
試験高合格率保証2023年10月28日 COBIT-2019試験問題と正確な回答!
テストエンジン練習問題COBIT-2019有効最新の問題集
ISACA COBIT-2019認定を取得することで、IT専門家には、企業のITを管理および統治するための知識とスキルが向上するだけでなく、仕事の機会とキャリア成長が増加し、雇用主や同僚から優れたIT専門家として認められます。この認定は、プロフェッショナル開発に対するコミットメントと、企業のIT管理のベストプラクティスへの献身を示すものでもあります。
質問 # 61
Which of the following benefits derived from the use of COBIT is PRIMARILY associated with an internal stakeholder?
- A. COBIT helps to ensure that a governance system is in place to sustain regulatory compliance.
- B. COBIT helps to ensure that a third-party vendor's operations are secure.
- C. COBIT provides insight on how to derive value from the use of I&T.
正解:C
質問 # 62
Which of the following is an important desired outcome to be achieved from the execution of an EGIT implementation program plan?
- A. Completion of EGIT project implementation regardless of the amount of time required
- B. Mitigation of all risks associated with the implementation of EGIT projects
- C. Transition of EGIT projects into the enterprise's normal development life cycle
- D. Development of a record of unapproved EGIT projects
正解:C
解説:
Explanation
The desired outcome of an EGIT implementation program plan is to ensure that the EGIT projects are aligned with the enterprise's strategy, objectives, and stakeholder needs, and that they deliver value and benefits to the enterprise. One of the key steps in achieving this outcome is to transition the EGIT projects into the enterprise's normal development life cycle, which involves ensuring that the projects are integrated with the existing processes, systems, and governance structures, and that they are monitored and controlled for quality, performance, and risk. This will also facilitate the continuous improvement and adaptation of the EGIT projects to changing business needs and environment12 References: 1: COBIT 2019 Implementation Guide, page 49-50 2: COBIT 2019 Design Guide, page 67-68
質問 # 63
Which COBIT principle addresses the need to consider how many changes in technology or strategy impact the enterprise governance system as a whole?
- A. A governance system should be dynamic.
- B. A governance system should cover the enterprise end to end.
- C. A governance system should be tailored to the enterprise's needs.
正解:A
解説:
Explanation
The COBIT principle that addresses the need to consider how changes in technology or strategy impact the enterprise governance system as a whole is that a governance system should be dynamic. This principle states that "a governance system should be responsive to changing stakeholder needs, conditions and options; adaptable to changing circumstances; able to learn from experience; and innovative in supporting continual improvement" 4. A dynamic governance system can anticipate and respond to changes in the internal and external environment, such as new technologies, business models, risks, or opportunities5. References: 4:
COBIT 2019 Framework: Introduction and Methodology, page 23 5: COBIT 2019 Framework: Governance and Management Objectives, page 20
質問 # 64
Which of the following is MOST important to providing trust in operations, confidence in the achievement of enterprise objectives, and an adequate understanding of residual risk?
- A. A continuity of operations response plan
- B. A managed system of internal controls
- C. A risk management framework
正解:B
質問 # 65
When refining the scope of a new IT governance system during the design phase, which of the following is the MOST significant driver to be considered?
- A. Cloud versus on-premises services
- B. The size of the enterprise
- C. National or international locations
正解:A
解説:
Explanation
According to the COBIT 2019 Implementation Guide: Implementing an Information and Technology Governance Solution, one of the most significant drivers to be considered when refining the scope of a new IT governance system during the design phase is cloud versus on-premises services. This driver reflects the different delivery models of I&T services, such as software as a service (SaaS), platform as a service (PaaS), infrastructure as a service (IaaS) or on-premises solutions. The choice of delivery model has implications for governance objectives, roles, responsibilities, policies, processes, controls, risks and performance measures.5, p. 40-41 References: 5: COBIT 2019 Implementation Guide: Implementing an Information and Technology Governance Solution
質問 # 66
What is the BEST way to determine whether IT governance is achieving intended outcomes one year after implementation?
- A. Survey the satisfaction level of key business stakeholders.
- B. Evaluate performance measurements identified in the business case
- C. Review change drivers to determine whether corresponding changes were successful.
正解:B
解説:
Explanation
The best way to determine whether IT governance is achieving intended outcomes one year after implementation is to evaluate performance measurements identified in the business case. The business case is a document that defines the objectives, benefits, costs, risks, and success factors of IT governance implementation, and specifies the key performance indicators (KPIs) and target values that will be used to measure and monitor the outcomes. By comparing the actual performance results with the expected results, the enterprise can assess the effectiveness and efficiency of IT governance and identify any gaps or issues that need to be addressed. The way is based on the COBIT 2019 Implementation Guide1, page 32. References: 1:
COBIT 2019 Implementation Guide | Digital | English
質問 # 67
Which of the following management objectives is related to optimization of system performance?
- A. Managed availability and capacity
- B. Managed I&T management framework
- C. Managed service agreements
正解:A
質問 # 68
What is the KEY benefit of considering the size of the enterprise when designing governance?
- A. Targeting capability levels of governance and management objectives
- B. Determining whether COBIT or SME focus area guidance should be used
- C. Identifying the implementation effort needed to finalize the design phase
- D. Assigning priorities to governance and management objectives
正解:A
解説:
Explanation
The size of the enterprise is a design factor that describes the scale or magnitude of an enterprise's information and technology activities in terms of aspects such as number of employees, customers, locations, products, services, processes, systems, data, etc. The size of the enterprise influences the governance and management of information and technology in terms of the level of complexity, diversity, variability, standardization, centralization, decentralization, etc., that are required for its information and technology activities. The key benefit of considering the size of the enterprise when designing governance is targeting capability levels of governance and management objectives. The capability levels are a measure of how well an enterprise performs its information and technology governance and management processes in terms of process attributes such as process performance, process definition, process deployment, process measurement, process control, process optimization, etc. The capability levels range from 0 (incomplete) to 5 (optimizing), indicating the degree of maturity and effectiveness of an enterprise's information and technology governance and management processes. The governance and management objectives are the statements of what an enterprise wants to achieve in terms of its information and technology governance. The governance and management objectives are derived from the enterprise goals, which are the high-level statements of what an enterprise wants to achieve in terms of its mission, vision, values, strategy, etc. By considering the size of the enterprise when designing governance, an enterprise can target capability levels of governance and management objectives that are appropriate for its scale and magnitude of information and technology activities. This will also help to optimize its information and technology performance and value delivery12 References: 1: COBIT
2019 Design Guide: page 47-48 2: COBIT 2019 Process Assessment Model: page 11-13
質問 # 69
Which of the following l&T implementation methods requites the HIGHEST level of participation by users at multiple stages of software development?
- A. DevOps
- B. Agile
- C. Traditional
- D. Hybrid
正解:B
解説:
Explanation
The IT implementation methods design factor describes how an enterprise develops, delivers, and maintains its IT solutions. There are four IT implementation methods defined in COBIT 2019: traditional, agile, DevOps, and hybrid. Each method has different implications for the governance and management of information and technology in terms of focus areas, processes, practices, roles, structures, and metrics. The IT implementation method that requires the highest level of participation by users at multiple stages of software development is agile. Agile is an IT implementation method that emphasizes flexibility, adaptability, collaboration, customer satisfaction, and value delivery. One of the characteristics of agile is that it involves frequent and direct interaction with users throughout the software development life cycle, from requirements gathering to testing to deployment. Users are considered as key stakeholders who provide feedback, input, validation, verification, acceptance, and evaluation of the IT solutions. Users are also involved in prioritizing the features and functionalities of the IT solutions based on their needs and expectations. Agile aims to deliver IT solutions that meet user requirements and expectations in a timely and cost-effective manner.References: : COBIT 2019 Design Guide, page 43-45 : COBIT 2019 Process Reference Guide: Governance and Management Objectives, page 67-69
質問 # 70
Ensuring the program team knows and understands the enterprise goals is a part of which of the following implementation phases?
- A. Where do we want to be?
- B. How do we get there?
- C. Where are we now?
- D. What are the drivers?
正解:A
解説:
Ensuring that the program team knows and understands the enterprise goals is a part of the implementation phase known as "Where do we want to be?". This phase is concerned with understanding the current state of the enterprise and identifying its objectives. This includes understanding the enterprise's goals, objectives, and any external drivers that might impact the way in which the enterprise operates. This phase also involves the development of a vision and strategy for the program, which will guide the development of a detailed plan. The goal of this phase is to ensure that all stakeholders understand what the enterprise is trying to achieve and to ensure that all decisions are aligned with the desired future state. Reference: https://www.isaca.org/COBIT/Pages/COBIT-2019-Framework.aspx
質問 # 71
Which COBIT domain of management objectives incorporates managed business process controls?
- A. Build, Acquire and Implement (BAI)
- B. Align, Plan and Organize (APO)
- C. Deliver, Service and Support (DSS)
正解:C
解説:
Explanation/Reference: https://graser.co.at/en/cobit-5-understand-the-framework/
質問 # 72
Within the COBIT goals cascade, stakeholder drivers are transformed into:
- A. the enterprise's actionable strategy.
- B. business unit performance metrics.
- C. the enterprise's governance framework.
正解:A
解説:
Explanation/Reference: https://blog.firstreference.com/the-isaca-has-traded-in-cobit-5-for-cobit-2019-part-3-of-3/
#.YGXbnh1RWQ4
質問 # 73
Which of the following is determined at each level of a capability maturity model?
- A. Who is responsible for ensuring all activities at a given level are performed successfully
- B. Which internal policies are relevant to a process at a given level
- C. How well a process is implemented and performing at a given level
正解:C
解説:
Explanation
A capability maturity model is a tool that assesses how well a process is implemented and performing at a given level, ranging from 0 (non-existent) to 5 (optimized). Each level defines a set of attributes that describe the characteristics of the process at that level, such as process performance, process documentation, process control, process measurement, etc. The model is based on the COBIT 2019 Process Assessment Model4, page
11. References: 4: COBIT 2019 Process Assessment Model | Digital | English
質問 # 74
Which of the following MUST be done before an enterprise can determine performance measures for a process improvement initiative?
- A. Perform a process risk assessment
- B. Conduct a capabilities assessment
- C. Calculate return on investment (ROI)
正解:B
質問 # 75
It is CRITICAL to perform a due diligence review following which type of event?
- A. External consultant assessment
- B. New business strategy or priority
- C. Merger, acquisition, or divestiture
- D. Shifts in the market or economy
正解:C
解説:
Performing a due diligence review following a merger, acquisition, or divestiture is critical to ensure that the new organizational structure is well-thought out, secure, and compliant with applicable regulations. The review should include an evaluation of the organization's IT assets, processes, and policies to ensure that they are appropriate for the new organization. Additionally, the review should evaluate the IT security and data privacy requirements for the new organization, as well as the potential impact of the change on the organization's IT services.
質問 # 76
Which of the following components should be considered for inclusion when considering the threat landscape design factor?
- A. Information security focus areas
- B. Impact and probability levels
- C. Information flows including security policy
- D. Compliance and assurance capabilities
正解:A
解説:
Explanation
The component that should be considered for inclusion when considering the threat landscape design factor is information security focus areas. The threat landscape is one of the 11 design factors defined in COBIT 2019, and it refers to the current and emerging threats that may affect the enterprise's information and technology assets, such as cyberattacks, natural disasters, human errors, etc. Information security focus areas are the specific domains or topics that need to be addressed by the governance system to ensure adequate protection of information and technology assets from potential threats, such as identity and access management, data protection, incident response, etc. The answer is based on the COBIT 2019 Design Guide4, page 17.
References: 4: COBIT 2019 Design Guide | Digital | English
質問 # 77
A privately held company is planning to be listed on the stock exchange and is working on meeting regulatory requirements. After considering an assessment by external consultants, the company has decided to implement the process 'Ensured Stakeholder Engagement." Who is BEST suited for this responsibility?
- A. The board and executive management
- B. Relationship manager
- C. Chief information security officer
- D. Chief information officer
正解:A
解説:
According to the ISACA COBIT 2019 official Manual, the board and executive management should be responsible for ensuring stakeholder engagement when a company is planning to be listed on the stock exchange and is working on meeting regulatory requirements. This is because they are the ones who need to ensure the company is meeting the necessary standards set by the regulatory body and engaging with stakeholders to ensure the company is being transparent and open about its plans. The board and executive management should ensure that all relevant stakeholders are consulted and that their views are taken into account when making decisions about listing the company on the stock exchange.
質問 # 78
What is the focus of an enterprise that has a cost leadership strategy design factor?
- A. Medium-term cost equalization
- B. Short-term cost minimization
- C. Long-term cost optimization
正解:B
質問 # 79
COBIT addresses governance issues by doing which of the following?
- A. Providing a full description of the entire IT environment within an enterprise
- B. Defining specific governance strategies and processes to implement in specific situations
- C. Grouping relevant governance components into objectives that can be managed to a required capability level
正解:C
質問 # 80
Which of the following roles should be involved when nominating key program roles to create the appropriate governance environment?
- A. Human resources
- B. Business management
- C. IT management
- D. Board and executives
正解:D
解説:
Explanation
The key program roles are the roles that are responsible for leading, directing, managing, supporting, and executing the EGIT implementation program. The nomination of these roles is a critical step in creating the appropriate governance environment for the program. One of the roles that should be involved in this nomination process is the board and executives, who are the highest-level governance body and decision makers in an enterprise. The board and executives provide strategic direction, oversight, guidance, and approval for the EGIT implementation program. They also ensure that the program is aligned with the enterprise's vision, mission, values, strategy, goals, and objectives. The board and executives also appoint or endorse other key program roles such as the program sponsor, program manager, program steering committee, change champion network, etc.References: : COBIT 2019 Implementation Guide, page 37-38 : COBIT 2019 Framework: Governance and Management Objectives, page 19-20
質問 # 81
Which of the following metrics would BEST enable an enterprise to evaluate an alignment goal specifically related to security of information and privacy?
- A. Ratio and extent of erroneous business decisions in which erroneous I&T-related information was a key factor
- B. Number of confidentiality incidents causing financial loss, business disruption or public embarrassment.
- C. Number of critical business processes supported by up-to-date infrastructure and applications
正解:B
質問 # 82
When tailoring the COBIT organizational structure, which of the following is the PRIMARY purpose for aligning role descriptions to the enterprise's business context, organization and operating environment?
- A. Developing hierarchy and reporting structure
- B. Assigning levels of accountability and responsibility
- C. Preparing key goal areas and metrics for each role
正解:C
質問 # 83
While value delivery focuses on the creation of value, risk management focuses on which of the following?
- A. Preservation of value
- B. Achievement of value
- C. Optimization of value
正解:A
質問 # 84
l&T-related issues should be considered as part of the design factors for a governance system in order to manage:
- A. risks that have a high impact.
- B. risks that have already materialized.
- C. risks that could materialize.
- D. risks that have a high probability.
正解:A
解説:
According to the COBIT 2019 Framework, L&T-related issues should be considered as part of the design factors for a governance system in order to manage risks that have a high impact. This includes considering the current and potential implications of the L&T-related risks, determining the maximum acceptable levels of risk for the organization and designing the governance system to minimize the risk to acceptable levels. This is outlined in the COBIT Governance of Enterprise IT (GEIT) section of the framework.
質問 # 85
......
試験解答COBIT-2019最新版とテストエンジン:https://www.jpntest.com/shiken/COBIT-2019-mondaishu
合格させるCOBIT-2019試験最新のCOBIT-2019試験問題集PDF:https://drive.google.com/open?id=1u3Axatlx9WzGRU7lmZ8Q24nV55VzKqq-