CISA EVALUATION EXAM 2026 QUESTIONS AND ANSWERS
GRADED A+
✔✔IT governance is PRIMARILY the responsibility of the:
Select an answer:
A.
chief executive officer (CEO).
B.
board of directors.
C.
IT steering committee.
D.
audit committee. - ✔✔A. The chief executive officer (CEO) is instrumental in
implementing IT governance according to the directions of the board of directors.
CORRECT B. IT governance is primarily the responsibility of the executives and
shareholders (as represented by the board of directors).
C. The IT steering committee monitors and facilitates deployment of IT resources for
specific projects in support of business plans. The IT steering committee enforces
governance on behalf of the board of directors.
D. The audit committee reports to the board of directors and executes governance-
related audits. The audit committee should monitor the implementation of audit
recommendations.
✔✔An IS auditor reviewing the IT organization would be MOST concerned if the IT
steering committee:
Select an answer:
A.
is responsible for project approval and prioritization.
B.
is responsible for developing the long-term IT plan.
C.
reports the status of IT projects to the board of directors.
D.
is responsible for determining business goals. - ✔✔A. The IT steering committee is
responsible for project approval and prioritization.
,B. The IT steering committee is responsible for oversight of the development of the
long-term IT plan.
C. The IT steering committee advises the board of directors on the status of
developments in IT.
CORRECT D. Determining the business goals is the responsibility of senior
management and not of the IT steering committee. IT should support business goals
and be driven by the business—not the other way around
✔✔As an outcome of information security governance, strategic alignment provides:
Select an answer:
A.
security requirements driven by enterprise requirements.
B.
baseline security following good practices.
C.
institutionalized and commoditized solutions.
D.
an understanding of risk exposure. - ✔✔CORRECT A. Information security governance,
when properly implemented, should provide four basic outcomes: strategic alignment,
value delivery, risk management and performance measurement. Strategic alignment
provides input for security requirements driven by enterprise requirements.
B. Strategic alignment ensures that security aligns with business goals. Providing a
standard set of security practices (i.e., baseline security following best practices or
institutionalized and commoditized solutions) is a part of value delivery.
C. Value delivery addresses the effectiveness and efficiency of solutions, but is not a
result of strategic alignment.
D. Risk management is a primary goal of IT governance, but strategic alignment is not
focused on understanding risk exposure.
✔✔Which of the following IT governance good practices improves strategic alignment?
Select an answer:
A.
Supplier and partner risk is managed.
B.
,A knowledge base on customers, products, markets and processes is in place.
C.
A structure is provided that facilitates the creation and sharing of business information.
D.
Top management mediates between the imperatives of business and technology. -
✔✔A. Supplier and partner risk being managed is a risk management good practice but
not a strategic function.
B. A knowledge base on customers, products, markets and processes being in place is
an IT value delivery good practice but does not ensure strategic alignment.
C. An infrastructure being provided to facilitate the creation and sharing of business
information is an IT value delivery and risk management good practice, but is not as
effective as top management involvement in business and technology alignment.
CORRECT D. Top management mediating between the imperatives of business and
technology is an IT strategic alignment good practice.
✔✔Effective IT governance requires organizational structures and processes to ensure
that:
Select an answer:
A.
risk is maintained at a level acceptable for IT management.
B.
the business strategy is derived from an IT strategy.
C.
IT governance is separate and distinct from the overall governance.
D.
the IT strategy extends the organization's strategies and objectives. - ✔✔A. Risk
acceptance levels are set by senior management, not by IT management.
B. The business strategy drives the IT strategy, not the other way around.
C. IT governance is not an isolated discipline; it must become an integral part of the
overall enterprise governance.
CORRECT D. Effective IT governance requires that board and executive management
extend governance to IT and provide the leadership, organizational structures and
processes that ensure that the organization's IT sustains and extends the organization's
strategies and objectives, and that the strategy is aligned with business strategy.
, ✔✔Which of the following is the MOST important element for the successful
implementation of IT governance?
Select an answer:
A.
Implementing an IT scorecard
B.
Identifying organizational strategies
C.
Performing a risk assessment
D.
Creating a formal security policy - ✔✔A. A scorecard is an excellent tool to implement a
program based on good governance, but the most important factor in implementing
governance is alignment with organizational strategies.
CORRECT B. The key objective of an IT governance program is to support the
business, thus the identification of organizational strategies is necessary to ensure
alignment between IT and corporate governance. Without identification of organizational
strategies, the remaining choices—even if implemented—would be ineffective.
C. A risk assessment is important to ensure that the security program is based on areas
of highest risk, but risk assessment must be based on organizational strategies.
D. A policy is a key part of security program implementation, but even the policy must
be based on organizational strategies.
✔✔When implementing an IT governance framework in an organization the MOST
important objective is:
Select an answer:
A.
IT alignment with the business.
B.
accountability.
C.
value realization with IT.
D.
enhancing the return on IT investments. - ✔✔CORRECT A. The goals of IT governance
are to improve IT performance, to deliver optimum business value and to ensure
GRADED A+
✔✔IT governance is PRIMARILY the responsibility of the:
Select an answer:
A.
chief executive officer (CEO).
B.
board of directors.
C.
IT steering committee.
D.
audit committee. - ✔✔A. The chief executive officer (CEO) is instrumental in
implementing IT governance according to the directions of the board of directors.
CORRECT B. IT governance is primarily the responsibility of the executives and
shareholders (as represented by the board of directors).
C. The IT steering committee monitors and facilitates deployment of IT resources for
specific projects in support of business plans. The IT steering committee enforces
governance on behalf of the board of directors.
D. The audit committee reports to the board of directors and executes governance-
related audits. The audit committee should monitor the implementation of audit
recommendations.
✔✔An IS auditor reviewing the IT organization would be MOST concerned if the IT
steering committee:
Select an answer:
A.
is responsible for project approval and prioritization.
B.
is responsible for developing the long-term IT plan.
C.
reports the status of IT projects to the board of directors.
D.
is responsible for determining business goals. - ✔✔A. The IT steering committee is
responsible for project approval and prioritization.
,B. The IT steering committee is responsible for oversight of the development of the
long-term IT plan.
C. The IT steering committee advises the board of directors on the status of
developments in IT.
CORRECT D. Determining the business goals is the responsibility of senior
management and not of the IT steering committee. IT should support business goals
and be driven by the business—not the other way around
✔✔As an outcome of information security governance, strategic alignment provides:
Select an answer:
A.
security requirements driven by enterprise requirements.
B.
baseline security following good practices.
C.
institutionalized and commoditized solutions.
D.
an understanding of risk exposure. - ✔✔CORRECT A. Information security governance,
when properly implemented, should provide four basic outcomes: strategic alignment,
value delivery, risk management and performance measurement. Strategic alignment
provides input for security requirements driven by enterprise requirements.
B. Strategic alignment ensures that security aligns with business goals. Providing a
standard set of security practices (i.e., baseline security following best practices or
institutionalized and commoditized solutions) is a part of value delivery.
C. Value delivery addresses the effectiveness and efficiency of solutions, but is not a
result of strategic alignment.
D. Risk management is a primary goal of IT governance, but strategic alignment is not
focused on understanding risk exposure.
✔✔Which of the following IT governance good practices improves strategic alignment?
Select an answer:
A.
Supplier and partner risk is managed.
B.
,A knowledge base on customers, products, markets and processes is in place.
C.
A structure is provided that facilitates the creation and sharing of business information.
D.
Top management mediates between the imperatives of business and technology. -
✔✔A. Supplier and partner risk being managed is a risk management good practice but
not a strategic function.
B. A knowledge base on customers, products, markets and processes being in place is
an IT value delivery good practice but does not ensure strategic alignment.
C. An infrastructure being provided to facilitate the creation and sharing of business
information is an IT value delivery and risk management good practice, but is not as
effective as top management involvement in business and technology alignment.
CORRECT D. Top management mediating between the imperatives of business and
technology is an IT strategic alignment good practice.
✔✔Effective IT governance requires organizational structures and processes to ensure
that:
Select an answer:
A.
risk is maintained at a level acceptable for IT management.
B.
the business strategy is derived from an IT strategy.
C.
IT governance is separate and distinct from the overall governance.
D.
the IT strategy extends the organization's strategies and objectives. - ✔✔A. Risk
acceptance levels are set by senior management, not by IT management.
B. The business strategy drives the IT strategy, not the other way around.
C. IT governance is not an isolated discipline; it must become an integral part of the
overall enterprise governance.
CORRECT D. Effective IT governance requires that board and executive management
extend governance to IT and provide the leadership, organizational structures and
processes that ensure that the organization's IT sustains and extends the organization's
strategies and objectives, and that the strategy is aligned with business strategy.
, ✔✔Which of the following is the MOST important element for the successful
implementation of IT governance?
Select an answer:
A.
Implementing an IT scorecard
B.
Identifying organizational strategies
C.
Performing a risk assessment
D.
Creating a formal security policy - ✔✔A. A scorecard is an excellent tool to implement a
program based on good governance, but the most important factor in implementing
governance is alignment with organizational strategies.
CORRECT B. The key objective of an IT governance program is to support the
business, thus the identification of organizational strategies is necessary to ensure
alignment between IT and corporate governance. Without identification of organizational
strategies, the remaining choices—even if implemented—would be ineffective.
C. A risk assessment is important to ensure that the security program is based on areas
of highest risk, but risk assessment must be based on organizational strategies.
D. A policy is a key part of security program implementation, but even the policy must
be based on organizational strategies.
✔✔When implementing an IT governance framework in an organization the MOST
important objective is:
Select an answer:
A.
IT alignment with the business.
B.
accountability.
C.
value realization with IT.
D.
enhancing the return on IT investments. - ✔✔CORRECT A. The goals of IT governance
are to improve IT performance, to deliver optimum business value and to ensure