Skip to content

COBIT-2019-Foundation COBIT 2019 Foundation Certificate Practice Questions

Prepare for COBIT-2019-Foundation with more than an answer.

257 questions in the full set20 sample questionsUpdated Oct 25, 2025
Exam fee
$175 USD
Level
Foundation
Valid for
No expiration
Domains covered on the exam 8
  1. Governance System and Components30%
  2. Governance and Management Objectives23%
  3. Principles13%
  4. Framework Introduction12%
  5. Implementation8%
  6. Designing a Tailored Governance System7%
  7. Performance Management4%
  8. Business Case3%
  1. 1

    A financial services firm is required by regulators to provide assurance on the effectiveness of its internal controls over financial reporting. The firm's IT systems are integral to this process. Which management objective in the MEA domain is specifically focused on providing this type of assurance to stakeholders?

    Show answer details

    Correct answer: D

    MEA04 Managed Assurance is the objective focused on planning, scoping, and executing assurance initiatives to provide confidence to stakeholders that governance and management objectives are achieved and that risk is managed. This directly aligns with the need to provide formal assurance on internal controls to regulators. While MEA02 manages the system of internal control, MEA04 is about the process of providing assurance on that system.

  2. 2

    A key principle of a COBIT 2019 governance system is the 'Holistic Approach'. This principle is embodied by the seven categories of components that work together. Which of the following are components of a governance system according to this principle? (Select THREE)

    Show answer details

    Correct answer: B, C, E

    Information is one of the seven core components of a governance system.

    Processes are one of the seven core components of a governance system.

    Organizational Structures are one of the seven core components of a governance system.

  3. 3

    A company has successfully implemented a new CRM system. The project manager is now focused on ensuring that business users are properly trained and that the new system and processes are fully integrated into daily operations. This focus on managing the human and procedural aspects of change aligns with which BAI domain objective?

    Show answer details

    Correct answer: B

    BAI05 Managed Organizational Change is focused on preparing and committing stakeholders for business change and reducing the risk of failure. This includes activities like communication, training, and ensuring business readiness to adopt new ways of working, which is exactly what the project manager is doing post-implementation.

  4. 4

    The governance board of an e-commerce company is reviewing its I&T risk profile. They want to ensure that the company's risk appetite is clearly defined and that I&T-related risk does not exceed this appetite. Which EDM governance objective is primarily responsible for this oversight?

    Show answer details

    Correct answer: C

    EDM03 Ensured Risk Optimization is the governance objective that ensures I&T-related risk does not exceed the enterprise’s risk appetite and risk tolerance. The governance body is responsible for evaluating and directing the setting of risk appetite and monitoring that risk stays within these defined limits. While APO12 manages risk at the management level, EDM03 is the corresponding governance oversight function.

  5. 5

    A company wants to ensure its IT strategy is fully aligned with its overall enterprise strategy. This involves creating a clear communication plan, defining I&T's role, and developing a strategic roadmap. Which management objective from the APO domain is dedicated to these activities?

    graph TD A[Enterprise Strategy] --> B{APO02 Managed Strategy}; B --> C[I&T Strategic Plan]; C --> D[Tactical Plans & Roadmaps];

    Show answer details

    Correct answer: B

    APO02 Managed Strategy focuses on leveraging the enterprise architecture and the I&T-related organizational structure to support the overall enterprise strategy. It involves understanding the enterprise environment, defining the target I&T capabilities, and developing plans to close any gaps, ensuring I&T and business strategies are aligned.

  6. 6

    A global logistics company is experiencing significant delays in its supply chain due to inconsistent data handling across different regional IT systems. The board has identified 'Improved Data Quality and Integration' as a primary enterprise goal. According to the COBIT 2019 goals cascade, which management objective should be prioritized to directly support this enterprise goal?

    Show answer details

    Correct answer: C

    The COBIT 2019 goals cascade links enterprise goals to alignment goals and then to specific governance and management objectives. An enterprise goal focused on data quality and integration maps directly to the management objective APO14 Managed Data. This objective's purpose is to ensure effective data management throughout its lifecycle, which is precisely what is needed to address the company's problem. While enterprise architecture (APO03) and knowledge management (BAI08) are related, APO14 is the most direct and primary objective for this specific issue. DSS06 is more about controls within business processes rather than the overarching data management strategy.

  7. 7

    A healthcare provider is designing its governance system for I&T. Due to the highly sensitive nature of patient data, the 'Threat Landscape' and 'Compliance Requirements' (HIPAA) design factors are given the highest importance. Which TWO management objectives would be most significantly influenced by these design factors? (Select TWO)

    Show answer details

    Correct answer: B, D

    A heightened threat landscape and stringent compliance requirements directly impact how security is defined and managed. APO13 establishes the overall information security management system (ISMS), which is fundamental.

    This objective covers the operational aspects of security, such as protecting against malware, managing network security, and handling security incidents. It is the direct operational counterpart to the planning done in APO13.

  8. 8

    True or False: In the COBIT 2019 framework, the 'Governance distinct from Management' principle implies that management activities are not accountable to any governance body.

    Show answer details

    Correct answer: B

    This statement is false. The principle 'Governance distinct from Management' clarifies that governance and management have different activities, objectives, and structures. Governance (Evaluate, Direct, Monitor) sets the direction and monitors performance, while Management (Plan, Build, Run, Monitor) executes activities to achieve the enterprise objectives set by governance. Management is therefore accountable to the governance body for its performance.

  9. 9

    Case Study:

    Company Background: FinSecure Bank, a regional financial institution, is undergoing a major digital transformation. Their goal is to launch a new mobile banking platform to remain competitive. The bank operates in a strict regulatory environment, subject to numerous financial and data privacy laws. The board has approved the project but is concerned about the potential for project failure, budget overruns, and security vulnerabilities, as past IT projects have struggled.

    Current Situation: The project is being managed using a traditional waterfall method, but different teams are informally adopting agile practices, leading to confusion. There is no central oversight of the program's portfolio of projects, and risk management is performed ad-hoc by individual project managers. The CIO reports that the business requirements are poorly defined and constantly changing, causing significant rework.

    Requirements: The board needs assurance that the new platform will be delivered on time, within budget, and in compliance with all regulations. They want a structured approach to oversee this transformation program and any future initiatives. They have decided to adopt COBIT 2019 to establish a formal governance structure.

    Question:
    Based on FinSecure Bank's situation, which governance objective should the board prioritize to establish the necessary oversight and strategic alignment for the digital transformation program?

    Show answer details

    Correct answer: B

    EDM02 is a governance objective focused on optimizing the value contribution to the business from the business processes, IT services, and IT assets resulting from investments made by IT at acceptable costs. This directly addresses the board's need for assurance that the digital transformation program delivers its intended value, stays within budget, and manages risks from a strategic, oversight perspective. It involves portfolio management and monitoring the value of programs, which is exactly what FinSecure Bank needs.

  10. 10

    During a performance review, an IT department is assessed at capability level 2 ('Managed') for the DSS03 'Managed Problems' process. To progress to capability level 3 ('Established'), the department must go beyond just addressing problems as they occur. What is the key characteristic that distinguishes a capability level 3 process from a level 2 process in this context?

    Show answer details

    Correct answer: D

    Capability Level 2 ('Managed') means the process is implemented and its performance is managed. However, to reach Level 3 ('Established'), the organization must define and deploy a standard process that is used consistently across applicable projects and departments. This standard process is tailored from the organization's set of standard processes and related assets. Quantitative management is characteristic of Level 4, and continuous improvement is the focus of Level 5.

Create an account to continue.