ISACA CISA — Certified Information Systems Auditor · Domain 2 · 18% of exam

Governance and Management of IT

Drill 20 practice questions focused entirely on Governance and Management of IT for the ISACA CISA exam. Tap an answer for instant feedback and a full explanation — no sign-up, always free.

Verified answer20 questions
Question 1 of 20

An IS auditor reviewing an enterprise's IT performance monitoring program notes that management measures internal metrics such as help desk ticket resolution time and server uptime, and reports steady year-over-year improvement. However, business units continue to complain that IT service quality lags behind competitors. Which action would BEST enable management to determine whether IT performance is genuinely competitive?

Reviewed for accuracy · Report an issue
Question 2 of 20

A multinational bank plans to migrate its customer transaction database to a public cloud provider. During the acquisition process, the IS auditor is asked to review the provider selection criteria. The organization operates in jurisdictions that legally require certain customer data to remain within national borders. Which of the following should the auditor recommend receive PRIMARY consideration before finalizing the provider contract?

Reviewed for accuracy · Report an issue
Question 3 of 20

An organization is launching an enterprise data protection program. Management wants to ensure that encryption, access restrictions, and retention rules are applied proportionately across all information assets. Before selecting specific technical controls, which activity should the IS auditor recommend be completed FIRST?

Reviewed for accuracy · Report an issue
Question 4 of 20

During a review of an organization's newly launched data governance program, an IS auditor finds that data quality issues in the customer master file keep recurring. The IT operations team applies technical fixes each time errors are reported, but no one in the business is designated as accountable for defining acceptable data quality rules or authorizing corrections. What should the auditor recommend as the MOST effective way to address the root cause?

Reviewed for accuracy · Report an issue
Question 5 of 20

A multinational retailer processes customer personal data in several countries. Its internal data protection policy was written to satisfy the requirements of the country where the corporate headquarters is located. During an audit, the IS auditor finds that one subsidiary operates in a jurisdiction whose privacy law imposes stricter consent and data-transfer requirements than the corporate policy. Which of the following should the auditor recommend as the MOST appropriate course of action?

Reviewed for accuracy · Report an issue
Question 6 of 20

An IS auditor reviewing an organization's IT strategy notices that a new enterprise architecture (EA) initiative was launched by the IT department to standardize technology platforms. However, business unit leaders complain that recent technology investments do not support their emerging market priorities. What is the auditor's PRIMARY concern?

Reviewed for accuracy · Report an issue
Question 7 of 20

An organization is finalizing a contract to license a mission-critical ERP application from a small software vendor. The vendor retains ownership of the source code and will provide only compiled binaries and ongoing support. Senior management is concerned about business continuity if the vendor ceases operations. Which contractual provision would BEST address this concern?

Reviewed for accuracy · Report an issue
Question 8 of 20

An IS auditor is reviewing how an organization measures the effectiveness of its IT function. Management reports IT performance solely through server uptime percentages and help desk ticket resolution times. The board has expressed concern that it cannot tell whether IT investments are advancing the corporate strategy. Which recommendation should the auditor MOST strongly make to address the board's concern?

Reviewed for accuracy · Report an issue
Question 9 of 20

An organization has decided to adopt a widely recognized IT governance framework to structure its IT-related processes. During the planning phase, the CIO proposes implementing every process, control objective, and metric described in the framework exactly as published. What is the IS auditor's BEST recommendation regarding this approach?

Reviewed for accuracy · Report an issue
Question 10 of 20

During a governance review, an IS auditor finds that the same individual manages the IT department's information security function and also serves as the head of IT operations, approving changes to production systems. Which of the following is the auditor's GREATEST concern regarding this organizational structure?

Reviewed for accuracy · Report an issue
Question 11 of 20

An IS auditor reviews the monthly IT performance dashboard presented to executive management. Every metric reported (e.g., number of security incidents last month, prior-month system downtime, tickets closed) describes outcomes that have already occurred. Management complains that the dashboard tells them what went wrong but never helps them prevent problems. What should the auditor recommend to BEST address this concern?

Reviewed for accuracy · Report an issue
Question 12 of 20

During a governance review, an IS auditor examines a document that states, 'All remote access must use multifactor authentication configured with a minimum of two distinct factor types.' The organization's leadership wants to understand where this document fits within its IT governance document hierarchy. How should the auditor most accurately classify this document?

Reviewed for accuracy · Report an issue
Question 13 of 20

An IS auditor reviewing IT resource management finds that the organization recently adopted a new cloud-native platform, but a skills-gap assessment shows most infrastructure staff lack the required competencies. The IT manager has been addressing this by hiring expensive short-term contractors for every incident. Which recommendation should the auditor prioritize to best support sustainable IT resource management?

Reviewed for accuracy · Report an issue
Question 14 of 20

An organization is preparing to sign a multi-year contract to outsource its core payment processing to a specialized IT service provider. During due diligence, the IS auditor is asked which factor is MOST important to assess to protect the organization from a critical service disruption over the life of the contract.

Reviewed for accuracy · Report an issue
Question 15 of 20

An IS auditor is reviewing the newly formed IT steering committee at a mid-sized manufacturing firm. The committee currently consists only of the CIO, the IT infrastructure manager, and two senior IT architects. Business unit leaders are not represented, and meeting minutes show decisions focused almost entirely on technology selection rather than investment prioritization. What is the auditor's PRIMARY concern with this committee's composition?

Reviewed for accuracy · Report an issue
Question 16 of 20

During a governance audit, an IS auditor finds that the IT department launches new technology projects based primarily on the personal preferences of individual business unit managers. There is no formal mechanism to evaluate whether proposed investments support the enterprise's documented strategic goals, and completed projects are never reviewed against expected business benefits. Which of the following is the MOST significant concern the auditor should raise?

Reviewed for accuracy · Report an issue
Question 17 of 20

An organization completed a major ERP implementation 18 months ago, promising significant efficiency gains and cost reductions in its business case. During a governance review, an IS auditor observes that no measurement of the projected benefits has taken place since go-live, and no one is accountable for confirming whether the expected value was achieved. Which of the following recommendations should the auditor emphasize FIRST to strengthen IT value delivery?

Reviewed for accuracy · Report an issue
Question 18 of 20

An IS auditor is reviewing the IT department's monthly performance dashboard, which reports on server uptime, help desk ticket resolution times, and batch job completion rates. The CIO states these metrics demonstrate that IT is delivering value to the business. What is the auditor's MOST important concern about relying on these metrics to conclude that IT is meeting business objectives?

Reviewed for accuracy · Report an issue
Question 19 of 20

During a governance review, an IS auditor finds that the organization's information security policies were last approved five years ago. Since then, the company has adopted cloud services, a remote-work model, and is now subject to new data protection regulations. Management states the policies are still 'technically valid.' What should the auditor conclude is the MOST significant governance weakness?

Reviewed for accuracy · Report an issue
Question 20 of 20

An IS auditor is evaluating a bank's reliance on a cloud-based payroll processing provider. Management states that the provider is 'trustworthy' but has never independently verified the provider's control environment. Which of the following would provide the auditor with the MOST reliable assurance over the effectiveness of the provider's internal controls?

Reviewed for accuracy · Report an issue

More CISA practice

Keep going with the other ISACA CISA — Certified Information Systems Auditor domains, or take a full timed mock exam.

← Back to CISA overview