ISACA Governance and Management of IT 2 — Questions and Answers
Question 1: Which COBIT 2019 governance objective focuses on ensuring that enterprise risk appetite and tolerance are understood and communicated?
- EDM03 - Ensured Risk Optimization (Correct answer)
- APO01 - Managed I&T Management Framework
- DSS02 - Managed Service Requests and Incidents
- MEA01 - Managed Performance and Conformance Monitoring
Correct answer: EDM03 - Ensured Risk Optimization
EDM03 ensures that risk appetite and tolerance are understood, and that residual IT risk is within enterprise limits.
Question 2: An IS auditor is reviewing IT governance at a company where the IT strategy committee meets quarterly but business unit heads rarely attend. What is the PRIMARY risk?
- IT decisions may not align with business objectives (Correct answer)
- IT costs may increase without oversight
- Security incidents may go unreported
- IT projects may be delivered late
Correct answer: IT decisions may not align with business objectives
Without business unit participation, IT decisions risk misalignment with actual business needs and strategy.
Question 3: Which metric BEST measures the effectiveness of IT governance in delivering business value?
- Number of IT projects completed on budget
- Percentage of IT investments achieving expected business outcomes (Correct answer)
- Total IT spending as a percentage of revenue
- Number of IT governance meetings held per year
Correct answer: Percentage of IT investments achieving expected business outcomes
Governance effectiveness is best measured by whether IT investments actually realize the business outcomes they were intended to deliver.
Question 4: Under ITIL 4, the concept that all IT services should be co-created with customers and stakeholders is called:
- Service integration
- Value co-creation (Correct answer)
- Demand management
- Continual improvement
Correct answer: Value co-creation
ITIL 4's service value system is built on the principle of value co-creation between the service provider and its stakeholders.
Question 5: A company's board has delegated IT governance oversight to a subcommittee. An IS auditor should verify PRIMARILY that the subcommittee:
- Has technical IT expertise among its members
- Reports its findings and decisions to the full board (Correct answer)
- Meets at least monthly to review IT performance
- Approves all IT project budgets individually
Correct answer: Reports its findings and decisions to the full board
Delegating oversight does not transfer accountability; the subcommittee must report to the full board so ultimate accountability remains intact.
Question 6: Which element of IT governance directly addresses the question: 'Who is entitled to make which IT decisions?'
- IT performance management
- IT risk management
- IT governance decision rights (Correct answer)
- IT resource management
Correct answer: IT governance decision rights
Decision rights define who has authority to make specific IT decisions, which is a foundational element of IT governance structure.
Question 7: When implementing COBIT, an organization starts by defining stakeholder needs and translating them into enterprise goals. This step is part of the:
- Governance and management objectives cascade (Correct answer)
- Process capability assessment
- Risk and compliance evaluation
- IT balanced scorecard
Correct answer: Governance and management objectives cascade
COBIT's goals cascade translates stakeholder needs into enterprise goals, then IT-related goals, then governance and management objectives.
Which COBIT 2019 governance objective focuses on ensuring that enterprise risk appetite and tolerance are understood and communicated?