Summer Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtreat

CGEIT Certified in the Governance of Enterprise IT Exam Questions and Answers

Questions 4

An enterprise has an ongoing issue of corporate applications not delivering the expected benefits due to missing key functionality. As a result, many groups are using spreadsheets and databases instead of approved enterprise applications to store and manipulate information. Which of the following will BEST improve the success rate of future IT initiatives?

Options:

A.

Engage the business user community in acceptance testing Of acquired applications.

B.

Engage stakeholders to identify and validate business requirements.

C.

Establish a process for risk and value management.

D.

Prohibit the use of non-approved alternate software solutions.

Buy Now
Questions 5

After experiencing poor recovery times following a catastrophic event, an enterprise is seeking to improve its disaster recovery capabilities. Which of the following would BEST enable the enterprise to accomplish this objective?

Options:

A.

Continuous testing of disaster recovery capabilities with implementation of lessons learned

B.

Increased training and monitoring for disaster recovery personnel who perform below expectations

C.

Annual review and updates to the disaster recovery plan (DRP)

D.

Increased outsourcing of disaster recovery capabilities to ensure reliability

Buy Now
Questions 6

Which of the following should be the MOST essential consideration when outsourcing IT services?

Options:

A.

Identification of core and non-core business processes.

B.

Compliance with enterprise architecture (EA).

C.

Alignment with existing human resources (HR) policies and practices.

D.

Adoption of a diverse vendor selection process.

Buy Now
Questions 7

Which of the following is the BEST way to manage the risk associated with outsourcing critical IT services?

Options:

A.

Ensure vendors hold information security certifications.

B.

Define controls within service level agreements (SLAs).

C.

Conduct quarterly performance reviews.

D.

Ensure exit clauses are added to the contract.

Buy Now
Questions 8

Which of the following BEST enables effective enterprise risk management (ERM)?

Options:

A.

Risk register

B.

Risk ownership

C.

Risk tolerance

D.

Risk training

Buy Now
Questions 9

Which of the following is the BEST way for a CIO to provide senior business management with increased visibility to the overall performance of the IT operation?

Options:

A.

Develop key risk indicators (KRIs).

B.

Provide return on investment (ROI) reports.

C.

Develop key performance indicators (KPIs).

D.

Provide service level agreement (SLA) performance statistics.

Buy Now
Questions 10

An enterprise is considering outsourcing non-core IT processes. Which of the following should be the FIRST step?

Options:

A.

Update resource allocation policies.

B.

Issue a formal request for proposal (RFP) to outsourcing vendors.

C.

Establish service-level metrics for outsourced activities.

D.

Conduct a cost-benefit analysis for outsourcing.

Buy Now
Questions 11

Which of the following is the MOST important reason that IT strategic planning processes need to be adequately documented and communicated?

Options:

A.

To justify spending on IT projects

B.

To promote transparency to stakeholders

C.

To ensure other departments are aligned with the direction set by IT

D.

To inform business units of IT department achievements

Buy Now
Questions 12

An enterprise's current business continuity plan (BCP) fails to consider many common crisis events. What would be MOST helpful to address this situation?

Options:

A.

Engage stakeholders in scenario development

B.

Review the root cause analysis

C.

Require further walk-through tests

D.

Review and update the crisis communication plan

Buy Now
Questions 13

Which of the following should be the PRIMARY consideration when developing an IT strategy for the global implementation of Internet of Things (IoT) solutions?

Options:

A.

Hiring additional IT staff with IoT expertise

B.

Addressing security and privacy

C.

Identifying cost-effective IoT devices

D.

Maintaining compatibility with legacy systems

Buy Now
Questions 14

Which of the following BEST supports an IT staff restructure as part of an annual IT strategy review with senior management?

Options:

A.

Established IT key performance indicators (KPIs)

B.

IT staff training program requirements

C.

External IT staffing benchmarks

D.

An updated business case for IT resourcing

Buy Now
Questions 15

An enterprise wants to implement metrics to monitor the performance of its IT portfolio. Whose input is MOST important to consider when establishing these metrics?

Options:

A.

Project management office (PMO).

B.

IT executives.

C.

The chief executive officer (CEO).

D.

Business unit stakeholders.

Buy Now
Questions 16

Forensic analysis revealed an attempted breach of a personnel database containing sensitive data. A subsequent investigation found that no one within the enterprise was aware of the breach attempt, even though logs recorded the unauthorized access actions. To prevent a similar situation in the future, what is MOST important for IT governance to require?

Options:

A.

Periodic analyses of logs and databases for unusual activity

B.

A review of the information security and risk management frameworks

C.

The creation of a comprehensive data management and storage policy

D.

The implementation of an intrusion detection and reporting process

Buy Now
Questions 17

What should be the FIRST action of a new CIO when considering an IT governance framework for an enterprise?

Options:

A.

Develop an IT balanced scorecard to monitor and track IT performance.

B.

Verify stakeholder sponsorship of the IT governance initiative.

C.

Understand corporate culture and IT’s role in providing business value.

D.

Understand critical IT processes to define the scope of the IT governance framework.

Buy Now
Questions 18

An ongoing project is on track according to project plan. However, a recent regulation change will have a major impact to the project. The project sponsor's NEXT step should be to:

Options:

A.

Seek exemption from the appropriate regulatory body

B.

Perform an impact analysis and update the business case

C.

Submit the project to the IT steering committee for reapproval

D.

Rescope the project to remove work impacted by the regulation

Buy Now
Questions 19

Which of the following is MOST likely to have a negative impact on

accountability for information risk ownership?

Options:

A.

The risk owner is a department manager, and the control owner is a member of the risk owner's staff.

B.

Information risk is assigned to a department, and an individual owner has not been assigned.

C.

The risk owner and the control owner of the information do not work in the same department.

D.

The same person is listed as both the control owner and the risk owner for the information.

Buy Now
Questions 20

An enterprise has launched a critical new IT initiative that is expected to produce substantial value. Which of the following would BEST facilitate the reporting of benefits realized by the IT investment to the board?

Options:

A.

Balanced scorecard

B.

Milestone chart

C.

Performance management

D.

Critical risk and issue walk through

Buy Now
Questions 21

An organization requires updates to their IT infrastructure to meet business needs. Which of the following will provide the MOST useful information when planning for the necessary IT investments?

Options:

A.

Enterprise architecture (EA)

B.

Risk assessment report

C.

Business user satisfaction metrics

D.

Audit findings

Buy Now
Questions 22

A small enterprise has just hired its first CIO, who has been tasked with making the IT department more efficient. What should be the CIO's NEXT step after identifying several new improvement initiatives?

Options:

A.

Mandate IT staff training.

B.

Request an IT balanced scorecard.

C.

Require a cost-benefit analysis.

D.

Allocate funding for the initiatives.

Buy Now
Questions 23

What should be the FIRST action of a new CIO when considering an IT governance framework for an enterprise?

Options:

A.

Understand corporate culture and IT'S role in providing business value.

B.

Understand critical IT processes to define the scope of the IT governance framework.

C.

Verify stakeholder sponsorship of the IT governance initiative.

D.

Develop an IT balanced scorecard to monitor and track IT performance.

Buy Now
Questions 24

Which of the following would be MOST helpful to review when determining how to allocate IT resources during a resource shortage?

Options:

A.

IT strategic plan

B.

IT skills inventory

C.

IT organizational structure

D.

IT skill development plan

Buy Now
Questions 25

To help ensure the IT portfolio provides maximum value to an organization, IT projects are BEST prioritized based on:

cost-benefit analysis results.

alignment with business strategy.

Options:

A.

recommendation Of business owners.

B.

alignment with IT architecture.

Buy Now
Questions 26

The board of an organization has been informed of possible cyberthreats. Which of the following should be the board’s NEXT course of action?

Options:

A.

Evaluate the security incident response process

B.

Reevaluate the risk tolerance of the organization

C.

Ask the CIO to report on a risk response

D.

Engage the CIO to evaluate the risk

Buy Now
Questions 27

Which of the following is the PRIMARY role of the governance function in enabling an enterprise to achieve its business objectives?

Options:

A.

Determining risk thresholds that the enterprise can sustain

B.

Preparing business continuity and resiliency plans

C.

Providing a means to effectively manage stakeholders

D.

Monitoring strategic plans to reach the desired target state

Buy Now
Questions 28

Which of the following provides an enterprise with the BEST understanding of the value proposition for employing a new cloud service?

Options:

A.

Key risk indicators (KRIs).

B.

Service level agreements (SLAs).

C.

Return on investment (ROI).

D.

Customer satisfaction surveys.

Buy Now
Questions 29

Business management is seeking assurance from the CIO that IT has a plan in place for early identification of potential issues that could impact the delivery of a new application. Which of the following is the BEST way to increase the chances of a successful delivery?

Options:

A.

Implement a release and deployment plan

B.

Ask the application owner to update the risk register

C.

Create a baseline configuration of the new application

D.

Perform user acceptance testing (UAT)

Buy Now
Questions 30

Which of the following would be the BEST way for an enterprise to address new legal and regulatory requirements applicable to IT?

Options:

A.

Treat as a risk to be assessed before developing a response.

B.

Benchmark how other IT organizations are treating the new requirements.

C.

Adopt a zero-tolerance approach for noncompliance with regulatory matters.

D.

Use a cost-benefit analysis to determine if compliance is warranted.

Buy Now
Questions 31

A publicly traded enterprise wants to demonstrate that its board of directors is providing adequate strategic oversight of IT. Which of the following BEST supports this objective?

Options:

A.

Annual IT governance communication to all staff.

B.

Press releases targeted at large investors.

C.

Inclusion of IT governance reporting in the annual report.

D.

Annual presentation of IT performance metrics.

Buy Now
Questions 32

An enterprise is assessing whether to utilize wearable technology. The enterprise has no prior experience with this technology and has asked the chief technology officer (CTO) to assess the impact to the enterprise. The CTO should FIRST:

Options:

A.

understand the enterprise’s risk tolerance.

B.

create an IT risk scorecard.

C.

prioritize wearable technology risk.

Buy Now
Questions 33

ACIO determines IT investment management processes are not fully realizing the benefits identified in business cases. Which of the following would be the BEST way to prevent this issue?

Options:

A.

Establish a requirement for ClO review and approval of each business case.

B.

Evaluate the delegation of investment approval authorities.

C.

Perform stage-gate reviews throughout the life cycle of each project.

D.

Document lessons learned throughout the investment life cycle.

Buy Now
Questions 34

Which of the following is necessary for effective risk management in IT governance?

Options:

A.

Risk evaluation is embedded in the management processes.

B.

IT risk management is separate from enterprise risk management (ERM).

C.

Local managers are solely responsible for risk evaluation.

D.

Risk management strategy is approved by the audit committee.

Buy Now
Questions 35

Which of the following would be an IT steering committee's BEST course of action upon learning business units have been independently procuring cloud services?

Options:

A.

Require cancellation of cloud-based application services not vetted by IT leadership.

B.

Include business unit leadership in the enterprise architecture (EA) review board.

C.

Limit cloud-based application service usage to open source solutions.

D.

Define a procurement strategy based on business unit needs.

Buy Now
Questions 36

A regulatory audit of an IT department has identified discrepancies between processes described in the procedures and what is actually done by system administrators.

The discrepancies were caused by recent IT application changes. Which of the following would be the BEST way to prevent the recurrence of similar findings in the future?

Options:

A.

Assign the responsibility for periodic revisions and changes to process owners.

B.

Require each IT employee to confirm compliance with IT procedures on an annual basis.

C.

Include the update of documentation within the change management framework.

D.

Establish high-level procedures to minimize process changes.

Buy Now
Questions 37

Which of the following is the MOST important consideration regarding IT measures as part of an IT strategic plan?

Options:

A.

Data collection for the metrics is automated.

B.

The metrics can be traced to enterprise goals.

C.

Minimum target levels are realistic.

D.

Thresholds align to key risk indicators (KRIs).

Buy Now
Questions 38

A CIO engages a consulting firm to conduct a benchmark analysis of the organization’s IT governance framework against industry best practices. Several recommendations to improve the maturity of the framework are identified. Which of the following should be the CIO's NEXT course of action?

Options:

A.

Develop a plan to integrate the recommendations

B.

Appoint a project manager to implement the recommendations

C.

Obtain approval from the IT steering committee to implement the recommendations

D.

Evaluate the feasibility of the recommendations

Buy Now
Questions 39

A CIO was notified that a new employee was observed wearing a headset with an optical lens at the organization's data center. The individual was entering voice commands into the device. When approached, the employee explained the device is a new personal technology serving as a hands-free version of a smart phone. The CIO is concerned with potential security vulnerabilities of allowing such devices, and whether they should be banned from the facility. What should be the NEXT course of action in response to the ClO's concern?

Options:

A.

Define a risk mitigation strategy.

B.

Update the acceptable use policy.

C.

Research competitor usage of similar devices.

D.

Assess the risk associated with the device.

Buy Now
Questions 40

An enterprise recently implemented a significant change in its business strategy by moving to a technologically advanced product with considerable impact on the business. What should be the FINAL step in completing the changes to IT processes?

Options:

A.

Updating the configuration management database (CMDB)

B.

Empowering the business to embrace the changes

C.

Ensuring a return to stabilized business operations

D.

Updating the enterprise architecture (EA)

Buy Now
Questions 41

Which of the following is the BEST indication of an effective information governance model?

Options:

A.

Senior management ensures quality goals are defined for information.

B.

The CIO defines information accountability, quality criteria, and criticality.

C.

Enterprise architects define information protection attributes.

D.

Process owners determine which information assets will be managed.

Buy Now
Questions 42

What is the BEST way for IT to achieve compliance with regulatory requirements?

Options:

A.

Enforce IT policies and procedures.

B.

Create an IT project portfolio.

C.

Review an IT performance dashboard.

D.

Report on IT audit findings and action plans.

Buy Now
Questions 43

An enterprise plans to implement a business intelligence tool with data sources from various enterprise applications. Which of the following is the GREATEST challenge to implementation?

Options:

A.

Interface issues between enterprise and business intelligence applications.

B.

The need for staff to be trained on the new business intelligence tool.

C.

Large volumes of data fed from enterprise applications.

D.

Data definition and mapping sources from applications.

Buy Now
Questions 44

An enterprise's IT department has been operating independently without regard to business concerns, leading to misalignment between business and IT. The BEST way to establish alignment would be to require:

Options:

A.

business to help define IT goals.

B.

business to fund IT services.

C.

IT to define business objectives.

D.

IT and business to define risks.

Buy Now
Questions 45

Which of the following is the PRIMARY objective of a data protection impact assessment?

Options:

A.

To identify and analyze how data privacy might be affected by business processes.

B.

To evaluate the quality and integrity of personal data stored in an enterprise.

C.

To estimate the value created by personal data as it progresses through its life cycle.

D.

To ensure key business processes and related data interfaces are documented.

Buy Now
Questions 46

A CIO has recently been made aware of a new regulatory requirement that may affect IT-enabled business activities. Which of the following should be the CIO s FIRST step in deciding the appropriate response to the new requirement?

Options:

A.

Revise initiatives that are active to reflect the new requirements.

B.

Confirm there are adequate resources to mitigate compliance requirements.

C.

Consult with legal and risk experts to understand the requirements.

D.

Consult with the board for guidance on the new requirements

Buy Now
Questions 47

A newly appointed CIO is concerned that IT is too reactive and wants to ensure IT adds value to the enterprise by proactively anticipating business needs. Which of the following will BEST contribute to meeting this objective?

Options:

A.

Incorporating IT planning into the enterprise strategic planning process

B.

Implementing an IT portfolio management framework

C.

Involving more IT representation in strategic business case reviews

D.

Including IT management within the program management office

Buy Now
Questions 48

A large enterprise is implementing an information security policy exception process. The BEST way to ensure that security risk is properly addressed is to:

confirm process owners' acceptance of residual risk.

perform an internal and external network penetration test.

obtain IT security approval on security policy exceptions.

Options:

A.

benchmark policy against industry best practice.

Buy Now
Questions 49

A global organization has noticed a significant decrease in the return on IT investments in a particular region. To enhance project governance in this region, the CEO should FIRST

Options:

A.

Perform a program benefit calculation and review the project selection methodology

B.

Suspend funding until project managers from better-performing regions can be assigned

C.

Perform an independent review of business cases for each current and proposed project in the region

D.

Work with the region's leadership to better understand why the situation has occurred

Buy Now
Questions 50

Which of the following BEST enables an enterprise to determine whether a current program for IT infrastructure migration to the cloud is continuing to provide benefits?

Options:

A.

Key performance indicators (KPls)

B.

Total cost of ownership (TCO)

C.

Key risk indicators (KRIS)

D.

Net present value (NPV)

Buy Now
Questions 51

An enterprise recently approved a bring your own device (BYOD) policy. The IT steering committee has directed IT management to develop a communication plan to disseminate information regarding the associated technical risks. Which of the following is MOST important to include in this communication plan?

Options:

A.

A link on the corporate intranet to the BYOD policy

B.

Potential exposures and impacts using common terms

C.

Schedule and content for mandatory training

D.

Disciplinary actions for violation of the BYOD policy

Buy Now
Questions 52

As a result of a new regulatory requirement, an enterprise’s board has mandated that steps be taken to ensure related IT governance activities are performing as originally designed and are continuously improved. Which of the following is the BEST approach?

Options:

A.

Mandate ongoing enterprise risk and control self-assessments (CSAs)

B.

Conduct quarterly reviews of the enterprise business architecture

C.

Engage periodic external audit reviews of IT governance processes

D.

Require annual mapping of key IT governance processes

Buy Now
Questions 53

Which of the following is the GREATEST driver of ethical decision making in an IT enterprise?

Options:

A.

Corporate culture

B.

Process and control environment

C.

Code of conduct

D.

Training and awareness programs

Buy Now
Questions 54

Which of the following roles is accountable for the confidentiality, integrity, and availability of information within an enterprise?

Options:

A.

Data owner

B.

Lead legal counsel

C.

Risk manager

D.

Data custodian

Buy Now
Questions 55

The BEST way for a CIO to manage the organizational impact of deploying a new enterprise-wide tool is to implement:

Options:

A.

change management.

B.

project management.

C.

risk management.

D.

resource management.

Buy Now
Questions 56

When selecting a cloud provider, which of the following provides the MOST comprehensive information regarding the current status and effectiveness of the provider's controls?

Options:

A.

Globally recognized certification

B.

Third-party audit report

C.

Control self-assessment (CSA)

D.

Maturity assessment

Buy Now
Questions 57

Which of the following is the FIRST step when developing an IT risk management framework?

Options:

A.

Promoting a culture of risk awareness

B.

Establishing a risk control library

C.

Aligning to enterprise risk management (ERM)

D.

Establishing risk appetite

Buy Now
Questions 58

A series of cyber events impacting internet-facing business services has been successfully contained. To minimize future business risk exposure, which of the following should the board require of the IT team?

Options:

A.

Review the internet service provider (ISP) contract.

B.

Purchase cybersecurity insurance.

C.

Conduct a business impact analysis (BIA).

D.

Perform a root cause analysis.

Buy Now
Questions 59

Which of the following is the MOST effective way to manage risks within the enterprise?

Options:

A.

Assign individuals responsibilities and accountabilities for management of risks.

B.

Make staff aware of the risks in their area and risk management techniques.

C.

Provide financial resources for risk management systems.

D.

Document procedures and reporting processes.

Buy Now
Questions 60

Which of the following groups should approve the implementation of new technology?

Options:

A.

IT steering committee

B.

IT audit department

C.

Portfolio management office

D.

Program management office

Buy Now
Questions 61

An enterprise has a large backlog of IT projects. The current strategy is to execute projects as they are submitted, but executive management does not believe this method is optimal. Which of the following is the MOST important action to address this concern?

Options:

A.

Implement stage-gating to determine the value of each project.

B.

Establish a performance dashboard that determines business value.

C.

Implement a methodology to prioritize projects based on resource availability.

D.

Create a combined business/IT committee to determine project prioritization.

Buy Now
Questions 62

Which of the following is the MOST effective way of assessing enterprise risk?

Options:

A.

Business impact analysis (BIA)

B.

Business vulnerability assessment

C.

Likelihood of threat analysis

D.

Operational risk assessment

Buy Now
Questions 63

An IT audit report indicates that a lack of IT employee risk awareness is creating serious security issues in application design and configuration. Which of the following would be the BEST key risk indicator (KRI) to show progress in IT employee behavior?

Options:

A.

Number of IT employees attending security training sessions

B.

Results of application security testing

C.

Number of reported security incidents

D.

Results of application security awareness training quizzes

Buy Now
Questions 64

An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?

Options:

A.

Authenticating access to information assets based on roles or business rules.

B.

Implementing multi-factor authentication controls

C.

Granting access to information based on information architecture

D.

Engaging an audit of logical access controls and related security policies

Buy Now
Questions 65

Prior to decommissioning an IT system, it is MOST important to:

Options:

A.

assess compliance with environmental regulations.

B.

assess compliance with the retention policy.

C.

review the media disposal records.

D.

review the data sanitation records.

Buy Now
Questions 66

Which of the following BEST reflects the ethical values adopted by an IT organization?

Options:

A.

IT principles and policies

B.

IT balanced scorecard

C.

IT governance framework

D.

IT goals and objectives

Buy Now
Questions 67

An enterprise is planning a change in business direction. As a result, IT risk will significantly increase. Which of the following should be the GO'S FIRST course of action?

Options:

A.

Recommend delaying the business change.

B.

Implement IT changes to align with the plan.

C.

Report the risk to executive management

D.

Plan for the corresponding IT reorganization.

Buy Now
Questions 68

An enterprise made a significant change to its business operating model that resulted in a new strategic direction. Which of the following should be reviewed FIRST to ensure IT congruence with the new business strategy?

Options:

A.

IT risk appetite

B.

Enterprise project management framework

C.

IT investment portfolio

D.

Information systems architecture

Buy Now
Questions 69

A CIO believes that a recent mission-critical IT decision by the board of directors is not in the best financial interest of all stakeholders. Which of the following is the MOST ethical course of action?

Options:

A.

Share concerns with the legal department.

B.

Request a meeting with the board.

C.

Engage an independent cost-benefit analysis.

D.

Request an internal audit review of the board's decision.

Buy Now
Questions 70

An organization's board of directors has questioned the value provided by IT key performance indicators (KPIs). Which of the following is the BEST way to determine whether the KPIs adequately support organizational objectives?

Options:

A.

Define a strategy for IT measurement.

B.

Define policies and procedures around current KPIs.

C.

Review the KPIs with key business executives.

D.

Work directly with the CEO to identify what measures should be used.

Buy Now
Questions 71

When determining the optimal IT service levels to support business, which of the following is MOST important?

Options:

A.

IT capacity utilization and availability.

B.

Cost/benefit to the business.

C.

Available IT budget.

D.

Business user requests

Buy Now
Questions 72

Which of the following is the MOST effective approach to ensure senior management sponsorship of IT risk management?

Options:

A.

Benchmark risk framework against best practices.

B.

Calculate financial impact for each IT risk finding.

C.

Periodically review the IT risk register entries.

D.

Integrate IT risk into enterprise risk management (ERM).

Buy Now
Questions 73

An IT director has become aware that a certain subset of data collected lawfully can be used to generate additional revenue. However, this particular use of the data is outside the original intention. What is the PRIMARY reason this situation should be escalated to the IT steering committee?

Options:

A.

Potential legal penalties

B.

Ethical concerns

C.

Regulatory requirements

D.

Data protection

Buy Now
Questions 74

Which of the following responsibilities should be retained within an enterprise when outsourcing a project management office (PMO) function?

Options:

A.

Selecting projects

B.

Managing projects

C.

Tracking project cost

D.

Defining project methodology

Buy Now
Questions 75

A board of directors wants to ensure the enterprise is responsive to changes in its environment that would directly impact critical business processes. Which of the following will BEST facilitate meeting this objective?

Options:

A.

Scheduling frequent threat analyses

B.

Monitoring key risk indicators (KRIs)

C.

Regularly reviewing the enterprise risk appetite

D.

Implementing a competitive intelligence tool

Buy Now
Questions 76

Which of the following should be the MOST important consideration when defining an information architecture?

Options:

A.

Frequency and quantity of information updates

B.

Information to justify business cases

C.

Incorporation of emerging technologies

D.

Access to and exchange of information

Buy Now
Questions 77

Which of the following would provide the BEST input for prioritizing strategic IT improvement initiatives?

Options:

A.

Business dependency assessment

B.

Business process analysis

C.

Business case evaluation

D.

Business impact analysis (BIA)

Buy Now
Questions 78

In a large enterprise, which of the following is the MOST effective way to understand the business activities associated with the enterprise's information architecture?

Options:

A.

Reviewing IT design with business process managers

B.

Reviewing business strategy with senior management

C.

Mapping business processes within a framework

D.

Aligning business objectives to organizational strategy

Buy Now
Questions 79

Due to continually missed service level agreements (SLAs), an enterprise plans to terminate its contract with a vendor providing IT help desk services. The enterprise s IT department willassume the help desk-related responsibilities. Which of the following would BEST facilitate this transition?

Options:

A.

Requiring the enterprise architecture (EA) be updated

B.

Validating that the balanced scorecard is still meaningful

C.

Ensuring IT will operate at a lower cost than the vendor

D.

Ensuring a change management plan is in place

Buy Now
Questions 80

Which of the following is the GREATEST impact to an enterprise that has ineffective information architecture?

Options:

A.

Poor desktop service delivery

B.

Data retention

C.

Redundant systems

D.

Poor business decisions

Buy Now
Questions 81

From a governance perspective, which of the following roles is MOST important for an enterprise to keep in-house?

Options:

A.

Information auditor

B.

Information architect

C.

Information steward

D.

Information analyst

Buy Now
Questions 82

Senior management wants to promote investment in IT, but is uncertain that associated risks are being properly identified. The BEST way to address this concern is to:

Options:

A.

engage an external consultant to develop risk scenarios.

B.

appoint an IT representative to the business risk committee.

C.

assign an IT cost controller to the finance department.

D.

ensure business cases are developed by IT.

Buy Now
Questions 83

When evaluating benefits realization of IT process performance, the analysis MUST be based on;

Options:

A.

key business objectives.

B.

industry standard key performance indicators (KPIs).

C.

portfolio prioritization criteria.

D.

IT risk policies.

Buy Now
Questions 84

A chief technology officer (CTO) wants to ensure IT governance practices adequately address risk management specific to mobile applications. To create the appropriate risk policies for IT, it is MOST important for the CTO to:

Options:

A.

understand the enterprise's risk tolerance.

B.

create an IT risk scorecard.

C.

map the business goals to IT risk processes.

D.

identify the mobile technical requirements.

Buy Now
Questions 85

The board of directors of an enterprise has approved a three-year IT strategic program to centralize the core business processes of its global entities into one core system. Which of the following should be the ClO's NEXT step?

Options:

A.

Engage a team to perform a business impact analysis (BIA).

B.

Require the development of a risk management plan.

C.

Determine resource requirements for program implementation.

D.

Require the development of a program roadmap.

Buy Now
Questions 86

Which of the following is PRIMARILY achieved through performance measurement?

Options:

A.

Process improvement

B.

Transparency

C.

Cost efficiency

D.

Benefit realization

Buy Now
Questions 87

An enterprise considering implementing IT governance should FIRST develop the scope of the IT governance program and:

Options:

A.

initiate the program using an implementation roadmap.

B.

establish initiatives for business and managers.

C.

acquire the resources that will be required.

D.

communicate the program to stakeholders to gain consensus.

Buy Now
Questions 88

Before an IT strategy committee can approve an IT risk assessment framework, which of the following is MOST important to have established?

Options:

A.

An enterprise risk mitigation strategy

B.

Leading and lagging risk indicators

C.

IT performance metrics and standards

D.

Enterprise definitions for risk impact and probability

Buy Now
Questions 89

What is the PRIMARY objective for performing an IT due diligence review prior to the acquisition of a competitor?

Options:

A.

Document the competitor's governance structure.

B.

Ensure that the competitor understands significant IT risks.

C.

Assess the status of the risk profile of the competitor.

D.

Determine whether the competitor is using industry-accepted practices.

Buy Now
Questions 90

Which of the following is the PRIMARY ongoing responsibility of the IT governance function related to risk?

Options:

A.

Responding to and controlling all IT risk events

B.

Communicating the enterprise risk management plan

C.

Ensuring IT risk management is aligned with business risk appetite

D.

Verifying that all business units have staff skilled at assessing risk

Buy Now
Questions 91

Which of the following is the BEST course of action to enable effective resource management?

Options:

A.

Conduct an enterprise risk assessment.

B.

Implement a cross-training program.

C.

Assign resources based on business priorities.

D.

Assign resources based on risk appetite.

Buy Now
Questions 92

The CIO in a large enterprise is seeking assurance that significant IT risk is being proactively monitored and does not exceed agreed risk tolerance levels. The BEST way to provide this ongoing assurance is to require the development of:

Options:

A.

an IT risk appetite statement.

B.

a risk management policy.

C.

key risk indicators (KRIs).

D.

a risk register.

Buy Now
Questions 93

The board of directors has mandated the use of geolocation software to track mobile assets assigned to employees who travel outside of their home country. To comply with this mandate, the IT steering committee should FIRST request

Options:

A.

the inclusion of mandatory training for remote device users.

B.

an architectural review to determine appropriate solution design.

C.

an assessment to determine if data privacy protection is addressed.

D.

an update to the acceptable use policy.

Buy Now
Questions 94

Which of the following is the BEST way for a CIO to secure support for a strategy to achieve long-term IT objectives?

Options:

A.

Make the necessary strategic decisions and notify staff accordingly.

B.

Develop tactics to implement the strategy and share with stakeholders.

C.

Develop a communication plan for distribution of information to staff.

D.

Meet with stakeholders to explain the strategy and incorporate feedback.

Buy Now
Questions 95

An enterprise has a zero-tolerance policy regarding security. This policy is causing a large number of email attachments to be blocked and is a disruption to enterprise. Which of the following should be the FIRST governance step to address this email issue?

Options:

A.

Direct the development of an email usage policy.

B.

Obtain senior management input based on identified risk.

C.

Recommend business sign-off on the zero-tolerance policy.

D.

Introduce an exception process.

Buy Now
Questions 96

Which of the following is the BEST way to ensure new systems can be adequately supported once in production?

Options:

A.

Establish a resource management framework.

B.

Evaluate the operational requirements of the business stakeholders.

C.

Identify key performance indicators (KPIs).

D.

Require operational management be identified in the business case.

Buy Now
Questions 97

A new and expanding enterprise has recently received a report indicating 90% of its data has been collected in just the last six months, triggering data breach and privacy concerns. What should be the IT steering committee's FIRST course of action to ensure new data is managed effectively?

Options:

A.

Mitigate and track data-related issues and risks.

B.

Modify legal and regulatory data requirements.

C.

Define data protection and privacy practices.

D.

Assess the information governance framework.

Buy Now
Questions 98

Results of an enterprise's customer survey indicate customers prefer using mobile applications. However, this same survey shows the enterprise's mobile applications are considered inferior compared to legacy browser-based applications. Which of the following should be the FIRST step in creating an effective long-term mobile application strategy?

Options:

A.

Establish service level agreements (SLAs) with the development team.

B.

Identify key risks and mitigation strategies for mobile applications.

C.

Implement key performance indicators (KPIs) that include application quality.

D.

Identify business requirements concerning mobile applications.

Buy Now
Questions 99

The board and senior management of a new enterprise recently met to formalize an IT governance framework. The board of directors' FIRST step in implementing IT governance is to ensure that:

Options:

A.

an IT balanced scorecard is implemented.

B.

a portfolio of IT-enabled investments is developed.

C.

IT roles and responsibilities are established.

D.

IT policies and procedures are defined.

Buy Now
Questions 100

Which of the following is an ADVANTAGE of using strategy mapping?

Options:

A.

It provides effective indicators of productivity and growth.

B.

It depicts the maturity levels of processes that support organizational strategy.

C.

It identifies barriers to strategic alignment and links them to specific outcomes.

D.

It depicts the cause-and-effect linked relationships between strategic objectives.

Buy Now
Questions 101

A large enterprise that is diversifying its business will be transitioning to a new software platform, which is expected to cause data changes. Which of the following should be done FIRST when developing the related metadata management process?

Options:

A.

Require an update to enterprise data policies.

B.

Request an impact analysis.

C.

Review documented data interdependence.

D.

Validate against existing architecture.

Buy Now
Questions 102

An enterprise considers implementing a system that uses a technology that is not in line with its IT strategy. The business case indicates significant benefit to the enterprise. Which of the following is the BEST way to manage this situation within an IT governance framework?

Options:

A.

Update the IT strategy to align with the new technology.

B.

Initiate an operational change request.

C.

Reject based on non-alignment.

D.

Address as part of an architecture exception process.

Buy Now
Questions 103

An enterprise has decided to create its first mobile application. The IT director is concerned about the potential impact of this initiative. Which of the following is the MOST important input for managing the risk associated with this initiative?

Options:

A.

Enterprise architecture (EA)

B.

IT risk scorecard

C.

Enterprise risk appetite

D.

Business requirements

Buy Now
Questions 104

A CIO has been asked to modify an organization's IT performance measurement system to reflect recent changes in technology, including the movement of some data processing to a cloud solution. Which of the following is the PRIMARY consideration when designing such a measurement system?

Options:

A.

Ensuring that cost of measurement and reporting is minimized

B.

Ensuring the measurement system maps to the enterprise architecture (EA)

C.

Adequately defining the scope of services moved to the cloud

D.

Correctly understanding stakeholder needs for IT-related measurement

Buy Now
Questions 105

The PRIMARY benefit of integrating IT resource planning into enterprise strategic planning is that it enables the enterprise to:

Options:

A.

allocate resources efficiently to achieve desired goals.

B.

adjust business goals depending upon resource availability.

C.

prioritize resource allocation based on sourcing strategy.

D.

develop tactical plans to achieve resource optimization.

Buy Now
Questions 106

Which of the following are PRIMARY factors in ensuring the success of an enterprise quality assurance program?

Options:

A.

Enterprise risk appetite and tolerance

B.

Risk management and control frameworks

C.

Continuous improvement plans

D.

A process maturity framework and documented procedures

Buy Now
Questions 107

Which of the following is the BEST way to ensure the continued usefulness of IT governance reports for stakeholders?

Options:

A.

Conduct quarterly audits and adjust reporting based on findings.

B.

Establish a standard process for providing feedback.

C.

Rely on IT leaders to advise when adjustments should be made.

D.

Issue frequent service level satisfaction surveys.

Buy Now
Questions 108

A large financial institution is considering outsourcing customer call center operations which will allow the chosen vendor to access systems from offshore locations. Which of the following represents the GREATEST risk?

Options:

A.

Inconsistent customer service and reporting

B.

Loss of data confidentiality

C.

Lack of network availability

D.

Inadequate business continuity planning

Buy Now
Questions 109

When a shortfall of IT resources is identified, the FIRST course of action is to;

Options:

A.

perform a business impact analysis (BIA).

B.

reallocate the budget to close the gap in resources.

C.

reduce business requirements.

D.

negotiate best pricing for contracted resources.

Buy Now
Questions 110

A CIO must determine if IT staff have adequate skills to deliver on key strategic objectives. Which of the following will provide the MOST useful information?

Options:

A.

Employee performance metrics

B.

Project risk reports

C.

Gap analysis results

D.

Training program statistics

Buy Now
Questions 111

The BEST way to ensure an IT steering committee meets enterprise objectives is to:

Options:

A.

require a member of the committee to have IT governance expertise.

B.

benchmark against industry best practices.

C.

establish key performance indicators (KPIs).

D.

have key business stakeholders represented on the committee.

Buy Now
Questions 112

Which of the following represents the GREATEST challenge to implementing IT governance?

Options:

A.

Determining the best practice to follow

B.

Planning the project itself

C.

Developing a business case

D.

Applying behavioral change management

Buy Now
Questions 113

Which of the following is the BEST way to demonstrate that IT strategy supports a new enterprise strategy?

Options:

A.

Monitor new key risk indicators (KRIs).

B.

Measure return on IT investments against balanced scorecards.

C.

Review and update the portfolio management process.

D.

Map IT programs to business goals.

Buy Now
Questions 114

A CEO determines the enterprise is lagging behind its competitors in consumer mobile offerings, and mandates an aggressive rollout of several new mobile services within the next 12 months. To ensure the IT organization is capable of supporting this business objective, what should the CIO do FIRST?

Options:

A.

Request an assessment of current in-house mobile technology skills.

B.

Create a sense of urgency with the IT team that mobile knowledge is mandatory.

C.

Procure contractors with experience in mobile application development.

D.

Task direct reports with creating training plans for their teams.

Buy Now
Questions 115

Which of the following MOST effectively prevents an IT system from becoming technologically obsolete before its planned return on investment (ROi)?

Options:

A.

Requesting periodic third-party assessments of the system throughout its life

B.

Obtaining long-term support commitments from the system platform vendors)

C.

Obtaining independent assurance that the system will conform to future business requirements

D.

Ensuring that the system is maintained in compliance with enterprise architecture (EA) standards

Buy Now
Questions 116

The PRIMARY reason for an enterprise to adopt an IT governance framework is to:

Options:

A.

assure IT sustains and extends the enterprise strategies and objectives.

B.

expedite IT investments among other competing business investments.

C.

establish IT initiatives focused on the business strategy.

D.

allow IT to optimize confidentiality, integrity, and availability of information assets.

Buy Now
Questions 117

Which of the following is MOST important to effectively initiate IT-enabled change?

Options:

A.

Establish a change management process.

B.

Obtain top management support and ownership.

C.

Ensure compliance with corporate policy.

D.

Benchmark against best practices.

Buy Now
Questions 118

An enterprise decides to accept the IT risk of a subsidiary located in another country even though it exceeds the enterprise's risk appetite. Which of the following would be the BEST justification for this decision?

Options:

A.

Risk framework alignment

B.

Local market common practices

C.

Compliance with local regulations

D.

Technical gaps among subsidiaries

Buy Now
Questions 119

A manufacturing company has recently decided to outsource portions of its IT operations. Which of the following would BEST justify this decision?

Options:

A.

Core legacy systems are not fully integrated with enterprise IT systems.

B.

Business users are not able to decide upon IT service levels to be provided.

C.

Increasing complexity of core business and IT processes have led to dramatic increasing costs.

D.

The business strategy requires significant IT resource scalability over the next five years.

Buy Now
Questions 120

A CEO is concerned that IT costs have significantly exceeded budget without resulting benefits. The root causes are an overlap of IT projects and a lack of alignment with business demands. Which of the following would BEST enable remediation of this situation?

Options:

A.

Require IT business cases be approved by the board of directors.

B.

Assign a set of key risk indicators (KRIs) to each new IT project.

C.

Conduct a performance assessment of IT projects.

D.

Implement an IT portfolio management policy.

Buy Now
Questions 121

Enterprise IT has overseen the implementation of an array of data services with overlapping functionality leading to business inefficiencies. Which of the following is the MOST likely cause of this situation?

Options:

A.

insufficient information architecture

B.

Ineffective project management

C.

An outdated service level agreement (SLA)

D.

An incomplete cost-benefit analysis

Buy Now
Questions 122

A strategic IT-enabled investment is failing due to unforeseen technology problems. What should be the board of directors' FIRST course of action?

Options:

A.

Terminate the investment.

B.

Assess the business risk and options.

C.

Approve an investment budget increase.

D.

Revise the investment selection process.

Buy Now
Questions 123

Which of the following MOST effectively demonstrates operational readiness to address information security risk issues?

Options:

A.

Executive management has announced an information security risk initiative.

B.

IT management has communicated the need for information security risk management to the business.

C.

A policy has been communicated stating enterprise commitment and readiness to address information security risk.

D.

Procedures have been established for assessing and mitigating information security risks.

Buy Now
Questions 124

Which of the following activities MUST be completed before developing an IT strategic plan?

Options:

A.

Review the enterprise business plan

B.

Align the enterprise vision statement with business processes

C.

Develop an enterprise architecture (EA) framework

D.

Review the enterprise risk tolerance level

Buy Now
Questions 125

When developing an IT strategic plan that supports an enterprise's business goals which of the following should be done FIRST?

Options:

A.

Ensure that IT drives business goals

B.

Analyze benchmarking data

C.

Understand the current vision

D.

Perform a business impact analysis (BIA)

Buy Now
Questions 126

An internal audit revealed a widespread perception that the enterprise's IT governance reporting lacks transparency Which of the following should the CIO do FIRST?

Options:

A.

Add stakeholder transparency metrics to the balanced scorecard

B.

Develop a communication and awareness strategy

C.

Meet with key stakeholders to understand their concerns

D.

Adopt an industry-recognized template to standardize reports.

Buy Now
Questions 127

Which of the following is the BEST way to maximize the value of an enterprise’s information asset base?

Options:

A.

Seek additional opportunities to leverage existing information assets.

B.

Facilitate widespread user access to all information assets

C.

Regularly purge information assets to minimize maintenance costs

D.

Implement an automated information management platform

Buy Now
Questions 128

An enterprise has developed a new digital strategy to improve fraud detection. Which of the following is MOST important to consider when updating the information architecture?

Options:

A.

Resource constraints related to implementing the digital strategy.

B.

The business use cases supporting the digital strategy

C.

Changes to the legacy business and data architectures

D.

The history of fraud incidents and their root causes

Buy Now
Questions 129

An enterprise has learned of a new regulation that may impact delivery of one of its core technology services Which of the following should the done FIRST?

Options:

A.

Update the risk management framework

B.

Determine whether the board wants to comply with the regulation

C.

Assess the risk associated with the new regulation

D.

Request an action plan from the risk team

Buy Now
Questions 130

Which of the following is the PRIMARY responsibility of a data steward?

Options:

A.

Ensuring the appropriate users have access to the right data

B.

Developing policies for data governance

C.

Reporting data analysis to the board

D.

Classifying and labeling organizational data assets

Buy Now
Questions 131

The CIO of an international enterprise is considering the use of an offshore cloud service provider to store customer data. Which of the following should be the MOST important consideration when making this decision?

Options:

A.

IT service delivery roles and responsibilities

B.

Compliance with applicable legislation

C.

Likelihood of natural disasters

D.

The cloud service provider's reputation

Buy Now
Questions 132

An airline wants to launch a new program involving the use of artificial intelligence (Al) and machine learning the mam objective of the program is to use customer behavior to determine new routes and markets Which of the following should be done NEXT?

Options:

A.

Consult with the enterprise privacy function

B.

Define the critical success factors (CSFs)

C.

Present the proposal to the IT strategy committee

D.

Perform a business impact analysis (BIA)

Buy Now
Questions 133

Which of the following is MOST important for an IT strategy committee to ensure before initiating the development of an IT strategic plan?

Options:

A.

Committee members are apprised of business needs

B.

A risk assessment has been conducted.

C.

Committee members are independent from business units.

D.

IT initiatives are fully supported by the business.

Buy Now
Questions 134

An enterprise is planning a transformation initiative by leveraging emerging technology that will have a significant impact on existing products and services Which of the following is the BEST way for IT to prepare for this change?

Options:

A.

Use a balanced scorecard to measure IT outcomes.

B.

Analyze emerging technology products and related training needs.

C.

Procure appropriate resources to support emerging technology

D.

Assess the impact on the existing IT strategy

Buy Now
Questions 135

An enterprise has decided to implement an enterprise resource planning (ERP) system to achieve operating and cost efficiencies through global IT standardization. The business units are resistant because they are used to operating autonomously. The CEO has instructed the CIO to move quickly with the implementation to force acceptance with business unit leaders. Which of the following should be the ClO's FIRST step?

Options:

A.

Build a governance framework for identifying non-standard processes.

B.

Request funding from the CEO to hire ERP consultants.

C.

Ask the CEO to be the sponsor of the program

D.

Engage a reluctant business unit to conduct a proof-of-concept pilot.

Buy Now
Questions 136

Business management is seeking assurance from the CIO that controls are in place to help minimize the risk of critical IT systems being unavailable during month-end financial processing. What is the BEST way to address this concern?

Options:

A.

Create a communication plan with risk owners.

B.

Outsource infrastructure hosting.

C.

Restrict and monitor user access.

D.

Develop key risk indicators (KRIs) and action plans.

Buy Now
Questions 137

Which of the following is MOST important to consider when monitoring the performance of IT resources?

Options:

A.

Business impact analysis (BIA)

B.

End-user feedback

C.

Centralized log analysis

D.

Service level requirements

Buy Now
Questions 138

Despite an adequate training budget. IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?

Options:

A.

Provide incentives for IT staff to attend outside conferences and training

B.

Create a standard-setting center of excellence for IT.

C.

Require human resources (HR) to recruit new talent using an established IT skills matrix.

D.

Establish an agreed-upon skills development plan with each employee

Buy Now
Questions 139

Which of the following is the BEST approach to ensure global regulatory compliance when implementing a new business process?

Options:

A.

Use a balanced scorecard to track the business process.

B.

Ensure the appropriate involvement Of the legal department.

C.

Review and revise the business architecture.

D.

Seek approval from the change management board.

Buy Now
Questions 140

Which of the following is the BEST way to address the risk associated with new IT investments?

Options:

A.

Develop security best practices to protect applications.

B.

Integrate security requirements at the beginning of projects

C.

Establish an enterprise-wide incident response process.

D.

Implement an enterprise-wide security awareness program.

Buy Now
Questions 141

Which of the following is the BEST way for an IT steering committee to monitor the adoption of a new enterprise IT strategy?

Options:

A.

Implement service level agreements (SLAs).

B.

Establish key performance indicators (KPIs).

C.

Schedule ongoing audit reviews.

D.

Establish key risk indicators (KRIs).

Buy Now
Questions 142

Which of the following is the BEST indicator of the effectiveness of IT governance in an enterprise?

Options:

A.

Value delivery

B.

Resource utilization

C.

Residual risk

D.

Project delivery

Buy Now
Questions 143

Which of the following is the FIRST consideration for a CISO when implementing Zero Trust architecture?

Options:

A.

Refining relevant business goals.

B.

Limiting the number of privileged accounts.

C.

Selecting a security framework that is relevant to the business.

D.

Defining security projects to address identified control gaps.

Buy Now
Questions 144

An interna! health organization has been notified that a data breach has resulted in patient records being published online. Which of the

following is MOST important consideration when determining the process for meeting the organization's legal and regulatory obligations?

Options:

A.

Organizational structure, including accountable partes

B.

Data classification and related security policy

C.

Context of the breach, including data ownership and location

D.

Details of how the breach occurred and related incident response efforts

Buy Now
Questions 145

Which of the following should a CIO review to obtain a holistic view of IT performance when identifying potential gaps in service delivery?

Options:

A.

Key performance indicators (KPIs)

B.

Return on investment (ROI) analysis

C.

Service level agreement (SLA) reporting

D.

Staff performance evaluations

Buy Now
Questions 146

Which of the following would be MOST important to update if a decision is made to ban end user-owned devices in the workplace?

Options:

A.

Employee nondisclosure agreement

B.

Enterprise risk appetite statement

C.

Enterprise acceptable use policy

D.

Orientation training materials

Buy Now
Questions 147

Which of the following is the MOST effective means for IT management to report to executive management regarding the value of IT?

Options:

A.

IT process maturity level

B.

Cost-benefit analysis

C.

Resource assessment

D.

Balanced scorecard

Buy Now
Questions 148

When implementing an IT governance framework, which of the following would BEST ensure acceptance of the framework?

Options:

A.

Factoring in the effects of enterprise culture

B.

Using subject matter experts

C.

Using industry-accepted practices

D.

Complying with regulatory requirements

Buy Now
Questions 149

A global financial enterprise has been experiencing a substantial number of information security incidents that have directly affected its business reputation. Which of the following should be the IT governance board's FIRST course of action?

Options:

A.

Require revisions to how security incidents are managed by the IT department.

B.

Request an IT security assessment to identify the main security gaps.

C.

Execute an IT maturity assessment of the security process.

D.

Mandate an update to the enterprise's IT security policy.

Buy Now
Questions 150

Which of the following is the BEST way to implement effective IT risk management?

Options:

A.

Align with business risk management processes.

B.

Establish a risk management function.

C.

Minimize the number of IT risk management decision points.

D.

Adopt risk management processes.

Buy Now
Questions 151

An organization is evaluating vendors to provide mobile device management (MDM) services. Which of the following is a KEY governance consideration for the IT steering committee?

Options:

A.

Service level targets align with business requirements.

B.

Employee-owned devices will be covered by the service.

C.

The MDM services are delivered via a cloud.

D.

Technology-owned devices will be covered by the service

Buy Now
Questions 152

Which of the following BEST supports an enterprise's ability to comply with privacy laws and regulations?

Options:

A.

Complete inventory of enterprise data

B.

Implementation of a breach notification process

C.

Accurate classification of enterprise data

D.

Robust enterprise policy related to data retention

Buy Now
Questions 153

When selecting a vendor to provide services associated with a critical application which of the following is the MOST important consideration with respect to business continuity planning (BCP)?

Options:

A.

Procuring a copy of the vendor's BCP during the contracting process

B.

Testing the vendor's BCP and analyzing the results

C.

Obtaining independent audit reports of the vendor's BCP

D.

Evaluating whether the vendor's BCP aligns with the enterprise's BCP

Buy Now
Questions 154

A CEO wants to establish a governance framework to facilitate the alignment of IT and business strategies. Which of the following should be a KEY requirement of this framework?

Options:

A.

Defined resourcing levels

B.

A defined enterprise architecture (EA)

C.

An outsourcing strategy

D.

A service delivery Strategy

Buy Now
Questions 155

A newly hired IT director of a large international enterprise has been asked to provide periodic updates regarding IT risk to the board. Which of the following is the MOST effective way to initially address this request?

Options:

A.

Include a complete IT risk register in the monthly letter given to each board member.

B.

Include key IT risks in a dashboard submitted to the board quarterly.

C.

Submit a register of all IT audit findings to board members monthly.

D.

Schedule quarterly meetings to discuss all open IT risks.

Buy Now
Questions 156

An enterprise is planning to migrate its IT infrastructure to a cloud-based solution but does not have experience with this

technology Which of the following should be done FIRST to reduce the risk of IT service disruptions when using this new technology?

Options:

A.

Implement key performance indicators (KPIs).

B.

Reflect the change in the enterprise architecture (EA).

C.

Evaluate the sourcing options.

D.

Engage an experienced IT consultant to perform the migration.

Buy Now
Questions 157

Enterprise leadership is concerned with the potential for discrimination against certain demographic groups resulting from the use of machine learning models What should be done FIRST to address this concern?

Options:

A.

Obtain stakeholders' input regarding the ethics associated with machine learning

B.

Revise the code of conduct to discourage bias within automated processes

C.

Develop a machine learning policy articulating guidelines for machine learning use

D.

Assess recent case law related to the enterprise's machine learning business strategy

Buy Now
Questions 158

To enable the development of required IT skill sets for the enterprise, it is MOST important to define skill requirements based on:

Options:

A.

training needs.

B.

one set of skills applicable to all IT staff.

C.

a best practices framework.

D.

each role within the IT department.

Buy Now
Questions 159

The PRIMARY reason a CIO and IT senior management should stay aware of the business environment is to:

Options:

A.

revisit prioritization of IT projects.

B.

adjust IT strategy as needed.

C.

measure efficiency of IT resources.

D.

re-assess the IT investment portfolio.

Buy Now
Questions 160

The risk committee is overwhelmed by the number of false positives included in risk reports. What action would BEST address this situation?

Options:

A.

Conduct a risk assessment

B.

Evaluate key risk indicators (KRIs).

C.

Change the reporting format.

D.

Adjust the IT balanced scorecard

Buy Now
Questions 161

When updating an IT governance framework to support an outsourcing strategy, which of the following is MOST important?

Options:

A.

Evaluating the choice of underlying technology platforms used by the service provider

B.

Ensuring the outsource provider's IT function is aligned with its business function

C.

Verifying the vendor has developed standard operation procedures for outsourced functions

D.

Ensuring the effective management of contracts with third-party providers

Buy Now
Questions 162

In a successful enterprise that is profitable in its marketplace and consistently growing in size, the non-IT workforce has grown by 50% in the last two years. The demand for IT staff in the marketplace is more than the supply, and the enterprise is losing staff to rival organizations. Due to the rapid growth. IT has struggled to keep up with the enterprise, and IT procedures and associated job roles are not well-defined. The MOST critical activity for reducing the impact caused by IT staff turnover is to:

Options:

A.

document processes and procedures.

B.

outsource the IT operation.

C.

increase compensation for IT staff

D.

hire temporary staff.

Buy Now
Questions 163

Which of the following should be the PRIMARY governance objective for selecting key risk indicators (KRIs) related to legal and regulatory compliance?

Options:

A.

Identifying the risk of noncompliance

B.

Demonstrating sound risk management practices

C.

Measuring IT alignment with enterprise risk management (ERM)

D.

Ensuring the effectiveness of IT compliance controls

Buy Now
Questions 164

After shifting from lease to purchase of IT infrastructure and software licenses, an enterprise has to pay for unexpected lease extensions causing significant cost overruns. The BEST direction for the IT steering committee would be to establish;

Options:

A.

an end-of-life program to remove aging infrastructure from the environment.

B.

budget cuts to compensate for the cost overruns.

C.

a program to annually review financial policy on overruns.

D.

a policy to consider total cost of ownership (TCO) in investment decisions.

Buy Now
Questions 165

Which of the following should occur FIRST in the IT investment process?

Options:

A.

Assess each project's impact on the enterprise's investment plan.

B.

Select IT projects that will best support the enterprise's mission.

C.

Analyze IT investments based on past data.

D.

Analyze the risks and benefits of the investment for each IT project.

Buy Now
Questions 166

Which of the following should be the ClO's GREATEST consideration when making changes to the IT strategy'?

Options:

A.

Has the impact to the enterprise architecture (EA) been assessed?

B.

Has the investment portfolio been revised?

C.

Have key stakeholders been consulted?

D.

Have IT risk metrics been adjusted?

Buy Now
Questions 167

Of the following, who is PRIMARILY responsible for applying frameworks for the governance of IT to balance the need for security controls with business requirements?

Options:

A.

Data scientists

B.

Data stewards

C.

Data analysts

D.

Data processors

Buy Now
Questions 168

Which of the following BEST indicates the success of an enterprise's IT governance framework after implementation?

Options:

A.

A high percentage of business owners involved with the approval of the IT strategic plan

B.

A high percentage of IT systems complying with corporate information security standards

C.

A high percentage of IT projects delivered on time and on budget

D.

A high percentage of IT investments delivering expected benefits

Buy Now
Questions 169

Which of the following is the MOST significant challenge faced by an enterprise when establishing information stewardship?

Options:

A.

Lack of documented policies and procedures

B.

Information requirements of regulatory authorities

C.

Insufficient knowledge of IT practices and controls

D.

Lack of role clarity and specific responsibilities

Buy Now
Questions 170

Which of the following is the MOST important reason to include internal audit as a stakeholder when establishing clear roles for the governance of IT?

Options:

A.

Internal audit has knowledge and technical expertise to advise on IT infrastructure.

B.

Internal audit is accountable for the overall enterprise governance of IT.

C.

Internal audit implements controls over IT risks and security.

D.

Internal audit provides input on relevant issues and control processes.

Buy Now
Questions 171

Which of the following is the BEST indication that information security requirements are taken into consideration when developing IT processes?

Options:

A.

The database is deployed in a distributed processing platform

B.

The information architecture incorporates data classification

C.

Customer profiles are stored with a domestic service provider

D.

The integrity of sensitive information is periodically reviewed

Buy Now
Questions 172

Which of the following is MOST important to review during IT strategy development?

Options:

A.

Industry best practices

B.

IT balanced scorecard

C.

Current business environment

D.

Data flows that indicate areas requiring IT support

Buy Now
Questions 173

The BEST time to identity metrics to measure the performance of an IT-enabled investment is during:

Options:

A.

system implementation

B.

project initiation

C.

investment feasibility analysis

D.

business case development.

Buy Now
Questions 174

Which of the following BEST facilitates governance oversight of data protection measures?

Options:

A.

Information ownership

B.

Information classification

C.

Information custodianship

D.

Information life cycle management

Buy Now
Questions 175

Before establishing IT key nsk indicators (KRls) which of the following should be defined FIRST?

Options:

A.

IT resource strategy

B.

IT risk and security framework

C.

IT goals and objectives

D.

IT key performance indicators (KPIs)

Buy Now
Questions 176

Which of the following is the BEST justification for a procurement manager to agree to purchase IT equipment from a specific vendor during a sales promotion?

Options:

A.

The IT benefit surpasses the business benefit from the purchase.

B.

The equipment adds value to the enterprise.

C.

The business profit surpasses the IT cost for the equipment.

D.

The product is offered at the lowest price.

Buy Now
Questions 177

Which of the following should be the PRIMARY input when developing IT strategy?

Options:

A.

Vision statement

B.

Process and capability maturity

C.

Governance objectives

D.

Balanced scorecard

Buy Now
Questions 178

Which of the following is the BEST approach to assist an enterprise in planning for iT-enabled investments?

Options:

A.

Enterprise architecture (EA).

B.

IT process mapping

C.

Task management

D.

Service level management

Buy Now
Questions 179

What should be done FIRST when feedback indicates recently implemented software products are not meeting business unit expectations?

Options:

A.

Review help desk logs.

B.

Confirm user acceptance testing (UAT) was completed.

C.

Request a gap analysis.

D.

Institute a new software training program

Buy Now
Questions 180

An enterprise's chief information officer (CIO) has been receiving complaints from business executives regarding the amount their units are being charged for IT services. To maintain a good relationship with business peers, the CIO wants to be responsive to these complaints. To address this issue, the FIRST step should be to:

Options:

A.

agree to reduce charge rates and improve relationship management with the business.

B.

look into outsourcing of support functions to drive down the cost structure.

C.

ask the chief financial officer (CFO) about budget revisions for the business units' IT expenditures.

D.

quantify consumption and service level agreement (SLA) achievements per business unit.

Buy Now
Questions 181

Which of the following is the BEST way to ensure all enterprise employees understand the corporate code of business conduct?

Options:

A.

Conduct scheduled and random compliance audits.

B.

Mandate annual ethics training that includes an exam.

C.

Require external business activities be documented and reported.

D.

Distribute a copy of the code and require a signature.

Buy Now
Questions 182

IT security is concerned with employees' increasing use of personal equipment for work-related purposes, while employees claim it allows them to be more productive. A decision on whether to modify the enterprise information security policy should be based on:

Options:

A.

audit findings.

B.

user access approval procedures.

C.

the impact to security.

D.

a risk and benefit evaluation.

Buy Now
Questions 183

A large bank has completed several acquisitions in the last few years that have resulted in redundant IT applications. To align with the strategic initiative of providing integrated services to customers, the IT steering committee has decided to share data and integrate applications. Which of the following would be MOST important to review in this situation?

Options:

A.

Enterprise architecture (EA)

B.

IT risk register

C.

Balanced scorecard measures

D.

IT strategic plan

Buy Now
Questions 184

An IT steering committee is concerned that enterprise technologies have grown stagnant and are outdated. Which of the following is the BEST strategy to invest in modern technology?

Options:

A.

Decrease spending on steady state and increase spending on modernization and enhancements.

B.

Redefine the target architecture to define new technologies that can be incorporated into the infrastructure.

C.

Create a new investment category for innovation that becomes a new way for tracking investment decisions.

D.

Update the IT human resource management plan to require training and development for emerging technologies.

Buy Now
Questions 185

The PRIMARY reason for periodically evaluating IT resource staffing requirements is to:

Options:

A.

ascertain the IT function has sufficient skilled staff to maintain daily operations.

B.

ensure the enterprise has sufficient resources to address changing business and IT needs.

C.

verify that human resource recruitment and retention processes meet enterprise IT objectives.

D.

confirm IT-related responsibilities are defined for the enterprise's business and IT staff.

Buy Now
Questions 186

Which of the following aspects of IT governance BEST addresses the potential intellectual property implications of a cloud service provider having a database in another country?

Options:

A.

Contract management

B.

Continuity planning

C.

Data management

D.

Security architecture

Buy Now
Questions 187

A CIO of an enterprise is concerned that IT and the business have different priorities. Which of the following would BEST demonstrate the current state of strategic alignment?

Options:

A.

IT maturity model

B.

Business case

C.

Balanced scorecard

D.

IT investment status

Buy Now
Questions 188

The CIO of a large enterprise has taken the necessary steps to align IT objectives with business objectives. What is the BEST way for the CIO to ensure these objectives are delivered effectively by IT staff?

Options:

A.

Map the IT objectives to an industry-accepted framework.

B.

Enhance Ihe budget for training based on the IT objectives.

C.

Include the IT objectives in staff performance plans.

D.

Include CIO sign-off of the objectives as part of the IT strategic plan.

Buy Now
Questions 189

An enterprise's decision to move to a virtualized architecture will have the GREATEST impact on:

Options:

A.

system life cycle management.

B.

asset classification.

C.

vendor management

D.

vulnerability management.

Buy Now
Questions 190

Which of the following is the PRIMARY purpose of information governance?

Options:

A.

To develop control procedures that help ensure information is adequately protected throughout its life cycle

B.

To monitor the processes that deliver and enhance the value of information assets

C.

To set direction for information management capabilities through prioritization and decision making

D.

To ensure regulatory compliance is maintained while optimizing the utilization of information

Buy Now
Questions 191

Which of the following BEST supports enterprise decision making for IT resource allocation?

Options:

A.

IT-related regulatory requirements

B.

Enterprise IT strategy

C.

Enterprise IT risk assessment

D.

IT balanced scorecard

Buy Now
Questions 192

Which of the following should be done FIRST when defining responsibilities for ownership of information and systems?

Options:

A.

Require an information risk assessment.

B.

Identify systems that are outsourced.

C.

Ensure information is classified.

D.

Require an inventory of information assets.

Buy Now
Questions 193

An enterprise has entered into a new market which brings additional regulatory compliance requirements. What should be done FIRST to address these requirements?

Options:

A.

Outsource the compliance process.

B.

Appoint a compliance officer.

C.

Update the organization's risk profile.

D.

Have executive management monitor compliance.

Buy Now
Questions 194

Which of the following would be the MOST effective way to ensure IT capabilities are appropriately aligned with business requirements for specific business processes?

Options:

A.

Establishing key performance indicators {KPIs)

B.

Requiring Internal IT architecture and design reviews

C.

Requiring architecture and design reviews with business process stakeholders

D.

Issuing a management mandate that IT and business process stakeholders work together

Buy Now
Questions 195

An enterprise is approaching the escalation date of a major IT risk. The IT steering committee wants to ascertain who is responsible for the risk response. Where should the committee find this information?

Options:

A.

Resource management plan

B.

RACl chart

C.

Risk management plan

D.

Risk register

Buy Now
Questions 196

Which of the following roles should be responsible for data normalization when it is found that a new system includes duplicates of data items?

Options:

A.

Business system owner

B.

Data steward

C.

Database administrator (DBA)

D.

Application manager

Buy Now
Questions 197

The board of directors of a large organization has directed IT senior management to improve IT governance within the organization. IT senior management's MOST important course of action should be to:

Options:

A.

understand the driver that led to a desire to change.

B.

assess the current slate of IT governance within the organization.

C.

review IT strategy and direction.

D.

analyze IT service levels and performance.

Buy Now
Questions 198

Which of the following BEST demonstrates the effectiveness of enterprise IT governance?

Options:

A.

An IT balanced scorecard is used.

B.

Business objectives are achieved.

C.

Business objectives are defined.

D.

IT processes are measured.

Buy Now
Questions 199

Which of the following IT governance actions would be the BEST way to minimize the likelihood of IT failures jeopardizing the corporate value of an IT-dependent organization?

Options:

A.

Implement an IT risk management framework.

B.

Install an IT continuous monitoring solution.

C.

Define IT performance management measures.

D.

Benchmark IT strategy against industry peers.

Buy Now
Questions 200

As part of the implementation of IT governance, the board of an enterprise should establish an IT strategy committee to:

Options:

A.

provide input to and ensure alignment of the enterprise and IT strategies.

B.

ensure IT risks inherent in the enterprise strategy implementation are managed

C.

drive IT strategy development and take responsibility for implementing the IT strategy.

D.

assume governance accountability for the business strategy on behalf of the board

Buy Now
Questions 201

IT management has reported difficulty retaining qualified IT personnel to support the organization's new strategy Given that outsourcing is not a viable approach, which of the following would be the BEST way for IT governance to address this situation?

Options:

A.

Implement an incentive-based employee referral program

B.

Direct the development of a strategic HR plan for IT

C.

Recommend enhancements to the online recruiting platform specific to IT

D.

Work with HR to enhance compensation packages for IT personnel

Buy Now
Questions 202

Which of the following BEST enables an enterprise to determine how business expectations should be addressed in a governance program?

Options:

A.

Business impact analysis (BIA)

B.

Cost-benefit analysis

C.

Enterprise risk analysis

D.

Stakeholder analysis

Buy Now
Questions 203

The responsibility for the development of a business continuity plan (BCP) is BEST assigned to the:

Options:

A.

business risk manager.

B.

business owner.

C.

chief executive officer (CEO).

D.

IT systems owner.

Buy Now
Questions 204

An enterprise-wide strategic plan has been approved by the board of directors. Which of the following would BEST support the planning of IT investments required for the enterprise?

Options:

A.

Service-oriented architecture

B.

Enterprise architecture (EA)

C.

Contingency planning

D.

Enterprise balanced scorecard

Buy Now
Exam Code: CGEIT
Exam Name: Certified in the Governance of Enterprise IT Exam
Last Update: Jun 15, 2025
Questions: 682
CGEIT pdf

CGEIT PDF

$29.75  $84.99
CGEIT Engine

CGEIT Testing Engine

$35  $99.99
CGEIT PDF + Engine

CGEIT PDF + Testing Engine

$47.25  $134.99