Courseiva

CISA Governance and Management of IT Practice Question

A multinational corporation is adopting a hybrid cloud strategy. The IT governance board must decide on a framework to ensure alignment with business objectives and regulatory compliance. Which framework is MOST appropriate?

⚠ Common exam trap

Candidates often confuse ITIL (service management) with governance, assuming that best practices for service delivery inherently cover board-level alignment and compliance, but ITIL lacks the governance objectives and stakeholder-driven goal cascade that COBIT provides for hybrid cloud strategies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

COBIT 2019

COBIT 2019 is the most appropriate framework because it is specifically designed for IT governance, providing a comprehensive set of controls and processes to align IT with business objectives and ensure regulatory compliance. In a hybrid cloud strategy, COBIT 2019's focus on governance objectives, stakeholder needs, and risk management directly addresses the board's need for oversight across on-premises and cloud environments, unlike frameworks that target service management, security, or project management.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    ITIL 4 Service Value System

    Why it's wrong here

    ITIL 4 structures service management value streams and practices, not enterprise governance of IT investment decisions or regulatory alignment. It suits organisations improving service delivery and support workflows. COBIT supplies the governance and management objectives linking IT activity to business goals and compliance obligations.

  • ✓

    COBIT 2019

    Why this is correct

    COBIT 2019 provides a governance and management framework explicitly linking IT objectives to business goals, with defined processes and control practices for regulatory compliance. This satisfies the board's need for enterprise-wide governance across hybrid cloud rather than technology-specific operational guidance.

  • ✗

    ISO/IEC 27001 Information Security Management

    Why it's wrong here

    ISO/IEC 27001 certifies an information security management system, addressing security controls rather than IT governance alignment with business objectives across a hybrid estate. It suits organisations seeking certifiable security assurance. Governance frameworks such as COBIT map IT outcomes to business goals and regulatory obligations.

  • ✗

    PMBOK Guide

    Why it's wrong here

    PMBOK provides project management processes for delivering individual projects within scope, schedule and budget; it does not establish enterprise IT governance or ongoing compliance oversight. It fits managing a defined project such as a cloud migration. COBIT is designed for governing enterprise IT to meet business and regulatory objectives.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.