mediumMultiple Choice
CAS-004 Practice Question: Is implementing a governance framework to ensure…
An organization is implementing a governance framework to ensure that security controls are aligned with business objectives. Which of the following frameworks is specifically designed for this purpose?
⚠ Common exam trap
CompTIA often tests the distinction between governance frameworks (COBIT) and operational or compliance frameworks (NIST SP 800-53, ITIL, ISO 27001), trapping candidates who confuse control implementation with strategic alignment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
COBIT 2019
COBIT 2019 is specifically designed to align IT governance and security controls with business objectives by providing a comprehensive framework that links business goals to IT goals and enablers. It focuses on governance of enterprise IT (GEIT), ensuring that security investments and controls directly support strategic business outcomes, unlike other frameworks that are more operational or compliance-focused.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
COBIT 2019
Why this is correct
COBIT 2019 is a governance framework that explicitly separates governance from management and maps IT objectives to enterprise goals, satisfying the stem's requirement to align security controls with business objectives. Other frameworks address control implementation or risk, not enterprise-wide IT governance alignment.
- ✗
NIST SP 800-53
Why it's wrong here
NIST SP 800-53 supplies a catalogue of security and privacy controls for federal information systems; it does not map controls to business objectives. It is tempting because it is the definitive control baseline for compliance and authorisation, and would be the right choice when selecting or assessing control implementations against a required baseline.
- ✗
ITIL 4
Why it's wrong here
ITIL 4 is a service management framework covering incident, change and service value streams; it does not align security controls with business objectives. It is tempting because its governance and continual improvement practices touch service delivery, and it would be correct when designing IT service management processes rather than a security control framework.
- ✗
ISO/IEC 27001
Why it's wrong here
ISO/IEC 27001 specifies requirements for an information security management system, including leadership, risk treatment and Annex A controls, but it does not itself align controls to business objectives. It is tempting because certification demonstrates governance maturity, and it would be correct when establishing a certifiable ISMS rather than a business-alignment framework.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.