CISA IT Governance and Strategy 5 — Questions and Answers
Question 1: An organization wants to improve IT governance maturity from level 2 to level 3 on a five-level scale. This MOST likely requires:
- Purchasing more advanced IT infrastructure
- Formalizing and documenting processes consistently across the organization (Correct answer)
- Hiring a new CIO with governance experience
- Implementing a zero-trust network architecture
Correct answer: Formalizing and documenting processes consistently across the organization
Moving from maturity level 2 (repeatable but intuitive) to level 3 (defined process) requires formalizing, documenting, and standardizing processes organization-wide.
Question 2: Which of the following scenarios BEST demonstrates effective IT governance?
- The CIO makes all IT investment decisions independently
- The board reviews quarterly IT performance dashboards and adjusts strategy accordingly (Correct answer)
- IT projects are approved based on technical complexity alone
- IT governance is only reviewed during annual audits
Correct answer: The board reviews quarterly IT performance dashboards and adjusts strategy accordingly
Board-level review of IT performance metrics with strategic adjustment demonstrates the evaluate-direct-monitor cycle central to effective IT governance.
Question 3: In the COBIT framework, which domain is MOST directly concerned with IT governance rather than IT management?
- Build, Acquire, and Implement (BAI)
- Deliver, Service, and Support (DSS)
- Evaluate, Direct, and Monitor (EDM) (Correct answer)
- Align, Plan, and Organize (APO)
Correct answer: Evaluate, Direct, and Monitor (EDM)
The EDM (Evaluate, Direct, and Monitor) domain in COBIT 2019 represents governance processes, while other domains represent management processes.
Question 4: A company has strong IT controls but no formal IT governance structure. The MOST likely consequence is:
- Controls will fail more frequently
- IT controls may not address the right risks or business priorities (Correct answer)
- The company will face immediate regulatory penalties
- IT staff turnover will increase significantly
Correct answer: IT controls may not address the right risks or business priorities
Without governance directing which risks matter most, even strong controls may protect against the wrong threats while leaving strategic risks unaddressed.
Question 5: Which of the following is MOST important when defining IT governance roles and responsibilities?
- Ensuring all roles are filled by IT professionals
- Clearly defining decision rights, accountability, and escalation paths (Correct answer)
- Minimizing the number of governance roles to reduce overhead
- Assigning governance responsibilities only to senior management
Correct answer: Clearly defining decision rights, accountability, and escalation paths
Effective governance requires that decision rights, accountability, and escalation procedures be unambiguously defined so that the right decisions are made at the right level.
Question 6: An auditor is assessing whether IT investments are governed effectively. The BEST evidence would be:
- A list of completed IT projects
- Board-approved IT investment portfolio with documented business cases and post-implementation reviews (Correct answer)
- Vendor invoices for technology purchases
- IT staff performance reviews
Correct answer: Board-approved IT investment portfolio with documented business cases and post-implementation reviews
A board-approved investment portfolio with business cases and post-implementation reviews demonstrates that IT investments are selected, authorized, and evaluated against expected benefits.
Question 7: When IT governance is described as 'principle-based' rather than 'rule-based,' it means:
- There are no specific controls required
- Decision-makers use overarching principles to guide judgments rather than following a rigid checklist (Correct answer)
- Governance only applies to regulated industries
- IT staff set their own individual standards
Correct answer: Decision-makers use overarching principles to guide judgments rather than following a rigid checklist
Principle-based governance empowers decision-makers to apply judgment guided by core principles, enabling flexible responses to diverse situations rather than rigid rule compliance.
An organization wants to improve IT governance maturity from level 2 to level 3 on a five-level scale.
This MOST likely requires: