Courseiva

CISA Governance and Management of IT Practice Question

Which TWO of the following are key responsibilities of an IT steering committee?

⚠ Common exam trap

A common mix-up: candidates confuse governance responsibilities (steering committee) with management or execution tasks (operations, coding, auditing), leading candidates to select options that sound plausible but belong to lower-level roles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Monitoring IT performance and value delivery

The IT steering committee is a senior-level governance body responsible for aligning IT strategy with business objectives. Monitoring IT performance and value delivery (A) is a key responsibility because the committee must ensure that IT investments generate the expected business benefits and that service levels meet agreed targets. Prioritizing IT projects and allocating resources (D) is also a core duty, as the committee decides which initiatives receive funding and staffing based on strategic importance and risk, rather than operational urgency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Monitoring IT performance and value delivery

    Why this is correct

    Monitoring IT performance and value delivery is a steering committee duty because the committee oversees whether IT investments deliver expected business benefits. It satisfies the governance constraint by providing ongoing oversight and accountability rather than day-to-day operational management.

  • ✗

    Managing day-to-day IT operations

    Why it's wrong here

    Day-to-day operational management belongs to IT operations management under the CIO, whereas a steering committee meets periodically to prioritise, fund and monitor the IT portfolio. It is tempting because the committee does oversee operational performance, but directing daily incidents and tasks is an execution responsibility, not governance.

  • ✗

    Writing and testing application code

    Why it's wrong here

    Coding and testing are delivery activities performed by development teams under change control; a steering committee sets priorities, approves funding and resolves escalations. It is tempting because the committee approves projects that produce code, yet writing that code sits with engineering, not governance.

  • ✓

    Prioritizing IT projects and allocating resources

    Why this is correct

    Prioritising IT projects and allocating resources is a steering committee responsibility because the committee arbitrates competing demands and aligns IT investment with strategic objectives. It satisfies the governance constraint by ensuring funding decisions rest with cross-functional executive authority.

  • ✗

    Conducting IT audit engagements

    Why it's wrong here

    Audit engagements are executed by internal audit or an independent assurance function, which reports objectively to the board; a steering committee that audits its own programmes destroys that independence. It is tempting because the committee does oversee IT risk and controls, but its role is governance direction, not performing assurance work.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.