Courseiva
easyMultiple Choice

CISA Practice Question: The IT governance objective…

The IT governance objective 'Evaluate-Direct-Monitor' in COBIT 2019 is primarily associated with which role?

⚠ Common exam trap

CISA often tests the governance-versus-management split — candidates confuse the IT steering committee (management oversight) with the board (governance accountability) and pick the committee as the EDM owner.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Board of directors

COBIT 2019 assigns the Evaluate, Direct and Monitor (EDM) governance objectives to the board of directors (or equivalent governing body). The board sets direction, evaluates stakeholder needs and options, and monitors performance and compliance, while management (under APO, BAI, DSS, MEA) executes. Internal audit provides independent assurance, and the IT steering committee typically operates at a management/oversight level rather than owning EDM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Board of directors

    Why this is correct

    The board of directors owns the Evaluate-Direct-Monitor governance objective, setting direction and evaluating performance against enterprise objectives. This satisfies COBIT 2019's separation of governance from management: the board evaluates stakeholder needs and directs strategy, while management plans, builds, runs and monitors activities under its mandate.

  • ✗

    Internal audit

    Why it's wrong here

    Internal audit provides independent assurance and reports to the board, so it cannot perform the governance body's own Evaluate, Direct and Monitor activities without losing objectivity. It is tempting because audit evaluates controls, and it would be correct for assessing whether governance processes operate effectively.

  • ✗

    IT management

    Why it's wrong here

    IT management executes and operates the governance framework, reporting into the governing body rather than performing the Evaluate, Direct and Monitor activities itself. It is tempting because management owns day-to-day delivery, and it would be the correct association for the Align, Plan and Organise domain.

  • ✗

    IT steering committee

    Why it's wrong here

    The IT steering committee typically supports direction-setting and prioritisation but is not the body COBIT 2019 assigns the Evaluate-Direct-Monitor objective to. It is tempting because steering committees oversee IT investment decisions, and it would be correct for approving project portfolios and resolving cross-functional IT priorities.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.