mediumMultiple Select
CISA Practice Question: An auditor is evaluating the IT governance…
An auditor is evaluating the IT governance framework of a large bank. Which TWO of the following are components of COBIT 2019's governance system? (Select TWO.)
⚠ Common exam trap
CISA often tests COBIT 2019's component model, and candidates mistakenly select specific processes (change management) or measurement tools (KPIs, SLAs) as governance system components rather than the seven defined building blocks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Organizational Structures
COBIT 2019 defines a governance system as composed of several distinct component types, and 'Organizational Structures' (C) is one of them — it refers to the formal roles, committees, and decision-making bodies (e.g., board, steering committees, CIO) that enable governance. 'Principles, Policies, and Frameworks' (D) is also an explicit COBIT 2019 governance system component, covering the rules, guidance, and frameworks that translate stakeholder needs into actionable direction. These two are among the defined component types (alongside processes, information, culture/ethics/behavior, services/infrastructure/applications, and people/skills/competencies). Key Performance Indicators (A) are measurement tools used within governance and management, not a standalone component type. Change Management Process (B) is a specific ITIL/ITSM process, not a COBIT component category. Service Level Agreements (E) are contractual service documents, not a COBIT 2019 governance system component.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Key Performance Indicators
Why it's wrong here
KPIs are measurement tools used within COBIT's performance management, not a defined component of the governance system itself. It is tempting because KPIs are widely used to evaluate governance effectiveness, and they would be the correct choice if the question asked how COBIT performance is monitored rather than what the system comprises.
- ✗
Change Management Process
Why it's wrong here
Change management is a management objective within COBIT's processes, not one of the governance system components (processes, organisational structures, principles, culture, information, services and infrastructure). It is tempting because change management is central to IT governance, and it would be the right answer if the question asked about COBIT management objectives.
- ✓
Organizational Structures
Why this is correct
Organizational structures are one of COBIT 2019's governance system components, defining decision rights, roles and reporting lines across the enterprise. This satisfies the question's requirement by being a recognised component alongside processes, principles and policies, information, culture and services.
- ✓
Principles, Policies, and Frameworks
Why this is correct
Principles, policies and frameworks form one of COBIT 2019's governance system components, translating stakeholder needs into practical guidance for behaviour and decision-making. This satisfies the question's requirement by being a recognised component alongside processes, organizational structures, culture and information.
- ✗
Service Level Agreements
Why it's wrong here
COBIT 2019's governance system comprises governance and management objectives, components, focus areas and design factors; SLAs are contractual service documents, not a governance system component. It is tempting because SLAs are common in IT governance discussions, and they would be relevant when assessing service delivery performance rather than framework structure.
Go deeper
Related to this question
About these practice questions
One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.