CISA IT Governance and Strategy 4 — Questions and Answers
Question 1: When reviewing IT governance, an auditor discovers that business units independently purchase software without IT involvement. This PRIMARILY indicates a weakness in:
- Change management
- IT demand management and governance oversight (Correct answer)
- Disaster recovery planning
- Application security testing
Correct answer: IT demand management and governance oversight
Shadow IT (business units procuring technology without IT oversight) signals a breakdown in IT demand management and governance authority.
Question 2: A CISA auditing IT strategy would MOST likely review which document to assess strategic alignment?
- IT architecture diagrams
- IT strategic plan compared against the enterprise strategic plan (Correct answer)
- Vendor contract terms
- Network security policies
Correct answer: IT strategic plan compared against the enterprise strategic plan
Comparing the IT strategic plan to the enterprise strategic plan directly reveals whether IT goals are aligned with organizational objectives.
Question 3: Which of the following is an example of an IT governance output?
- A server patch applied to production systems
- An approved IT policy defining acceptable use (Correct answer)
- A firewall rule blocking external traffic
- A database backup completed overnight
Correct answer: An approved IT policy defining acceptable use
IT governance outputs include policies, principles, frameworks, and accountability structures—not day-to-day operational activities like patching or backups.
Question 4: In IT governance, the concept of 'accountability' differs from 'responsibility' in that accountability:
- Can be shared among multiple parties
- Rests with one individual who answers for the final outcome (Correct answer)
- Only applies to financial matters
- Is assigned to lower-level technical staff
Correct answer: Rests with one individual who answers for the final outcome
Accountability is singular and non-delegable—one person ultimately answers for an outcome—while responsibility can be shared or delegated.
Question 5: Which of the following BEST characterizes an IT governance framework versus an IT management framework?
- Governance sets direction and evaluates performance; management plans and operates (Correct answer)
- Governance focuses on daily operations; management sets strategic direction
- They are interchangeable terms in COBIT
- Governance applies only to public sector organizations
Correct answer: Governance sets direction and evaluates performance; management plans and operates
Governance defines the direction, evaluates outcomes, and ensures accountability, while management handles planning, building, running, and monitoring IT activities.
Question 6: An auditor finds that IT project prioritization is done solely by the IT department without business input. The GREATEST risk of this practice is:
- IT projects may not align with business strategic priorities (Correct answer)
- IT projects will cost more than budgeted
- IT staff will be overburdened with too many projects
- Security vulnerabilities will go unaddressed
Correct answer: IT projects may not align with business strategic priorities
Without business input, IT prioritization may fund technically attractive but strategically irrelevant projects, undermining the value of IT investments.
Question 7: The PRIMARY purpose of IT governance performance metrics is to:
- Justify IT headcount increases
- Provide management with objective evidence for informed decision-making (Correct answer)
- Automate IT audit reporting
- Benchmark against competitors
Correct answer: Provide management with objective evidence for informed decision-making
IT governance metrics give management quantitative and qualitative evidence about IT performance, enabling informed decisions about resource allocation and risk.
When reviewing IT governance, an auditor discovers that business units independently purchase software without IT involvement.
This PRIMARILY indicates a weakness in: