Вы находитесь на странице: 1из 23

SUPINFO

Academic Dept.

5MET - CobiT : Gouvernance,


Risks and Compliance
Graded Quiz

Version 1.0
Use: Students/Staff
Author: SAD

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Important notes to be read before beginning the quiz


Exam resources

This activity is a closed-book one.
It means that documents(especially course) and other activity(Internet, Social Networks,

...) during the graded exercise are not allowed.
If you do not follow these rules, your instructor will ask you to leave the assessment room
and will assign to you the "Cheater" grade for this evaluation.

Guidelines
You'll answer using the Excel file contained in the archive, named Quiz_AnswerFile_5MET.xlsx.
First, you'll rename it to append at the end your IDBOOSTER like the following pattern,
Quiz_AnswerFile_5MET_12345.xlsx, where 12345 is your own IDBOOSTER.
You'll use exclusively Microsoft Excel 2010, 2011 or 2013 to open and save the XSLX file.
When opening the file, you should see the following layout:

To fill the Excel file, you must follow those rules:


- For questions with one answer, fill the answer associated letter in the column Answer 1.
- For questions with multiple answers, fill the answers associated letters in the answers
columns.

- For matching question, fill the associations answers in the answers columns
- For questions without proposed answers, fill the answer in the column Answer 1.

Failure to comply with any of these rules will result in the complete discard of your
delivery and thus a 0/20 mark.
Page
1 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Fill example with the answer file


- Question 1 is a question with a single answer, with the answer A

- Question 2 is a question with multiple answers, A and B


- Question 3 is a matching question, with associations A1,B2,C3,D4,E5,F6,G7,H8.

- Question 4 is a question without proposed answers , with the right answer is "thing".


With a proper filling, this would give the following:

Note: Answers aren't case-sensitive. Multiple answers and matching questions aren't order
sensitive. Fill-in-the-blank answers are not case-sensitive as well.

Good luck !

Page
2 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 1: Why are the enabler dimensions important?


A. A link between governance and management is provided

B. They allow an entity to manage its complex interactions

C. They facilitate the planning, building, running and monitoring of an entitys IT

D. A link between COBIT 5 to other standards and frameworks is provided

Question 2: Which requirement was a major driver for developing the COBIT
5 framework?
A. To obtain commitment of executive management for making IT related decisions
B. To deliver programmes on time, on budget and meeting stakeholder requirements
C. To provide further guidance in the area of innovation and emerging technologies

D. To enable the management of a portfolio of competitive products and services

Page
3 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 3: What is the name of an enterprise communication mechanism

which provides more guidance on desired organisational behaviour?

A. Rules and norms


B. Statement of actions


C. Principles and policies

D. Escalation procedures
Question 4: Which statement related to capability and maturity is not correct?
A. Organizational maturity has a relationship to the achievement of the organization business
goals
B. A maturity assessment can use the findings of a capability assessment
C. A maturity assessment is done at an enterprise or organizational level and a capability
assessment is done at process level
D. Maturity and capability assessments are only defined by CMMI (Capacity Maturity Model

integrated) not by ISO 15504

Page
4 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 5: Which type of process goal is only known to and used by those

who need it?

A. Contextual


B. Accessibility and security


C. Intrinsic

D. Confidentiality
Question 6: What attribute describes the quantity of information that is
suitable for the required activity?
A. Appropriate amount of information
B. Relevancy
C. Completeness

D. Ease of manipulation

Page
5 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 7: Which statement about the difference between the capability

dimension and the process dimension is correct?

A. Specific work products are defined in the capability dimension and do not relate to the process

dimension


B. The capability dimension focuses on the process attribute indicators, the process dimension
focuses on the processes

C. Capability dimension focuses on specific base practices, the process dimension focuses on
generic base practices

D. The definition of all COBIT processes are the basis for the capability dimension and not or the
process dimension

Question 8: What do processes produce to ensure consistent implementation?


A. Cultural and behavioural aspects
B. Roles which operate according to RACI charts
C. Business and IT goals

D. Policies and procedures

Page
6 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 9: Which principle is key for the governance and management of an

enterprise?

A. Managing information


B. Ensure resources optimization


C. Enabling a holistic approach

D. Managing IT operations
Question 10: Which attribute is relevant to a process activity?
A. Aligns with standards and good practices
B. Provides specific detailed activities
C. Provides statements of actions to deliver benefits

D. Supports establishment of distinct roles and responsibilities

Page
7 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 11: Which mechanism is not considered to be a good practice of an

organisational structure?

A. Process reference


B. Delegation of authority


C. Escalation procedures

D. Span of control
Question 12: Which option is a driver that influences stakeholder needs?
A. Enterprise resources
B. Strategy changes
C. Lead indicators

D. Good practices

Page
8 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 13: What term refers to an artefact associated with the execution of

a process?

A. A base practice


B. A process purpose


C. A work product

D. A process outcome
Question 14: Which is not a purpose of the process reference model?
A. Provides the mechanism whereby defined process assessment models are related the
measurement framework
B. Provides the basis for one or more process assessment models
C. Provides the basis to undertake an assessment on the process dimension

D. Forms the basis of a process capability assessment for the Capability dimension

Page
9 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 15: Which item describes a key component of a Governance System?


A. Identifying responsibilities for governance

B. Setting the governance framework

C. Ensuring compliance with regulations

D. Optimisation of IT assets, resources and capabilities

Question 16: Which aspect relates to the COBIT 5 principle


shareholders needs?
A. Aligns with the latest views on Governance
B. Defines relationship between governance and management
C. Translates stakeholder requirements into strategy

D. Provides a simple architecture

Page
10 / 22
SUPINFO International University http://www.supinfo.com

the

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 17: Which items is considered a good practice for inclusion within

policy framework?

A. Skill categories


B. Compliance requirements


C. Statement of actions

D. Defined goals
Question 18: Who is an internal stakeholder?
A. Shareholder
B. Regulator
C. Business process owner

D. Business process partner

Page
11 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 19: One of the benefits of the COBIT 5 capability assessment model

is improved reliability and of process capability assessment activities
and evaluations


A. Repeatability

B. Enablement
C. Integrity

D. Effectiveness

Question 20: Which option is an environmental factor which enterprise is


dependent upon when designing its implementation plan?
A. Capabilities and available resources
B. Tailoring COBIT to fit the unique context of the enterprise
C. Focusing on quick wins and improvements

D. Effective communication of the necessary changes

Page
12 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 21: Which characteristic should a good policy framework provide?


A. Access to social media

B. Confirmation that practices are applied

C. Detailed process activities

D. A structure for consistency

Question 22: Which statement describes the difference between specific and
generic work products?
A. Specific work products define the objectives at activity level generic work products the high
level objectives of a process
B. Specific work products are specified or each process generic work products are defined for all
generic processes from level 2 to 5
C. Specific work products are associated with the IT related goals generic work products are
associated with the higher level enterprise goals
D. Specific work products are specified at each capability level generic work products are

defined on an organisational level

Page
13 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 23: What is the name of the architectural principle that is designed

to be as straightforward as possible but still meeting enterprise
requirements?


A. Openness

B. Agility
C. Simplicity

D. Reuse

Question 24: Which aspects is fundamental to the COBIT 5 Integrator model?


A. To ling Plan, Build, Run and Monitor
B. To link governance with management
C. To link stakeholder needs with enterprise goals

D. To link COBIT 5 to the existing ISACA guidance

Page
14 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 25: Identify the missing word in the following sentence Service

capabilities are leveraged primarily through the to deliver internal
and external services


A. Processes

B. IT goals
C. Physical infrastructure

D. Policies

Question 26: What statement describes the main difference between policies
and principles as stated by COBIT 5?
A. Policies provide detailed guidance to influence decision making
B. Principles are designed to achieve the stated purpose
C. Policies express the core values of the enterprise

D. Principles are designed to provide detailed controls over regulatory requirements

Page
15 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 27: What is the name of the Change Enablement life cycle phase

which supports phase 4 What needs to be done?

A. Define target state


B. Plan programme


C. Identify role players

D. Define problems and opportunities


Question 28: What role does the governing body plan in the governance and
management of enterprise IT?
A. Operates, executes and reports to management
B. Instructs, aligns and monitors performance
C. Delegates and is accountable for the governance of enterprise IT

D. Sets direction and is responsible to the owners and stakeholders

Page
16 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 29: Identify the missing word in the following sentence. The

definition of is a collection of practices influenced by the enterprise
policies and procedures that takes input from a number of sources,

manipulates the inputs and produces output.

A. Processes

B. Principles

C. Enterprise goals
D. Intrinsic Goals

Question 30: Which mechanism can define and implement policies within
their span of control?
A. Rules and norms
B. Governance framework
C. Process practices

D. Organisational structures

Page
17 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 31: Which information should a business case include?


A. A review of the success factors of the initiative

B. An improvement target for identifiable gaps and solutions

C. The proposed solutions and definitions of the initiative

D. How the investment and value creation will be monitored throughout the economic cycle

Question 32: What item is generated by business processes as the first stage
of the information cycle?
A. Information
B. Data
C. Knowledge

D. Volume

Page
18 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 33: At what level are Inputs and Outputs defined?


A. Process

B. Detailed activity

C. Activity

D. Management practice

Question 34: Which activity should be done by governance?


A. Set principles and policies
B. Plan activities to meet enterprise goals
C. Implement and appetite

D. Execute strategy

Page
19 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 35: What do lead indicators monitor in the generic enabler model?


A. Stakeholder needs are being addressed

B. Good practices are being applied

C. Enabler outcomes are being made

D. Enabler goals are being achieved

Question 36: Why is COBIT 5 considered to be an integrated standard?


A. It aligns with other relevant standards
B. It integrates in any governance system
C. It integrates enterprise goals with IT related goals

D. It integrates IT related goals with enablers

Page
20 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 37: Which is not a good policy?


A. Non-intrusive

B. Implemented in the most efficient way

C. Achieves the stated purpose

D. Limited in number

Question 38: Which process is included in the Build, Acquire and Implement
process domain of the management of enterprise IT?
A. Manage continuity
B. Manage operations
C. Manage availability and capacity

D. Manage risk

Page
21 / 22
SUPINFO International University http://www.supinfo.com

5MET
- CobiT : Gouvernance, Risks and Compliance

Graded Quiz


Question 39: Which process domain is the most suitable for skills as project

management and capacity management?

A. Deliver, Service and Support (DSS)


B. Align, Plan and Organize (APO)


C. Monitor, Evaluate and assess (MEA)

D. Build, Acquire and Implement (BAI)


Question 40: What percentage represents F: full achievement of an attribute
in an assessed process, defined by COBIT5 assessment approach?
A. 75 to 100%
B. 100%
C. On average 85%

D. 85% to 100%

Page
22 / 22
SUPINFO International University http://www.supinfo.com

Вам также может понравиться