CISA Governance and Management of IT: 89 practice questions
7-day money-back guarantee — full refund within 7 days of purchase if you've completed under 20% of the questions. See pricing →
Certifications Tools Flashcards Career Paths Exam Guides Blog Pricing For Teams About

Language

✓ EnglishDeutschEspañolFrançaisPortuguês
Check readiness — free →

CISA Governance and Management of IT: 89 practice questions

CISA 89 questions 12 shown free

12 of the 89 Governance and Management of IT questions in the Certsqill CISA bank, shown in full below. Each one carries an explanation for every option, not just the correct one — the wrong answers are where the marks go.

Preparing for CISA? Take the free 5-min readiness check →

1. Evaluating stakeholder needs and setting enterprise: In the COBIT 2019 framework, which of the following is an

Easy
In the COBIT 2019 framework, which of the following is an activity of GOVERNANCE rather than management?
  1. Evaluating stakeholder needs and setting enterprise direction and priorities for the use of IT
    Correct. COBIT 2019 places governance in the Evaluate, Direct and Monitor (EDM) domain: the board evaluates stakeholder needs, sets direction through prioritization and decision-making, and monitors performance against that direction.
  2. Building, acquiring, and implementing technology solutions to satisfy the business requirements that have already been formally approved
    Incorrect. Building and acquiring is a management activity in the COBIT Build, Acquire and Implement (BAI) domain, which executes within the direction that governance has set.
  3. Running and supporting IT services against agreed service levels
    Incorrect. Operating and supporting services is a management activity in the Deliver, Service and Support (DSS) domain, not a governance role.
  4. Planning the day-to-day allocation of operational IT staff to tickets
    Incorrect. Operational resource scheduling is a low-level management task; governance sets direction and priorities, it does not manage daily operations.
The trap
Assuming that because management also 'monitors' (the MEA domain), any monitoring is governance; monitoring operational service performance is management, whereas governance monitors achievement of the direction it set.

Governance (EDM) evaluates, directs and monitors; management (APO/BAI/DSS/MEA) plans, builds, runs and monitors within that direction.

2. The board of directors: Ultimate accountability for the governance of enterprise IT rests with which of the fo

Easy
Ultimate accountability for the governance of enterprise IT rests with which of the following?
  1. The board of directors
    Correct. Governance of enterprise IT is a board responsibility; the board is ultimately accountable to stakeholders for ensuring IT delivers value and that IT-related risk is managed, even when it delegates execution.
  2. The chief information officer (CIO)
    Incorrect. The CIO is accountable for managing IT and executing strategy, but the ultimate accountability for governance and for stakeholder value remains with the board.
  3. The IT steering committee
    Incorrect. The steering committee prioritizes and oversees initiatives on management's behalf, but it does not carry the board's ultimate accountability to stakeholders.
  4. The information systems auditor
    Incorrect. The IS auditor provides independent assurance over governance; it cannot be accountable for the governance it must objectively evaluate.
The trap
Equating day-to-day management accountability (CIO) with ultimate governance accountability, which remains with the board.

The board of directors holds ultimate accountability for governance of enterprise IT.

3. A framework for the governance and management: What does the COBIT 2019 framework primarily provide to an ente

Easy
What does the COBIT 2019 framework primarily provide to an enterprise?
  1. A framework for the governance and management of enterprise IT
    Correct. COBIT 2019 is a business framework for the governance and management of enterprise IT (EGIT), offering governance/management objectives, principles and design guidance.
  2. A prescriptive software development lifecycle methodology
    Incorrect. Software development methodologies (e.g., Agile, waterfall) address how systems are built; COBIT addresses governing and managing IT overall, not coding lifecycles.
  3. A project management body of knowledge for scheduling and cost control
    Incorrect. Project scheduling and cost control are covered by project management standards; COBIT is broader and focused on governance and management of IT.
  4. A technical standard for network segmentation and firewall configuration
    Incorrect. Technical configuration standards address specific controls; COBIT is a governance and management framework, not a device configuration standard.
The trap
Mistaking COBIT for a lifecycle, project, or technical standard because auditors encounter those alongside it; COBIT sits above them as a governance/management framework.

COBIT 2019 is a framework for the governance and management of enterprise IT (EGIT).

4. ensure IT investments and plans enable the enterprise's: The PRIMARY purpose of aligning the IT strategy with

Easy
The PRIMARY purpose of aligning the IT strategy with the business strategy is to:
  1. ensure IT investments and plans enable the enterprise's business objectives
    Correct. Strategic alignment exists so that IT direction, investment and capabilities are driven by, and demonstrably support, the enterprise's business objectives and desired value.
  2. maximize the utilization of existing servers and storage hardware
    Incorrect. Maximizing hardware utilization is an operational efficiency goal; alignment is about supporting business objectives, which may or may not favor higher utilization.
  3. allow the IT function to set its technology direction independently of the business
    Incorrect. Independence from the business is the opposite of alignment and typically results in investments that deliver little business value.
  4. standardize employee desktop images and software builds
    Incorrect. Standardizing builds is a narrow operational task; strategic alignment concerns the direction of IT relative to enterprise goals, not endpoint standardization.
The trap
Confusing operational efficiency measures (utilization, standardization) with the strategic purpose of alignment, which is enabling business objectives.

Alignment ensures IT plans and investments enable the enterprise's business objectives.

5. As mandatory minimum requirements that the policies must: When an organization develops its IT policies, how s

Easy
When an organization develops its IT policies, how should applicable legal and regulatory requirements be treated?
  1. As automatically superseded by any adopted industry standard
    Incorrect. Voluntary industry standards do not override statutory obligations; where they conflict, the law prevails and standards supplement it.
  2. As mandatory minimum requirements that the policies must meet or exceed
    Correct. Laws and regulations are non-negotiable obligations; internal policies must at least satisfy them and may impose stricter controls where the enterprise chooses.
  3. As optional guidance to be adopted selectively only in the areas where a formal cost-benefit analysis shows compliance to be worthwhile
    Incorrect. Legal obligations are mandatory; treating compliance as a cost-benefit choice exposes the organization to penalties and liability.
  4. As matters relevant only to the legal department and not to IT policy
    Incorrect. Many regulations impose specific IT control obligations, so they must be reflected in IT policies, not siloed in legal.
The trap
Believing that adopting a respected industry standard, or applying a cost-benefit test, can substitute for meeting a binding legal requirement.

Legal and regulatory requirements are mandatory minimums that IT policies must meet or exceed.

6. The IT strategy committee: Which body is typically established to advise the board of directors on the strateg

Easy
Which body is typically established to advise the board of directors on the strategic direction and value of IT investments?
  1. The IT strategy committee
    Correct. An IT strategy committee operates at the board level and advises the board on IT strategic direction, alignment and the value of major IT investments.
  2. The IT steering committee
    Incorrect. The steering committee operates at the management/executive level to prioritize and oversee initiatives; it implements direction rather than advising the board on it.
  3. The change advisory board (CAB)
    Incorrect. A CAB assesses and authorizes individual changes to production; it is an operational change-management body, not a strategic advisory group.
  4. The IT operations team
    Incorrect. IT operations runs and supports services day to day and has no mandate to advise the board on strategy.
The trap
Swapping the board-level strategy committee with the management-level steering committee; the former advises the board, the latter executes prioritization.

The board-level IT strategy committee advises the board on IT direction and investment value.

7. Without business representation: Which of the following is the auditor's GREATEST concern?

Medium
At Fjordhaug Aquaculture, a Nordic salmon-farming company, IT projects routinely overrun budget and deliver features the business units say they never requested. The IS auditor finds that the IT steering committee is composed entirely of IT department managers. Which of the following is the auditor's GREATEST concern?
  1. Without business representation, the committee cannot ensure IT investments reflect enterprise priorities
    Correct. A steering committee dominated by IT lacks the business perspective needed to prioritize investments by business value, which directly explains the misaligned, over-budget outcomes observed.
  2. The committee should be chaired by the internal audit manager so that its investment decisions retain independence and objectivity
    Incorrect. Audit must remain independent of management decisions; placing audit in charge of steering would destroy its ability to provide objective assurance over those decisions.
  3. The committee is not performing the detailed technical design reviews of each project
    Incorrect. Detailed technical design is a project-team responsibility; the steering committee sets priorities and oversees alignment, so this is not its role.
  4. The committee meets too infrequently to track individual sprint velocity
    Incorrect. Tracking sprint velocity is delivery-team detail; a governance/oversight body should monitor value and alignment, not day-to-day agile metrics.
The trap
Reaching for a technical or scheduling fix when the root cause is governance composition: no business voice in investment prioritization.

An IT-only steering committee cannot prioritize by business value, producing misaligned, over-budget projects.

8. The IT strategy is not aligned with the business strategy: Which of the following should be the IS auditor's P

Medium
Meridian Rail Freight's IT department has independently adopted several emerging technologies over the past year, none of which trace to the company's published three-year business plan. Which of the following should be the IS auditor's PRIMARY concern?
  1. The IT strategy is not aligned with the business strategy, so investments may not deliver business value
    Correct. Technology adopted without linkage to business objectives signals a breakdown in strategic alignment, the central risk being spend that yields no business value.
  2. The emerging technologies may not yet have vendor certifications
    Incorrect. Certification maturity is a narrower operational/vendor concern; the overriding governance issue is that the investments are not tied to business objectives.
  3. The IT department has not documented the rollback procedures for each technology
    Incorrect. Rollback procedures are an operational change-management control; they do not address why the technologies were chosen without business justification.
  4. The help desk has not been trained to support the new technologies
    Incorrect. Support readiness matters operationally but is secondary to the strategic problem that the investments lack any business-objective basis.
The trap
Being drawn to concrete operational gaps (rollback, training) and missing that the primary issue is strategic misalignment of the investments themselves.

Adopting technology unlinked to the business plan is a strategic alignment failure risking wasted value.

9. Evaluate, Direct and Monitor: In COBIT 2019, these responsibilities fall within which domain?

Medium
A Vietnamese textile exporter wants to ensure that its board evaluates stakeholder needs, sets clear direction for the use of IT, and monitors whether that direction is being followed to optimize value. In COBIT 2019, these responsibilities fall within which domain?
  1. Deliver, Service and Support (DSS)
    Incorrect. DSS is a management domain for operating and supporting services; it does not encompass board-level governance responsibilities.
  2. Evaluate, Direct and Monitor (EDM)
    Correct. EDM is the single governance domain in COBIT 2019; its objectives cover evaluating stakeholder needs, directing through prioritization, and monitoring achievement of that direction and value delivery.
  3. Align, Plan and Organize (APO)
    Incorrect. APO is a management domain covering how IT is planned and organized to execute strategy; it acts within direction set by governance rather than setting that direction.
  4. Build, Acquire and Implement (BAI)
    Incorrect. BAI is a management domain concerned with delivering solutions, not with the board's evaluate/direct/monitor governance role.
The trap
Choosing APO because it contains the word 'plan' and sounds strategic; APO is management, whereas evaluate/direct/monitor is the governance domain EDM.

Board-level evaluate/direct/monitor responsibilities belong to COBIT 2019's governance domain, EDM.

10. Expand board reporting to cover IT value delivery: Which of the following is the IS auditor's BEST recommendat

Medium
The board of Talava Pathology Labs receives a quarterly IT report that shows only system uptime percentages. Which of the following is the IS auditor's BEST recommendation?
  1. Expand board reporting to cover IT value delivery, risk and strategic alignment, not just operational availability
    Correct. Governance reporting to the board should let directors evaluate value, risk and alignment; uptime alone tells the board nothing about whether IT is delivering business value or managing risk.
  2. Replace uptime reporting with detailed mean-time-to-repair and mean-time-between-failure statistics compiled separately for each individual server
    Incorrect. MTTR is another operational metric; substituting one operational figure for another still fails to give the board governance-level insight.
  3. Discontinue board IT reporting because availability is already high
    Incorrect. High availability does not indicate that IT is aligned, well-governed or delivering value; removing reporting would blind the board to governance risks.
  4. Route the uptime report to the help desk supervisor instead of the board
    Incorrect. Redirecting an operational metric to operations does not address the board's need for governance-relevant information.
The trap
Judging IT reporting by whether metrics look healthy rather than whether they inform the board's governance responsibilities of value, risk and alignment.

Board IT reporting must convey value, risk and alignment, not just operational uptime.

11. Establish an ongoing process to monitor regulatory changes: Which of the following would BEST strengthen the o

Medium
Andesol Energy has just begun operating in a country whose IT-related regulations change frequently. The compliance team currently updates controls only after an external auditor flags a gap. Which of the following would BEST strengthen the organization's regulatory governance?
  1. Establish an ongoing process to monitor regulatory changes and assess their impact on IT controls
    Correct. A defined, continuous monitoring-and-impact-assessment process lets the organization adapt controls before violations occur, rather than reacting to audit findings after the fact.
  2. Wait for the annual external audit and remediate whatever gaps are reported
    Incorrect. Relying on annual external findings is reactive and leaves the organization non-compliant between audits, exactly the weakness identified.
  3. Adopt a single international standard and assume that certifying against it automatically satisfies all present and future local regulatory obligations
    Incorrect. Voluntary standards do not guarantee coverage of specific local statutes; assuming they do creates undetected compliance gaps.
  4. Delegate all regulatory interpretation to the IT operations manager
    Incorrect. Interpreting frequently changing regulations is a specialized compliance/governance function; assigning it to operations lacks the required expertise and independence.
The trap
Treating compliance as a periodic remediation exercise driven by audit findings rather than as a continuous governance process.

A continuous process to monitor regulatory change and assess its control impact beats reactive, audit-driven fixes.

12. Setting the enterprise's risk appetite is a governance: Which of the following should be the IS auditor's PRIM

Medium
At Cobalt Peak Mining, the CIO unilaterally decided and documented the enterprise's IT risk appetite and communicated it to staff as approved policy. Which of the following should be the IS auditor's PRIMARY concern?
  1. Setting the enterprise's risk appetite is a governance decision that should be owned by the board, not by management
    Correct. Risk appetite expresses the level of risk the enterprise is willing to accept in pursuit of objectives; establishing it is a board governance responsibility, so a unilateral CIO decision represents a governance breakdown.
  2. The CIO did not circulate the risk appetite statement to the help desk for comment
    Incorrect. Wide consultation with operations is not the core issue; the fundamental problem is that a management role made a decision reserved to governance.
  3. The risk appetite statement was not written in the corporate template format
    Incorrect. Formatting is trivial compared with the fact that the decision was made at the wrong level of the organization.
  4. The CIO should have encrypted the risk appetite document before distribution
    Incorrect. Document confidentiality is unrelated; the governance issue is that risk appetite must be set by the board, not unilaterally by the CIO.
The trap
Focusing on process cosmetics (consultation, template, encryption) instead of the decision-rights violation: management set a governance-level parameter.

Defining risk appetite is a board-level governance decision, not something a CIO sets unilaterally.

77 more Governance and Management of IT questions

The remaining 77 questions in this domain are part of the full CISA bank — 496 questions, every option explained. Start with the free five-minute check and see your score per domain.

Test your CISA readiness — free

Other CISA domains

Part of the Certsqill CISA question bank · Governance and Management of IT · Every answer, right and wrong, comes with its own explanation.