ISACA Governance and Management of IT 4 β Questions and Answers
Question 1: An organization has a high IT risk appetite but weak internal controls. An IS auditor should PRIMARILY recommend:
- Increasing IT spending to match the risk appetite
- Aligning the control environment with the documented risk appetite (Correct answer)
- Reducing the risk appetite to match existing controls
- Transferring all residual risk to a third party
Correct answer: Aligning the control environment with the documented risk appetite
Risk appetite must be supported by a matching control environment; the audit finding is the misalignment between stated appetite and actual controls.
Question 2: Which of the following BEST describes the difference between IT governance and IT management?
- Governance is operational; management is strategic
- Governance sets direction and evaluates; management plans and executes (Correct answer)
- Governance is performed by IT staff; management is performed by the board
- Governance applies only to security; management applies to all IT functions
Correct answer: Governance sets direction and evaluates; management plans and executes
Governance involves evaluating, directing, and monitoring, while management focuses on planning, building, running, and monitoring operations.
Question 3: A large enterprise uses a federated IT governance model. This means IT governance decisions are:
- Made exclusively by the corporate IT department
- Distributed across business units with some central coordination (Correct answer)
- Outsourced to a third-party governance provider
- Made solely by the board of directors
Correct answer: Distributed across business units with some central coordination
A federated model distributes IT governance authority to business units while maintaining central coordination for enterprise-wide standards.
Question 4: When assessing IT governance maturity using COBIT's capability model, a score of Level 2 indicates:
- The process is undefined and undocumented
- The process is performed and managed with planned objectives (Correct answer)
- The process is optimized and continuously improved
- The process is established and conforms to standards
Correct answer: The process is performed and managed with planned objectives
COBIT's Level 2 (Managed Process) means the process is performed and managed β planned, monitored, and adjusted β with defined outcomes.
Question 5: Which concept in IT governance ensures that the board of directors remains informed about significant IT risks and opportunities?
- Escalation procedures (Correct answer)
- IT service continuity management
- IT demand management
- Service level agreements
Correct answer: Escalation procedures
Escalation procedures ensure significant IT risks, incidents, and opportunities are reported up to senior management and the board.
Question 6: An IS auditor reviewing IT governance notes that IT investments are approved project-by-project with no portfolio view. The PRIMARY risk is:
- Individual projects may exceed their budgets
- IT investments may be duplicated or conflict with each other (Correct answer)
- Projects may not follow the system development life cycle
- IT vendors may not be evaluated consistently
Correct answer: IT investments may be duplicated or conflict with each other
Without a portfolio view, investments can overlap, conflict, or miss opportunities for synergy, resulting in suboptimal resource use.
Question 7: Under the CISA framework, which of the following is the MOST important indicator that an organization's IT governance is effective?
- IT governance policies are documented and published
- IT goals consistently support and enable business objectives (Correct answer)
- IT governance committee meets on a quarterly schedule
- IT governance roles are assigned to senior IT staff
Correct answer: IT goals consistently support and enable business objectives
Effective IT governance is ultimately demonstrated by IT outcomes that consistently support and advance business objectives, not just process compliance.
An organization has a high IT risk appetite but weak internal controls.
An IS auditor should PRIMARILY recommend: