CISA IT Governance and Strategy 3 — Questions and Answers
Question 1: Which metric BEST measures the effectiveness of IT governance in delivering business value?
- Number of IT staff certifications
- Return on IT investments (ROI) (Correct answer)
- Server uptime percentage
- Number of IT projects initiated per year
Correct answer: Return on IT investments (ROI)
ROI on IT investments directly measures whether IT is delivering measurable business value, which is the core objective of IT governance.
Question 2: In the context of IT governance, 'strategic alignment' means:
- IT and business strategies are synchronized so IT supports business goals (Correct answer)
- All IT systems are integrated into a single platform
- IT projects are always delivered on schedule
- The CIO reports directly to the CEO
Correct answer: IT and business strategies are synchronized so IT supports business goals
Strategic alignment ensures that IT plans, priorities, and investments are directly linked to and supportive of the organization's overall business strategy.
Question 3: During an IT governance audit, the auditor finds that the IT strategy document has not been updated in five years. This is MOST concerning because:
- The document may not reflect current business objectives and technology changes (Correct answer)
- Older documents are harder to read and interpret
- The IT staff may not have printing access
- Five-year-old strategies are always obsolete under COBIT
Correct answer: The document may not reflect current business objectives and technology changes
An outdated IT strategy is a red flag that IT planning may not be aligned with current business needs, regulatory changes, or the evolving technology landscape.
Question 4: A 'governance gap' in IT occurs when:
- There is a difference between the intended governance design and its actual implementation (Correct answer)
- The IT budget exceeds approved limits
- Network latency exceeds acceptable thresholds
- Business users bypass IT approval for new software
Correct answer: There is a difference between the intended governance design and its actual implementation
A governance gap exists when the governance framework as designed does not match how governance is actually practiced within the organization.
Question 5: Which of the following BEST describes the purpose of an IT governance maturity model?
- To benchmark an organization's IT governance practices against defined capability levels (Correct answer)
- To certify IT staff in governance best practices
- To automate IT governance reporting
- To determine the number of governance controls needed
Correct answer: To benchmark an organization's IT governance practices against defined capability levels
A maturity model allows organizations to assess and compare their governance practices against defined levels of capability, guiding improvement efforts.
Question 6: Which of the following represents a KEY principle of IT governance according to ISO/IEC 38500?
- Acquire only proven technology
- Evaluate, direct, and monitor (Correct answer)
- Prioritize cost savings over innovation
- Delegate all IT decisions to the CIO
Correct answer: Evaluate, direct, and monitor
ISO/IEC 38500 defines IT governance through three key principles: evaluate current and future IT use, direct preparation and implementation of plans, and monitor conformance and performance.
Question 7: An organization's IT governance structure should be PRIMARILY designed to:
- Minimize the number of IT projects
- Ensure IT decisions are made at the appropriate organizational level (Correct answer)
- Centralize all IT authority under one executive
- Focus exclusively on cybersecurity risk
Correct answer: Ensure IT decisions are made at the appropriate organizational level
Effective IT governance structures ensure decisions are made by those with the appropriate authority, accountability, and knowledge at each organizational level.
Which metric BEST measures the effectiveness of IT governance in delivering business value?