Courseiva

CRISC Information Technology and Security Practice Question

According to COBIT 2019, which governance objective is primarily concerned with evaluating, directing, and monitoring the management of IT risk?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

EDM03 — Ensure Risk Optimization

EDM03 — Ensure Risk Optimization is the governance objective that focuses on evaluating, directing, and monitoring risk management to ensure the enterprise's risk appetite and risk tolerance are understood and articulated.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    EDM03 — Ensure Risk Optimization

    Why this is correct

    EDM03 addresses risk optimisation within the Evaluate, Direct and Monitor domain, ensuring IT-related risk is identified, assessed and kept within the enterprise's risk appetite. It satisfies the stem's governance objective because EDM03 specifically covers evaluating, directing and monitoring IT risk management.

  • ✗

    EDM02 — Ensure Benefits Delivery

    Why it's wrong here

    EDM02 concerns ensuring that IT investments deliver promised benefits and value. It is tempting because risk management supports value delivery. It does not cover evaluating, directing and monitoring IT risk management, which is the remit of EDM03, Ensure Risk Optimisation.

  • ✗

    EDM04 — Ensure Resource Optimization

    Why it's wrong here

    EDM04 covers optimising IT resources — people, infrastructure, applications and information — to deliver value. It is tempting because risk treatment consumes resources. It does not address evaluating, directing and monitoring risk management; that is EDM03, Ensure Risk Optimisation.

  • ✗

    EDM01 — Ensure Governance Framework Setting and Maintenance

    Why it's wrong here

    EDM01 addresses the governance framework itself — its design, maintenance and alignment with enterprise objectives — rather than risk specifically. It is tempting because governance frameworks underpin risk oversight. The objective concerned with evaluating, directing and monitoring IT risk management is EDM03, Ensure Risk Optimisation.

About these practice questions

This CRISC question is part of Courseiva's 1,062-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CRISC practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CRISC exam.