
CISA exam practice question: daily practice for the Certified Information Systems Auditor (CISA) exam — domain: Governance and Management of IT.
Question
As part of an audit of IT governance, you receive the CIO's quarterly IT performance report containing uptime percentages, mean-time-to-repair, project status, and customer satisfaction scores. What is the most appropriate first step to evaluate whether these metrics demonstrate effective IT governance?
Show the answer and explanation
Correct answer: A. Determine whether each reported metric is linked to specific business objectives and verify the accuracy and completeness of the underlying data sources
The best first step is to confirm that metrics are tied to business objectives and to test the reliability of their data. Metrics that are not aligned with business goals or that are based on inaccurate data cannot demonstrate effective governance. Option B is incorrect because board presentation or origin does not guarantee relevance or accuracy. Option C is incomplete: trend analysis is useful but should follow validation of alignment and data integrity, not precede it. Option D is premature because adding technical counters may increase noise unless those counters are selected for their relevance to business objectives and validated data quality.
Want more practice?
Prepare for the Certified Information Systems Auditor (CISA) exam with IT Department Audit: Risk, IT Control and Governance Evaluation.
