ISACA Governance and Management of IT 3 β Questions and Answers
Question 1: Which ISO standard provides the code of practice for information security controls and is frequently referenced alongside ISO/IEC 27001?
- ISO/IEC 27002 (Correct answer)
- ISO/IEC 38500
- ISO/IEC 20000
- ISO/IEC 31000
Correct answer: ISO/IEC 27002
ISO/IEC 27002 is the code of practice providing guidance on implementing information security controls referenced in ISO/IEC 27001.
Question 2: An organization uses a Responsibility Assignment Matrix (RACI) for IT governance decisions. The 'A' in RACI stands for:
- Authorized
- Accountable (Correct answer)
- Acknowledged
- Advised
Correct answer: Accountable
In a RACI matrix, 'A' stands for Accountable β the one person ultimately answerable for the correct completion of a task.
Question 3: An IS auditor finds that IT management reports to the CFO rather than directly to the CEO or board. What governance concern should be raised?
- IT budget oversight may be duplicated across departments
- IT strategy may be overly focused on financial efficiency over innovation (Correct answer)
- IT security may be under-resourced
- IT projects may bypass procurement controls
Correct answer: IT strategy may be overly focused on financial efficiency over innovation
Reporting to the CFO can bias IT decisions toward cost reduction rather than strategic business enablement.
Question 4: Under Val IT, the concept of 'investment portfolio management' means:
- Managing the server and application asset inventory
- Selecting and balancing IT investments across risk and return profiles (Correct answer)
- Tracking ROI on completed IT projects only
- Ensuring IT hardware is depreciated correctly
Correct answer: Selecting and balancing IT investments across risk and return profiles
Val IT's investment portfolio management ensures an organization selects, balances, and monitors IT investments to maximize business value.
Question 5: Which COBIT 2019 design factor relates to the organization's current level of capability in its IT processes?
- Enterprise strategy
- IT implementation methods
- Current IT capability level (Correct answer)
- Risk profile
Correct answer: Current IT capability level
Current IT capability level is one of COBIT 2019's design factors that shapes how governance and management objectives are prioritized.
Question 6: A CISA candidate reviewing an IT governance framework notices that corrective actions from audits are tracked but never followed up. Which governance process is MOST deficient?
- Risk identification
- Strategic IT planning
- Monitoring and evaluation (Correct answer)
- Resource allocation
Correct answer: Monitoring and evaluation
Monitoring and evaluation includes following up on audit findings to ensure corrective actions are implemented and effective.
Question 7: ISO/IEC 38500 defines IT governance principles for corporate governance of IT. Which of the following is NOT one of its six principles?
- Responsibility
- Strategy
- Acquisition
- Optimization (Correct answer)
Correct answer: Optimization
ISO/IEC 38500's six principles are Responsibility, Strategy, Acquisition, Performance, Conformance, and Human Behaviour β Optimization is not among them.
Which ISO standard provides the code of practice for information security controls and is frequently referenced alongside ISO/IEC 27001?