Courseiva

CISA Governance and Management of IT Practice Question

An IS auditor is evaluating an organization's IT governance maturity using COBIT 2019. The auditor finds that IT processes are largely ad hoc, with no formal documentation or consistent monitoring. However, the organization has recently implemented a tool to automate some IT service management tasks. Management believes this tool elevates their maturity to a managed level. The auditor should:

⚠ Common exam trap

The trap here is equating the implementation of a tool with process maturity, overlooking that COBIT maturity is about process capability, not technology adoption.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assess the actual process maturity against COBIT criteria, noting that tool implementation without process definition does not raise maturity.

COBIT 2019 maturity levels assess process capability, not the presence of tools. The organization's processes are ad hoc and undocumented, which aligns with the initial level. Implementing an automation tool does not automatically elevate maturity because the underlying processes are not defined, managed, or measured. The IS auditor should evaluate the processes against COBIT criteria and conclude that the tool alone does not raise maturity to the managed level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Assess the actual process maturity against COBIT criteria, noting that tool implementation without process definition does not raise maturity.

    Why this is correct

    COBIT 2019 maturity levels are based on the capability of processes, not on the tools used. Implementing a tool without defining, documenting, and consistently executing processes does not move the organization beyond the initial or ad hoc level. The auditor should evaluate the processes against the COBIT criteria for each maturity level, recognizing that automation can support but not substitute for process management.

  • ✗

    Recommend immediate reclassification to the managed level to reflect management's commitment to improvement.

    Why it's wrong here

    Maturity levels should reflect actual process capability, not management's intentions or commitments. Reclassifying to managed level without evidence of planned, monitored, and adjusted processes would misrepresent the organization's true state. The auditor must remain objective and base conclusions on verifiable evidence, such as process documentation, performance metrics, and consistent execution, rather than on management's aspirations.

  • ✗

    Conclude that the organization is at an initial level because the tool is not fully integrated with all IT processes.

    Why it's wrong here

    While the organization may still be at an initial level, the auditor's conclusion should be based on the lack of formal documentation and consistent monitoring, not solely on the tool's integration status. COBIT maturity levels are determined by the extent to which processes are defined, managed, and measured. The tool's integration is one factor, but the primary deficiency is the ad hoc nature of processes, which the tool alone does not remediate.

  • ✗

    Agree that the tool implementation demonstrates a managed level because automation implies repeatable processes.

    Why it's wrong here

    Automation alone does not equate to a managed level of maturity. COBIT 2019 defines managed level (Level 2) as processes that are planned, monitored, and adjusted, and work products are established, controlled, and maintained. A tool can support these activities but without formal documentation, consistent execution, and monitoring, the processes remain ad hoc. The auditor should not accept automation as sufficient evidence of maturity.

About these practice questions

This CISA question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.