Labour Day Special Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

Isaca COBIT-2019 COBIT 2019 Foundation Exam Practice Test

Page: 1 / 19
Total 186 questions

COBIT 2019 Foundation Questions and Answers

Question 1

What is the BEST way to determine whether IT governance is achieving intended outcomes one year after implementation?

Options:

A.

Evaluate performance measurements identified in the business case

B.

Survey the satisfaction level of key business stakeholders.

C.

Review change drivers to determine whether corresponding changes were successful.

Question 2

Which of the following management objectives would be given HIGHER priority in an enterprise's governance system when the enterprise is very risk-averse?

Options:

A.

Managed operations

B.

Managed security

C.

Managed portfolio

Question 3

Which of the following is an important desired outcome to be achieved from the execution of an EGIT implementation program plan?

Options:

A.

Completion of EGIT project implementation regardless of the amount of time required

B.

Transition of EGIT projects into the enterprise's normal development life cycle

C.

Development of a record of unapproved EGIT projects

D.

Mitigation of all risks associated with the implementation of EGIT projects

Question 4

Which of the following is an example of a governance system component?

Options:

A.

The risk register of the enterprise

B.

The compliance regulations applicable to the enterprise

C.

The role of IT for the enterprise

D.

The geopolitical landscape in which the enterprise operates

Question 5

Which of the following describes a specific governance topic, domain or issue that can be addressed by a collection of governance and management objectives and their components?

Options:

A.

Design factor

B.

Focus area

C.

Enablers

Question 6

Responsibility for developing an EGIT business case outline and details resides with which of the following?

Options:

A.

IT managers and IT process owners

B.

CIO and program steering committee

C.

Board of directors and business executives

D.

Risk and compliance function and IT audit

Question 7

According to the principles for a governance framework, which of the following is a PRIMARY consideration when addressing new issues within a flexible and open framework?

Options:

A.

Maintaining integrity and consistency

B.

Aligning with internal IT policies and procedures

C.

Identifying related industry standards

Question 8

Which of the following is the MOST essential attribute of the highest process capability level (Level 5)?

Options:

A.

Pursuit of continuous improvement

B.

Full achievement of the process’s purpose

C.

Quantitative performance measures

Question 9

What IT governance implementation approach should be utilized in order to achieve maximum enterprise benefits?

Options:

A.

Separating business and IT-related activities during implementation

B.

Including improvement initiatives in implementation

C.

Treating implementation as a program

Question 10

In most cases, management of the enterprise is the responsibility of:

Options:

A.

the project management office.

B.

the executive management team.

C.

the board of directors.

Question 11

Which COBIT domain of management objectives incorporates managed business process controls?

Options:

A.

Build, Acquire and Implement (BAI)

B.

Align, Plan and Organize (APO)

C.

Deliver, Service and Support (DSS)

Question 12

When considering the IT implementation methods design factor, and the design factor value is DevOps, which of the following should be a management objective priority?

Options:

A.

Managed change acceptance and transitioning (BAI07)

B.

Managed availability and capacity (BAI04)

C.

Managed service requests and incidents (DSS02)

D.

Managed solution identification and build (BAI03)

Question 13

An enterprise is not having success implementing IT governance because key staff are not participating in planning meetings. What is the MOST likely underlying cause?

Options:

A.

Lack of consequences for not attending

B.

Failure to utilize program management principles

C.

Lack of senior leadership commitment

Question 14

Which of the following MUST be defined before determining alignment goals?

Options:

A.

External laws and regulations

B.

Stakeholder drivers and needs

C.

Governance and management objectives

Question 15

When Tailoring a governance system, what would be the MOST appropriate level of threat landscape for an enterprise in the health care sector?

Options:

A.

Normal

B.

Low

C.

High

D.

Critical

Question 16

When tailoring COBIT 2019 to enterprise requirements, which of the following is the PRIMARY objective of preparing a risk profile?

Options:

A.

To identify areas of risk that require mitigation

B.

To identify areas of risk that cause technology disruption

C.

To identify areas of risk that impact business continuity

D.

To identify areas of risk that exceed risk appetite

Question 17

What is the role of the internal audit function when defining the EGIT target state?

Options:

A.

Provide advice and assist with target-state positioning and gap priorities.

B.

Prepare the detailed business case and high-level program plan.

C.

Align targeted process improvement solutions to enterprise goals.

D.

Develop and communicate a change enablement plan and objectives.

Question 18

Which of the following components should be considered for inclusion when considering the threat landscape design factor?

Options:

A.

Compliance and assurance capabilities

B.

Impact and probability levels

C.

Information flows including security policy

D.

Information security focus areas

Question 19

Which of the following is an important principle of a proper governance framework?

Options:

A.

The governance framework should be rigorous and focus exclusively on prioritized existing issues.

B.

The governance framework should be based on a single relevant standard, framework or regulation.

C.

The governance framework should allow for flexibility in addressing new issues.

Question 20

A privately held company is planning to be listed on the stock exchange and is working on meeting regulatory requirements. After considering an assessment by external consultants, the company has decided to implement the process 'Ensured Stakeholder Engagement." Who is BEST suited for this responsibility?

Options:

A.

Relationship manager

B.

Chief information officer

C.

The board and executive management

D.

Chief information security officer

Question 21

The COBIT framework is designed to meet the I&T goals for which of the following?

Options:

A.

Board and executive management only

B.

IT department only

C.

Entire enterprise

Question 22

An enterprise’s business line managers have voiced concerns because the cost of governance-required improvements is perceived as too expensive. How can the IT governance team BEST address this concern?

Options:

A.

Improve the communication of business benefits.

B.

Involve business line managers in the improvement planning process.

C.

Share the return on investment (ROI) analysis.

Question 23

One year after IT governance is implemented, what KEY question should be asked and evaluated?

Options:

A.

Has the enterprise leveraged lessons learned?

B.

Has the enterprise reduced its risk exposure?

C.

Has the enterprise achieved expected benefits?

Question 24

COBIT addresses governance issues by doing which of the following?

Options:

A.

Grouping relevant governance components into objectives that can be managed to a required capability level

B.

Providing a full description of the entire IT environment within an enterprise

C.

Defining specific governance strategies and processes to implement in specific situations

Question 25

An enterprise that specializes in software development is designing a new IT governance system as part of a transition from traditional waterfall to a more agile approach. Which step in the design phase would this transition impact the MOST?

Options:

A.

Compliance requirements

B.

Implementation method

C.

Sourcing model

Question 26

Which COBIT principle addresses the need to consider how many changes in technology or strategy impact the enterprise governance system as a whole?

Options:

A.

A governance system should be tailored to the enterprise’s needs.

B.

A governance system should cover the enterprise end to end.

C.

A governance system should be dynamic.

Question 27

How do the assigned capability levels in the COBIT core model facilitate the achievement of the different capability levels?

Options:

A.

By defining organizational structure with specific roles and responsibilities

B.

By setting performance metrics for enabler goals

C.

By providing clear definition of the processes and required activities

Question 28

Which of the following components of the governance system are the KEY decision-making entities in an enterprise?

Options:

A.

Organizational structures

B.

People, skills and competencies

C.

Principles, policies and frameworks

Question 29

Which of the following would be an appropriate metric to align with a goal of “Delivery of programs on time, on budget, and meeting requirements and quality standards”?

Options:

A.

Percent of stakeholders satisfied with program/project quality

B.

Percent of business staff satisfied that IT service delivery meets agreed service levels

C.

Level of user satisfaction with the quality and availability of I&T-related management information

Question 30

Which of the following enterprise goals is within the Customer dimension of the IT balanced scorecard?

Options:

A.

Delivery of programs on time and on budget

B.

Product and business innovation

C.

Quality of management information

Question 31

Which of the following is a CRITICAL requirement when the IT function is strategic and crucial to the success of the business?

Options:

A.

Documented IT policies and procedures

B.

High involvement of IT-related roles in organizational structures

C.

Highly capable security-related processes and ensured risk optimization

Question 32

What is the PRIMARY benefit of conducting a high-level risk analysis during governance design?

Options:

A.

Establishing a risk response strategy

B.

Identifying enterprise key risk indicators (KRl)

C.

Prioritizing governance and management objectives

D.

Communicating IT and business risk scenarios

Question 33

Which of the following roles should be involved when nominating key program roles to create the appropriate governance environment?

Options:

A.

IT management

B.

Business management

C.

Human resources

D.

Board and executives

Question 34

Which of the following is an important component for an enterprise strategy archetype of cost leadership as defined by COBIT 2019?

Options:

A.

Organizational structures

B.

Skills and competencies

C.

Enterprise architect

D.

Support for the portfolio management role with an investment office

Question 35

Which of the following is a strategy archetype focused on increasing revenues?

Options:

A.

Innovation/differentiation

B.

Client service/stability

C.

Growth/acquisition

D.

Cost leadership

Question 36

Which "Role of IT" design factor is viewed as a driver for business process and service innovation?

Options:

A.

Turnaround

B.

Strategic

C.

Support

Question 37

Which of the following is an enterprise goal according to COBIT?

Options:

A.

Managed IT-related risks

B.

IT compliance with internal policies

C.

Business service continuity and availability

Question 38

Which of the following is a KEY change enablement task that must be completed during the driver identification phase of an IT initiative?

Options:

A.

Define high-level improvement targets.

B.

Identify the business and governance drivers.

C.

Establish urgency for the changes needed.

D.

Assign high-level roles and responsibilities.

Question 39

Which of the following enterprise risk management concepts is MOST important to fully understand prior to finalizing the design of an IT governance system?

Options:

A.

The enterprise’s risk tolerance

B.

The enterprise’s risk profile

C.

The enterprise’s risk appetite

Question 40

Which of the following is the BEST starting point when translating enterprise goals into actionable governance and management objectives?

Options:

A.

Generic enterprise goals

B.

Risk-based enterprise goals

C.

Selective enterprise goals

D.

Prioritized enterprise goals

Question 41

What functional task area is responsible for assessing the potential return on investment (ROI) during future state planning?

Options:

A.

Continuous improvement

B.

Change enablement

C.

Risk management

D.

Program management

Question 42

Which enterprise role ensures the board is kept informed of major decisions related to value delivery of I&T deployment in accordance with the enterprise strategy?

Options:

A.

Chief information officer

B.

Executive committee

C.

Chief executive officer

Question 43

Which of the following is an output of the "what needs to be done" phase?

Options:

A.

Risk response document

B.

Identified quick wins

C.

High-level program plan

D.

Detailed business case

Question 44

Which of the following figures BEST illustrates the context of an enterprise governance of information and technology (EGIT) system?

A)

Question # 44

B)

Question # 44

C)

Question # 44

D)

Question # 44

Options:

A.

Option A

B.

Option B

C.

Option C

D.

Option D

Question 45

Which of the following cascades to enterprise goals?

Options:

A.

Stakeholder needs

B.

Organizational objectives

C.

Enterprise strategy

Question 46

Which of the following MUST be done before an enterprise can determine performance measures for a process improvement initiative?

Options:

A.

Conduct a capabilities assessment.

B.

Calculate return on investment (ROI).

C.

Perform a process risk assessment.

Question 47

The alignment goal titled "Security of information, processing infrastructure and privacy" is part of which IT balanced scorecard (BSC) dimension?

Options:

A.

Internal

B.

Learning and growth

C.

Customer

Question 48

A CIO of a global enterprise has been mandated by the board to change the IT organizational structure from a divisional model to a centralized model and adopt outsourcing as required. The CIO identifies specific design factors that increase the importance of certain governance and management objectives. Which of the following is MOST likely to increase as a result?

Options:

A.

Risk appetite and tolerance

B.

Capability levels

C.

Threat landscape

D.

IT deployment

Question 49

Who is accountable for monitoring the performance of the execution of an EGIT implementation program plan against success metrics and adjusting long-term targets when necessary?

Options:

A.

Board of directors

B.

IT process owners

C.

IT audit department

D.

CIO

Question 50

Before designing an enterprise IT governance system, an organization should FIRST review and understand:

Options:

A.

the enterprise's risk profile.

B.

the enterprise's strategy.

C.

current IT-related issues.

Question 51

Which of the following BEST describes the objectives of the Evaluate, Direct and Monitor (EDM) domain?

Options:

A.

Assessing strategic options and guiding senior management on the options chosen

B.

Addressing the overall organization, strategy and supporting activities for IT

C.

Addressing the operational delivery and support of l&T services, including security

Question 52

Which of the following metrics would BEST enable an enterprise to evaluate an alignment goal specifically related to security of information and privacy?

Options:

A.

Ratio and extent of erroneous business decisions in which erroneous I&T-related information was a key factor

B.

Number of critical business processes supported by up-to-date infrastructure and applications

C.

Number of confidentiality incidents causing financial loss, business disruption or public embarrassment.

Question 53

Which of the following l&T implementation methods requites the HIGHEST level of participation by users at multiple stages of software development?

Options:

A.

Hybrid

B.

Traditional

C.

DevOps

D.

Agile

Question 54

Which of the following BEST enables a governance system to achieve governance and management objectives?

Options:

A.

The governance system includes many components that work together in a holistic way.

B.

The governance system primarily addresses the culture and behavior of the individuals involved in the system.

C.

The governance system focuses specifically on organizational structures for decision making.

Question 55

The value that I&T delivers should be:

Options:

A.

aligned directly with the values on which the business is focused.

B.

focused exclusively on I&T investments that generate financial benefits.

C.

restricted to maintaining and increasing value derived from existing I&T investments.

Page: 1 / 19
Total 186 questions