Summer Sale- Special Discount Limited Time 65% Offer - Ends in 0d 00h 00m 00s - Coupon code: netdisc

Isaca COBIT-2019 COBIT 2019 Foundation Exam Practice Test

Page: 1 / 20
Total 195 questions

COBIT 2019 Foundation Questions and Answers

Question 1

Which of the following is an important component for an enterprise strategy archetype of growth/acquisition as defined by COBIT 2019?

Options:

A.

Support for the portfolio management role with an investment office

B.

Important influence of culture and behavior component for innovation

C.

Skills and competencies

D.

Services, infrastructure, and applications component

Question 2

A privately held company is planning to be listed on the stock exchange and is working on meeting regulatory requirements. After considering an assessment by external consultants, the company has decided to implement the process 'Ensured Stakeholder Engagement." Who is BEST suited for this responsibility?

Options:

A.

Relationship manager

B.

Chief information officer

C.

The board and executive management

D.

Chief information security officer

Question 3

Which of the following components of governance and management objectives includes the expected capability level?

Options:

A.

Process activities

B.

Alignment goals

C.

Organization structure

Question 4

An enterprise has been consistently growing over the years and has decided to adapt the COBIT framework from the growth perspective of the balanced scorecard dimensions. Which of the following enterprise goals is MOST relevant to select?

Options:

A.

Customer-oriented service culture

B.

Managed business risk

C.

Optimization of business process costs

D.

Product and business innovation

Question 5

What would be the PRIMARY reason for management to conduct a process capability assessment?

Options:

A.

To better understand the current state as compared to the target

B.

To better understand the cost of implementing the improved process

C.

To better understand the current level of risk versus future risk

Question 6

The different levels of involvement associated with roles and organizational structure are PRIMARILY divided into:

Options:

A.

governance and management levels.

B.

responsibility and accountability levels.

C.

operational and practitioner levels.

Question 7

Which of the following includes capability levels that can be used as benchmarks?

Options:

A.

Process metrics

B.

Process practices

C.

Process purpose

D.

Process activities

Question 8

Within a tailored enterprise governance system, a sourcing model for information and technology is associated with:

Options:

A.

design factors.

B.

relevant industry frameworks.

C.

focus areas.

Question 9

Which of the following would be an appropriate metric to align with a goal of “Delivery of programs on time, on budget, and meeting requirements and quality standards”?

Options:

A.

Percent of stakeholders satisfied with program/project quality

B.

Percent of business staff satisfied that IT service delivery meets agreed service levels

C.

Level of user satisfaction with the quality and availability of I&T-related management information

Question 10

Which of the following involves numeric mapping tables created for each of the design factors?

Options:

A.

An architecture design approach

B.

A quantitative approach

C.

A qualitative approach

D.

A risk-based approach

Question 11

Which of the following is an IT implementation method design factor that focuses on software building, deployment and operations?

Options:

A.

Traditional

B.

Agile

C.

DevOps

Question 12

An enterprise will often fail to realize implementation commitments during the execution of an EGIT implementation program plan if it:

Options:

A.

leverages existing mechanisms and ways of working.

B.

simplifies the implementation process.

C.

reduces projects into smaller executable pieces.

D.

focuses on enabling IT value over business value.

Question 13

Which of the following performance measures is used to assess a specific focus area?

Options:

A.

Maturity level

B.

Key goal indicator

C.

Process capability rating

Question 14

Which of the following describes the COBIT performance model?

Options:

A.

The COBIT performance model is a stand-alone model that can be used in conjunction with the COBIT core model.

B.

The COBIT performance model is integrated into the COBIT core model.

C.

The COBIT performance model is unique and not aligned with existing maturity and capability models.

Question 15

When Tailoring a governance system, what would be the MOST appropriate level of threat landscape for an enterprise in the health care sector?

Options:

A.

Normal

B.

Low

C.

High

D.

Critical

Question 16

Which of the following is MOST critical to ensuring the objective of managed availability and capacity?

Options:

A.

Identification of single points of failure

B.

Allocation of budgets for business continuity

C.

Future prediction of l&T resource requirements

Question 17

Which of the following is considered good practice with regard to performance management of organizational structures?

Options:

A.

Decision rights of the organizational structure are situation-dependent to facilitate escalation processes.

B.

The organizational structure is informally established to enable agile change management.

C.

Organizational meeting reports/minutes are available and meaningful to ensure transparency.

Question 18

When assessing organizational structures, it is MOST helpful when subcriteria for each criterion are defined and linked to:

Options:

A.

job descriptions.

B.

capability levels.

C.

performance metrics.

Question 19

Who is responsible for performing a stakeholder satisfaction survey and gathering feedback on lessons learned from the implementation of an EGIT program plan?

Options:

A.

The CIO and the program steering committee

B.

Business executives and the l&I governance board

C.

IT managers and IT process owners

D.

The risk and compliance function and IT audit

Question 20

The number of focus areas describing a certain governance topic or issue that can be addressed by governance objectives is:

Options:

A.

dependent on process maturity

B.

determined by the size of the enterprise

C.

virtually unlimited

Question 21

Which of the following is a principle of a proper governance framework?

Options:

A.

It should be based on a conceptual model.

B.

It should be independent of other standards, frameworks and regulations.

C.

It should be self-contained and not allow for the addition of new content.

Question 22

What is the focus of an enterprise that has a cost leadership strategy design factor?

Options:

A.

Long-term cost optimization

B.

Medium-term cost equalization

C.

Short-term cost minimization

Question 23

A CIO of a global enterprise has been mandated by the board to change the IT organizational structure from a divisional model to a centralized model and adopt outsourcing as required. The CIO identifies specific design factors that increase the importance of certain governance and management objectives. Which of the following is MOST likely to increase as a result?

Options:

A.

Risk appetite and tolerance

B.

Capability levels

C.

Threat landscape

D.

IT deployment

Question 24

Which of the following benefits derived from the use of COBIT is PRIMARILY associated with an internal stakeholder?

Options:

A.

COBIT provides insight on how to derive value from the use of I&T.

B.

COBIT helps to ensure that a third-party vendor's operations are secure.

C.

COBIT helps to ensure that a governance system is in place to sustain regulatory compliance.

Question 25

Which of the following is a KEY change enablement task that must be completed during the driver identification phase of an IT initiative?

Options:

A.

Define high-level improvement targets.

B.

Identify the business and governance drivers.

C.

Establish urgency for the changes needed.

D.

Assign high-level roles and responsibilities.

Question 26

Which of the following components of a governance system translates desired behavior into practical guidance?

Options:

A.

Culture, ethics and behavior

B.

Principles, policies and frameworks

C.

People, skills and competencies

Question 27

Which of the following alignment goals is MOST likely to be associated with the metric "percent of l&T services with defined operational costs and expected benefits?

Options:

A.

Quality of technology-related financial information

B.

Delivery of l&T services in line with business requirements

C.

Agility to turn business requirements into operational solutions

Question 28

Once IT governance is implemented, what is the NEXT phase in the life cycle of governance?

Options:

A.

Measuring objectives

B.

Initiating improvements

C.

Updating the program

Question 29

Within the COBIT goals cascade, stakeholder drivers are transformed into:

Options:

A.

the enterprise’s actionable strategy.

B.

business unit performance metrics.

C.

the enterprise’s governance framework.

Question 30

Which of the following describes a specific governance topic, domain or issue that can be addressed by a collection of governance and management objectives and their components?

Options:

A.

Design factor

B.

Focus area

C.

Enablers

Question 31

Which of the following is a PRIMARY objective of reviewing the effectiveness of a new IT governance system that has been operational for 6 months?

Options:

A.

Obtaining executive management support for IT governance

B.

Identifying further governance requirements

C.

Evaluating business performance reports

Question 32

An enterprise is designing a specific governance system that is using diverse technology deployments with multiple domains of business operations. Which of the following is the expected deliverable when tailoring the COBIT 2019 framework?

Options:

A.

Focus area guidance

B.

Capability levels

C.

Enterprise goals

D.

Aligned goals

Question 33

Which of the following COBIT components is a PRIMARY driver for the execution of corrective actions required to achieve governance or management objectives?

Options:

A.

Organizational structures

B.

People, skills and competencies

C.

Principles, policies and frameworks

Question 34

What is the function of a mapping table when determining the initial scope of a new governance system?

Options:

A.

It provides a means for calculating the cost/benefit associated with prioritized governance and management objectives.

B.

It indicates the relevance of a governance or management objective with a particular design factor.

C.

It indicates the degree of alignment of each governance and management objective with enterprise strategy.

D.

It provides a high level view of the importance of governance and management objectives for presentation purposes.

Question 35

An enterprise plans to outsource all of its noncore IT operations but wants to ensure the proper level of governance, risk and compliance (GRC) controls. Which of the following governance and management objectives would provide the MOST relevant management practices for the enterprise?

Options:

A.

AP012 Managed Risk

B.

APO10 Managed Vendors

C.

AP013 Managed Security

D.

APO09 Managed Service Agreements

Question 36

What is the PRIMARY role of business leadership when defining the future state in a business case?

Options:

A.

Assess proposed solutions against goals.

B.

Review compliance with legal issues.

C.

Verify the as-is assessment results.

D.

Determine capabilities required from IT.

Question 37

Which of the following domains deals with the definition of IT solutions and their integration in business processes?

Options:

A.

Align, Plan and Organize (APO)

B.

Deliver, Service and Support (DSS)

C.

Build, Acquire and Implement (BAI)

Question 38

Which of the following is a CRITICAL requirement when the IT function is strategic and crucial to the success of the business?

Options:

A.

Documented IT policies and procedures

B.

High involvement of IT-related roles in organizational structures

C.

Highly capable security-related processes and ensured risk optimization

Question 39

Which of the following frameworks has been used as a basis for developing guidance for the COBIT governance component of people, skills and competencies?

Options:

A.

Sans Security Policy Framework

B.

Cyber Security Framework

C.

Skills Framework for the Information Age

Question 40

Which of the following is a KEY consideration when determining the initial scope of a governance system?

Options:

A.

Compliance requirements faced by the enterprise

B.

Current l&T-related issues of the enterprise

C.

The role of IT within the enterprise

D.

The size of the enterprise

Question 41

Which of the following is a principle associated with the key components of a governance framework?

Options:

A.

The interaction among key components will impede automation and should therefore be limited.

B.

The relationships among key components should be identified to maximize consistency.

C.

Key components should function independently to maintain integrity.

Question 42

Which of the following BEST enables an enterprise to show and prove the benefits realized from the implementation of an EGIT program plan?

Options:

A.

Adopting performance metrics that are easy to achieve

B.

Tracking expected benefits and targets until program implementation

C.

Delivering a solution from a long-term and complex project

D.

Communicating the results and benefits in business impact terms

Question 43

Time-to-market is a metric that is directly related to which of the following enterprise goals?

Options:

A.

Managed digital transformation programs

B.

Optimization of internal business process functionality

C.

Portfolio of competitive products and services

Question 44

Which of the following components should be considered for inclusion when considering the threat landscape design factor?

Options:

A.

Compliance and assurance capabilities

B.

Impact and probability levels

C.

Information flows including security policy

D.

Information security focus areas

Question 45

Which of the following is determined at each level of a capability maturity model?

Options:

A.

Who is responsible for ensuring all activities at a given level are performed successfully

B.

How well a process is implemented and performing at a given level

C.

Which internal policies are relevant to a process at a given level

Question 46

When tailoring the COBIT organizational structure, which of the following is the PRIMARY purpose for aligning role descriptions to the enterprise's business context, organization and operating environment?

Options:

A.

Assigning levels of accountability and responsibility

B.

Developing hierarchy and reporting structure

C.

Preparing key goal areas and metrics for each role

Question 47

Which of the following is a KEY principle associated with the Accountable (A) role of an organizational structure?

Options:

A.

Accountability can be delegated.

B.

Accountability must be approved by the board.

C.

Accountability cannot be shared.

Question 48

Within the principles for a governance system, the value generated from the use of I&T reflects:

Options:

A.

the ratio of costs versus achieved service levels.

B.

a balance among benefits, risk and resources.

C.

maximized financial benefits to the investment portfolio.

Question 49

Which of the following benefits derived from the use of COBIT is PRIMARILY associated with an external stakeholder?

Options:

A.

COBIT provides guidance on how to organize and monitor the performance of I&T across the enterprise.

B.

COBIT helps to manage the dependency on the use of external service providers.

C.

COBIT helps to ensure compliance with applicable rules and regulations.

Question 50

Time-to-market is a market that is directly related to which of the following enterprise goals?

Options:

A.

Optimization of internal business process functionality

B.

Portfolio of competitive products and services

C.

Managed digital transformation programs

Question 51

Which of the following components of the governance system are required for successful completion of all activities?

Options:

A.

People, skills and competencies

B.

Processes

C.

Principles, policies and frameworks

Question 52

It is CRITICAL to perform a due diligence review following which type of event?

Options:

A.

Merger, acquisition, or divestiture

B.

Shifts in the market or economy

C.

External consultant assessment

D.

New business strategy or priority

Question 53

Which enterprise role ensures the board is kept informed of major decisions related to value delivery of I&T deployment in accordance with the enterprise strategy?

Options:

A.

Chief information officer

B.

Executive committee

C.

Chief executive officer

Question 54

Ensuring the program team knows and understands the enterprise goals is a part of which of the following implementation phases?

Options:

A.

Where are we now?

B.

How do we get there?

C.

Where do we want to be?

D.

What are the drivers?

Question 55

One year after IT governance is implemented, what KEY question should be asked and evaluated?

Options:

A.

Has the enterprise leveraged lessons learned?

B.

Has the enterprise reduced its risk exposure?

C.

Has the enterprise achieved expected benefits?

Question 56

What is the KEY benefit of considering the size of the enterprise when designing governance?

Options:

A.

Identifying the implementation effort needed to finalize the design phase

B.

Determining whether COBIT or SME focus area guidance should be used

C.

Assigning priorities to governance and management objectives

D.

Targeting capability levels of governance and management objectives

Question 57

What is the BEST approach when determining which of the archetype enterprise strategies most closely aligns with an enterprise's own strategy?

Options:

A.

Select a mix of equally important strategy archetypes.

B.

Select one primary strategy archetype and only one secondary strategy archetype.

C.

Select all the strategy archetypes that are applicable to the enterprise.

D.

Select the strategy archetype most closely aligned to the enterprise's information and technology risk profile.

Question 58

Which function within the IT corporate structure is responsible for classifying information using an agreed-upon classification scheme for a new data collection system?

Options:

A.

Information privacy

B.

IT governance

C.

Information security

D.

Enterprise architecture

Page: 1 / 20
Total 195 questions