Courseiva
easyMultiple Choice

CISA Practice Question: Which COBIT 2019 governance objective describes…

Which COBIT 2019 governance objective describes the board's responsibility for overseeing IT?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Evaluate, Direct, and Monitor (EDM)

COBIT 2019 defines the governance objective as Evaluate, Direct, and Monitor (EDM), which is the board's responsibility.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deliver, Service, and Support (DSS)

    Why it's wrong here

    DSS covers delivering, servicing and supporting IT, including operations, service desk and continuity. Board-level oversight of IT value and risk sits in EDM; DSS is tempting because it governs day-to-day IT service delivery, which is a management concern rather than a governance one.

  • ✗

    Align, Plan, and Organize (APO)

    Why it's wrong here

    APO addresses IT strategy, architecture and portfolio planning by management, not board oversight. EDM is the governance objective covering board evaluation, direction and monitoring of IT; APO tempts because strategic alignment sounds board-level, yet it remains an execution responsibility.

  • ✓

    Evaluate, Direct, and Monitor (EDM)

    Why this is correct

    The Evaluate, Direct and Monitor domain covers the governing body's own responsibilities, including evaluating options, directing the entity and monitoring performance. It is the governance objective describing board-level oversight of IT, distinct from the management objectives.

  • ✗

    Build, Acquire, and Implement (BAI)

    Why it's wrong here

    BAI governs building, acquiring and implementing IT solutions and changes, an execution activity delegated to management. EDM is the governance domain for board oversight; BAI appeals because project delivery feels strategic, but it concerns solution lifecycle, not evaluating and directing IT.

About these practice questions

One of 934 original CISA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.