ExamGecko
Home Home / Isaca / COBIT 2019

Isaca COBIT 2019 Practice Test - Questions Answers, Page 7

Question list
Search
Search

List of questions

Search

Which of the following COBIT organizational structure roles fulfills the practice and creates the intended outcome?

A.

Accountable (A)

A.

Accountable (A)

Answers
B.

Responsible (R)

B.

Responsible (R)

Answers
C.

Consulted (C)

C.

Consulted (C)

Answers
Suggested answer: B

Explanation:

The responsible role fulfills the practice and creates the intended outcome within an organizational structure chart (RACI chart). A RACI chart is a tool that assigns different levels of responsibility, accountability, consultation, and information to roles and organizational structures for each governance and management objective. The responsible role means performing or overseeing a task or process. There can be more than one responsible role for each task or process, but they must be coordinated by the accountable role.The responsible role fulfills the practice and creates the intended outcome by executing or supervising the process activities.13Reference:COBIT 2019 Framework: Introduction and Methodology,COBIT 2019 Framework: Roles, Responsibilities & RACI Charts

Which enterprise role ensures the board is kept informed of major decisions related to value delivery of I&T deployment in accordance with the enterprise strategy?

A.

Chief information officer

A.

Chief information officer

Answers
B.

Executive committee

B.

Executive committee

Answers
C.

Chief executive officer

C.

Chief executive officer

Answers
Suggested answer: A

Explanation:

The chief information officer (CIO) ensures the board is kept informed of major decisions related to value delivery of I&T deployment in accordance with the enterprise strategy. The CIO is the senior executive responsible for leading, directing, and managing the information and technology function of the enterprise. The CIO has a strategic role in aligning I&T with business requirements, ensuring I&T performance, managing I&T risks, fostering innovation, etc.The CIO ensures the board is kept informed of major decisions related to value delivery of I&T deployment by providing regular reports, updates, feedback, recommendations, etc., as well as by participating in board meetings or committees.1Reference:COBIT 2019 Framework: Introduction and Methodology, [COBIT 2019 Framework: Roles, Responsibilities & RACI Charts]

Which of the following is the MOST essential attribute of the highest process capability level (Level 5)?

A.

Pursuit of continuous improvement

A.

Pursuit of continuous improvement

Answers
B.

Full achievement of the process's purpose

B.

Full achievement of the process's purpose

Answers
C.

Quantitative performance measures

C.

Quantitative performance measures

Answers
Suggested answer: A

Explanation:

The pursuit of continuous improvement is the most essential attribute of the highest process capability level (Level 5). A process capability level is a measure of how well a process or activity is performed in terms of effectiveness, efficiency, completeness, reliability, etc. A process capability level can range from 0 (incomplete) to 5 (optimizing). Level 5 (optimizing) means that the process continuously improves its performance through both incremental and innovative improvements.The pursuit of continuous improvement is the most essential attribute of Level 5, as it implies that the process is constantly monitored, evaluated, learned from, and enhanced.14Reference:CMMI for Development, Version 1.3,CMMI Institute - Capability Maturity Model Integration

The level achieved when all processes of a focus area achieve a particular capability level is referred to as:

A.

the rating level.

A.

the rating level.

Answers
B.

the maturity level.

B.

the maturity level.

Answers
C.

the performance level.

C.

the performance level.

Answers
Suggested answer: B

Explanation:

The level achieved when all processes of a focus area achieve a particular capability level is referred to as the maturity level. A focus area is a topic or issue that can be addressed by governance objectives, such as digital transformation, cybersecurity, privacy, etc. A focus area consists of a set of processes that are relevant and applicable for the topic or issue. A capability level is a measure of how well a process or activity is performed in terms of effectiveness, efficiency, completeness, reliability, etc. A capability level can range from 0 (incomplete) to 5 (optimizing). A maturity level is the level achieved when all processes of a focus area achieve a particular capability level.A maturity level can range from 0 (non-existent) to 5 (optimized).12Reference:COBIT 2019 Framework: Introduction and Methodology,COBIT 2019 Framework: Governance System

When assessing organizational structures, it is MOST helpful when subcriteria for each criterion are defined and linked to:

A.

job descriptions.

A.

job descriptions.

Answers
B.

capability levels.

B.

capability levels.

Answers
C.

performance metrics.

C.

performance metrics.

Answers
Suggested answer: B

Explanation:

When assessing organizational structures, it is most helpful when subcriteria for each criterion are defined and linked to capability levels. Organizational structures are the arrangements of roles and responsibilities that enable the enterprise to achieve its objectives. Organizational structures can be assessed using six criteria: clarity, comprehensiveness, integration, alignment, authority, and accountability. Each criterion can be further divided into subcriteria that describe the specific aspects or attributes of the criterion. Capability levels are the measures of how well a process or activity is performed in terms of effectiveness, efficiency, completeness, reliability, etc. Capability levels can range from 0 (incomplete) to 5 (optimizing).Defining and linking subcriteria to capability levels helps to evaluate the current and desired state of organizational structures, as well as to identify gaps and improvement opportunities.123Reference:COBIT 2019 Framework: Introduction and Methodology,COBIT 2019 Design Guide: Designing an Information and Technology Governance Solution,COBIT 2019 Framework: Roles, Responsibilities & RACI Charts

The design factor associated with a highly regulated enterprise is likely to attribute MORE importance to which of the following?

A.

Managed strategy and operations

A.

Managed strategy and operations

Answers
B.

Documented work products and policies

B.

Documented work products and policies

Answers
C.

Understanding of the business by IT professionals

C.

Understanding of the business by IT professionals

Answers
Suggested answer: B

Explanation:

The design factor associated with a highly regulated enterprise is likely to attribute more importance to documented work products and policies. A design factor is a characteristic or aspect of an enterprise that influences the design and implementation of a governance system. They include factors such as enterprise size, industry sector, risk profile, regulatory environment, sourcing model, etc. A highly regulated enterprise is one that operates in an industry or market that is subject to strict laws, rules, standards, or guidelines that affect its business processes, products, services, etc.A highly regulated enterprise would need to ensure compliance with these requirements by documenting its work products and policies, as well as by providing evidence of their implementation and effectiveness.12Reference:COBIT 2019 Framework: Introduction and Methodology,COBIT 2019 Design Guide: Designing an Information and Technology Governance Solution

Which of the following is a CRITICAL requirement when the IT function is strategic and crucial to the success of the business?

A.

Documented IT policies and procedures

A.

Documented IT policies and procedures

Answers
B.

High involvement of IT-related roles in organizational structures

B.

High involvement of IT-related roles in organizational structures

Answers
C.

Highly capable security-related processes and ensured risk optimization

C.

Highly capable security-related processes and ensured risk optimization

Answers
Suggested answer: B

Explanation:

The high involvement of IT-related roles in organizational structures is a critical requirement when the IT function is strategic and crucial to the success of the business. The IT function is the part of the enterprise that is responsible for planning, delivering, operating, and supporting information and technology services. The IT function can have different levels of strategic importance for the business, depending on the nature, scope, and objectives of the enterprise. When the IT function is strategic and crucial to the success of the business, it means that information and technology are essential for creating value, achieving competitive advantage, enabling innovation, etc.In this case, it is critical to have high involvement of IT-related roles in organizational structures, such as having IT representation at the board level, having clear IT leadership roles and responsibilities, having effective IT governance committees or forums, etc.13Reference:COBIT 2019 Framework: Introduction and Methodology,COBIT 2019 Framework: Roles, Responsibilities & RACI Charts

Which of the following enterprise risk management concepts is MOST important to fully understand prior to finalizing the design of an IT governance system?

A.

The enterprise's risk tolerance

A.

The enterprise's risk tolerance

Answers
B.

The enterprise's risk profile

B.

The enterprise's risk profile

Answers
C.

The enterprise's risk appetite

C.

The enterprise's risk appetite

Answers
Suggested answer: B

Explanation:

The enterprise's risk profile is the most important enterprise risk management concept to fully understand prior to finalizing the design of an IT governance system. Enterprise risk management is the process of identifying, analyzing, evaluating, treating, monitoring, and communicating risks that affect the achievement of enterprise objectives. Enterprise risk management concepts include risk appetite (the amount and type of risk that an enterprise is willing to accept), risk tolerance (the acceptable variation in outcomes related to specific performance measures), risk profile (the overall exposure or level of risk that an enterprise faces), etc.The enterprise's risk profile is the most important concept to fully understand prior to finalizing the design of an IT governance system because it helps to determine the appropriate level of risk optimization for each governance objective.14Reference:COBIT 2019 Framework: Introduction and Methodology,COBIT 2019 Framework: Governance System

Which of the following is the FINAL action before completing the design of an IT governance system?

A.

Resolving inherent priority conflicts

A.

Resolving inherent priority conflicts

Answers
B.

Determining a sourcing model

B.

Determining a sourcing model

Answers
C.

Selecting an implementation method

C.

Selecting an implementation method

Answers
Suggested answer: C

Explanation:

Selecting an implementation method is the final action before completing the design of an IT governance system. An IT governance system is a set of components that provide direction, oversight, evaluation, monitoring, assurance, etc., for an enterprise's information and technology. The design of an IT governance system involves several steps or actions that help to customize and tailor the system to the specific needs and context of the enterprise. These steps or actions include defining design factors, defining focus areas, defining current state, defining target state, identifying gaps and improvement opportunities, defining roadmap and priorities, etc.Selecting an implementation method is the final action before completing the design of an IT governance system because it helps to determine how the system will be put into practice, what resources and activities are needed, what challenges and risks are expected, etc.12Reference:COBIT 2019 Framework: Introduction and Methodology,COBIT 2019 Design Guide: Designing an Information and Technology Governance Solution

An enterprise that specializes in software development is designing a new IT governance system as part of a transition from traditional waterfall to a more agile approach. Which step in the design phase would this transition impact the MOST?

A.

Compliance requirements

A.

Compliance requirements

Answers
B.

Implementation method

B.

Implementation method

Answers
C.

Sourcing model

C.

Sourcing model

Answers
Suggested answer: B

Explanation:

The transition from traditional waterfall to a more agile approach would impact the implementation method step in the design phase the most. The implementation method is the approach or strategy that is used to put the IT governance system into practice. The design phase is the stage in the IT governance life cycle that involves customizing and tailoring the IT governance system to the specific needs and context of the enterprise.The transition from traditional waterfall to a more agile approach would affect the implementation method step in the design phase because it would require a different way of planning, executing, monitoring, and controlling the IT governance system, as well as a different set of skills, tools, techniques, and practices.12Reference:COBIT 2019 Framework: Introduction and Methodology,COBIT 2019 Design Guide: Designing an Information and Technology Governance Solution

Total 194 questions
Go to page: of 20