CISA Governance and Management of IT Practice Question
Which THREE of the following are responsibilities of the board of directors regarding IT governance? (Choose three.)
⚠ Common exam trap
CISA often tests the distinction between governance and management responsibilities; candidates may incorrectly assign operational tasks like implementing controls or designing architecture to the board.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Setting IT risk appetite
Option B is correct because setting the IT risk appetite is a core board-level governance responsibility: the board defines how much risk the organization is willing to accept in pursuit of its objectives, which then guides management's risk decisions. Option C is correct because reviewing IT performance is a board oversight duty — the board monitors whether IT is delivering value, meeting objectives, and staying within risk tolerances, typically through metrics and reporting. Option E is correct because approving IT strategy is a fundamental board responsibility, ensuring IT initiatives align with and support the enterprise's overall business strategy and goals. Options A and D are not board responsibilities: designing network security architecture (A) and implementing IT controls (D) are hands-on operational and technical tasks performed by IT management and staff, not by the board, which focuses on direction, oversight, and accountability rather than execution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Designing network security architecture
Why it's wrong here
Network security architecture design is an operational/technical task executed by security architects and IT staff, not a governance duty of the board. It tempts because boards do approve security strategy and risk appetite, but detailed architecture design sits below the oversight layer the board occupies.
- ✓
Setting IT risk appetite
Why this is correct
Setting IT risk appetite is a board-level governance duty: it defines how much technology risk the enterprise will accept in pursuit of objectives. Management then operates within that tolerance, giving the board the boundary against which IT risk decisions are escalated and measured.
- ✓
Reviewing IT performance
Why this is correct
Reviewing IT performance lets the board confirm that technology delivers value and remains aligned with strategy. Management supplies metrics and reports; the board evaluates them, satisfying the governance requirement for independent oversight rather than day-to-day operational involvement.
- ✗
Implementing IT controls
Why it's wrong here
Implementing IT controls is management's execution work, performed by IT and control owners, not the board. It tempts because the board does set control expectations and monitors their effectiveness, yet hands-on implementation belongs to executive management under governance direction.
- ✓
Approving IT strategy
Why this is correct
IT strategy approval sits with the board because it aligns technology investment with enterprise objectives and risk tolerance. Management drafts and executes the strategy; the board retains authority to sanction it, satisfying the governance requirement for direction-setting and oversight of IT.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CISA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE of the following are responsibilities of the board of directors regarding IT governance? (Choose three.)
hard- A.Implementing IT security controls
- ✓ B.Approving the IT strategy
- ✓ C.Reviewing and approving IT policies
- D.Monitoring daily IT operations
- ✓ E.Ensuring that IT risks are managed within acceptable levels
Why B: Option B is correct because the board of directors is responsible for approving the organization's IT strategy, ensuring it aligns with business objectives and long-term goals. Option C is correct because reviewing and approving IT policies is a core governance duty that sets the direction and boundaries for how IT is managed and controlled. Option E is correct because the board must ensure that IT risks are managed within acceptable levels, which is a fundamental element of IT governance and risk oversight. Option A is incorrect because implementing IT security controls is an operational/management responsibility, typically carried out by IT staff, not the board. Option D is incorrect because monitoring daily IT operations is an operational task performed by IT management and staff, not a board-level governance responsibility.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.