CISA Governance and Management of IT Practice Question
Which THREE of the following are responsibilities of the board of directors regarding IT governance? (Choose three.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Approving the IT strategy
Correct answers: B, C, E. The board is responsible for approving the IT strategy (B), reviewing and approving IT policies (C), and ensuring that IT risks are managed within acceptable levels (E). Implementing IT security controls (A) is a management duty, and monitoring daily IT operations (D) is an operational responsibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implementing IT security controls
Why it's wrong here
Implementation is management's role.
- ✓
Approving the IT strategy
Why this is correct
Board approves strategic direction.
- ✓
Reviewing and approving IT policies
Why this is correct
Policy approval is a board function.
- ✗
Monitoring daily IT operations
Why it's wrong here
Daily operations are management's responsibility.
- ✓
Ensuring that IT risks are managed within acceptable levels
Why this is correct
Board oversees risk management.
Go deeper
Related to this question
About these practice questions
One of 995 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.