Courseiva
Governance and Management of ITmediumMultiple SelectObjective-mapped

CISA Governance and Management of IT Practice Question

Which TWO of the following are key responsibilities of an IT steering committee?

⚠ Common exam trap

Many candidates confuse strategic governance roles (steering committee) with operational or technical roles (system administrators, developers, or network engineers), leading candidates to select hands-on tasks like monitoring, coding, or firewall configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Approving the annual IT budget and major capital expenditures

The IT steering committee is a senior-level governance body responsible for aligning IT strategy with business objectives. Approving the annual IT budget and major capital expenditures (A) is a core fiduciary duty, ensuring resources are allocated to approved projects and initiatives. Defining IT policies and standards (C) establishes the governance framework for security, compliance, and operational consistency across the enterprise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Approving the annual IT budget and major capital expenditures

    Why this is correct

    The steering committee typically approves the IT budget and major expenditures to ensure alignment with business strategy.

  • Performing daily system monitoring and incident response

    Why it's wrong here

    Daily monitoring is an operational task handled by IT operations, not the steering committee.

  • Defining IT policies and standards

    Why this is correct

    The steering committee sets high-level policies and standards to guide IT governance.

  • Writing application code for new software features

    Why it's wrong here

    Coding is a development task, not a governance responsibility.

  • Configuring firewall rules and network access controls

    Why it's wrong here

    Network configuration is an operational or security task, not a steering committee function.

About these practice questions

This CISA question is part of Courseiva's 995-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on CISA

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. What is the committee's MOST important role?

medium
  • A.Approving technical specifications
  • B.Selecting the vendor
  • C.Ensuring alignment with business objectives
  • D.Managing the project budget

Why C: The IT steering committee's most important role is to ensure that proposed IT projects align with the organization's business objectives. Option A is incorrect as technical specifications are typically reviewed by technical architects or engineering teams. Option B is incorrect because vendor selection is often a procurement or business decision, and while the committee may provide input, it is not their primary role. Option D is incorrect because managing the project budget is the responsibility of the project manager and project team, not the steering committee.

Variation 2. An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. Which of the following BEST demonstrates that the proposal aligns with the organization's strategic goals?

easy
  • A.The business case includes a clear link to the organization's five-year strategic plan.
  • B.The project manager has extensive experience with CRM implementations.
  • C.The proposed system includes advanced analytics capabilities.
  • D.The vendor offers discounted licensing for the first year.

Why A: A clear link to the organization's five-year strategic plan demonstrates that the proposal aligns with strategic goals. Option B is about the project manager's experience, which does not indicate strategic alignment. Option C describes a feature that may be beneficial but is not inherently tied to strategic goals. Option D is a cost-saving tactic, not evidence of strategic alignment.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.