Home › Certifications › CPA ISC › IT governance
45 multiple-choice questions and 76 flashcards on IT governance, about 12% of the CPA ISC bank. Every one carries a written rationale.
IT governance is one of 5 chapters in CoStudy's CPA — Information Systems & Controls (ISC) [Discipline] bank, and it holds 45 of the bank's 378 multiple-choice questions — roughly 12% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.
Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.
10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.
Within the NIST CSF, the 'Identify' function primarily involves:
Answer: B — Understanding organizational context, assets, risks, and governance to manage cybersecurity risk (e.g., asset inventories, risk assessments)
A) Actively blocking an attack describes activities within PROTECT or RESPOND, not Identify. B) Correct — Identify focuses on developing organizational understanding of context, assets, data, and risks (asset inventories, risk assessments, governance structures) that inform the rest of the cybersecurity risk management program. C) Post-incident restoration describes the RECOVER function, not Identify. D) Detecting anomalous activity describes the DETECT function, not Identify.
The Three Lines of Defense model assigns risk responsibilities to:
Answer: C — Operational management, risk and compliance functions, and internal audit oversight
A) Those are business functions, not the three lines. B) Those are all first-line operational teams. C) Correct — 1st: operations, 2nd: risk/compliance, 3rd: internal audit. D) The board and external auditor sit outside the three lines model.
A comprehensive ISC synthesis scenario asks a candidate to evaluate an organization's overall technology risk posture using ISMS certification status, identity governance maturity, AI/ML model governance, OT security segmentation, and BCP/DR metrics together. The BEST approach is to:
Answer: C — Synthesize findings across areas — for example, linking weak identity governance (SoD gaps) to elevated risk in a poorly segmented OT environment with immature BCP/DR targets, informing an overall technology risk conclusion
A) Isolated single-area review misses the exam's clear intent to test integrated judgment across governance, security, and resilience domains simultaneously. C) Correct — the ISC exam (and real-world technology risk assessment) rewards synthesizing multiple data points into a coherent overall risk posture, connecting how weaknesses in one area (e.g., identity governance) can compound risk in another (e.g., an under-segmented OT environment with weak recovery capability). B) Fixating on a single certification while ignoring other risk indicators would produce an incomplete and potentially misleading overall risk conclusion. D) These areas are interconnected in a real technology environment (access controls, segmentation, model governance, and resilience all interact), and a well-reasoned synthesis is both possible and expected.
A company evaluating whether to build a formal AI/ML model risk governance program alongside its existing COBIT-based IT governance structure should recognize that:
Answer: A — COBIT's governance/management structure (evaluate, direct, monitor / plan, build, run, monitor) can be extended to explicitly cover AI/ML-specific risks like model drift, bias, and explainability, rather than requiring an entirely separate, disconnected governance structure
A) Correct — COBIT's governance/management structure is designed to be extensible to emerging technology risks; an organization can incorporate AI/ML-specific risk considerations (drift, bias, explainability) into its existing governance objectives rather than building an entirely siloed, disconnected framework. B) AI/ML models used in impactful business decisions clearly warrant governance, given the model risk, bias, and explainability concerns discussed throughout this topic area. C) COBIT is a flexible, technology-agnostic governance framework intended to remain applicable as new technologies emerge, not tied to specific technologies existing at its publication. D) Effective governance benefits from integration and communication between IT governance and specialized risk domains like AI/ML, rather than complete organizational silos.
COBIT's governance and management objectives are organized around the distinction that:
Answer: A — Governance ensures stakeholder needs are evaluated and direction is set, while management plans, builds, runs, and monitors activities to achieve enterprise objectives
A) Correct — COBIT explicitly separates governance (evaluate, direct, monitor at the board/executive level) from management (plan, build, run, monitor at the operational level). B) Wrong — COBIT deliberately distinguishes the two as separate but related activities. C) Wrong — management activities are typically performed by operational management, not the board. D) Wrong — COBIT's governance/management distinction applies broadly to enterprise IT, not as a departmental split.
Considering ISC's full content arc through Part 25 — spanning governance frameworks, technical security architecture, privacy law, emerging technology risk, assurance/audit skills, and now deeper SOC reporting mechanics, cryptographic lifecycle management, and business continuity testing rigor — a well-prepared candidate's mental model should treat these domains as:
Answer: B — An integrated whole, where a realistic engagement or business scenario often requires drawing on multiple domains simultaneously (e.g., a cloud migration scenario touching shared responsibility, encryption, access control, and SOC report scoping all at once)
A) Incorrect — the numerous synthesis/capstone questions throughout Parts 18-25 specifically demonstrate that these domains interact and combine in realistic scenarios, not stay siloed. B) Correct — ISC content is best understood as an integrated whole: realistic business and engagement scenarios (like the cloud migration example) routinely require simultaneously drawing on cloud shared-responsibility concepts, cryptography scope decisions, access control model selection, and assurance/reporting considerations together, reflecting how these domains genuinely interact in practice. C) Incorrect — the exam's design (and this content's extensive synthesis questions) specifically reward the ability to combine topics, not memorize them in isolation. D) Incorrect — this understates how interconnected governance, technical security, privacy, and assurance actually are in real engagements and in how the ISC Discipline blueprint is structured and tested.
COBIT's 'Evaluate, Direct, Monitor' (EDM) activities are performed at which organizational level?
Answer: B — The governing body (e.g., board or executive governance committee), setting direction and monitoring outcomes rather than performing day-to-day operations
A) Front-line help desk staff perform operational management tasks, not the board-level EDM governance activities. B) Correct — EDM activities are performed by the enterprise's governing body, which evaluates stakeholder needs, directs strategy/priorities, and monitors performance and compliance, distinct from operational management. C) Third-party vendors execute contracted services; they don't perform the enterprise's own governance evaluation and direction-setting function. D) Entry-level support tasks like password resets are operational management activities, far removed from board-level governance.
Effective board oversight of cybersecurity typically requires that the board:
Answer: D — Understand cyber risk, review key metrics, and oversee management's response plans
A) Boards oversee; they don't manage day-to-day operations. B) Full delegation without oversight fails governance obligations. C) Boards don't perform technical scanning. D) Correct — the standard board oversight model for cyber risk.
Primary purpose of an ERP system:
Answer: A — Integrate core business processes on one platform with shared data
A) Correct — ERP unifies finance, HR, supply chain, sales on one platform. B) That describes CRM, not ERP. C) That describes SCM, not ERP. D) That describes RPA, not ERP.
A 'containerized' approach to BYOD device management (separating a secure corporate 'container' app/workspace from personal apps/data on the same device) is primarily intended to:
Answer: D — Logically isolate and protect corporate data and applications from the device's personal side, allowing the organization to manage/wipe only the corporate container without affecting personal data
A) Containerization is a logical/software-based separation, not a physical hardware split of the device. D) Correct — containerization creates a logically isolated, managed workspace for corporate data/apps, allowing the organization to enforce policies and perform actions like a selective wipe of just the corporate container, without touching the employee's personal data and apps. C) Containerized workspaces typically still rely on underlying encryption for the protected data; it doesn't replace that need. B) Containerization is specifically valuable in TRUE BYOD scenarios, precisely because it lets personal and corporate data coexist on the same personally owned device with appropriate separation.
4 cards from the 76 in this chapter.
COBIT design factors?
Used to tailor a governance system to an enterprise's specific context — strategy, risk profile, threat landscape, compliance needs, etc.
Classification without a tailored retention period — what risk does this create?
Data may be destroyed too early (non-compliance) or kept too long (increased exposure) — classification and retention must work together.
'Shifting left' on security?
Moving security testing/controls earlier in the development lifecycle (coding, build) rather than only at the end.
Why do automated controls need less extensive samples than manual controls?
A properly functioning automated control applies identical logic to every transaction (absent a change), reducing the variability manual controls introduce.
These are a sample. The full IT governance chapter runs 121 items with per-chapter progress tracking, on the web and in the iOS app.