hardMultiple Select
CISA Practice Question: Which TWO of the following are indicators of poor…
Which TWO of the following are indicators of poor project governance that an IS auditor should identify?
⚠ Common exam trap
It's easy for candidates to confuse agile methodology with poor governance, but agile includes its own governance mechanisms (e.g., sprint reviews, backlog grooming, definition of done) that, when followed, do not indicate weak oversight.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Scope changes are frequently requested and approved verbally.
Option A is correct because approving scope changes verbally indicates a lack of formal change control procedures, which is a hallmark of poor project governance; without documented approval, scope creep and accountability issues arise. Option B is correct because inconsistent progress reports lacking key metrics (e.g., earned value, schedule variance, milestone completion) mean the project lacks reliable monitoring and oversight, preventing stakeholders from making informed decisions. Option C is not an indicator of poor governance because agile methodology is a legitimate, structured project management approach when properly governed. Option D is not an indicator of poor governance because weekly status meetings are a normal and often beneficial communication practice. Option E is not an indicator of poor governance because reallocating budget across phases can be a legitimate, approved response to changing project needs when done through proper change control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Scope changes are frequently requested and approved verbally.
Why this is correct
Verbal approval of frequent scope changes bypasses formal change control, the mechanism that preserves baselined scope, cost and schedule. This directly evidences weak governance, since the stem asks for indicators of poor project governance: undocumented, unauthorised scope creep escapes audit trail and steering committee oversight.
- ✓
Project progress reports are inconsistent and lack key metrics.
Why this is correct
Inconsistent progress reports lacking key metrics signal weak governance because the steering committee cannot monitor scope, schedule, or budget against baselines, preventing informed decisions. This directly satisfies the stem's requirement to identify poor governance indicators, as unreliable reporting undermines oversight, accountability, and early risk detection.
- ✗
Project team uses an agile methodology.
Why it's wrong here
Agile delivery is a legitimate methodology choice; governance quality depends on oversight of scope, risk and deliverables, not on waterfall versus iterative working. Agile would be the correct answer only if the organisation mandated waterfall and the team bypassed that approved standard.
- ✗
Project status meetings are held weekly.
Why it's wrong here
Weekly status meetings are routine project communication and evidence of active monitoring, not a governance deficiency. Meeting frequency becomes an indicator only when meetings are skipped, undocumented or lack decision-making authority over scope, budget and risk.
- ✗
The project budget is reallocated across phases.
Why it's wrong here
Reallocating budget between phases is normal portfolio and financial management, reflecting revised estimates or reprioritised scope, and is not itself a governance weakness. It would warrant audit attention only if done without approved change control or documented justification.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.