CISA IT Governance and Strategy 2 — Questions and Answers
Question 1: Which framework is MOST commonly used by organizations to align IT governance with corporate governance objectives?
- ITIL
- COBIT (Correct answer)
- ISO 27001
- TOGAF
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is the primary framework used to align IT governance with enterprise governance goals.
Question 2: An IT steering committee's PRIMARY responsibility is to:
- Approve the IT budget and resolve resource conflicts between business units (Correct answer)
- Conduct daily IT operations and manage system configurations
- Perform internal audits of IT processes
- Develop detailed technical standards for application development
Correct answer: Approve the IT budget and resolve resource conflicts between business units
The IT steering committee's primary role is to prioritize IT investments, approve budgets, and resolve conflicts over shared IT resources across business units.
Question 3: When auditing IT governance, a CISA should FIRST review:
- Network topology diagrams
- IT policies and the organizational IT governance structure (Correct answer)
- Source code of critical applications
- Help desk ticket logs
Correct answer: IT policies and the organizational IT governance structure
Reviewing IT policies and governance structure provides the auditor a baseline to assess whether IT governance is properly designed before testing controls.
Question 4: A balanced scorecard used in IT governance typically measures performance across how many perspectives?
- Two
- Three
- Four (Correct answer)
- Six
Correct answer: Four
The balanced scorecard measures performance across four perspectives: financial, customer, internal processes, and learning and growth.
Question 5: Which role is PRIMARILY accountable for ensuring IT risks are managed within acceptable tolerance levels?
- Chief Information Officer (CIO)
- Chief Risk Officer (CRO)
- Board of Directors (Correct answer)
- IT Security Manager
Correct answer: Board of Directors
The Board of Directors holds ultimate accountability for setting risk appetite and ensuring IT risks are managed within acceptable tolerance at the enterprise level.
Question 6: An organization implements an IT governance framework but employees are unaware of their roles. This MOST likely indicates a failure in:
- Risk assessment
- Communication and awareness (Correct answer)
- Technical security controls
- Business continuity planning
Correct answer: Communication and awareness
Effective IT governance requires that roles, responsibilities, and policies be communicated to all relevant stakeholders to ensure compliance.
Question 7: The concept of 'IT value delivery' in governance PRIMARILY focuses on:
- Reducing hardware procurement costs
- Ensuring IT investments deliver business benefits on time and within budget (Correct answer)
- Maximizing the number of IT projects completed per year
- Eliminating all IT-related risks
Correct answer: Ensuring IT investments deliver business benefits on time and within budget
IT value delivery ensures that IT investments and projects realize the expected business benefits, on schedule and within approved budgets.
Which framework is MOST commonly used by organizations to align IT governance with corporate governance objectives?