COBIT 2019 Design and Implementation Free Sample Questions

Create a free account to browse all 20 sample questions. The full practice test includes 244 questions. Use the simulator for timed and flashcard mode.

Try Simulator

cobit-2019-design-and-implementation Sample Questions

  1. Question 1

    Q1

    A multinational logistics company has just completed Phase 2 ('Where are we now?') of the COBIT implementation lifecycle. The assessment revealed significant gaps in process capability, particularly in BAI03 (Managed Solutions Identification and Build). The program steering committee is pushing to immediately jump to Phase 5 ('How do we get there?') by purchasing a new ERP system. What is the MOST significant risk of this approach?

    Show answer & explanation

    Correct answer: A

    Skipping Phase 3 ('Where do we want to be?') and Phase 4 ('What needs to be done?') means no target state has been defined and no detailed improvement plan has been created. Purchasing a solution without this context risks misalignment with actual business needs and strategic goals, leading to wasted investment and unresolved governance gaps.

  2. Question 2

    Q2

    A governance design team is working through Step 3 ('Refine scope using design factors') of the design workflow. They have determined that the company's enterprise strategy is 'Growth/Acquisition'. How does this specific design factor value primarily influence the prioritization of governance and management objectives?

    Show answer & explanation

    Correct answer: B

    A 'Growth/Acquisition' strategy demands the ability to rapidly integrate new businesses, manage complex programs of change, and innovate to capture new markets. Therefore, objectives focused on program management, organizational change, and innovation (like BAI02) become paramount.

  3. Question 3

    Q3Multiple answers

    A rapidly scaling FinTech startup is designing its first formal governance system. The company operates in a highly regulated environment, has a high risk profile due to handling sensitive financial data, and follows a DevOps implementation method. Which of the following governance system components must be MOST carefully designed and integrated to ensure success? (Select TWO)

    Show answer & explanation

    Correct answers: A, D

    In a DevOps environment, processes must be highly automated and integrated into the CI/CD pipeline. To meet regulatory and risk requirements, these processes (e.g., for change control, security testing, deployment) must be robust, auditable, and efficient, making their design critical.

    DevOps relies heavily on a culture of shared responsibility ('you build it, you run it'). In a high-risk, regulated environment, fostering a strong culture of security, compliance, and ethical behavior ('DevSecOps') is paramount to prevent catastrophic failures. This cultural component is as critical as the automated processes.

  4. Question 4

    Q4

    A university is implementing a new student information system. During Phase 6 ('Did we get there?') of the implementation lifecycle, the primary focus is on monitoring the achievement of the goals defined in the business case. Which COBIT process provides the most relevant guidance for this activity?

    Show answer & explanation

    Correct answer: C

    MEA01 is specifically designed to monitor performance against agreed-upon targets and ensure conformance with requirements. This directly supports the objective of Phase 6, which is to track progress, measure benefits realization, and report on the achievement of business case goals.

  5. Question 5

    Q5

    True or False: The COBIT 2019 Design Guide prescribes a single, mandatory target capability level for each prioritized governance objective, regardless of the enterprise's specific context or design factors.

    Show answer & explanation

    Correct answer: B

    This is false. The essence of the COBIT 2019 design process is to tailor the governance system, including target capability levels, to the specific needs and context of the enterprise. The Design Guide provides suggested levels based on design factors, but these are inputs to the decision, not mandatory prescriptions.

  6. Question 6

    Q6

    A manufacturing company is designing a governance system. A key design factor is its threat landscape, which has recently shifted to include sophisticated industrial espionage targeting intellectual property stored in product design systems. How does this specific design factor value impact the required capability level of the 'Managed Security' (DSS05) process component?

    Show answer & explanation

    Correct answer: C

    A sophisticated threat landscape necessitates a mature and robust security posture. This translates to requiring a higher target capability level (e.g., 3, 4, or 5) for DSS05 to ensure security processes are not just performed, but are well-defined, quantitatively managed, and continuously optimized to counter advanced threats.

  7. Question 7

    Q7

    A hospital group is implementing an Electronic Health Record (EHR) system. The board of directors is primarily concerned with patient data privacy and compliance with healthcare regulations like HIPAA. According to the COBIT Key Topics Decision Matrix (RACI chart), who is ULTIMATELY accountable for decisions regarding the I&T risk management policy?

    Show answer & explanation

    Correct answer: C

    In COBIT, the governing body (e.g., Board of Directors) is ultimately Accountable (A) for governance, which includes setting the direction for risk management and approving the enterprise risk policy. This aligns with their fiduciary duty to oversee risk for the entire organization.

  8. Question 8

    Q8

    During the design of a governance system for an e-commerce company, the team identifies that the primary enterprise goal is 'Customer-oriented service culture'. Which alignment goal from the COBIT goals cascade MOST directly supports this enterprise goal?

    Show answer & explanation

    Correct answer: C

    The alignment goal AG05 directly addresses the need for I&T to deliver services that meet the expectations and requirements of the business, which in this case are defined by the customer-oriented service culture. This includes service levels, quality, and responsiveness to customer needs.

  9. Question 9

    Q9

    A financial services firm is in Phase 7 ('How do we keep the momentum going?') of its governance implementation program. The initial project focused on improving the DSS04 (Managed Continuity) process. What is the MOST effective activity to ensure the improvements are sustained and embedded in the organization?

    Show answer & explanation

    Correct answer: C

    Phase 7 is about sustaining the improvements. The most effective way to do this is to embed the new way of working into ongoing operations through continuous monitoring and reporting. Tracking metrics and reporting to a governance body like the risk committee ensures visibility, accountability, and a driver for continuous improvement.

  10. Question 10

    Q10

    A government agency is designing a governance system. Due to strict public accountability and data privacy laws, its compliance requirements are 'High'. At the same time, its technology adoption strategy is 'Slow/Follower' due to budget constraints. How would these two conflicting design factors MOST likely be resolved in the final governance system design?

    Show answer & explanation

    Correct answer: B

    This represents a balanced resolution. The design must meet the non-negotiable compliance requirements, dictating high capability for processes like MEA03 (Managed Compliance) and APO12 (Managed Risk). The 'Slow/Follower' tech strategy means the agency can de-prioritize and accept lower capability in areas related to innovation and managing emerging technologies, thus resolving the conflict.

Register free to unlock 10 more sample questions

Create a free account to continue with the rest of the cobit-2019-design-and-implementation sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 244 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon