ExamGecko
Home Home / Isaca / NIST-COBIT-2019

Isaca NIST-COBIT-2019 Practice Test - Questions Answers, Page 4

Question list
Search
Search

Which of the following is the PRIMARY reason for establishing open communication between all participants and stakeholders as part of the implementation phase?

A.

To describe the high-level roadmap for achieving the vision

A.

To describe the high-level roadmap for achieving the vision

Answers
B.

To ensure issues can be identified and resolved

B.

To ensure issues can be identified and resolved

Answers
C.

To establish the sharing of information with external partners

C.

To establish the sharing of information with external partners

Answers
Suggested answer: B

Explanation:

The primary reason for establishing open communication between all participants and stakeholders as part of the implementation phase is to ensure issues can be identified and resolved, as this can facilitate the collaboration, coordination, and feedback among the involved parties, and help to overcome the challenges and risks that may arise during the implementation12.

Reference Connecting COBIT 2019 to the NIST Cybersecurity Framework - ISACA Questions and Answers | NIST

During CSF life cycle action plan review, which of the following tasks is associated with realizing benefits?

A.

Developing business cases indicating success factors

A.

Developing business cases indicating success factors

Answers
B.

Monitoring performance against objectives

B.

Monitoring performance against objectives

Answers
C.

Documenting risk issues and remediation plans

C.

Documenting risk issues and remediation plans

Answers
Suggested answer: B

Explanation:

According to the ISACA guide, monitoring performance against objectives is one of the tasks associated with realizing benefits, as it helps to measure the outcomes and value of the CSF implementation, and to identify and address any issues or gaps that may arise1. This task also involves reporting and communicating the results and feedback to the relevant stakeholders and ensuring continuous improvement2.

Reference Connecting COBIT 2019 to the NIST Cybersecurity Framework - ISACA Manage Enterprise Cyberrisk by Applying the NIST CSF With COBIT ... - ISACA

The PRIMARY function of COBIT Implementation Phase 7: How Do We Keep the Momentum Going is to provide an opportunity for which of the following?

A.

Closing the loop for communication workflow

A.

Closing the loop for communication workflow

Answers
B.

Documenting improvements in a prioritized action plan

B.

Documenting improvements in a prioritized action plan

Answers
C.

Ensuring frequent stakeholder communication

C.

Ensuring frequent stakeholder communication

Answers
Suggested answer: A

Explanation:

The primary function of COBIT Implementation Phase 7 is to provide an opportunity for closing the loop for communication workflow, which means to ensure that the results and feedback of the implementation are reported and communicated to the relevant stakeholders, and that the lessons learned and best practices are captured and shared for future reference12.

Reference 7 Phases in COBIT Implementation | COBIT Certification - Simplilearn COBIT 2019 Design and Implementation COBIT Implementation, page 31.

Combining CSF principles with COBIT 2019 practices helps to ensure value, manage risk, and support mission drivers through support and direction of:

A.

the chief information officer and IT management.

A.

the chief information officer and IT management.

Answers
B.

the board of directors and executive management.

B.

the board of directors and executive management.

Answers
C.

the chief information security manager and the data protection officer.

C.

the chief information security manager and the data protection officer.

Answers
Suggested answer: B

Explanation:

Combining CSF principles with COBIT 2019 practices helps to ensure value, manage risk, and support mission drivers through support and direction of the board of directors and executive management, as they are responsible for setting the vision, strategy, and objectives of the organization, and for overseeing the governance and management of IT-related operations12.

Reference Connecting COBIT 2019 to the NIST Cybersecurity Framework - ISACA COBIT 2019 (With Principles, Components, Users and Benefits)


Which of the following is an objective of COBIT Implementation Phase 3-Where Do We Want to Be?

A.

Identify critical processes or other components addressed in the improvement plan.

A.

Identify critical processes or other components addressed in the improvement plan.

Answers
B.

Determine the target capability for processes within governance and management

B.

Determine the target capability for processes within governance and management

Answers
C.

objectives.

C.

objectives.

Answers
D.

Integrate the metrics for project performance and benefits realization.

D.

Integrate the metrics for project performance and benefits realization.

Answers
Suggested answer: B

Explanation:

This is an objective of COBIT Implementation Phase 3: Where Do We Want to Be?, because it involves defining the desired state of the enterprise's governance and management system, based on the stakeholder needs, drivers, and scope12. This objective also includes using the COBIT Performance Management system to assess the current and target capability levels of the processes that support the governance and management objectives34.

Which of the following is an objective of Implementation Phase 3 - Where Do We Want to Be?

A.

Integrate the improvement projects into the overall program plan.

A.

Integrate the improvement projects into the overall program plan.

Answers
B.

Monitor, measure, and report on project progress.

B.

Monitor, measure, and report on project progress.

Answers
C.

Create a detailed business case and high-level program plan from gathered information.

C.

Create a detailed business case and high-level program plan from gathered information.

Answers
Suggested answer: C

Explanation:

This is an objective of Implementation Phase 3: Where Do We Want to Be?, because it involves defining the desired state of the enterprise's governance and management system, based on the stakeholder needs, drivers, and scope12. This objective also includes developing a business case that provides the rationale and justification for the improvement program, and a high-level program plan that outlines the scope, objectives, approach, and resources of the program3 .

Which of the following is an objective of COBIT Implementation Phase 3 - Where Do We Want to Be?

A.

Determine the current capability of selected processes.

A.

Determine the current capability of selected processes.

Answers
B.

Identify critical processes or other components addressed in the improvement plan.

B.

Identify critical processes or other components addressed in the improvement plan.

Answers
C.

Create a detailed business case and high-level program plan.

C.

Create a detailed business case and high-level program plan.

Answers
Suggested answer: C

Explanation:

The objective of COBIT Implementation Phase 3 is to set an improvement target and identify gaps and potential solutions using COBIT's guidance. This involves creating a detailed business case and a high-level program plan for the implementation.

Reference COBIT 2019 Design and Implementation COBIT Implementation, page 31. 7 Phases in COBIT Implementation | COBIT Certification - Simplilearn

Documenting opportunities for improvement occurs within which implementation phase?

A.

Phase 4 - What Needs to Be Done?

A.

Phase 4 - What Needs to Be Done?

Answers
B.

Phase 2 - Where Are We Now?

B.

Phase 2 - Where Are We Now?

Answers
C.

Phase 3 - Where Do We Want to Be?

C.

Phase 3 - Where Do We Want to Be?

Answers
Suggested answer: B

Explanation:

The objective of COBIT Implementation Phase 2 is to define the scope of the implementation using COBIT's mapping of enterprise goals to IT-related goals and the associated IT processes, and to consider how risk scenarios could also highlight key processes on which to focus. This phase also involves documenting the current capability and performance of the selected processes and identifying opportunities for improvement12.

Reference 7 Phases in COBIT Implementation | COBIT Certification - Simplilearn COBIT 2019 Design and Implementation COBIT Implementation, page 31.

Which of the following COBIT and NIST implementation steps may be reversed depending on the culture of the organization?

A.

Step 4: Conduct a Risk Assessment and Step 6: Determine, Analyze, and Prioritize Gaps

A.

Step 4: Conduct a Risk Assessment and Step 6: Determine, Analyze, and Prioritize Gaps

Answers
B.

Step 3: Create a Current Profile and Step 5: Create a Target Profile

B.

Step 3: Create a Current Profile and Step 5: Create a Target Profile

Answers
C.

Step 1: Prioritize and Scope and Step 2: Orient

C.

Step 1: Prioritize and Scope and Step 2: Orient

Answers
Suggested answer: C

Explanation:

According to the ISACA guide, the order of these two steps may be reversed depending on the culture of the organization and the level of stakeholder engagement1. Some organizations may prefer to start with a broad orientation of the NIST CSF and COBIT 2019 before scoping and prioritizing the implementation, while others may want to define the scope and priorities first and then orient the stakeholders accordingly.

Reference Implementing the NIST Cybersecurity Framework Using COBIT 2019, page 17.

Which of the following is the MOST critical process tool to performing Implementation Phase 3-Where Do We Want to Be?

A.

Control self-assessment

A.

Control self-assessment

Answers
B.

Gap assessment

B.

Gap assessment

Answers
C.

Cost-benefit analysis

C.

Cost-benefit analysis

Answers
Suggested answer: B

Explanation:

A gap assessment is the most critical process tool to performing Implementation Phase 3, as it helps to identify the current and desired states of the selected processes, and the gaps and potential solutions to bridge them. A gap assessment also helps to create a detailed business case and a high-level program plan for the implementation12.

Reference 7 Phases in COBIT Implementation | COBIT Certification - Simplilearn COBIT 2019 Design and Implementation COBIT Implementation, page 31.

Total 50 questions
Go to page: of 5