without business representation, IT may become isolated; without IT representation, decisions may be impractical.

The committee should also include other stakeholders as needed, but the core should be business and IT leadership.

Exam trap

The trap here is assuming that IT governance committees should be dominated by IT or finance experts, when effective governance requires cross-functional representation to align IT with business objectives.

112
Multi-Selecthard

An IS auditor is assessing whether an organization's IT steering committee is fulfilling its governance responsibilities. The committee charter states that it oversees IT investment prioritization, monitors IT performance against agreed objectives, and resolves escalated resource conflicts. Which TWO of the following observations would the auditor MOST likely identify as deficiencies in the committee's operation? (Choose two.)

Select 2 answers
A.Performance dashboards report only project schedule and budget, with no measures of realized business outcomes.
B.Escalated resource conflicts are resolved through a documented decision log with assigned owners.
C.Investment proposals are approved without documented business cases linking them to strategic objectives.
D.The committee's membership includes the CIO, the CFO, and several business unit leaders.
E.The committee meets monthly and maintains minutes that are distributed to attendees.
AnswersA, C

The charter requires monitoring IT performance against agreed objectives, which implies outcome-oriented measurement. Dashboards limited to schedule and budget track delivery activity, not whether investments achieved their intended results. The committee therefore cannot detect value shortfalls, reallocate funding, or hold sponsors accountable. This gap undermines the performance monitoring responsibility and is a substantive operational deficiency.

Why this answer

The charter obligates the committee to prioritize investments against strategic objectives and to monitor performance against agreed objectives. Business cases are the mechanism that connects funding decisions to strategy, and outcome measures are what allow the committee to judge whether objectives were met. Approving investments without business cases and reporting only schedule and budget leave both obligations unfulfilled.

Cross-functional membership, documented conflict resolutions, and regular minuted meetings all support effective operation.

Exam trap

The trap here is treating visible committee activity, such as meeting monthly and keeping minutes, as evidence of effective governance even when the substantive oversight responsibilities in the charter are not being exercised.

113
Multi-Selecthard

Which THREE of the following are indicators of mature IT governance?

Select 3 answers
A.The IT department has high staff retention.
B.IT risks are formally assessed and managed.
C.IT projects are completed on time and within budget.
D.IT decisions are aligned with business strategy.
E.The board receives regular IT performance reports.
AnswersB, D, E

Formal assessment and management of IT risks indicates mature IT governance by demonstrating a structured, proactive approach to safeguarding organisational assets. This systematic process moves beyond ad-hoc reactions, encompassing continuous identification, evaluation, mitigation, and monitoring of potential threats. Such formalisation signifies an organisation's commitment to repeatable, controlled mechanisms for achieving strategic objectives, a definitive characteristic of governance maturity.

Why this answer

Option B is correct because mature IT governance requires a formal, repeatable risk management process — risks are identified, assessed, prioritized, and mitigated with defined ownership and reporting, typically aligned to frameworks such as COBIT or ISO/IEC 27005. Option D is correct because governance maturity means IT strategy and investment decisions are driven by and traceable to business objectives, not by technology for its own sake. Option E is correct because board-level oversight through regular IT performance reporting (KPIs, dashboards, risk and compliance updates) demonstrates accountability and direction-setting at the highest level of the organization.

Option A does not belong because high staff retention is an HR outcome that may reflect pay or market conditions rather than governance maturity. Option C does not belong because on-time, on-budget delivery is a project management performance metric, not an indicator of governance maturity — projects can be delivered efficiently under poor governance and vice versa.

Exam trap

CISA often tests the confusion between operational metrics (like project timeliness or staff retention) and true governance indicators (like risk management and strategic alignment).

114
MCQmedium

An IT department is struggling with project delays and budget overruns. Which governance practice would be MOST effective?

A.Establishing a project management office (PMO)
B.Outsourcing projects
C.Increasing IT staff
D.Adopting agile methodology
AnswerA

A PMO imposes standardised project methodologies, stage gates and resource oversight across the portfolio, directly addressing the root causes of schedule slippage and cost overruns. It centralises reporting and accountability, giving governance bodies the visibility needed to correct deviations early.

Why this answer

A PMO provides centralized governance, standardizes project management processes, and enforces oversight across all projects. This directly addresses the root causes of delays and overruns—lack of consistent methodology, resource coordination, and performance monitoring. By establishing a PMO, the IT department gains the structure needed to plan, execute, and control projects effectively, making it the most comprehensive governance practice.

Exam trap

CISA often tests the distinction between governance practices and operational improvements; candidates may mistakenly choose agile or outsourcing as quick fixes, but governance requires establishing oversight structures like a PMO.

How to eliminate wrong answers

Option B is wrong because outsourcing projects does not inherently improve governance; it may introduce new risks and dependencies without addressing internal process deficiencies. Option C is wrong because increasing IT staff without governance can lead to more uncoordinated efforts and does not ensure better project outcomes. Option D is wrong because adopting agile methodology is a project management approach, not a governance practice; without proper oversight, agile can still suffer from delays and overruns.

115
Drag & Dropmedium

Arrange the steps to perform a risk assessment in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Risk assessment begins with asset identification, then threat/vulnerability identification, followed by risk analysis, prioritization, and documentation of treatment.

116
Multi-Selectmedium

An IS auditor is assessing the effectiveness of an organization's IT governance framework. Which TWO of the following are essential components that the auditor should verify are in place? (Choose two.)

Select 2 answers
A.A formal IT risk management process integrated with enterprise risk management
B.IT strategic planning aligned with business objectives
C.A centralized help desk with 24/7 support for all IT issues
D.Detailed technical training for all IT staff on emerging technologies
E.A policy requiring all software purchases to be approved by the CIO
AnswersA, B

IT risk management is critical for identifying, assessing, and mitigating risks that could impact business objectives. Integration with enterprise risk management ensures that IT risks are considered in the broader organizational context. The auditor should verify that risk assessments are performed regularly, risk appetite is defined, and mitigation strategies are implemented. This process helps the organization avoid surprises and ensures that IT governance is proactive rather than reactive, aligning with frameworks like COBIT and ISO 27001.

Why this answer

Effective IT governance requires alignment of IT strategy with business objectives and integration of IT risk management with enterprise risk management. These components ensure that IT delivers value, risks are managed, and resources are optimized. The auditor should verify that these elements are formally established, documented, and actively used.

Without them, governance is incomplete and may fail to meet organizational needs. Operational elements like training, help desks, and approval policies are not core governance components.

Exam trap

The trap here is equating operational IT practices, such as help desk support or software approval, with essential governance components, which focus on strategic alignment and risk oversight.

117
MCQhard

An IS auditor is assessing an organization's IT governance framework and finds that the IT balanced scorecard includes metrics such as system uptime, number of help desk tickets resolved, and average response time. The auditor notes that these are all internal IT operational metrics. The MOST significant concern is that:

A.The scorecard does not include financial metrics such as IT cost per employee or return on IT investment.
B.The metrics are too technical for the board to understand and may lead to misinterpretation.
C.The scorecard lacks metrics that measure the contribution of IT to business strategy and customer value.
D.The metrics are not benchmarked against industry standards, making them less useful for comparison.
AnswerC

A balanced scorecard should include metrics from multiple perspectives, including business contribution and customer orientation. Focusing solely on internal operational metrics like uptime and ticket resolution provides an incomplete view of IT performance. The most significant concern is that the scorecard does not measure how IT contributes to business strategy or delivers value to customers, which is essential for effective IT governance and alignment.

Why this answer

An IT balanced scorecard should provide a balanced view of IT performance across multiple perspectives, including business contribution, customer orientation, operational excellence, and future orientation. The scenario describes only internal operational metrics, which means the scorecard does not measure IT's contribution to business strategy or customer value. This imbalance is the most significant concern because it prevents the board and management from assessing whether IT is delivering strategic value.

Exam trap

The trap here is focusing on the technical nature or lack of benchmarking of the metrics rather than the fundamental imbalance in the scorecard's perspectives.

118
MCQeasy

An organization is developing its IT strategy to align with the overall business strategy. The business strategy emphasizes rapid market expansion through digital products. Which of the following IT strategies would BEST support this business goal?

A.Standardize all IT systems to reduce complexity.
B.Adopt agile development methods and scalable cloud infrastructure.
C.Outsource all IT operations to a low-cost provider.
D.Minimize IT investment to preserve capital for business growth.
AnswerB

Agile methods enable rapid iterative delivery of digital products, while scalable cloud infrastructure absorbs unpredictable demand during market expansion. Together they satisfy the strategy's requirement for speed and elasticity, which traditional waterfall development and fixed on-premises capacity cannot match.

Why this answer

A business strategy focused on rapid market expansion through digital products requires IT to deliver quickly and scale elastically. Agile development methods enable fast iteration and responsiveness to market feedback, while scalable cloud infrastructure provides the elasticity to handle growth without heavy upfront capital investment. Together they directly enable speed and scale, which are the core requirements of the stated strategy.

Exam trap

CISA often tests whether candidates equate cost reduction with strategic alignment, so the trap is picking the low-cost outsourcing or standardization option when the business goal is speed and growth.

How to eliminate wrong answers

Option A is wrong because standardizing all IT systems reduces complexity but can slow innovation and does not directly enable rapid digital product expansion. Option C is wrong because outsourcing to a low-cost provider may reduce cost but does not inherently provide the agility or scalability needed for rapid market expansion. Option D is wrong because minimizing IT investment starves the digital product initiatives that the business strategy depends on.

119
MCQmedium

A company is considering restructuring its IT department from a centralized to a decentralized model to give business units more autonomy. What is a PRIMARY governance risk associated with this move?

A.Difficulty in managing vendor contracts due to decentralization.
B.Reduced innovation due to lack of central coordination.
C.Increased risk of project cost overruns.
D.Inconsistent IT policies and security controls across business units.
AnswerD

Decentralisation pushes policy and control decisions to individual business units, which then apply differing standards. The stem's autonomy constraint means no single authority enforces uniform configuration, so inconsistent IT policies and security controls across business units become the primary governance risk.

Why this answer

Decentralizing IT gives business units autonomy, but the primary governance risk is that each unit may adopt its own policies, standards, and security controls. This fragmentation leads to inconsistent security postures, compliance gaps, and difficulty enforcing enterprise-wide governance. The core risk is loss of centralized control over policy and security consistency.

Exam trap

CISA often tests whether candidates confuse operational risks (cost overruns, vendor management) with governance risks (policy and control consistency), so the trap is picking a cost-related option.

How to eliminate wrong answers

Option A is wrong because vendor contract management can be centralized even in a decentralized IT model, and it is not the primary governance risk. Option B is wrong because decentralization typically increases innovation at the business unit level, not reduces it. Option C is wrong because project cost overruns can occur in any model and are a project management risk, not the primary governance risk of decentralization.

120
MCQmedium

An organization has experienced several security incidents due to unauthorized changes to production systems. Which governance mechanism should be strengthened?

A.IT asset management
B.Configuration management database
C.Incident response plan
D.Change management process
AnswerD

Unauthorised changes to production systems indicate that changes are not being requested, assessed, approved and tracked before implementation. Strengthening change management enforces authorisation, testing and rollback controls, directly preventing the uncontrolled modifications that caused the incidents.

Why this answer

Unauthorized changes to production systems indicate a failure in the change management process, which is designed to control and authorize modifications. Strengthening change management ensures that all changes are reviewed, approved, and documented, reducing the risk of unauthorized alterations. The other mechanisms address asset inventory, configuration data, or incident response, but do not directly prevent unauthorized changes.

Exam trap

CISA often tests the confusion between change management and configuration management; candidates must remember that change management controls modifications, while configuration management tracks the state of assets.

How to eliminate wrong answers

Option A is wrong because IT asset management focuses on tracking hardware and software assets, not on controlling changes to them. Option B is wrong because a configuration management database (CMDB) records configuration items and relationships but does not enforce change approval. Option C is wrong because an incident response plan deals with reacting to incidents, not preventing unauthorized changes.

121
MCQeasy

An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. Which of the following BEST demonstrates that the proposal aligns with the organization's strategic goals?

A.The business case includes a clear link to the organization's five-year strategic plan.
B.The project manager has extensive experience with CRM implementations.
C.The proposed system includes advanced analytics capabilities.
D.The vendor offers discounted licensing for the first year.
AnswerA

A business case explicitly linking the CRM proposal to the five-year strategic plan demonstrates traceable alignment with stated organisational objectives. This direct mapping gives the steering committee the clearest evidence that the investment supports long-term goals rather than isolated departmental needs.

Why this answer

The business case including a clear link to the organization's five-year strategic plan directly demonstrates alignment with strategic goals. This shows that the CRM proposal is not just a tactical IT purchase but is explicitly tied to the long-term objectives of the organization, which is the best evidence of strategic alignment.

Exam trap

CISA often tests the difference between tactical benefits (features, cost savings) and strategic alignment, where candidates may be distracted by attractive features or cost reductions.

How to eliminate wrong answers

Option B is wrong because the project manager's experience, while valuable, does not demonstrate that the CRM system aligns with strategic goals; it only speaks to execution capability. Option C is wrong because advanced analytics capabilities are a feature, not evidence of strategic alignment; the system could have advanced analytics but still not support the organization's strategy. Option D is wrong because discounted licensing is a financial incentive, not a strategic alignment factor; it may reduce cost but does not show how the system supports strategic objectives.

← PreviousPage 2 of 2 · 121 questions total

Ready to test yourself?

Try a timed practice session using only It Governance Mgmt questions.