Courseiva

CRISC Information Technology and Security Practice Question

A risk manager is designing an IT risk management program. According to COBIT 2019, which governance objective is specifically focused on ensuring that risk management is optimized?

⚠ Common exam trap

CRISC often tests the distinction between the four EDM objectives (EDM01 governance framework, EDM02 benefits delivery, EDM03 risk optimization, EDM04 resource optimization), so candidates who confuse 'risk optimization' with 'resource optimization' pick EDM04.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EDM03 — Ensure Risk Optimization

COBIT 2019's governance objectives are organized under the EDM (Evaluate, Direct, Monitor) domain. EDM03 — Ensure Risk Optimization is the specific governance objective that ensures enterprise risk is identified, assessed, and managed within the entity's risk appetite, and that risk management activities are optimized. It is the governance-level counterpart to the management-level APO12 (Manage Risk) objective.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    EDM03 — Ensure Risk Optimization

    Why this is correct

    COBIT 2019's EDM03 governance objective sits within the Evaluate, Direct and Monitor domain and explicitly assigns accountability for ensuring risk management is optimised, aligning risk appetite with enterprise objectives. It is the specific objective covering risk optimisation, not risk identification or treatment execution.

  • ✗

    EDM04 — Ensure Resource Optimization

    Why it's wrong here

    EDM04 addresses optimising resource use, covering sourcing and capability decisions, not risk optimisation. It is tempting because optimisation sounds governance-wide. The objective specifically focused on risk management optimisation is EDM03, Ensure Risk Optimisation, which sets risk appetite and monitors risk management effectiveness.

  • ✗

    EDM02 — Ensure Benefits Delivery

    Why it's wrong here

    EDM02 optimises value from investments, not risk management, so it fails the stem's requirement for the governance objective governing risk optimisation. It is tempting because benefits delivery genuinely addresses investment value realisation, and would be the correct choice where the scenario concerned ensuring that IT-enabled investments deliver expected benefits against defined business cases.

  • ✗

    EDM01 — Ensure Governance Framework Setting and Maintenance

    Why it's wrong here

    EDM01 covers designing and maintaining the governance framework itself — its components, principles and decision structures — not the optimisation of risk management activities. It tempts because governance framework maintenance underpins every objective, but COBIT 2019 assigns risk optimisation specifically to EDM03, Ensure Risk Optimisation, which sets risk appetite and tolerance.

About these practice questions

One of 1,062 original CRISC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.