IT GOVERNANCE FRAMEWORKS
EXAM 2025/2026 QUESTIONS AND
ANSWERS 100% PASS
IT Governance - ANS Ensures effective IT use for company goals and value
IT Governance Frameworks - ANS Define criteria for IT governance implementation and
monitoring
COBIT - ANS IT governance standard by ISACA for control objectives
COBIT 2019 - ANS Aids in regulatory compliance, IT risk management, and strategy alignment
COSO - ANS Corporate governance framework for management and audits
IT Governance Objectives - ANS Strategy creation by board of directors and IT management
Five Domains of COBIT 2019 - ANS Framework areas: Evaluate, Direct, Monitor, Plan, Build,
Run
Information Security Management - ANS Responsibility of management, not just technology
pg. 1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
, Logical Access Controls - ANS Includes authorization, authentication, and user access
Physical Access Controls - ANS Tracks facility access, complements logical controls
Preventative Controls (Authentication) - ANS Verifies identity using passwords, biometrics,
etc.
Preventative Controls (Authorization) - ANS Restricts user access to specific system parts
User Access Roles - ANS Assigns access rights based on user roles
User Access Provisioning - ANS Formal process for granting new user access
User Access Deprovisioning - ANS Revokes user access, reviews access matches
responsibilities
Data Center - ANS Facility for system and data protection, NOC
Business Continuity Planning - ANS Procedures to protect employees, assets during
disruptions
Disaster Recovery - ANS Part of BCP, focuses on tech recovery after disasters
Hot Backup Site - ANS Immediately operational post-disaster, costly
Warm Backup Site - ANS Less costly, takes longer to switch over than hot site
Cold Backup Site - ANS Empty room, no equipment, cheapest but slowest to recover
pg. 2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
EXAM 2025/2026 QUESTIONS AND
ANSWERS 100% PASS
IT Governance - ANS Ensures effective IT use for company goals and value
IT Governance Frameworks - ANS Define criteria for IT governance implementation and
monitoring
COBIT - ANS IT governance standard by ISACA for control objectives
COBIT 2019 - ANS Aids in regulatory compliance, IT risk management, and strategy alignment
COSO - ANS Corporate governance framework for management and audits
IT Governance Objectives - ANS Strategy creation by board of directors and IT management
Five Domains of COBIT 2019 - ANS Framework areas: Evaluate, Direct, Monitor, Plan, Build,
Run
Information Security Management - ANS Responsibility of management, not just technology
pg. 1 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED
, Logical Access Controls - ANS Includes authorization, authentication, and user access
Physical Access Controls - ANS Tracks facility access, complements logical controls
Preventative Controls (Authentication) - ANS Verifies identity using passwords, biometrics,
etc.
Preventative Controls (Authorization) - ANS Restricts user access to specific system parts
User Access Roles - ANS Assigns access rights based on user roles
User Access Provisioning - ANS Formal process for granting new user access
User Access Deprovisioning - ANS Revokes user access, reviews access matches
responsibilities
Data Center - ANS Facility for system and data protection, NOC
Business Continuity Planning - ANS Procedures to protect employees, assets during
disruptions
Disaster Recovery - ANS Part of BCP, focuses on tech recovery after disasters
Hot Backup Site - ANS Immediately operational post-disaster, costly
Warm Backup Site - ANS Less costly, takes longer to switch over than hot site
Cold Backup Site - ANS Empty room, no equipment, cheapest but slowest to recover
pg. 2 @COPYRIGHT 2025/2026 ALLRIGHTS RESERVED