training mcq Flashcards
(50 cards)
- Which COBIT domain focuses on the execution of IT applications and support processes? a) Plan and Organize b) Acquire and Implement c) Deliver and Support d) Monitor and Evaluate
c) Deliver and Support
- COBIT 5 is primarily categorized under which framework type? a) Architectures b) IT Service Management c) Governance d) HR Management
c) Governance
- What does the COBIT principle “Meeting Stakeholder Needs” emphasize? a) Defines relationship between Governance and Management b) Translates stakeholder requirements into strategy c) Provides a simple architecture d) Aligns with latest governance views
b) Translates stakeholder requirements into strategy
- Which COBIT resource category includes skill sets, certifications, and morale? a) Products b) People c) Partners d) Processes
b) People
- What is the main focus of IT governance? a) IT executive compensation b) IT policy c) Security policy d) IT strategy
d) IT strategy
- Which COBIT domain addresses the development of a maintenance plan for IT systems? a) Acquire and Implement b) Deliver and Support c) Monitor and Evaluate d) Plan and Organize
a) acquire and implement
- Which of the following is NOT a general IT control? a) IT governance b) Business continuity and backup procedures c) Application-specific input controls d) Change management
c) application specific input controls
- What is the primary purpose of substantive testing in IT audits? a) To assess control design only b) To substantiate audit assertions through detailed testing c) To perform walkthroughs d) To conduct interviews only
b) To substantiate audit assertions through detailed testing
- Which COBIT principle is based on a holistic approach to enterprise IT governance? a) Stakeholder Value-driven b) Governance and Management c) Enabler Based d) All of the above
d) All of the above
- What is the key difference between policies and principles according to COBIT 5? a) Principles provide detailed controls b) Policies express core values and provide detailed guidance c) Policies are designed to achieve stated purpose d) Principles provide regulatory requirements
c) Policies are designed to achieve stated purpose
- COSO framework primarily focuses on: a) IT governance b) Enterprise risk management and internal control c) Disaster recovery d) IT service management
b) Enterprise risk management and internal control
- Which COBIT domain includes monitoring IT performance and compliance? a) Plan and Organize b) Acquire and Implement c) Deliver and Support d) Monitor and Evaluate
d) Monitor and Evaluate
- Which COSO component is critical for risk assessment? a) Control environment b) Risk assessment c) Control activities d) Information and communication
b) Risk assessment
- COBIT’s “Plan and Organize” domain primarily deals with: a) IT strategy and tactics b) IT operations c) IT service delivery d) IT performance monitoring
. a) IT strategy and tactics
- Which of the following is a key enabler in COBIT? a) Processes b) Organizational structures c) Culture, ethics, and behavior d) All of the above
d) All of the above
- What is the primary objective of a Business Continuity Plan (BCP)? a) To eliminate all cyber threats b) To ensure uninterrupted availability of key business resources c) To promote unrestricted data sharing d) To recover data only
b) To ensure uninterrupted availability of key business resources
- What is a Business Impact Analysis (BIA)? a) A process to eliminate vulnerabilities b) A process to identify events that could affect business continuity and their impact c) A method to test disaster recovery sites d) A financial audit process
b) A process to identify events that could affect business continuity and their impact
- The critical recovery time period in BCP is: a) The time to complete the recovery b) The window within which processing must resume to avoid significant loss c) The time to notify stakeholders d) The time to backup data
. b) The window within which processing must resume to avoid significant loss
- Which of the following costs are associated with IT outages? a) Lost transaction revenue b) Marketing costs c) Brand damage d) All of the above
d) All of the above
- What is the first step in developing a Business Continuity Plan? a) Testing the plan b) Identifying business requirements c) Implementing recovery strategies d) Conducting risk assessment
. b) Identifying business requirements
- Which is NOT a traditional phase in preparing a BCP? a) Business Impact Analysis b) Quantitative Risk Analysis c) Project Management and Initiation d) Disaster Recovery Testing
. b) Quantitative Risk Analysis
- What is the focus of a Disaster Recovery Plan (DRP)? a) Recovery of damaged facilities and IT components to normal operations b) Crisis communication c) Employee evacuation d) Financial reporting
a) Recovery of damaged facilities and IT components to normal operations
- What is the most critical factor in developing a DRP? a) Annual testing b) Management support c) Business impact analysis d) Participation from every department
c) Business impact analysis
- Which type of test involves representatives from each department walking through the disaster recovery plan collectively? a) Structured walk-through test b) Simulation test c) Parallel test d) Full interruption test
a) Structured walk-through test