Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 27 pages
Exam (elaborations)

CISA IT Governance Domain – 30+ Certified Information Systems Auditor (CISA) Practice Questions & Answers | IT Governance, Risk Management, Information Security Policy & Strategic Alignment | ISACA CISA Certification

Document preview thumbnail
Preview 3 out of 27 pages

This comprehensive CISA IT Governance study guide contains more than 30 certification-style practice questions and detailed answers covering the core principles of IT governance, enterprise risk management, information security governance, strategic alignment, policy management, and IT control frameworks. Designed for professionals preparing for the Certified Information Systems Auditor (CISA) examination, the document focuses on high-priority governance concepts frequently tested within the ISACA CISA certification domains and information systems auditing assessments. The material provides extensive coverage of IT governance structures, board oversight responsibilities, IT steering committees, balanced scorecards, strategic planning, risk management frameworks, information security policies, governance accountability, organizational structures, audit responsibilities, corporate governance, IT project portfolio management, policy compliance, security governance, cloud governance risks, data ownership, access control principles, business alignment, and enterprise-wide risk assessment methodologies. Questions are presented in a scenario-based format that mirrors the analytical reasoning required on the CISA certification examination and in real-world IS audit engagements. Key learning areas include governance roles and responsibilities, strategic alignment between business and IT, policy development and approval processes, performance measurement, risk identification and prioritization, security architecture development, audit risk concepts, IT governance implementation, firewall policy development, information asset protection, cloud computing governance, organizational accountability, business process reengineering (BPR), decision support systems, and security program management. The resource helps candidates strengthen their understanding of governance controls, risk-based auditing, and enterprise technology oversight while preparing for certification success and professional auditing responsibilities. This study guide aligns with recognized industry frameworks and authoritative references including the ISACA CISA Review Manual, COBIT 2019 Framework: Governance and Management Objectives, NIST Cybersecurity Framework (CSF), ISO/IEC 27001 Information Security Management Systems, ISO 31000 Risk Management Guidelines, and The Institute of Internal Auditors (IIA) Standards. These globally accepted frameworks support the governance, risk management, control, compliance, and information security concepts reviewed throughout the document. Relevant for students and professionals studying: Certified Information Systems Auditor (CISA) Information Systems Auditing IT Governance Cybersecurity Governance Information Security Management Risk Management and Compliance IT Audit and Assurance Information Assurance Governance, Risk and Compliance (GRC) Enterprise Risk Management Cybersecurity Audit ISACA Certification Preparation Information Security Governance Technology Risk Management Keywords CISA exam questions, CISA IT governance, ISACA CISA certification, information systems auditing, IT governance framework, COBIT 2019, enterprise risk management, IT risk management, information security governance, security policy management, strategic alignment IT and business, IT balanced scorecard, IT steering committee, board of directors governance, audit risk management, detection risk, information security policy, cloud governance risk, data ownership controls, access control authorization, security architecture, governance and compliance, IT control frameworks, cybersecurity governance, organizational accountability, risk assessment methodology, enterprise security management, business process reengineering BPR, governance audit questions, CISA practice test, information security audit, policy compliance review, IT project portfolio management, corporate governance controls, IT audit certification review, risk management framework, technology governance, security governance framework, audit and assurance, governance risk and compliance GRC

Content preview

CISA - IT Governance 2026
Exam Questions and Answers |
Already Graded A+



Which of the following should be of GREATEST concern to an IS auditor

when reviewing an information security policy? The policy:

A. is driven by an IT department's objectives.

B. is published, but users are not required to read the policy.

C. does not include information security procedures.


D. has not been updated in over a year. - ANSWER ✔✔A. is driven

by an IT department's objectives.

,Business objectives drive the information security policy, and the

information security policy drives the selection of IT department

objectives. A policy driven by IT objectives is at risk of not being aligned

with business goals.

An IS auditor reviews an organizational chart PRIMARILY for:

A. an understanding of the complexity of the organizational structure.

B. investigating various communication channels.

C. understanding the responsibilities and authority of individuals.

D. investigating the network connected to different employees. -

ANSWER ✔✔C. understanding the responsibilities and authority of

individuals.




An organizational chart provides information about the responsibilities

and authority of individuals in the organization

IT governance is PRIMARILY the responsibility of the:

A. chief executive officer.

B. board of directors.

C. IT steering committee.

, D. audit committee. - ANSWER ✔✔B. board of directors.




IT governance is primarily the responsibility of the executives and

shareholders (as represented by the board of directors).

To aid management in achieving IT and business alignment, an IS

auditor should recommend the use of:

A. control self-assessments.

B. a business impact analysis.

C. an IT balanced scorecard.


D. business process reengineering. - ANSWER ✔✔C. an IT

balanced scorecard.




This provides the bridge between IT objectives and business objectives

by supplementing the traditional financial evaluation with measures to

evaluate customer satisfaction, internal processes and the ability to

innovate.

An IS audit department is planning to minimize the risk of short-term

employees. Activities contributing to this objective are documented

procedures, knowledge sharing, cross-training and:

COPYRIGHT©PROFFKERRYMARTIN 2025/2026. YEAR PUBLISHED 2026. COMPANY REGISTRATION NUMBER: 619652435. TERMS OF USE.
PRIVACY STATEMENT. ALL RIGHTS RESERVED

Document information

Uploaded on
May 29, 2026
Number of pages
27
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$18.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
PROFFKERRYMARTIN
3.3
(58)
Sold
295
Followers
10
Items
11283
Last sold
21 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions