Latest COBIT Exam Prep Questions
and Answers (Verified)
• What is IT governance? -✓✓The process that ensures effective and efficient use of IT
so a company can achieve goals and provide value.
• What do IT governance frameworks help companies with? -✓✓They define criteria for
implementing, managing, and monitoring IT governance, including measurements for
leveraging IT resources.
• What does COBIT stand for? -✓✓Control Objectives for Information and Related
Technology.
• Who developed COBIT? -✓✓The Information Systems Audit and Control Association
(ISACA).
• What is the purpose of COBIT 2019? -✓✓To help companies meet regulatory
compliance, manage IT risks, and align IT strategies with corporate goals.
• What are the two categories of the five domains of COBIT 2019? -✓✓IT Governance
Objectives and Management IT Objectives.
• What is the focus of the Evaluate, Direct, and Monitor (EDM) domain in COBIT 2019?
-✓✓It focuses on evaluating stakeholder needs, creating direction, and monitoring IT
strategies for performance and compliance.
• What does Align, Plan, and Organize (APO) address in COBIT 2019? -✓✓It addresses
how IT is used to meet organizational objectives.
• What is the purpose of Build, Acquire, and Implement (BAI) in COBIT 2019? -✓✓To
assess IT requirements, acquire technology, and implement it.
• What does Deliver, Service, and Support (DSS) relate to in COBIT 2019? -✓✓It relates
to the operational side of IT projects, including IT support.
• What is the focus of Monitor, Evaluate, and Assess (MEA) in COBIT 2019? -✓✓It
focuses on existing IT projects and their alignment with organizational objectives.
• What are logical access controls? -✓✓Controls that identify, authorize, authenticate,
and provide access to users of a computer information system.
, • What are physical access controls? -✓✓Controls that help track who enters and exits a
facility to prevent unauthorized access.
• What is role-based access control (RBAC)? -✓✓A type of authorization that restricts
network access by assigning individuals specific roles with predefined access criteria.
• What is user authentication? -✓✓The process of associating a username with a unique
identifier to verify the identity of a user.
• What is user access provisioning? -✓✓The formal process of granting access to a new
user.
• What is user access de-provisioning? -✓✓The formal process of changing a user's
access.
• What is dormant access? -✓✓When a user has not accessed the system for a
significant period but still has an active role granting access.
• What are user access reviews? -✓✓Periodic reviews of all current users and their
system roles to protect data and security.
• What risks can unauthorized access to a company's systems lead to? -✓✓Employee
fraud, malicious attacks, ransom situations, and data breaches.
• What is a data center? -✓✓An area dedicated to the physical storage of computer and
telecommunication systems, also known as a network operations center (NOC).
• What are the three key environments of a data center? -✓✓Outside environment,
inside environment (including HVAC and fire suppression), and physical security.
• What is business continuity planning (BCP)? -✓✓A set of procedures to ensure that a
company can continue operations during and after a disaster.
• What is the purpose of Disaster Recovery (DR) in relation to BCP? -✓✓DR is a subset
of BCP focused on recovering systems and data after a disaster.
• What are the three key considerations for backup systems? -✓✓Backup site location,
backup strategy, and backup cycle frequency.
• What is a backup site? -✓✓A physical location where personnel go to recover systems
and data after a disaster.
• What characterizes a hot backup site? -✓✓It is immediately operational after a disaster
and continuously backs up data.
and Answers (Verified)
• What is IT governance? -✓✓The process that ensures effective and efficient use of IT
so a company can achieve goals and provide value.
• What do IT governance frameworks help companies with? -✓✓They define criteria for
implementing, managing, and monitoring IT governance, including measurements for
leveraging IT resources.
• What does COBIT stand for? -✓✓Control Objectives for Information and Related
Technology.
• Who developed COBIT? -✓✓The Information Systems Audit and Control Association
(ISACA).
• What is the purpose of COBIT 2019? -✓✓To help companies meet regulatory
compliance, manage IT risks, and align IT strategies with corporate goals.
• What are the two categories of the five domains of COBIT 2019? -✓✓IT Governance
Objectives and Management IT Objectives.
• What is the focus of the Evaluate, Direct, and Monitor (EDM) domain in COBIT 2019?
-✓✓It focuses on evaluating stakeholder needs, creating direction, and monitoring IT
strategies for performance and compliance.
• What does Align, Plan, and Organize (APO) address in COBIT 2019? -✓✓It addresses
how IT is used to meet organizational objectives.
• What is the purpose of Build, Acquire, and Implement (BAI) in COBIT 2019? -✓✓To
assess IT requirements, acquire technology, and implement it.
• What does Deliver, Service, and Support (DSS) relate to in COBIT 2019? -✓✓It relates
to the operational side of IT projects, including IT support.
• What is the focus of Monitor, Evaluate, and Assess (MEA) in COBIT 2019? -✓✓It
focuses on existing IT projects and their alignment with organizational objectives.
• What are logical access controls? -✓✓Controls that identify, authorize, authenticate,
and provide access to users of a computer information system.
, • What are physical access controls? -✓✓Controls that help track who enters and exits a
facility to prevent unauthorized access.
• What is role-based access control (RBAC)? -✓✓A type of authorization that restricts
network access by assigning individuals specific roles with predefined access criteria.
• What is user authentication? -✓✓The process of associating a username with a unique
identifier to verify the identity of a user.
• What is user access provisioning? -✓✓The formal process of granting access to a new
user.
• What is user access de-provisioning? -✓✓The formal process of changing a user's
access.
• What is dormant access? -✓✓When a user has not accessed the system for a
significant period but still has an active role granting access.
• What are user access reviews? -✓✓Periodic reviews of all current users and their
system roles to protect data and security.
• What risks can unauthorized access to a company's systems lead to? -✓✓Employee
fraud, malicious attacks, ransom situations, and data breaches.
• What is a data center? -✓✓An area dedicated to the physical storage of computer and
telecommunication systems, also known as a network operations center (NOC).
• What are the three key environments of a data center? -✓✓Outside environment,
inside environment (including HVAC and fire suppression), and physical security.
• What is business continuity planning (BCP)? -✓✓A set of procedures to ensure that a
company can continue operations during and after a disaster.
• What is the purpose of Disaster Recovery (DR) in relation to BCP? -✓✓DR is a subset
of BCP focused on recovering systems and data after a disaster.
• What are the three key considerations for backup systems? -✓✓Backup site location,
backup strategy, and backup cycle frequency.
• What is a backup site? -✓✓A physical location where personnel go to recover systems
and data after a disaster.
• What characterizes a hot backup site? -✓✓It is immediately operational after a disaster
and continuously backs up data.