Courseiva
easyMultiple Select

CISA Practice Question: Which TWO of the following are examples of IT…

Which TWO of the following are examples of IT governance frameworks? (Select TWO.)

⚠ Common exam trap

CISA often tests the distinction between governance frameworks and management/process frameworks, causing candidates to confuse ITIL (service management) or PMBOK (project management) as governance frameworks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

COBIT 2019

COBIT 2019 (A) is correct because it is ISACA's dedicated IT governance framework, providing governance and management objectives across the five domains (EDM, APO, BAI, DSS, MEA) to align IT with enterprise goals. ISO/IEC 38500 (D) is correct because it is the international standard for corporate governance of IT, defining principles (responsibility, strategy, acquisition, performance, conformance, human behaviour) and a governance model for directing and controlling IT. PMBOK (B) is a project management body of knowledge, ITIL 4 (C) is an IT service management framework, and Six Sigma (E) is a process-improvement methodology — none of these are IT governance frameworks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    COBIT 2019

    Why this is correct

    COBIT 2019 is ISACA's governance framework for enterprise IT, defining governance and management objectives across a full domain structure. It is explicitly a governance framework, distinguishing it from audit standards, control sets or project delivery methods that operate at lower levels.

  • ✗

    PMBOK

    Why it's wrong here

    PMBOK is a project-management body of knowledge covering scope, schedule and cost processes for delivering individual projects, not enterprise IT governance. It is tempting because it defines formal processes, roles and controls, which suits managing a specific project rather than governing IT across an organisation.

  • ✗

    ITIL 4

    Why it's wrong here

    ITIL 4 is a service-management framework describing practices for delivering and supporting IT services, not a governance framework for directing and controlling the enterprise. It is tempting because it is widely adopted, prescriptive and control-oriented, which suits service desk and operations improvement rather than board-level IT governance.

  • ✓

    ISO/IEC 38500

    Why this is correct

    ISO/IEC 38500 is the international standard providing governing-body principles for the effective, efficient and acceptable use of IT, covering direction, evaluation and monitoring. It is a recognised governance framework, unlike control catalogues or process maturity models that address management rather than governance.

  • ✗

    Six Sigma

    Why it's wrong here

    Six Sigma is a process-improvement methodology for reducing defects and variation, not a framework for directing and controlling enterprise IT. It is tempting because it uses structured governance-like roles and controls, which suits manufacturing or service quality programmes rather than IT governance.

About these practice questions

Courseiva writes every CISA question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISA practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISA exam.