Spring Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

CGEIT Certified in the Governance of Enterprise IT Exam Questions and Answers

Questions 4

Which of the following is the BEST way to express the value of financial investments in cybersecurity?

Options:

A.

Payback period

B.

Cost-benefit analysis

C.

Net present value (NPV)

D.

Internal rate of return (IRR)

Buy Now
Questions 5

A CIO realizes a significant change is required in the way IT responds to key external customers and needs to gain support from the enterprise to address this situation. What should be done FIRST?

Options:

A.

Empower key IT staff to implement a solution.

B.

Establish new customer service policies.

C.

Engage customer service training providers.

D.

Engage the IT steering committee.

Buy Now
Questions 6

An enterprise is evaluating both a virtual reality (VR) project and an augmented reality (AR) project. Which of the following should be the MOST important objective when evaluating these two projects within IT portfolio management?

Options:

A.

Maximizing the earned value of IT investments

B.

Determining which IT project to discontinue

C.

Implementing efficient and effective solutions

D.

Reducing the risk exposure of the projects

Buy Now
Questions 7

IT governance within an enterprise is attempting to drive a cultural shift to enhance compliance with IT security policies. The BEST way to support this objective is to ensure that enterprise IT policies are:

Options:

A.

communicated on a regular basis.

B.

acknowledged and signed by each employee.

C.

centrally posted and contain detailed instructions.

D.

integrated into individual performance objectives.

Buy Now
Questions 8

The board of an enterprise has decided to implement an emerging technology, and employees are extremely concerned about the unknown future of the company. What should be the CIO’s PRIMARY responsibility in addressing these concerns?

Options:

A.

Develop and communicate new performance measures.

B.

Define new roles and responsibilities for IT staff.

C.

Initiate IT workforce training on the new technology.

D.

Define and communicate a new IT strategy.

Buy Now
Questions 9

Which of the following is MOST important to ensure when aligning IT and enterprise resource management processes?

Options:

A.

IT sourcing processes are in place

B.

IT provides input for business strategy development

C.

IT resources are mapped to business priorities

D.

IT resource monitoring and oversight is in place

Buy Now
Questions 10

Which of the following would BEST help assess the effectiveness of a newly established IT governance framework?

Options:

A.

Develop a business case for the program portfolio.

B.

Evaluate key performance indicator (KPI) results.

C.

Benchmark the IT governance framework to industry best practice.

D.

Review results of IT audit reports.

Buy Now
Questions 11

A CIO engages a consulting firm to conduct a benchmark analysis of the organization’s IT governance framework against industry best practices. Several recommendations to improve the maturity of the framework are identified. Which of the following should be the CIO’s NEXT course of action?

Options:

A.

Evaluate the feasibility of the recommendations.

B.

Obtain approval from the IT steering committee to implement the recommendations.

C.

Develop a plan to integrate the recommendations.

D.

Appoint a project manager to implement the recommendations.

Buy Now
Questions 12

Which of the following is the BEST indication of an effective information governance model?

Options:

A.

Senior management ensures quality goals are defined for information.

B.

The CIO defines information accountability, quality criteria, and criticality.

C.

Enterprise architects define information protection attributes.

D.

Process owners determine which information assets will be managed.

Buy Now
Questions 13

What is the PRIMARY benefit of aligning information architecture with enterprise architecture (EA)?

Options:

A.

It improves communication with senior management and the business.

B.

It ensures the adoption of enterprise data quality standards.

C.

It enables the tracing of data to business functions.

D.

It facilitates appropriate access to data consumers.

Buy Now
Questions 14

Which of the following is the BEST way for a CIO to provide senior business management with increased visibility to the overall performance of the IT operation?

Options:

A.

Develop key risk indicators (KRIs).

B.

Provide return on investment (ROI) reports.

C.

Develop key performance indicators (KPIs).

D.

Provide service level agreement (SLA) performance statistics.

Buy Now
Questions 15

Which of the following will BEST enable an enterprise to convey IT governance direction and objectives?

Options:

A.

Skills and competencies

B.

Principles and policies

C.

Corporate culture

D.

Business processes

Buy Now
Questions 16

Which of the following is the BEST indicator of effective IT governance?

Options:

A.

Regulatory authorities have given a favorable report on IT controls.

B.

Executive management is involved in important IT decisions and activities.

C.

The chief information security officer (CISO) reports to a board member.

D.

IT management is proactive in reporting IT project status to executive management.

Buy Now
Questions 17

An enterprise recently acquired technology that will enable it to offer products to customers through a mobile device application. The business is eager to use this technology as soon as possible for products currently offered through legacy IT systems. What is the CIO's MAIN responsibility?

Options:

A.

Ensure proper metrics are established to measure technology usage throughout the enterprise.

B.

Ensure business units are aware of new opportunities available with the acquired technology.

C.

Ensure the enterprise architecture (EA) is reviewed and updated.

D.

Ensure risk associated with implementation and support of the new technology is properly managed.

Buy Now
Questions 18

An IT governance committee is reviewing its current risk management policy in light of increased usage of social media within an enterprise. The FIRST task for the governance committee is to:

Options:

A.

recommend blocking access to social media.

B.

review current level of social media usage.

C.

initiate an assessment of the impact on the business.

D.

reassess the enterprise's bring your own device (BYOD) policy.

Buy Now
Questions 19

In which of the following situations is it acceptable to retain data beyond the stated policy?

Options:

A.

The business created an analytics model based on historical records.

B.

There is a high probability that the enterprise will enter into litigation.

C.

New data privacy regulations are expected in a few months.

D.

A core system database is going through an upgrade.

Buy Now
Questions 20

An enterprise’s IT director is concerned that the chair of the IT steering committee is stealing confidential company information. Which of the following is the IT director’s BEST course of action?

Options:

A.

File a report with the local law enforcement agency.

B.

Report the concern to the ethics hotline.

C.

Discuss the concern with the chair directly.

D.

Conduct an investigation to substantiate the chair’s activities.

Buy Now
Questions 21

Which of the following would be the BEST way for an enterprise to address new legal and regulatory requirements applicable to IT?

Options:

A.

Treat as a risk to be assessed before developing a response.

B.

Benchmark how other IT organizations are treating the new requirements.

C.

Adopt a zero-tolerance approach for noncompliance with regulatory matters.

D.

Use a cost-benefit analysis to determine if compliance is warranted.

Buy Now
Questions 22

An enterprise’s IT department has been operating independently without regard to business concerns, leading to misalignment between business and IT. The BEST way to establish alignment would be to require:

Options:

A.

Business to help define IT goals.

B.

IT and business to define risks.

C.

Business to fund IT services.

D.

IT to define business objectives.

Buy Now
Questions 23

An IT governance committee is defining a risk management policy for a portfolio of IT-enabled investments. Which of the following should be the PRIMARY consideration when developing the policy?

Options:

A.

Risk appetite of the enterprise.

B.

Possible investment failures.

C.

Risk management framework.

D.

Value obtained with minimum risk.

Buy Now
Questions 24

Which of the following should be done FIRST when developing an IT strategy to support a new AI business strategy?

Options:

A.

Assess current AI capabilities and infrastructure

B.

Establish guidelines and policies for responsible use of AI

C.

Create use cases to understand the impact of AI

D.

Build a team of AI professionals

Buy Now
Questions 25

Which of the following should be the MOST essential consideration when outsourcing IT services?

Options:

A.

Identification of core and non-core business processes.

B.

Compliance with enterprise architecture (EA).

C.

Alignment with existing human resources (HR) policies and practices.

D.

Adoption of a diverse vendor selection process.

Buy Now
Questions 26

An enterprise is planning to upgrade its current enterprise resource planning (ERP) system to remain competitive within the industry. Which of the following would be MOST helpful to facilitate a successful implementation?

Options:

A.

Documenting the current ERP processes and procedures

B.

Reviewing the ERP post-implementation report

C.

Establishing a change and transition planning process

D.

Conducting a comprehensive requirements review

Buy Now
Questions 27

Which of the following is MOST important for a data steward to verify when a system's data is edited by an automated tool to fix an incident?

Options:

A.

The change has been requested by the business department and approved by the data owner.

B.

The change is documented in preparation for future audits.

C.

The change maintains consistency among databases and has no other impacts.

D.

The change is a temporary fix for the incident, and the permanent solution is addressed by problem management.

Buy Now
Questions 28

A CEO realizes the need to implement IT governance to support the strategic alignment of business and IT goals. Which of the following would BEST enable this initiative?

Options:

A.

A RACI chart

B.

An increased IT budget

C.

Well-trained IT staff

D.

Effective culture change

Buy Now
Questions 29

Which of the following should be the PRIMARY consideration when implementing IT governance in a small, newly established organization?

Options:

A.

Assigning a budget for IT governance applications.

B.

Defining IT project management methodology.

C.

Approving enterprise architecture (EA) and standards.

D.

Assigning IT roles and responsibilities.

Buy Now
Questions 30

An enterprise has decided to adopt cloud services. Which of the following should be established FIRST?

Options:

A.

Service level agreements (SLAs)

B.

Business continuity plan (BCP)

C.

Risk tolerance levels

D.

Third-party management framework

Buy Now
Questions 31

An enterprise's decision to move to a virtualized architecture will have the GREATEST impact on:

Options:

A.

system life cycle management.

B.

asset classification.

C.

vendor management

D.

vulnerability management.

Buy Now
Questions 32

An enterprise has lost an unencrypted backup tape of archived customer data. A data breach report is not mandatory in the relevant jurisdiction. From an ethical standpoint, what should the enterprise do NEXT?

Options:

A.

Initiate disciplinary proceedings against relevant employees.

B.

Mandate a review of backup tape inventory procedures.

C.

Communicate the breach to customers.

D.

Require an evaluation of storage facility vendors.

Buy Now
Questions 33

Which of the following has PRIMARY responsibility to define the requirements for IT service levels for the enterprise?

Options:

A.

The business manager

B.

The help desk

C.

The CIO

D.

The business continuity vendor

Buy Now
Questions 34

An airline wants to launch a new program involving the use of artificial intelligence (Al) and machine learning the mam objective of the program is to use customer behavior to determine new routes and markets Which of the following should be done NEXT?

Options:

A.

Consult with the enterprise privacy function

B.

Define the critical success factors (CSFs)

C.

Present the proposal to the IT strategy committee

D.

Perform a business impact analysis (BIA)

Buy Now
Questions 35

The PRIMARY reason a CIO and IT senior management should stay aware of the business environment is to:

Options:

A.

revisit prioritization of IT projects.

B.

adjust IT strategy as needed.

C.

measure efficiency of IT resources.

D.

re-assess the IT investment portfolio.

Buy Now
Questions 36

An enterprise is planning to outsource data processing for personally identifiable information (Pll). When is the MOST appropriate time to define the requirements for security and privacy of information?

Options:

A.

When issuing requests for proposals (RFPs)

B.

After an assessment of the current information architecture.

C.

When developing service level agreements (SLAs)

D.

During the initial vendor selection process

Buy Now
Questions 37

In a successful enterprise that is profitable in its marketplace and consistently growing in size, the non-IT workforce has grown by 50% in the last two years. The demand for IT staff in the marketplace is more than the supply, and the enterprise is losing staff to rival organizations. Due to the rapid growth. IT has struggled to keep up with the enterprise, and IT procedures and associated job roles are not well-defined. The MOST critical activity for reducing the impact caused by IT staff turnover is to:

Options:

A.

document processes and procedures.

B.

outsource the IT operation.

C.

increase compensation for IT staff

D.

hire temporary staff.

Buy Now
Questions 38

Which of the following IT governance actions would be the BEST way to minimize the likelihood of IT failures jeopardizing the corporate value of an IT-dependent organization?

Options:

A.

Implement an IT risk management framework.

B.

Install an IT continuous monitoring solution.

C.

Define IT performance management measures.

D.

Benchmark IT strategy against industry peers.

Buy Now
Questions 39

Which of the following would a CIO use to present the overall view of IT performance to the board of directors?

Options:

A.

Balanced scorecard

B.

Key risk indicators (KRIs)

C.

Maturity model

D.

Key performance indicators (KPIs)

Buy Now
Questions 40

An IT steering committee wants to select a disaster recovery site based on available risk data Which of the following would BE ST enable the mapping of cost to risk?

Options:

A.

Key risk indicators (KRIs)

B.

Scenario-based assessment

C.

Business impact analysis (BIA)

D.

Qualitative forecasting

Buy Now
Questions 41

The PRIMARY reason for periodically evaluating IT resource staffing requirements is to:

Options:

A.

ascertain the IT function has sufficient skilled staff to maintain daily operations.

B.

ensure the enterprise has sufficient resources to address changing business and IT needs.

C.

verify that human resource recruitment and retention processes meet enterprise IT objectives.

D.

confirm IT-related responsibilities are defined for the enterprise's business and IT staff.

Buy Now
Questions 42

The CIO of an international enterprise is considering the use of an offshore cloud service provider to store customer data. Which of the following should be the MOST important consideration when making this decision?

Options:

A.

IT service delivery roles and responsibilities

B.

Compliance with applicable legislation

C.

Likelihood of natural disasters

D.

The cloud service provider's reputation

Buy Now
Questions 43

A business unit is planning to replace an existing IT legacy solution with a hosted Software as a Service (SaaS) solution. However, business management is concerned that stored data will be at risk. Which of the following is the MOST effective way to reduce the risk associated with the SaaS solution?

Options:

A.

Research the technology and identify potential security threats.

B.

Include risk-related requirements in the SaaS contract.

C.

Create key risk indicators (KRls) for the SaaS solution.

D.

Redefine the risk appetite and risk tolerance.

Buy Now
Questions 44

An IT strategy committee has reviewed an audit report indicating sales employees are using personal smartphones to conduct corporate business. Although the committee appreciates the business benefits, it is also concerned with the security risk. To deliver the business benefit, what should be the committee's FIRST recommendation?

Options:

A.

Document procedures for securing personal devices.

B.

Improve training courses on securing corporate information.

C.

Perform a risk assessment on personal device data protection.

D.

Update the corporate security policy to include personal devices.

Buy Now
Questions 45

IT senior management has just received a survey report indicating that more than one third of the organization's key IT staff plan to retire within the next 12 months. Which of the following is the MOST important governance action to prepare for this possibility?

Options:

A.

Engage human resources (HR) for recruitment of new staff.

B.

Request the development of a succession plan.

C.

Review motivation drivers for key IT staff.

D.

Evaluate lower-level staff as succession candidates.

Buy Now
Questions 46

The BEST way to decide how to prioritize issues identified in an IT risk and control self-assessment (CSA) is to understand the risk and:

Options:

A.

impact to the enterprise.

B.

criticality of IT services affected.

C.

number of IT systems affected.

D.

funds required for remediation.

Buy Now
Questions 47

An enterprise's executive team has recently released a new IT strategy and related objectives. Which of the following would be the MOST effective way for the CIO to ensure IT personnel are supporting the new strategy's objectives?

Options:

A.

Measure progress towards IT objectives and communicate the results to IT staff.

B.

Incorporate IT objectives into individual performance evaluations.

C.

Develop communication materials to promote the new IT strategy and objectives.

D.

Require IT managers to assign activities aligned to the IT objectives.

Buy Now
Questions 48

Business management is seeking assurance from the CIO that controls are in place to help minimize the risk of critical IT systems being unavailable during month-end financial processing. What is the BEST way to address this concern?

Options:

A.

Create a communication plan with risk owners.

B.

Outsource infrastructure hosting.

C.

Restrict and monitor user access.

D.

Develop key risk indicators (KRIs) and action plans.

Buy Now
Questions 49

To evaluate IT resource management, it is MOST important to define:

Options:

A.

responsibilities for executing resource management.

B.

applicable key goals.

C.

principles for the IT strategy.

D.

IT resource utilization reporting procedures.

Buy Now
Questions 50

Reviewing which of the following should be the FIRST step when evaluating the possibility of outsourcing an IT system?

Options:

A.

Outsourcing strategy

B.

Outsourced business processes

C.

Service level agreements (SLAs)

D.

IT staff skill sets

Buy Now
Questions 51

An organization is evaluating vendors to provide mobile device management (MDM) services. Which of the following is a KEY governance consideration for the IT steering committee?

Options:

A.

Service level targets align with business requirements.

B.

Employee-owned devices will be covered by the service.

C.

The MDM services are delivered via a cloud.

D.

Technology-owned devices will be covered by the service

Buy Now
Questions 52

An internal audit revealed a widespread perception that the enterprise's IT governance reporting lacks transparency Which of the following should the CIO do FIRST?

Options:

A.

Add stakeholder transparency metrics to the balanced scorecard

B.

Develop a communication and awareness strategy

C.

Meet with key stakeholders to understand their concerns

D.

Adopt an industry-recognized template to standardize reports.

Buy Now
Questions 53

The CEO of an organization is concerned that there are inconsistencies in the way information assets are classified across the enterprise. Which of the following is be the BEST way for the CIO to address these concerns?

Options:

A.

Include data assets in the IT inventory.

B.

Identify data owners across the enterprise.

C.

Require enterprise risk assessments.

D.

Implement enterprise data governance.

Buy Now
Questions 54

IT security is concerned with employees' increasing use of personal equipment for work-related purposes, while employees claim it allows them to be more productive. A decision on whether to modify the enterprise information security policy should be based on:

Options:

A.

audit findings.

B.

user access approval procedures.

C.

the impact to security.

D.

a risk and benefit evaluation.

Buy Now
Questions 55

Which of the following would be the BEST way to facilitate the successful adoption of a new technology across the enterprise?

Options:

A.

Ensure the use of a business case

B.

Review business goals.

C.

Establish an IT balanced scorecard.

D.

Highlight the risk the new technology will address.

Buy Now
Questions 56

An IT department outsourced application support and negotiated service level agreements (SLAs) directly with the vendor Although the vendor met the SLAs business owner expectations are not met and senior management cancels the contract This situation can be avoided in the future by:

Options:

A.

improving the business requirements gathering process

B.

improving the negotiation process for service level agreements (SLAs)

C.

implementing a vendor performance scorecard

D.

assigning responsibility for vendor management

Buy Now
Questions 57

Which of the following is the PRIMARY responsibility of a data steward?

Options:

A.

Ensuring the appropriate users have access to the right data

B.

Developing policies for data governance

C.

Reporting data analysis to the board

D.

Classifying and labeling organizational data assets

Buy Now
Questions 58

Once the strategic vision has been established, which of the following would be the BEST activity for supporting the implementation of performance measures?

Options:

A.

Monitor service level performance.

B.

Document strengths, weaknesses, opportunities, and threats.

C.

Document policy requirements

D.

Identify key performance indicators (KPIs).

Buy Now
Questions 59

A major data leakage incident at an enterprise has resulted in a mandate to strengthen and enforce current data governance practices. Which of the following should be done FIRST to achieve this objective?

Options:

A.

Assess data security controls.

B.

Review data logs.

C.

Analyze data quality.

D.

Verify data owners.

Buy Now
Questions 60

The PRIMARY objective of IT resource planning within an enterprise should be to:

Options:

A.

determine risk associated with IT resources.

B.

maximize value received from IT.

C.

determine IT outsourcing options.

D.

finalize service level agreements (SLAs) for IT

Buy Now
Questions 61

In a large enterprise, which of the following should be responsible for the implementation of an IT balanced scorecard?

Options:

A.

Project management office

B.

Chief information officer (CIO)

C.

IT steering committee

D.

Chief risk officer (CRO)

Buy Now
Questions 62

An enterprise has made the strategic decision to reduce operating costs for the next year and is taking advantage of cost reductions offered by an external cloud service provider. Which of the following should be the IT steering committee's PRIMARY concern?

Options:

A.

Calculating the cost of the current solution

B.

Updating the business risk profile

C.

Changing the IT steering committee charter

D.

Revising the business's balanced scorecard

Buy Now
Questions 63

Which of the following is the BEST outcome measure to determine the effectiveness of IT nsk management processes?

Options:

A.

Frequency of updates to the IT risk register

B.

Time lag between when IT risk is identified and the enterprise's response

C.

Number of events impacting business processes due to delays in responding to risks

D.

Percentage of business users satisfied with the quality of risk training

Buy Now
Questions 64

Which of the following is the BEST justification for a procurement manager to agree to purchase IT equipment from a specific vendor during a sales promotion?

Options:

A.

The IT benefit surpasses the business benefit from the purchase.

B.

The equipment adds value to the enterprise.

C.

The business profit surpasses the IT cost for the equipment.

D.

The product is offered at the lowest price.

Buy Now
Questions 65

Which of the following would BEST help a CIO enhance the competencies of an IT business analytics team?

Options:

A.

Understanding current staff skill sets and identifying gaps

B.

Creating operational processes and identifying resources

C.

Defining the IT architecture and identifying training areas

D.

Establishing team goals and identifying the proper structure

Buy Now
Questions 66

An enterprise's chief information officer (CIO) has been receiving complaints from business executives regarding the amount their units are being charged for IT services. To maintain a good relationship with business peers, the CIO wants to be responsive to these complaints. To address this issue, the FIRST step should be to:

Options:

A.

agree to reduce charge rates and improve relationship management with the business.

B.

look into outsourcing of support functions to drive down the cost structure.

C.

ask the chief financial officer (CFO) about budget revisions for the business units' IT expenditures.

D.

quantify consumption and service level agreement (SLA) achievements per business unit.

Buy Now
Questions 67

Which of the following roles should be responsible for data normalization when it is found that a new system includes duplicates of data items?

Options:

A.

Business system owner

B.

Data steward

C.

Database administrator (DBA)

D.

Application manager

Buy Now
Questions 68

From an IT governance perspective, establishing performance measurements is PRIMARILY the responsibility of:

Options:

A.

the IT architecture review board.

B.

senior management.

C.

the board of directors.

D.

enterprise risk management (ERM).

Buy Now
Questions 69

When considering an IT change that would enable a potential new line of business, the FIRST strategic step for IT governance would be to ensure agreement among the stakeholders regarding:

Options:

A.

objectives to achieve goals.

B.

metrics to measure effectiveness

C.

a vision for the future state,

D.

a change response plan

Buy Now
Questions 70

A CIO observes that many information assets are hosted on legacy technology that can no longer be patched or updated. The systems are not currently in use, but business units are reluctant to decommission assets due to information retention requirements. Which of the following is the BEST strategic response to this situation?

Options:

A.

Ensure the legacy systems are behind a secure firewall

B.

Isolate the legacy systems and disconnect them from the internet

C.

Apply legacy system surcharges to the business units

D.

Develop and enforce life cycle policies in consultation with business

Buy Now
Questions 71

IT management has reported difficulty retaining qualified IT personnel to support the organization's new strategy Given that outsourcing is not a viable approach, which of the following would be the BEST way for IT governance to address this situation?

Options:

A.

Implement an incentive-based employee referral program

B.

Direct the development of a strategic HR plan for IT

C.

Recommend enhancements to the online recruiting platform specific to IT

D.

Work with HR to enhance compensation packages for IT personnel

Buy Now
Questions 72

An enterprise is developing an ethics program, and the ethical standards have been defined. Which of the following should the enterprise do NEXT?

Options:

A.

Establish a training and awareness program focused on ethics.

B.

Implement an enterprise-wide employee monitoring program.

C.

Develop key performance indicators (KPIs) for program implementation.

D.

Outline and document consequences for noncompliance.

Buy Now
Questions 73

Which of the following would be the GREATEST obstacle for effective implementation of an enterprise's information security policy?

Options:

A.

Corporate culture

B.

Threats to corporate information

C.

Utilization of cloud-based applications

D.

Geographically dispersed staff

Buy Now
Questions 74

Which of the following is the BEST way for a CIO to ensure that IT-related training is taken seriously by the IT management team and direct employees?

Options:

A.

Develop training programs based on results of an IT staff survey of preferences.

B.

Embed training metrics into the annual performance appraisal process.

C.

Promote IT-specific training awareness program.

D.

Research and identify training needs based on industry trends.

Buy Now
Questions 75

The CIO of a large enterprise has taken the necessary steps to align IT objectives with business objectives. What is the BEST way for the CIO to ensure these objectives are delivered effectively by IT staff?

Options:

A.

Map the IT objectives to an industry-accepted framework.

B.

Enhance Ihe budget for training based on the IT objectives.

C.

Include the IT objectives in staff performance plans.

D.

Include CIO sign-off of the objectives as part of the IT strategic plan.

Buy Now
Questions 76

An enterprise is approaching the escalation date of a major IT risk. The IT steering committee wants to ascertain who is responsible for the risk response. Where should the committee find this information?

Options:

A.

Resource management plan

B.

RACl chart

C.

Risk management plan

D.

Risk register

Buy Now
Questions 77

When preparing a new IT strategic plan for board approval, the MOST important consideration is to ensure the plan identifies:

Options:

A.

roles and responsibilities that link to IT objectives.

B.

specific resourcing requirements for identified IT projects.

C.

frameworks that will be aligned to IT programs.

D.

implications of the strategy on the procurement process.

Buy Now
Questions 78

Which of the following should be established FIRST so that data owners can consistently assess the level of data protection needed across the enterprise?

Options:

A.

Data encryption program

B.

Data risk management program

C.

Data retention policy

D.

Data classification policy

Buy Now
Questions 79

Which of the following is MOST critical to support IT governance cultural changes within an organization?

Options:

A.

Established IT monitoring and measuring

B.

Regularly scheduled governance training

C.

Demonstrated management commitment

D.

IT governance process manuals

Buy Now
Questions 80

Which of the following is a responsibility of an IT strategy committee?

Options:

A.

Providing oversight on enterprise strategy implementation

B.

Approving the business strategy and its IT implications

C.

Advising the board on the development of IT goals

D.

Tracking projects in the IT investment portfolio

Buy Now
Questions 81

Which of the following is the BEST indication that information security requirements are taken into consideration when developing IT processes?

Options:

A.

The database is deployed in a distributed processing platform

B.

The information architecture incorporates data classification

C.

Customer profiles are stored with a domestic service provider

D.

The integrity of sensitive information is periodically reviewed

Buy Now
Questions 82

Which of the following would be MOST useful for prioritizing IT improvement initiatives to achieve desired business outcomes?

Options:

A.

Budget variance analysis

B.

Enterprise architecture (EA)

C.

IT skills matrix

D.

Portfolio management

Buy Now
Questions 83

A board of directors has just received a report indicating that only a small number of IT initiatives have been completed on time and within budget, A third of the projects were cancelled prior to completion, and more than half will cost almost double their original estimates. An analysis has determined that no one is held responsible for the completion of investmentinitiatives, and there is no consistency in execution. Which of the following would BEST help the enterprise address these problems?

Options:

A.

Establishing a project governance framework

B.

Assigning business management to an IT investment review board

C.

Establishing an IT risk management plan

D.

Aligning IT investment priorities to the business

Buy Now
Questions 84

An independent consultant has been hired to conduct an ad hoc audit of an enterprise’s information security office with results reported to the IT governance committee and the board Which of the following is MOST important to provide to the consultant before the audit begins?

Options:

A.

Acceptance of the audit risks and opportunities

B.

The scope and stakeholders of the audit

C.

The organizational structure of the security office

D.

The policies and framework used by the security office

Buy Now
Questions 85

An enterprise is planning to migrate its IT infrastructure to a cloud-based solution but does not have experience with this

technology Which of the following should be done FIRST to reduce the risk of IT service disruptions when using this new technology?

Options:

A.

Implement key performance indicators (KPIs).

B.

Reflect the change in the enterprise architecture (EA).

C.

Evaluate the sourcing options.

D.

Engage an experienced IT consultant to perform the migration.

Buy Now
Questions 86

When evaluating the process for acquiring third-party IT resources, management identified several suppliers with repeated downtime issues impacting the enterprise. Which of the following is the BEST approach to help ensure future service delivery in accordance with business objectives?

Options:

A.

Establish key performance indicators (KPls)

B.

Appoint a procurement oversight committee

C.

Establish key risk indicators (KRIs).

D.

Implement contract monitoring.

Buy Now
Questions 87

Following a re-prioritization of business objectives by management, which of the following should be performed FIRST to allocate resources to IT processes?

Options:

A.

Perform a maturity assessment.

B.

Implement a RACI model.

C.

Refine the human resource management plan.

D.

Update the IT strategy.

Buy Now
Questions 88

A data governance strategy has been defined by the IT strategy committee which includes privacy objectives related to access controls, authorized use. and data collection. Which of the following should the committee do NEXT?

Options:

A.

Mandate data privacy training for employees.

B.

Establish a data privacy budget

C.

Perform a data privacy impact assessment.

D.

Mandate the creation of a data privacy policy.

Buy Now
Questions 89

Which of the following should be the FIRST step in updating an IT strategic plan?

Options:

A.

Revise the enterprise architecture (EA).

B.

Review IT performance objectives and indicators.

C.

Evaluate IT capabilities and resources.

D.

Identify changes in enterprise goals.

Buy Now
Questions 90

Which of the following is the GREATEST advantage of earned value management when used for evaluating benefits from the implementation of blockchain projects for IT contracts management?

Options:

A.

It automates project progress reporting to business executives.

B.

It provides a measure of project progress that is easy to understand.

C.

It eliminates potential risks related to project earnings.

D.

It enables accurate forecasts of the number of blocks to be completed.

Buy Now
Questions 91

An enterprise-wide strategic plan has been approved by the board of directors. Which of the following would BEST support the planning of IT investments required for the enterprise?

Options:

A.

Service-oriented architecture

B.

Enterprise architecture (EA)

C.

Contingency planning

D.

Enterprise balanced scorecard

Buy Now
Questions 92

An IT steering committee is concerned that enterprise technologies have grown stagnant and are outdated. Which of the following is the BEST strategy to invest in modern technology?

Options:

A.

Decrease spending on steady state and increase spending on modernization and enhancements.

B.

Redefine the target architecture to define new technologies that can be incorporated into the infrastructure.

C.

Create a new investment category for innovation that becomes a new way for tracking investment decisions.

D.

Update the IT human resource management plan to require training and development for emerging technologies.

Buy Now
Questions 93

Which of the following should be the FIRST step for executive management to take in communicating what is considered acceptable use with regard to personally owned devices for company business?

Options:

A.

Require employees to read and sign a disclaimer.

B.

Develop and disseminate an applicable policy.

C.

Post awareness messages throughout the facility.

D.

Provide training on how to protect data on personal devices.

Buy Now
Questions 94

Which of the following should be done FIRST when concerns have been identified regarding the financial viability of a potential software supplier?

Options:

A.

Implement an escrow agreement

B.

Perform a risk assessment

C.

Include a right-to-audit clause in the contract

D.

License the intellectual property

Buy Now
Questions 95

Which of the following is the BEST way for an organization to minimize the difference between expected and delivered services when acquiring resources?

Options:

A.

Negotiate service level agreements (SLAs)

B.

Measure service delivery using industry benchmarks

C.

Require quarterly benefits realization reporting

D.

Include a right-to-audit clause in the contract.

Buy Now
Questions 96

An IT governance committee is defining a risk management policy for a portfolio of IT-enabled investments Which of the following should be the PRIMARY consideration when developing the policy?

Options:

A.

Risk management framework

B.

Possible investment failures

C.

Value obtained with minimum risk

D.

Risk appetite of the enterprise

Buy Now
Questions 97

Which of the following roles should approve major IT purchases to help prevent conflicts of interest?

Options:

A.

IT steering committee

B.

Chief information officer (CIO)

C.

Chief compliance officer

D.

Project management office (PMO)

Buy Now
Questions 98

Before establishing IT key nsk indicators (KRls) which of the following should be defined FIRST?

Options:

A.

IT resource strategy

B.

IT risk and security framework

C.

IT goals and objectives

D.

IT key performance indicators (KPIs)

Buy Now
Questions 99

Which of the following is MOST important to document for a business ethics program?

Options:

A.

Guiding principles and best practices

B.

Violation response matrix

C.

Whistle-blower protection protocols.

D.

Employee awareness and training content

Buy Now
Questions 100

Which of the following should be done FIRST when designing an IT balanced scorecard?

Options:

A.

Develop key performance indicators (KPIs).

B.

Communicate to stakeholders

C.

Analyze the business strategy.

D.

Review the IT resource plan.

Buy Now
Questions 101

A project sponsor has circumvented the request for proposal (RFP) selection process. Which of the following is the MOST likely reason for this control gap?

Options:

A.

Inadequate stage-gate reviews

B.

Inadequate board oversight

C.

Lack of accountability for policy adherence

D.

Lack of a legal and regulatory review process

Buy Now
Questions 102

An IT audit reveals inconsistent maintenance of data privacy in enterprise systems primarily due to a lack of data sensitivity categorizations. Once the categorizations are defined, what is the BEST long-term strategic response by IT governance to address this problem?

Options:

A.

Standardize data classification processes throughout the enterprise.

B.

Incorporate enterprise privacy categorizations into contracts.

C.

Require business impact analyses (BIAs) for enterprise systems.

D.

Reassess the data governance policy.

Buy Now
Questions 103

An enterprise has finalized a major acquisition and a new business strategy in line with stakeholder needs has been introduced to help ensure continuous alignment of IT with the new business strategy the CiO should FIRST

Options:

A.

review the existing IT strategy against the new business strategy

B.

revise the existing IT strategy to align with the new business strategy

C.

establish a new IT strategy committee for the new enterprise

D.

assess the IT cultural aspects of the acquired entity

Buy Now
Questions 104

An enterprise made a significant change to its business operating model that resulted in a new strategic direction. Which of the following should be reviewed FIRST to ensure IT congruence with the new business strategy?

Options:

A.

IT risk appetite

B.

Enterprise project management framework

C.

IT investment portfolio

D.

Information systems architecture

Buy Now
Questions 105

Which of the following is the BEST indication of effective IT-business strategic alignment?

Options:

A.

Business management is involved as IT strategies are developed.

B.

IT senior management is required to report to the board.

C.

Business strategy is documented to allow IT architecture to be designed quickly.

D.

IT-business collaboration results in a strategy focused on IT cost reduction.

Buy Now
Questions 106

An IT director is negotiating a contract with a vendor for application management services. There is concern by other departments that the outsourced services may not be delivered successfully. Which of the following is the BEST way for the IT director to address this concern?

Options:

A.

Implement a communication management plan.

B.

Develop a comprehensive vendor management plan.

C.

Review the IT service risk management plan.

D.

Establish a policy on operational level agreements with vendors.

Buy Now
Questions 107

While assessing the feasibility of introducing new IT practices and standards into the IT governance framework, it is CRITICAL to understand an organization's:

Options:

A.

culture.

B.

level of outsourcing.

C.

enterprise architecture (EA).

D.

maturity of IT processes.

Buy Now
Questions 108

An enterprise is developing several consumer-based services using emerging technologies involving sensitive personal data. The CIO is under pressure to ensure the enterprise is first to market, but security scan results have not been adequately addressed. Reviewing which of the following will enable the CIO to make the BEST decision for the customers?

Options:

A.

Acceptable use policy

B.

Risk register

C.

Ethics standards

D.

Change management policy

Buy Now
Questions 109

Which of the following is the PRIMARY ongoing responsibility of the IT governance function related to risk?

Options:

A.

Responding to and controlling all IT risk events

B.

Communicating the enterprise risk management plan

C.

Ensuring IT risk management is aligned with business risk appetite

D.

Verifying that all business units have staff skilled at assessing risk

Buy Now
Questions 110

An enterprise has a zero-tolerance policy regarding security. This policy is causing a large number of email attachments to be blocked and is a disruption to enterprise. Which of the following should be the FIRST governance step to address this email issue?

Options:

A.

Direct the development of an email usage policy.

B.

Obtain senior management input based on identified risk.

C.

Recommend business sign-off on the zero-tolerance policy.

D.

Introduce an exception process.

Buy Now
Questions 111

Which of the following BEST reflects mature risk management in an enterprise?

Options:

A.

A regularly updated risk register

B.

Ongoing risk assessment

C.

Ongoing investment in risk mitigation

D.

Responsive risk awareness culture

Buy Now
Questions 112

Which of the following is the BEST way to ensure new systems can be adequately supported once in production?

Options:

A.

Establish a resource management framework.

B.

Evaluate the operational requirements of the business stakeholders.

C.

Identify key performance indicators (KPIs).

D.

Require operational management be identified in the business case.

Buy Now
Questions 113

The board of directors has mandated the use of geolocation software to track mobile assets assigned to employees who travel outside of their home country. To comply with this mandate, the IT steering committee should FIRST request

Options:

A.

the inclusion of mandatory training for remote device users.

B.

an architectural review to determine appropriate solution design.

C.

an assessment to determine if data privacy protection is addressed.

D.

an update to the acceptable use policy.

Buy Now
Questions 114

A regulator has expressed concerns about the timeliness of information reported from an enterprise. Which of the following should be done FIRST to address this issue?

Options:

A.

Assess the reporting delivery process.

B.

Negotiate an exception process with the regulator.

C.

Automate the reporting process.

D.

Evaluate the implications of risk acceptance.

Buy Now
Questions 115

Which of the following is the PRIMARY benefit to an enterprise when risk management is practiced effectively throughout the organization?

Options:

A.

Decisions are made with an awareness of probability and impact.

B.

IT objectives and goals are aligned to business objectives and goals.

C.

Business opportunity losses are minimized.

D.

Innovative strategic initiatives are encouraged.

Buy Now
Questions 116

Which of the following is MOST helpful in determining whether an enterprise’s quality assurance (QA) program is meeting business requirements?

Options:

A.

Review the quality framework.

B.

Perform a SWOT analysis.

C.

Review service outage reports.

D.

Perform a quality audit.

Buy Now
Questions 117

The GREATEST benefit associated with a decision to implement performance metrics for key IT assets is the ability to:

Options:

A.

establish the span of control during the life cycle of IT assets.

B.

determine the average cost of controls for protection of IT assets.

C.

compare the performance Of IT assets against industry best practices.

D.

determine the contribution of IT assets in achievement of IT goals.

Buy Now
Questions 118

Which of the following presents the GREATEST challenge for a large-scale enterprise when procuring Infrastructure as a Service (IaaS)?

Options:

A.

Testing the vendor resiliency plan annually

B.

Protecting the enterprise from labor liability

C.

Ensuring the vendor meets corporate requirements

D.

Monitoring key performance indicators (KPIs)

Buy Now
Questions 119

Which of the following BEST enables informed IT investment decisions?

Options:

A.

Business case

B.

Technology roadmap

C.

Program plan

D.

Risk classification

Buy Now
Questions 120

Which of the following should be considered FIRST when migrating data to a cloud environment?

Options:

A.

Disaster recovery plan (DRP).

B.

Skills matrix.

C.

Information architecture.

D.

Data structure.

Buy Now
Questions 121

An audit department recently uncovered a series of security breaches. It was determined that network intrusion detection logs were recording the suspicious activity, but IT staff were not reviewing logs due to competing business demands. To address this situation, the IT steering committee’s FIRST priority should be:

Options:

A.

A re-prioritization of IT projects to address critical needs

B.

Updating the RACI chart to establish responsibility

C.

The hiring of additional staff to cope with the demand

D.

An assessment of the capacity of current resources

Buy Now
Questions 122

Which of the following is the PRIMARY reason to monitor data classification efforts?

Options:

A.

To identify and minimize data security breaches

B.

To identify deviations in the data that are outside risk thresholds

C.

TO ensure alignment with data protection regulations

D.

To ensure assets are protected appropriately

Buy Now
Questions 123

A large enterprise that is diversifying its business will be transitioning to a new software platform, which is expected to cause data changes. Which of the following should be done FIRST when developing the related metadata management process?

Options:

A.

Require an update to enterprise data policies.

B.

Request an impact analysis.

C.

Review documented data interdependence.

D.

Validate against existing architecture.

Buy Now
Questions 124

Which of the following would be the PRIMARY impact on IT governance when a business strategy is changed?

Options:

A.

Performance outcomes of IT objectives

B.

IT governance structure

C.

Maturity level of IT processes

D.

Relationship level with IT outsourcers

Buy Now
Questions 125

A board of directors is concerned that a major IT implementation has the potential to significantly disrupt enterprise operations. Which of the following would be MOST helpful in identifying the extent of the potential impact of the disruption?

Options:

A.

An analysis of the current enterprise risk appetite

B.

An earned value analysis (EVA) of the implementation

C.

A risk assessment of the implementation

D.

A review of lessons learned from previous implementations

Buy Now
Questions 126

An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?

Options:

A.

Authenticating access to information assets based on roles or business rules.

B.

Implementing multi-factor authentication controls

C.

Granting access to information based on information architecture

D.

Engaging an audit of logical access controls and related security policies

Buy Now
Questions 127

Which of the following is the MOST important success factor when adopting an enterprise IT governance framework?

Options:

A.

Implementing an enterprise risk management (ERM) framework.

B.

Aligning to the enterprise-specific business environment.

C.

Complying with legal and regulatory requirements.

D.

Using a globally accepted IT governance framework.

Buy Now
Questions 128

When selecting a cloud provider, which of the following provides the MOST comprehensive information regarding the current status and effectiveness of the provider's controls?

Options:

A.

Globally recognized certification

B.

Third-party audit report

C.

Control self-assessment (CSA)

D.

Maturity assessment

Buy Now
Questions 129

Which of the following is MOST important to consider when monitoring the performance of IT resources?

Options:

A.

End-user feedback

B.

Business impact analysis (BIA)

C.

Centralized log analysis

D.

Service level requirements

Buy Now
Questions 130

A global organization has noticed a significant decrease in the return on IT investments in a particular region. To enhance project governance in this region, the CEO should FIRST:

Options:

A.

Perform an independent review of business cases for each current and proposed project in the region.

B.

Work with the region’s leadership to better understand why the situation has occurred.

C.

Suspend funding until project managers from better-performing regions can be assigned.

D.

Perform a program benefit calculation and review the project selection methodology.

Buy Now
Questions 131

The CIO of a financial services company is tasked with ensuring IT processes are in compliance with recently instituted regulatory changes. The FIRST course of action should be to:

Options:

A.

align IT project portfolio with regulatory requirements.

B.

create an IT balanced scorecard.

C.

identify the penalties for noncompliance.

D.

perform a current state assessment.

Buy Now
Questions 132

IT has launched new portfolio management policies and processes to improve the alignment of IT projects with enterprise goals. The latest audit report indicates that no improvement has been made due to confusion in the decision-making process. Which of the following is the BEST course of action for the CIO?

Options:

A.

Deliver prioritization and facilitation training.

B.

Implement a performance management framework.

C.

Create an IT portfolio management risk framework.

D.

Develop and communicate an accountability matrix.

Buy Now
Questions 133

When implementing an IT governance framework, which of the following would BEST ensure acceptance of the framework?

Options:

A.

Factoring in the effects of enterprise culture

B.

Using subject matter experts

C.

Using industry-accepted practices

D.

Complying with regulatory requirements

Buy Now
Questions 134

Which of the following is the PRIMARY element in sustaining an effective governance framework?

Options:

A.

Identification of optimal business resources

B.

Establishment of a performance metric system

C.

Ranking of critical business risks

D.

Assurance of the execution of business controls

Buy Now
Questions 135

Due to continually missed service level agreements (SLAs), an enterprise plans to terminate its contract with a vendor providing IT help desk services. The enterprise s IT department willassume the help desk-related responsibilities. Which of the following would BEST facilitate this transition?

Options:

A.

Requiring the enterprise architecture (EA) be updated

B.

Validating that the balanced scorecard is still meaningful

C.

Ensuring IT will operate at a lower cost than the vendor

D.

Ensuring a change management plan is in place

Buy Now
Questions 136

Which of the following MUST be established before implementing an information architecture that restricts access to data based on sensitivity?

Options:

A.

Risk and control frameworks

B.

Probability and impact analysis

C.

Classification and ownership

D.

Security and privacy policies

Buy Now
Questions 137

The use of an IT balanced scorecard enables the realization of business value of IT through:

Options:

A.

business value and control mechanisms.

B.

outcome measures and performance drivers.

C.

financial measures and investment management.

D.

vision and alignment with corporate programs.

Buy Now
Questions 138

A CEO determines the enterprise is lagging behind its competitors in consumer mobile offerings, and mandates an aggressive rollout of several new mobile services within the next 12 months. To ensure the IT organization is capable of supporting this business objective, what should the CIO do FIRST?

Options:

A.

Request an assessment of current in-house mobile technology skills.

B.

Create a sense of urgency with the IT team that mobile knowledge is mandatory.

C.

Procure contractors with experience in mobile application development.

D.

Task direct reports with creating training plans for their teams.

Buy Now
Questions 139

What is the PRIMARY objective for performing an IT due diligence review prior to the acquisition of a competitor?

Options:

A.

Document the competitor's governance structure.

B.

Ensure that the competitor understands significant IT risks.

C.

Assess the status of the risk profile of the competitor.

D.

Determine whether the competitor is using industry-accepted practices.

Buy Now
Questions 140

The board of directors of an enterprise has approved a three-year IT strategic program to centralize the core business processes of its global entities into one core system. Which of the following should be the ClO's NEXT step?

Options:

A.

Engage a team to perform a business impact analysis (BIA).

B.

Require the development of a risk management plan.

C.

Determine resource requirements for program implementation.

D.

Require the development of a program roadmap.

Buy Now
Questions 141

Which of the following is the BEST way for a CIO to secure support for a strategy to achieve long-term IT objectives?

Options:

A.

Make the necessary strategic decisions and notify staff accordingly.

B.

Develop tactics to implement the strategy and share with stakeholders.

C.

Develop a communication plan for distribution of information to staff.

D.

Meet with stakeholders to explain the strategy and incorporate feedback.

Buy Now
Questions 142

The BEST way to manage an outsourced vendor relationship is by:

Options:

A.

conducting periodic risk assessments.

B.

reviewing annual independent third-party reports.

C.

providing clear objectives and transparency.

D.

analyzing performance statistics from the vendor.

Buy Now
Questions 143

An enterprise is evaluating a Software as a Service (SaaS) solution to support a core business process. There is no outsourcing governance or vendor management in place. What should be the CEO's FIRST course of action?

Options:

A.

Ensure the roles and responsibilities to manage service providers are defined.

B.

Establish a contract with the SaaS solution provider.

C.

Instruct management to use the standard procurement process.

D.

Ensure the service level agreements (SLAs) for service providers are defined.

Buy Now
Questions 144

An enterprise embarked on an aggressive strategy requiring the implementation of several large IT projects impacting multiple business processes across all departments. Initially employees were supportive of the strategy, but there is growing fatigue and frustration with the ongoing newcapabilities which must be learned. Which of the following would be the BEST action performed by senior management?

Options:

A.

Incorporate an organizational change management program.

B.

Establish "Reward and Recognition" efforts to boost employee morale.

C.

Improve the system development life cycle (SDLC) process.

D.

Assess current business and IT competencies.

Buy Now
Questions 145

Which of the following is an ADVANTAGE of using strategy mapping?

Options:

A.

It provides effective indicators of productivity and growth.

B.

It depicts the maturity levels of processes that support organizational strategy.

C.

It identifies barriers to strategic alignment and links them to specific outcomes.

D.

It depicts the cause-and-effect linked relationships between strategic objectives.

Buy Now
Questions 146

The CIO of an enterprise learns the payroll server of a competitor has been the victim of ransomware. To help plan for the possibility of ransomed corporate data, what should be the ClO's FIRST course of action?

Options:

A.

Require development of key risk indicators (KRls).

B.

Develop a policy to address ransomware.

C.

Request a targeted risk assessment.

D.

Back up corporate data to a secure location.

Buy Now
Questions 147

To reduce the risk of reputational damage through inappropriate use of social media by employees outside of the workplace, the enterprise approach regarding social media should PRIMARILY focus on;

Options:

A.

implementing preventative controls.

B.

developing policies on social media.

C.

implementing a review of processes utilizing social media.

D.

ensuring each use of social media is approved by management.

Buy Now
Questions 148

An audit report has revealed that data scientists are analyzing sensitive "big data" files using an offsite cloud because corporate servers do not have the necessary processing capabilities. A review of policies indicates this practice is not prohibited. Which of the following should be the FIRST strategic action to address the report?

Options:

A.

Authorize a risk analysis of the practice.

B.

Update data governance practices.

C.

Revise the information security policy.

D.

Recommend the use of a private cloud.

Buy Now
Questions 149

Which of the following would be the BEST way to facilitate the adoption of strong IT governance practices throughout a multi-divisional enterprise?

Options:

A.

Ensuring each divisional policy is consistent with corporate policy

B.

Ensuring divisional governance fosters continuous improvement processes

C.

Mandating data standardization across the distributed enterprise

D.

Documenting and communicating key management practices across divisions

Buy Now
Questions 150

It has been discovered that multiple business units across an enterprise are using duplicate IT applications and services to fulfill their individual needs. Which of the following would be MOST helpful to address this concern?

Options:

A.

Enterprise architecture (EA)

B.

Enterprise risk framework

C.

IT service management

D.

IT project roadmap

Buy Now
Questions 151

An enterprise's information security function is making changes to its data retention and backup policies. Which of the following presents the GREATEST risk?

Options:

A.

Business data owners were not consulted.

B.

The new policies Increase the cost of data backups.

C.

Data backups will be hosted at third-party locations.

D.

The retention period for data backups is Increased.

Buy Now
Questions 152

To benefit from economies of scale, a CIO is deciding whether to outsource some IT services. Which of the following would be the MOST important consideration during the decision-making process?

Options:

A.

IT staff morale

B.

Core IT processes

C.

Outsourcer's reputation

D.

New service level agreements (SLAs)

Buy Now
Questions 153

Which of the following is PRIMARILY achieved through performance measurement?

Options:

A.

Process improvement

B.

Transparency

C.

Cost efficiency

D.

Benefit realization

Buy Now
Questions 154

Which of the following represents the GREATEST challenge to implementing IT governance?

Options:

A.

Determining the best practice to follow

B.

Planning the project itself

C.

Developing a business case

D.

Applying behavioral change management

Buy Now
Questions 155

Which of the following should be the MAIN reason for an enterprise to implement an IT risk management framework?

Options:

A.

The need to enable IT risk-aware decisions by executives

B.

The results of an external audit report concerning IT risk management processes.

C.

The need to address market regulations and internal compliance in IT risk

D.

The ability to benchmark IT risk policies against major competitors

Buy Now
Questions 156

Which of the following is the MOST comprehensive method to report on overall IT performance to the board of directors?

Options:

A.

Balanced scorecard

B.

Net present value (NPV)

C.

Performance-based payments

D.

Return on investment (ROI)

Buy Now
Questions 157

An IT strategy committee wants to ensure that a risk program is successfully implemented throughout the enterprise. Which of the following would BEST support this goal?

Options:

A.

A risk management framework

B.

Mandatory risk awareness courses for staff

C.

A risk recognition and reporting policy

D.

Commitment from senior management

Buy Now
Questions 158

Which of the following is the BEST way to demonstrate that IT strategy supports a new enterprise strategy?

Options:

A.

Monitor new key risk indicators (KRIs).

B.

Measure return on IT investments against balanced scorecards.

C.

Review and update the portfolio management process.

D.

Map IT programs to business goals.

Buy Now
Questions 159

Prior to setting IT objectives, an enterprise MUST have established its:

Options:

A.

architecture.

B.

policies.

C.

strategies.

D.

controls.

Buy Now
Questions 160

An enterprise has made the strategic decision to reduce operating costs for the next year and is taking advantage of cost reductions offered by an external cloud service provider. Which of the following should be the IT steering committee's PRIMARY concern?

Options:

A.

Revising the business $ balanced store card

B.

Updating the business risk profile

C.

Changing the IT steering committee charter

D.

Calculating the cost of the current solution

Buy Now
Questions 161

An IT governance committee wants to ensure there is a clear description of the "data owner" in the enterprise data policy. Which of the following would BEST define the owner of data stored in an external cloud?

Options:

A.

The business leader who is most impacted by the loss of data.

B.

The risk manager who is responsible for protecting data stored in the cloud.

C.

The contract manager who monitors the security of the cloud provider.

D.

The vendor who submits the data to the organization via online forms

Buy Now
Questions 162

Which of the following is MOST important to effectively initiate IT-enabled change?

Options:

A.

Establish a change management process.

B.

Obtain top management support and ownership.

C.

Ensure compliance with corporate policy.

D.

Benchmark against best practices.

Buy Now
Questions 163

An enterprise considers implementing a system that uses a technology that is not in line with its IT strategy. The business case indicates significant benefit to the enterprise. Which of the following is the BEST way to manage this situation within an IT governance framework?

Options:

A.

Update the IT strategy to align with the new technology.

B.

Initiate an operational change request.

C.

Reject based on non-alignment.

D.

Address as part of an architecture exception process.

Buy Now
Questions 164

An enterprise is evaluating a possible strategic initiative for which IT would be the main driver. There are several risk scenarios associated with the initiative that have been identified. Which of the following should be done FIRST to facilitate a decision?

Options:

A.

Define the risk mitigation strategy.

B.

Assess the impact of each risk.

C.

Establish a baseline for each initiative.

D.

Select qualified personnel to manage the project.

Buy Now
Questions 165

An IT director has become aware that a certain subset of data collected lawfully can be used to generate additional revenue. However, this particular use of the data is outside the original intention. What is the PRIMARY reason this situation should be escalated to the IT steering committee?

Options:

A.

Potential legal penalties

B.

Ethical concerns

C.

Regulatory requirements

D.

Data protection

Buy Now
Questions 166

An enterprise's board of directors can BEST manage enterprise risk by:

Options:

A.

mandating board-approved enterprise risk management (ERM) modifications.

B.

requiring the establishment of an enterprise risk management (ERM) framework.

C.

requiring the establishment of an enterprise-wide program management office.

D.

ensuring the cost-effectiveness of the internal control system.

Buy Now
Questions 167

Which of the following roles has PRIMARY accountability for the security related to data assets?

Options:

A.

Database administrator

B.

Data owner

C.

Data analyst

D.

Security architect

Buy Now
Questions 168

Which of the following aspects of the transition from X-rays to digital images would be BEST addressed by implementing information security policy and procedures?

Options:

A.

Establishing data retention procedures

B.

Training technicians on acceptable use policy

C.

Minimizing the impact of hospital operation disruptions on patient care

D.

Protecting personal health information

Buy Now
Questions 169

Which of the following components of a policy BEST enables the governance of enterprise IT?

Options:

A.

Disciplinary actions

B.

Regulatory requirements

C.

Roles and responsibilities

D.

Terms and definitions

Buy Now
Questions 170

A marketing enterprise is considering procuring customer information to more accurately target customer communications and increase sales. The data has a very high cost to the enterprise. Which of the following would provide the MOST comprehensive view into the potential value to the organization?

Options:

A.

Investment services board review

B.

Net present value {NPV) calculation

C.

Risk assessment results

D.

Cost-benefit analysis results

Buy Now
Questions 171

Which of the following would BEST help to improve an enterprise's ability to manage large IT investment projects?

Options:

A.

Creating a change management board

B.

Reviewing and evaluating existing business cases

C.

Implementing a review and approval process for each phase

D.

Publishing the IT approval process online for wider scrutiny

Buy Now
Questions 172

A recent benchmarking analysis has indicated an IT organization is retaining more data and spending significantly more on data retention than its competitors. Which of the following would BEST ensure the optimization of retention costs?

Options:

A.

Requiring that all business cases contain data deletion and retention plans

B.

Revalidating the organization's risk tolerance and re-aligning the retention policy

C.

Moving all high-risk and medium-risk data backups to cloud storage

D.

Redefining the retention policy to align with industry best practices

Buy Now
Questions 173

An IT investment review board wants to ensure that IT will be able to support business initiatives. Each initiative is comprised of several interrelated IT projects. Which of the following would help ensure that the initiatives meet their goals?

Options:

A.

Review of project management methodology

B.

Review of the business case for each initiative

C.

Establishment of portfolio management

D.

Verification of initiatives against the architecture

Buy Now
Questions 174

Which of the following is the BEST method for determining an enterprise's current appetite for risk?

Options:

A.

Interviewing senior management

B.

Evaluating the balanced scorecard

C.

Reviewing recent audit findings

D.

Assessing social media adoption

Buy Now
Questions 175

A CEO is concerned that IT costs have significantly exceeded budget without resulting benefits. The root causes are an overlap of IT projects and a lack of alignment with business demands. Which of the following would BEST enable remediation of this situation?

Options:

A.

Require IT business cases be approved by the board of directors.

B.

Assign a set of key risk indicators (KRIs) to each new IT project.

C.

Conduct a performance assessment of IT projects.

D.

Implement an IT portfolio management policy.

Buy Now
Questions 176

The MOST important aspect of an IT governance framework to ensure that IT supports repeatable business processes is:

Options:

A.

earned value management.

B.

quality management,

C.

resource management.

D.

risk management

Buy Now
Questions 177

A global financial institution has decided to integrate data from branch locations into a common database to address regulatory reporting requirements. Analysis of data flows and the full data life cycle should be conducted at which level?

Options:

A.

Transaction level

B.

Enterprise level

C.

Branch level

D.

Department level

Buy Now
Questions 178

An IT steering committee is presented with an audit finding that new software applications are delivered on time but consistently have unacceptable levels of defects. Which of the following would be the BEST direction from the committee?

Options:

A.

Implement performance indicators.

B.

Evaluate the change management process.

C.

Establish code peer reviews.

D.

Evaluate the quality assurance process.

Buy Now
Questions 179

Six months ago, an enterprise's CIO reorganized IT to improve service delivery to the business. Which of the following would BEST demonstrate the effectiveness of the reorganization?

Options:

A.

The number of help desk calls

B.

A balanced scorecard

C.

A survey of IT staff

D.

IT cost reduction

Buy Now
Questions 180

Which of the following responsibilities should be retained within an enterprise when outsourcing a project management office (PMO) function?

Options:

A.

Selecting projects

B.

Managing projects

C.

Tracking project cost

D.

Defining project methodology

Buy Now
Questions 181

An enterprise has had the same IT governance framework in place for several years. Currently, large and small capital projects go through the same architectural governance reviews. Despite repeated requests to streamline the review process for small capital projects, business units have received no response from IT. The business units have recently escalated this issue to the newly appointed GO. Which of the following should be done FIRST to begin addressing business needs?

Options:

A.

Create a central repository for the business to submit requests.

B.

Explain the importance of the IT governance framework.

C.

Assess the impact of the proposed change.

D.

Assign a project team to implement necessary changes.

Buy Now
Questions 182

Which of the following would provide the BEST input for prioritizing strategic IT improvement initiatives?

Options:

A.

Business dependency assessment

B.

Business process analysis

C.

Business case evaluation

D.

Business impact analysis (BIA)

Buy Now
Questions 183

An enterprise has been focused on establishing an IT risk management framework. Which of the following should be the PRIMARY motivation behind this objective?

Options:

A.

Promoting responsibility throughout the enterprise for managing IT risk.

B.

Increasing the enterprise's risk tolerance level and risk appetite.

C.

Engaging executives in examining IT risk when developing policies.

D.

Maintaining a complete and accurate risk registry to belief manage IT risk

Buy Now
Questions 184

An enterprise decides to accept the IT risk of a subsidiary located in another country even though it exceeds the enterprise's risk appetite. Which of the following would be the BEST justification for this decision?

Options:

A.

Risk framework alignment

B.

Local market common practices

C.

Compliance with local regulations

D.

Technical gaps among subsidiaries

Buy Now
Questions 185

Which of the following roles is accountable for the confidentiality, integrity, and availability of information within an enterprise?

Options:

A.

Data owner

B.

Lead legal counsel

C.

Risk manager

D.

Data custodian

Buy Now
Questions 186

Which of the following is the BEST way for an IT steering committee to monitor the adoption of a new enterprise IT strategy?

Options:

A.

Implement service level agreements (SLAs).

B.

Establish key performance indicators (KPIs).

C.

Schedule ongoing audit reviews.

D.

Establish key risk indicators (KRIs).

Buy Now
Questions 187

Which of the following would be MOST useful in developing IT strategic plans aligned with technological needs?

Options:

A.

Business impact analysis (BIA)

B.

Business case

C.

Enterprise architecture (EA)

D.

Benchmark analysis

Buy Now
Questions 188

An enterprise's board of directors is concerned about the ongoing costs of a large inventory of Internet of Things (IoT) devices. Which of the following should the CIO do FIRST?

Options:

A.

Implement performance measures for each IoT device

B.

Suggest replacing IoT devices that are too expensive

C.

Assess the benefits of IoT capabilities

D.

Reduce the budget for IoT capability to meet stakeholder expectations

Buy Now
Questions 189

An enterprise's board of directors is developing a strategy change. Although the strategy is not finalized, the board recognizes the need for IT to be responsive. Which of the following is the FIRST step to prepare for this change?

Options:

A.

Ensure IT has knowledgeable representation and is included in the strategic planning process.

B.

Increase the IT budget and approve an IT staff level increase to ensure resource availability for the strategy change.

C.

Initiate an IT service awareness campaign to business system owners and implement service level agreements (SLAs).

D.

Outsource both IT operations and IT development and implement controls based on a standardized framework.

Buy Now
Questions 190

An interna! health organization has been notified that a data breach has resulted in patient records being published online. Which of the

following is MOST important consideration when determining the process for meeting the organization's legal and regulatory obligations?

Options:

A.

Organizational structure, including accountable partes

B.

Data classification and related security policy

C.

Context of the breach, including data ownership and location

D.

Details of how the breach occurred and related incident response efforts

Buy Now
Questions 191

A CIO is planning to implement an enterprise resource planning (ERP) system at the request of the business. Of the following, who is accountable for providing sponsorship for the IT-enabled change across the enterprise?

Options:

A.

CEO

B.

Human resource (HR) director

C.

IT strategy committee

D.

CIO

Buy Now
Questions 192

When conducting a risk assessment in support of a new regulatory

requirement, the IT risk committee should FIRST consider the:

Options:

A.

cost burden to achieve compliance.

B.

readiness of IT systems to address the risk.

C.

risk profile of the enterprise.

D.

disruption to normal business operations.

Buy Now
Questions 193

An enterprise has an ongoing issue of corporate applications not delivering the expected benefits due to missing key functionality. As a result, many groups are using spreadsheets and databases instead of approved enterprise applications to store and manipulate information. Which of the following will BEST improve the success rate of future IT initiatives?

Options:

A.

Engage the business user community in acceptance testing Of acquired applications.

B.

Engage stakeholders to identify and validate business requirements.

C.

Establish a process for risk and value management.

D.

Prohibit the use of non-approved alternate software solutions.

Buy Now
Questions 194

A CIO has recently been made aware of a new regulatory requirement that may affect IT-enabled business activities. Which of the following should be the CIO s FIRST step in deciding the appropriate response to the new requirement?

Options:

A.

Revise initiatives that are active to reflect the new requirements.

B.

Confirm there are adequate resources to mitigate compliance requirements.

C.

Consult with legal and risk experts to understand the requirements.

D.

Consult with the board for guidance on the new requirements

Buy Now
Questions 195

A large enterprise is implementing an information security policy exception process. The BEST way to ensure that security risk is properly addressed is to:

confirm process owners' acceptance of residual risk.

perform an internal and external network penetration test.

obtain IT security approval on security policy exceptions.

Options:

A.

benchmark policy against industry best practice.

Buy Now
Questions 196

Which of the following BEST facilitates the adoption of an IT governance program in an enterprise?

Options:

A.

Defining clear roles and responsibilities for the participants

B.

Using a comprehensive business case for the initiative

C.

Communicating the planned IT strategy to stakeholders

D.

Addressing the behavioral and cultural aspects of change

Buy Now
Questions 197

An enterprise recently approved a bring your own device (BYOD) policy. The IT steering committee has directed IT management to develop a communication plan to disseminate information regarding the associated technical risks. Which of the following is MOST important to include in this communication plan?

Options:

A.

A link on the corporate intranet to the BYOD policy

B.

Potential exposures and impacts using common terms

C.

Schedule and content for mandatory training

D.

Disciplinary actions for violation of the BYOD policy

Buy Now
Questions 198

An enterprise has launched a digitization effort requiring a single view of customer information across all product lines. Which of the following should be done FIRST to enable this initiative?

Options:

A.

Develop funding estimates for integrating applications

B.

Modify the future state enterprise architecture (EA)

C.

Assess the current data standards that are in use for applications

D.

Audit the infrastructure architecture for integration points

Buy Now
Questions 199

An enterprise recently experienced a major breach that was escalated effectively. However, the recovery took far longer than expected, resulting in significant financial loss. Which of the following is MOST likely the root cause of this scenario?

Options:

A.

Key performance indicators (KPIs) were not regularly monitored

B.

The recovery point objective (RPO) was not established

C.

The disaster recovery plan (DRP) was not routinely updated

D.

The business continuity plan (BCP) was not recently tested

Buy Now
Questions 200

Which of the following should a new CIO do FIRST to set the strategic direction for IT?

Options:

A.

Develop well-defined business cases that include strategic outcomes.

B.

Remap stakeholder analysis and desired expectations.

C.

Review existing enterprise strategic objectives.

D.

Redesign detailed RACI charts of the IT function.

Buy Now
Questions 201

A healthcare enterprise is procuring Internet of Things (IoT) devices to be used across its facilities. Which of the following is MOST important to establish before vendors are engaged to provide the devices?

Options:

A.

Product compliance criteria

B.

Patient training

C.

Physical security audits

D.

Vendor delivery timelines

Buy Now
Questions 202

When establishing a comprehensive approach for analyzing IT risk in an international, multi-division enterprise, it is MOST important to ensure:

Options:

A.

Risk management methodologies are aligned with local best practices.

B.

IT senior managers perform the analysis.

C.

Risk scenarios are compartmentalized by division.

D.

A consistent risk management methodology is used.

Buy Now
Questions 203

Which of the following BEST enables an enterprise to minimize the risks of intellectual property theft and loss of sensitive information when acquiring Internet of Things (IoT) hardware and software components?

Options:

A.

Review the data classification policy and relevant documentation

B.

Terminate contracts with suppliers from sanctioned regions of the world

C.

Require nondisclosure agreements (NDAs) from all suppliers

D.

Integrate supply chain cyber risk management processes

Buy Now
Questions 204

Which of the following is the BEST way to address the risk associated with new IT investments?

Options:

A.

Develop security best practices to protect applications.

B.

Integrate security requirements at the beginning of projects

C.

Establish an enterprise-wide incident response process.

D.

Implement an enterprise-wide security awareness program.

Buy Now
Questions 205

Upcoming IT-related regulations carry costly penalties for an enterprise. The issuing regulatory agency has a history of weak enforcement. The IT steering committee should FIRST direct management to:

Options:

A.

Develop mitigation plans for noncompliance.

B.

Update the enterprise architecture (EA).

C.

Evaluate the impact of the emerging risk.

D.

Perform benchmarking activities.

Buy Now
Questions 206

ACIO determines IT investment management processes are not fully realizing the benefits identified in business cases. Which of the following would be the BEST way to prevent this issue?

Options:

A.

Establish a requirement for ClO review and approval of each business case.

B.

Evaluate the delegation of investment approval authorities.

C.

Perform stage-gate reviews throughout the life cycle of each project.

D.

Document lessons learned throughout the investment life cycle.

Buy Now
Questions 207

Which of the following is the PRIMARY consideration for an enterprise when deciding whether to adopt a qualitative risk assessment method?

The method identifies areas to immediately address vulnerabilities.

The method provides specific objective measurements of exposure.

The method enables an analysis Of recommended controls.

Options:

A.

The method provides a platform for all departments to contribute to the risk assessment.

Buy Now
Exam Code: CGEIT
Exam Name: Certified in the Governance of Enterprise IT Exam
Last Update: Apr 7, 2026
Questions: 692
CGEIT pdf

CGEIT PDF

$25.5  $84.99
CGEIT Engine

CGEIT Testing Engine

$30  $99.99
CGEIT PDF + Engine

CGEIT PDF + Testing Engine

$40.5  $134.99