Courseiva
hardMultiple Select

CISA Practice Question: Which TWO of the following are indicators that a…

Which TWO of the following are indicators that a project is at risk of failure according to ISACA's project governance framework?

⚠ Common exam trap

Test-takers frequently confuse a lack of communication channels with other common risk factors like scope creep, but ISACA specifically lists communication breakdowns as a distinct risk indicator separate from scope change management.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Lack of clear communication channels among team members.

Option B is correct because ISACA's project governance framework identifies poor or unclear communication among team members as a key warning sign of project failure, since it leads to misalignment, unresolved issues, and unmanaged dependencies. Option D is correct because frequent scope changes without formal approval indicate weak change control and governance, which ISACA cites as a major risk factor for cost overruns, schedule slippage, and loss of stakeholder confidence. The remaining options do not indicate risk: regular status meetings with stakeholders (A) and use of a PMO (E) are actually governance-strengthening practices that improve oversight and communication, while adoption of iterative development (C) is a legitimate delivery approach that, when properly governed, supports incremental value delivery rather than signaling failure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Regular status meetings with stakeholders.

    Why it's wrong here

    Regular stakeholder status meetings evidence active communication and governance engagement, which ISACA treats as a health indicator, not a risk signal. It is tempting because frequent meetings can mask underlying issues, yet the framework's risk indicators are absent sponsorship, unclear scope and unrealistic schedules, not structured reporting cadence.

  • ✓

    Lack of clear communication channels among team members.

    Why this is correct

    Weak or absent communication channels prevent risks, dependencies and issues from surfacing to governance bodies, so decisions are made on incomplete information. ISACA's project governance framework treats this breakdown in information flow as a leading indicator of project failure risk.

  • ✗

    Adoption of iterative development.

    Why it's wrong here

    Iterative development is a recognised delivery approach that improves feedback and reduces risk, so it signals healthy practise rather than project failure. It is tempting because iterative methods can appear uncontrolled to plan-driven auditors, but ISACA's risk indicators concern governance gaps such as unclear objectives and missing executive sponsorship.

  • ✓

    Frequent changes to project scope without formal approval.

    Why this is correct

    Unapproved scope changes erode the baseline against which cost, schedule and benefits are measured, bypassing the governance controls that authorise change. ISACA's framework identifies this uncontrolled scope creep as a key indicator that a project is at risk of failure.

  • ✗

    Use of a project management office (PMO).

    Why it's wrong here

    A PMO provides governance, standardised methodology and oversight, all of which ISACA associates with reduced project risk. It is tempting because an overbearing PMO can add bureaucracy, yet the framework's failure indicators are weak sponsorship, scope creep and unrealistic baselines, not the existence of a project management office.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.