CISA Domain 2A-2 Practice Test 001

This practice test covers Domain 2 (Governance & Management of IT) Subdomain A-2 (Organizational Structure, IT Governance, and IT Strategy) from the CISA exam content outline.

These questions are inspired by the ISACA CISA exam and are designed to help you test your knowledge of information systems auditing, governance, risk management, IT operations, business resilience, and information asset protection.

These are not official exam questions or brain dumps. They are original scenario-based questions created to reflect the audit judgment, control evaluation, and risk-based decision-making skills tested in the CISA exam.

Note: CISA and Certified Information Systems Auditor are registered trademarks of ISACA. This content is not affiliated with or endorsed by ISACA.

To choose CISA practice tests based on specific domains and subdomains, click that link.

CISA 2A-2 Organizational Structure, IT Governance, and IT Strategy Practice Test 001
10 questions • Single best answer
Question 1
An IS auditor is evaluating IT governance at a hospital network where the IT department launches technology initiatives without formal board or executive review. The most recent IT plan was prepared solely by the IT director. Which of the following should the auditor recommend FIRST to strengthen IT governance?
    Question 2
    During a governance audit of a financial services firm, the IS auditor notes that the information security function reports directly to the head of IT operations. Management states this arrangement improves efficiency. Which of the following is the auditor's GREATEST concern regarding this reporting structure?
      Question 3
      An IS auditor is assessing whether a retailer's IT strategy supports its corporate expansion objectives. Management provides several documents intended to demonstrate alignment between the two. Which of the following would provide the BEST evidence that the IT strategy is aligned with the business strategy?
        Question 4
        An IS auditor reviews the charter and meeting minutes of an organization's IT steering committee. The committee approves individual technology purchases but does not prioritize competing projects against the overall enterprise portfolio. Which of the following is the MOST significant weakness in how the committee is functioning?
          Question 5
          During an audit of IT governance at a government agency, the IS auditor finds that the board receives no reporting on IT risk or performance. All IT decisions are delegated entirely to operational management. Which of the following BEST describes the governance risk this situation creates?
            Question 6
            An IS auditor examines the IT organizational structure of an insurance company and finds that a single manager oversees both application development and production operations. No compensating monitoring controls are described in the process documentation. Which of the following is the MOST significant risk associated with this structure?
              Question 7
              An IS auditor is evaluating the governance bodies overseeing IT at a manufacturing enterprise. The board wants to understand which body should advise it on the future direction of IT and the alignment of technology investments with corporate strategy. Which body is MOST appropriate for this responsibility?
                Question 8
                An IS auditor discovers that a utility company's approved IT strategy still references business goals that were superseded two years ago, following a major corporate restructuring. Management has not updated the strategy document since then. Which of the following should the auditor do FIRST in this situation?
                  Question 9
                  During a governance review, an IS auditor finds that no role or committee has been formally assigned ownership of IT risk and control standards, and each department applies its own inconsistent approach to managing technology risk. Which of the following is the auditor's BEST recommendation?
                    Question 10
                    An IS auditor is assessing how a bank measures whether IT delivers value that aligns with its strategic goals. Management reports only on system uptime and help-desk ticket volumes to demonstrate IT performance to the board. Which of the following would BEST improve measurement of IT's strategic contribution?

                      Leave a Comment

                      Your email address will not be published. Required fields are marked *

                      Scroll to Top