CISA Governance and Management of IT: 89 practice questions
12 of the 89 Governance and Management of IT questions in the Certsqill CISA bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.
Preparing for CISA? Take the free 5-min readiness check →
1. Evaluating stakeholder needs and setting enterprise: In the COBIT 2019 framework, which of the following is an
- Evaluating stakeholder needs and setting enterprise direction and priorities for the use of IT ✓Correct. COBIT 2019 places governance in the Evaluate, Direct and Monitor (EDM) domain: the board evaluates stakeholder needs, sets direction through prioritization and decision-making, and monitors performance against that direction.
- Building, acquiring, and implementing technology solutions to satisfy the business requirements that have already been formally approvedIncorrect. Building and acquiring is a management activity in the COBIT Build, Acquire and Implement (BAI) domain, which executes within the direction that governance has set.
- Running and supporting IT services against agreed service levelsIncorrect. Operating and supporting services is a management activity in the Deliver, Service and Support (DSS) domain, not a governance role.
- Planning the day-to-day allocation of operational IT staff to ticketsIncorrect. Operational resource scheduling is a low-level management task; governance sets direction and priorities, it does not manage daily operations.
Governance (EDM) evaluates, directs and monitors; management (APO/BAI/DSS/MEA) plans, builds, runs and monitors within that direction.
2. The board of directors: Ultimate accountability for the governance of enterprise IT rests with which of the fo
- The board of directors ✓Correct. Governance of enterprise IT is a board responsibility; the board is ultimately accountable to stakeholders for ensuring IT delivers value and that IT-related risk is managed, even when it delegates execution.
- The chief information officer (CIO)Incorrect. The CIO is accountable for managing IT and executing strategy, but the ultimate accountability for governance and for stakeholder value remains with the board.
- The IT steering committeeIncorrect. The steering committee prioritizes and oversees initiatives on management's behalf, but it does not carry the board's ultimate accountability to stakeholders.
- The information systems auditorIncorrect. The IS auditor provides independent assurance over governance; it cannot be accountable for the governance it must objectively evaluate.
The board of directors holds ultimate accountability for governance of enterprise IT.
3. A framework for the governance and management: What does the COBIT 2019 framework primarily provide to an ente
- A framework for the governance and management of enterprise IT ✓Correct. COBIT 2019 is a business framework for the governance and management of enterprise IT (EGIT), offering governance/management objectives, principles and design guidance.
- A prescriptive software development lifecycle methodologyIncorrect. Software development methodologies (e.g., Agile, waterfall) address how systems are built; COBIT addresses governing and managing IT overall, not coding lifecycles.
- A project management body of knowledge for scheduling and cost controlIncorrect. Project scheduling and cost control are covered by project management standards; COBIT is broader and focused on governance and management of IT.
- A technical standard for network segmentation and firewall configurationIncorrect. Technical configuration standards address specific controls; COBIT is a governance and management framework, not a device configuration standard.
COBIT 2019 is a framework for the governance and management of enterprise IT (EGIT).
4. ensure IT investments and plans enable the enterprise's: The PRIMARY purpose of aligning the IT strategy with
- ensure IT investments and plans enable the enterprise's business objectives ✓Correct. Strategic alignment exists so that IT direction, investment and capabilities are driven by, and demonstrably support, the enterprise's business objectives and desired value.
- maximize the utilization of existing servers and storage hardwareIncorrect. Maximizing hardware utilization is an operational efficiency goal; alignment is about supporting business objectives, which may or may not favor higher utilization.
- allow the IT function to set its technology direction independently of the businessIncorrect. Independence from the business is the opposite of alignment and typically results in investments that deliver little business value.
- standardize employee desktop images and software buildsIncorrect. Standardizing builds is a narrow operational task; strategic alignment concerns the direction of IT relative to enterprise goals, not endpoint standardization.
Alignment ensures IT plans and investments enable the enterprise's business objectives.
5. As mandatory minimum requirements that the policies must: When an organization develops its IT policies, how s
- As automatically superseded by any adopted industry standardIncorrect. Voluntary industry standards do not override statutory obligations; where they conflict, the law prevails and standards supplement it.
- As mandatory minimum requirements that the policies must meet or exceed ✓Correct. Laws and regulations are non-negotiable obligations; internal policies must at least satisfy them and may impose stricter controls where the enterprise chooses.
- As optional guidance to be adopted selectively only in the areas where a formal cost-benefit analysis shows compliance to be worthwhileIncorrect. Legal obligations are mandatory; treating compliance as a cost-benefit choice exposes the organization to penalties and liability.
- As matters relevant only to the legal department and not to IT policyIncorrect. Many regulations impose specific IT control obligations, so they must be reflected in IT policies, not siloed in legal.
Legal and regulatory requirements are mandatory minimums that IT policies must meet or exceed.
6. The IT strategy committee: Which body is typically established to advise the board of directors on the strateg
- The IT strategy committee ✓Correct. An IT strategy committee operates at the board level and advises the board on IT strategic direction, alignment and the value of major IT investments.
- The IT steering committeeIncorrect. The steering committee operates at the management/executive level to prioritize and oversee initiatives; it implements direction rather than advising the board on it.
- The change advisory board (CAB)Incorrect. A CAB assesses and authorizes individual changes to production; it is an operational change-management body, not a strategic advisory group.
- The IT operations teamIncorrect. IT operations runs and supports services day to day and has no mandate to advise the board on strategy.
The board-level IT strategy committee advises the board on IT direction and investment value.
7. Without business representation: Which of the following is the auditor's GREATEST concern?
- Without business representation, the committee cannot ensure IT investments reflect enterprise priorities ✓Correct. A steering committee dominated by IT lacks the business perspective needed to prioritize investments by business value, which directly explains the misaligned, over-budget outcomes observed.
- The committee should be chaired by the internal audit manager so that its investment decisions retain independence and objectivityIncorrect. Audit must remain independent of management decisions; placing audit in charge of steering would destroy its ability to provide objective assurance over those decisions.
- The committee is not performing the detailed technical design reviews of each projectIncorrect. Detailed technical design is a project-team responsibility; the steering committee sets priorities and oversees alignment, so this is not its role.
- The committee meets too infrequently to track individual sprint velocityIncorrect. Tracking sprint velocity is delivery-team detail; a governance/oversight body should monitor value and alignment, not day-to-day agile metrics.
An IT-only steering committee cannot prioritize by business value, producing misaligned, over-budget projects.
8. The IT strategy is not aligned with the business strategy: Which of the following should be the IS auditor's P
- The IT strategy is not aligned with the business strategy, so investments may not deliver business value ✓Correct. Technology adopted without linkage to business objectives signals a breakdown in strategic alignment, the central risk being spend that yields no business value.
- The emerging technologies may not yet have vendor certificationsIncorrect. Certification maturity is a narrower operational/vendor concern; the overriding governance issue is that the investments are not tied to business objectives.
- The IT department has not documented the rollback procedures for each technologyIncorrect. Rollback procedures are an operational change-management control; they do not address why the technologies were chosen without business justification.
- The help desk has not been trained to support the new technologiesIncorrect. Support readiness matters operationally but is secondary to the strategic problem that the investments lack any business-objective basis.
Adopting technology unlinked to the business plan is a strategic alignment failure risking wasted value.
9. Evaluate, Direct and Monitor: In COBIT 2019, these responsibilities fall within which domain?
- Deliver, Service and Support (DSS)Incorrect. DSS is a management domain for operating and supporting services; it does not encompass board-level governance responsibilities.
- Evaluate, Direct and Monitor (EDM) ✓Correct. EDM is the single governance domain in COBIT 2019; its objectives cover evaluating stakeholder needs, directing through prioritization, and monitoring achievement of that direction and value delivery.
- Align, Plan and Organize (APO)Incorrect. APO is a management domain covering how IT is planned and organized to execute strategy; it acts within direction set by governance rather than setting that direction.
- Build, Acquire and Implement (BAI)Incorrect. BAI is a management domain concerned with delivering solutions, not with the board's evaluate/direct/monitor governance role.
Board-level evaluate/direct/monitor responsibilities belong to COBIT 2019's governance domain, EDM.
10. Expand board reporting to cover IT value delivery: Which of the following is the IS auditor's BEST recommendat
- Expand board reporting to cover IT value delivery, risk and strategic alignment, not just operational availability ✓Correct. Governance reporting to the board should let directors evaluate value, risk and alignment; uptime alone tells the board nothing about whether IT is delivering business value or managing risk.
- Replace uptime reporting with detailed mean-time-to-repair and mean-time-between-failure statistics compiled separately for each individual serverIncorrect. MTTR is another operational metric; substituting one operational figure for another still fails to give the board governance-level insight.
- Discontinue board IT reporting because availability is already highIncorrect. High availability does not indicate that IT is aligned, well-governed or delivering value; removing reporting would blind the board to governance risks.
- Route the uptime report to the help desk supervisor instead of the boardIncorrect. Redirecting an operational metric to operations does not address the board's need for governance-relevant information.
Board IT reporting must convey value, risk and alignment, not just operational uptime.
11. Establish an ongoing process to monitor regulatory changes: Which of the following would BEST strengthen the o
- Establish an ongoing process to monitor regulatory changes and assess their impact on IT controls ✓Correct. A defined, continuous monitoring-and-impact-assessment process lets the organization adapt controls before violations occur, rather than reacting to audit findings after the fact.
- Wait for the annual external audit and remediate whatever gaps are reportedIncorrect. Relying on annual external findings is reactive and leaves the organization non-compliant between audits, exactly the weakness identified.
- Adopt a single international standard and assume that certifying against it automatically satisfies all present and future local regulatory obligationsIncorrect. Voluntary standards do not guarantee coverage of specific local statutes; assuming they do creates undetected compliance gaps.
- Delegate all regulatory interpretation to the IT operations managerIncorrect. Interpreting frequently changing regulations is a specialized compliance/governance function; assigning it to operations lacks the required expertise and independence.
A continuous process to monitor regulatory change and assess its control impact beats reactive, audit-driven fixes.
12. Setting the enterprise's risk appetite is a governance: Which of the following should be the IS auditor's PRIM
- Setting the enterprise's risk appetite is a governance decision that should be owned by the board, not by management ✓Correct. Risk appetite expresses the level of risk the enterprise is willing to accept in pursuit of objectives; establishing it is a board governance responsibility, so a unilateral CIO decision represents a governance breakdown.
- The CIO did not circulate the risk appetite statement to the help desk for commentIncorrect. Wide consultation with operations is not the core issue; the fundamental problem is that a management role made a decision reserved to governance.
- The risk appetite statement was not written in the corporate template formatIncorrect. Formatting is trivial compared with the fact that the decision was made at the wrong level of the organization.
- The CIO should have encrypted the risk appetite document before distributionIncorrect. Document confidentiality is unrelated; the governance issue is that risk appetite must be set by the board, not unilaterally by the CIO.
Defining risk appetite is a board-level governance decision, not something a CIO sets unilaterally.
77 more Governance and Management of IT questions
The remaining 77 questions in this domain are part of the full CISA bank — 496 questions, every option explained. Start with the free five-minute check and see your score per domain.
Test your CISA readiness — freeOther CISA domains
- Information Systems Operations and Business Resilience — 129 questions →
- Protection of Information Assets — 129 questions →
- Information Systems Auditing Process — 89 questions →
- Information Systems Acquisition, Development and Implementation — 60 questions →
- All 496 CISA questions →