Skip to content

cobit-2019-design-and-implementation COBIT 2019 Design and Implementation Practice Questions

Prepare for cobit-2019-design-and-implementation with more than an answer.

244 questions in the full set20 sample questionsUpdated Oct 18, 2025
Exam fee
$275 USD
Level
Advanced
Valid for
Lifetime (no expiration)
Domains covered on the exam 7
  1. Governance Implementation Lifecycle32%
  2. The Governance System Design Workflow32%
  3. Design Factors for a Governance System15%
  4. COBIT Basic Concepts8%
  5. Implementing & Optimizing I&T Governance Overview7%
  6. Impact of Design Factors3%
  7. Key Topics Decision Matrix3%
  1. 1

    True or False: In a COBIT RACI chart, a role assigned as 'Accountable' (A) for a particular activity must also be 'Responsible' (R) for carrying out that activity.

    Show answer details

    Correct answer: B

    This statement is false. The role that is 'Accountable' has ultimate ownership and is the final authority, but the work itself is often performed by those who are 'Responsible'. A manager may be accountable for a report, while their team members are responsible for creating it.

  2. 2

    A global retailer is designing a governance system. The company's risk profile indicates a high level of risk related to cybersecurity threats and data breaches. Which of the following governance or management objectives would receive the HIGHEST priority weighting based on this specific design factor?

    Show answer details

    Correct answer: C

    When the risk profile is the primary driver, the APO12 (Managed Risk) process naturally becomes the highest priority. This process ensures that I&T-related risks, including cybersecurity threats, are identified, assessed, and responded to in line with the enterprise's risk appetite.

  3. 3

    A consultant is performing a process capability assessment as part of Phase 2 ('Where are we now?') of a governance implementation. The IT department has a documented procedure for incident management, but interviews reveal that different teams follow their own informal methods, and there is no consistent tracking or reporting. What is the HIGHEST capability level that can be assigned to this process?

    Show answer details

    Correct answer: B

    The process is at Level 1. It is being performed and generally achieves its purpose (incidents get resolved). However, the lack of consistent application, tracking, and management means it does not meet the criteria for Level 2 (Managed), which requires the process to be planned, monitored, and controlled.

  4. 4

    A company has successfully designed its governance system and is now in the implementation phase. The implementation plan consists of several distinct projects, such as 'Implement Service Desk,' 'Establish Risk Register,' and 'Roll out Security Awareness Training.' Which COBIT process is MOST relevant for overseeing these related projects to ensure they collectively achieve the desired governance improvements?

    Show answer details

    Correct answer: A

    The scenario describes a collection of related projects aimed at a common strategic objective (improved governance). This is the definition of a program. BAI01 Managed Programs provides the framework for managing a portfolio of projects, coordinating resources, managing interdependencies, and ensuring the program delivers the intended value.

  5. 5

    The following diagram shows the relationship between different elements in the COBIT framework. What does the arrow from 'Alignment Goals' to 'Governance and Management Objectives' represent?

    graph TD A[Enterprise Goals] --> B[Alignment Goals] B --> C(Governance and Management Objectives)

    Show answer details

    Correct answer: A

    This step in the goals cascade represents the translation of I&T-related outcomes (Alignment Goals) into the specific processes and activities (Governance and Management Objectives) that need to be performed at a certain capability level to achieve those outcomes.

  6. 6

    A multinational logistics company has just completed Phase 2 ('Where are we now?') of the COBIT implementation lifecycle. The assessment revealed significant gaps in process capability, particularly in BAI03 (Managed Solutions Identification and Build). The program steering committee is pushing to immediately jump to Phase 5 ('How do we get there?') by purchasing a new ERP system. What is the MOST significant risk of this approach?

    Show answer details

    Correct answer: A

    Skipping Phase 3 ('Where do we want to be?') and Phase 4 ('What needs to be done?') means no target state has been defined and no detailed improvement plan has been created. Purchasing a solution without this context risks misalignment with actual business needs and strategic goals, leading to wasted investment and unresolved governance gaps.

  7. 7

    A governance design team is working through Step 3 ('Refine scope using design factors') of the design workflow. They have determined that the company's enterprise strategy is 'Growth/Acquisition'. How does this specific design factor value primarily influence the prioritization of governance and management objectives?

    Show answer details

    Correct answer: B

    A 'Growth/Acquisition' strategy demands the ability to rapidly integrate new businesses, manage complex programs of change, and innovate to capture new markets. Therefore, objectives focused on program management, organizational change, and innovation (like BAI02) become paramount.

  8. 8

    A rapidly scaling FinTech startup is designing its first formal governance system. The company operates in a highly regulated environment, has a high risk profile due to handling sensitive financial data, and follows a DevOps implementation method. Which of the following governance system components must be MOST carefully designed and integrated to ensure success? (Select TWO)

    Show answer details

    Correct answer: A, D

    In a DevOps environment, processes must be highly automated and integrated into the CI/CD pipeline. To meet regulatory and risk requirements, these processes (e.g., for change control, security testing, deployment) must be robust, auditable, and efficient, making their design critical.

    DevOps relies heavily on a culture of shared responsibility ('you build it, you run it'). In a high-risk, regulated environment, fostering a strong culture of security, compliance, and ethical behavior ('DevSecOps') is paramount to prevent catastrophic failures. This cultural component is as critical as the automated processes.

  9. 9

    A university is implementing a new student information system. During Phase 6 ('Did we get there?') of the implementation lifecycle, the primary focus is on monitoring the achievement of the goals defined in the business case. Which COBIT process provides the most relevant guidance for this activity?

    Show answer details

    Correct answer: C

    MEA01 is specifically designed to monitor performance against agreed-upon targets and ensure conformance with requirements. This directly supports the objective of Phase 6, which is to track progress, measure benefits realization, and report on the achievement of business case goals.

  10. 10

    True or False: The COBIT 2019 Design Guide prescribes a single, mandatory target capability level for each prioritized governance objective, regardless of the enterprise's specific context or design factors.

    Show answer details

    Correct answer: B

    This is false. The essence of the COBIT 2019 design process is to tailor the governance system, including target capability levels, to the specific needs and context of the enterprise. The Design Guide provides suggested levels based on design factors, but these are inputs to the decision, not mandatory prescriptions.

Create an account to continue.