CRISC Information Technology and Security Practice Question
A risk manager is designing an IT risk management program. According to COBIT 2019, which governance objective is specifically focused on ensuring that risk management is optimized?
⚠ Common exam trap
CRISC often tests the distinction between the four EDM objectives (EDM01 governance framework, EDM02 benefits delivery, EDM03 risk optimization, EDM04 resource optimization), so candidates who confuse 'risk optimization' with 'resource optimization' pick EDM04.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
EDM03 — Ensure Risk Optimization
COBIT 2019's governance objectives are organized under the EDM (Evaluate, Direct, Monitor) domain. EDM03 — Ensure Risk Optimization is the specific governance objective that ensures enterprise risk is identified, assessed, and managed within the entity's risk appetite, and that risk management activities are optimized. It is the governance-level counterpart to the management-level APO12 (Manage Risk) objective.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
EDM03 — Ensure Risk Optimization
Why this is correct
COBIT 2019's EDM03 governance objective sits within the Evaluate, Direct and Monitor domain and explicitly assigns accountability for ensuring risk management is optimised, aligning risk appetite with enterprise objectives. It is the specific objective covering risk optimisation, not risk identification or treatment execution.
- ✗
EDM04 — Ensure Resource Optimization
Why it's wrong here
EDM04 addresses optimising resource use, covering sourcing and capability decisions, not risk optimisation. It is tempting because optimisation sounds governance-wide. The objective specifically focused on risk management optimisation is EDM03, Ensure Risk Optimisation, which sets risk appetite and monitors risk management effectiveness.
- ✗
EDM02 — Ensure Benefits Delivery
Why it's wrong here
EDM02 optimises value from investments, not risk management, so it fails the stem's requirement for the governance objective governing risk optimisation. It is tempting because benefits delivery genuinely addresses investment value realisation, and would be the correct choice where the scenario concerned ensuring that IT-enabled investments deliver expected benefits against defined business cases.
- ✗
EDM01 — Ensure Governance Framework Setting and Maintenance
Why it's wrong here
EDM01 covers designing and maintaining the governance framework itself — its components, principles and decision structures — not the optimisation of risk management activities. It tempts because governance framework maintenance underpins every objective, but COBIT 2019 assigns risk optimisation specifically to EDM03, Ensure Risk Optimisation, which sets risk appetite and tolerance.
Go deeper
Related to this question
About these practice questions
One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.