ISACA Governance and Management of IT 5 — Questions and Answers
Question 1: A multinational company wants to adopt a single IT governance framework across all subsidiaries with different regulatory requirements. The BEST approach is to:
- Mandate one framework globally and ignore local variations
- Select a flexible framework and tailor it to local regulatory contexts (Correct answer)
- Allow each subsidiary to choose its own framework independently
- Adopt whichever framework the largest subsidiary already uses
Correct answer: Select a flexible framework and tailor it to local regulatory contexts
A flexible framework like COBIT can be tailored to accommodate local regulatory and operational differences while maintaining global consistency.
Question 2: Which of the following BEST describes the role of Key Risk Indicators (KRIs) in IT governance?
- They measure the financial return on IT investments
- They provide early warning signals of increasing risk exposure (Correct answer)
- They track whether IT service level agreements are being met
- They document historical security incidents for audit purposes
Correct answer: They provide early warning signals of increasing risk exposure
KRIs are forward-looking metrics that signal when risk levels are rising, enabling proactive governance responses before risks materialize.
Question 3: An IS auditor discovers that IT governance policies were last updated five years ago. What should the auditor PRIMARILY recommend?
- Immediately suspend all IT operations until policies are updated
- Establish a periodic policy review cycle aligned with business change (Correct answer)
- Replace all policies with industry-standard templates
- Require management to sign off on existing policies as-is
Correct answer: Establish a periodic policy review cycle aligned with business change
Governance policies must be reviewed and updated periodically to remain aligned with evolving business strategy, technology, and regulatory requirements.
Question 4: Which practice BEST demonstrates that an organization's IT governance framework supports ethical use of technology?
- Publishing an annual IT spending report
- Establishing and enforcing an acceptable use policy with consequences (Correct answer)
- Deploying data loss prevention tools across all endpoints
- Conducting annual IT audits with external auditors
Correct answer: Establishing and enforcing an acceptable use policy with consequences
An acceptable use policy with enforced consequences establishes clear ethical boundaries and holds users accountable for technology use.
Question 5: In the context of IT governance, 'benefit realization' refers to:
- Calculating the total cost of ownership of IT assets
- Ensuring IT investments deliver their intended business value (Correct answer)
- Documenting the technical capabilities of IT systems
- Measuring IT uptime and system availability
Correct answer: Ensuring IT investments deliver their intended business value
Benefit realization is the governance practice of ensuring that promised business benefits from IT investments are actually achieved post-implementation.
Question 6: An organization's IT steering committee approves a major ERP implementation but the business case shows negative NPV. An IS auditor should FIRST:
- Require the project to be cancelled immediately
- Verify whether non-financial strategic benefits justify the investment (Correct answer)
- Report the decision to external regulators
- Recommend the organization reduce the project scope
Correct answer: Verify whether non-financial strategic benefits justify the investment
A negative NPV does not automatically make an investment wrong; strategic, compliance, or competitive benefits may justify it if properly documented.
Question 7: Which of the following BEST illustrates the separation between governance and management of IT as defined in COBIT 2019?
- The board approves IT strategy; the CIO allocates IT resources to execute it (Correct answer)
- The CIO sets IT policy; the board monitors IT performance metrics
- IT auditors assess controls; IT managers report results to regulators
- The IT steering committee selects vendors; finance approves payments
Correct answer: The board approves IT strategy; the CIO allocates IT resources to execute it
COBIT 2019 defines governance as setting direction (board approves strategy) and management as executing within that direction (CIO allocates resources).
A multinational company wants to adopt a single IT governance framework across all subsidiaries with different regulatory requirements.
The BEST approach is to: