Summer Special Sale Limited Time 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 713PS592

CGEIT Certified in the Governance of Enterprise IT Exam Questions and Answers

Questions 4

An enterprise plans to migrate its applications and data to an external cloud environment. Which of the following should be the ClO's PRIMARY focus before the migration?

Options:

A.

Reviewing the information governance framework

B.

Selecting best-of-breed cloud offerings

C.

Updates the enterprise architecture (EA) repository

D.

Conducting IT staff training to manage cloud workloads

Buy Now
Questions 5

A newly appointed CIO is concerned that IT is too reactive and wants to ensure IT adds value to the enterprise by proactively anticipating business needs. Which of the following will BEST contribute to meeting this objective?

Options:

A.

Incorporating IT planning into the enterprise strategic planning process

B.

Implementing an IT portfolio management framework

C.

Involving more IT representation in strategic business case reviews

D.

Including IT management within the program management office

Buy Now
Questions 6

When determining the desired maturity levels for IT governance processes, it is MOST important to:

Options:

A.

Focus on existing strengths as key drivers for the target levels

B.

Ensure target levels are in line with external competitor benchmarks

C.

Agree on target levels in response to need

D.

Ensure that maturity can be achieved at the lowest cost

Buy Now
Questions 7

Which of the following BEST enables an enterprise to minimize the risks of intellectual property theft and loss of sensitive information when acquiring Internet of Things (IoT) hardware and software components?

Options:

A.

Review the data classification policy and relevant documentation

B.

Terminate contracts with suppliers from sanctioned regions of the world

C.

Require nondisclosure agreements (NDAs) from all suppliers

D.

Integrate supply chain cyber risk management processes

Buy Now
Questions 8

Which of the following would BEST enable an enterprise to ensure selected cloud vendors meet stringent regulatory requirements?

Options:

A.

Stage gate reviews

B.

Risk assessment

C.

Internal audit report

D.

Third-party audit reports

Buy Now
Questions 9

Which of the following is the BEST way to minimize the potential mishandling of customer personal information in a system that is located in a country with strict privacy regulations?

Options:

A.

Revise IT policies, standards, and procedures

B.

Implement a SIEM solution

C.

Consult the legal and compliance department

D.

Establish new IT key risk indicators (KRIs)

Buy Now
Questions 10

The use of new technology in an enterprise will require specific expertise and updated system development processes. There is concern that IT is not properly sourced. Which of the following should be the FIRST course of action?

Options:

A.

Perform a risk assessment on potential outsourcing.

B.

Update the enterprise architecture (EA) with the new technology.

C.

Review the IT balanced scorecard for sourcing opportunities.

D.

Assess the gap between current and required staff competencies.

Buy Now
Questions 11

To reduce the risk of reputational damage through inappropriate use of social media by employees outside of the workplace, the enterprise approach regarding social media should PRIMARILY focus on;

Options:

A.

implementing preventative controls.

B.

developing policies on social media.

C.

implementing a review of processes utilizing social media.

D.

ensuring each use of social media is approved by management.

Buy Now
Questions 12

An enterprise recently implemented a significant change in its business strategy by moving to a technologically advanced product with considerable impact on the business. What should be the FINAL step in completing the changes to IT processes?

Options:

A.

Updating the configuration management database (CMDB)

B.

Empowering the business to embrace the changes

C.

Ensuring a return to stabilized business operations

D.

Updating the enterprise architecture (EA)

Buy Now
Questions 13

What should be the FIRST action of a new CIO when considering an IT governance framework for an enterprise?

Options:

A.

Develop an IT balanced scorecard to monitor and track IT performance.

B.

Verify stakeholder sponsorship of the IT governance initiative.

C.

Understand corporate culture and IT’s role in providing business value.

D.

Understand critical IT processes to define the scope of the IT governance framework.

Buy Now
Questions 14

An enterprise's internal audit group has scheduled a control review of a payroll system project but has been told to wait until the system is implemented. Which of the following is the GREATEST risk associated with the delay?

Options:

A.

delay in the development of new key performance indicators (KPIs)

B.

Continued dependency on compliant legacy systems

C.

Increased cost to mitigate deficiencies

D.

Lack of adherence to industry best practices

Buy Now
Questions 15

An enterprise made a significant change to its business operating model that resulted in a new strategic direction. Which of the following should be reviewed FIRST to ensure IT congruence with the new business strategy?

Options:

A.

IT risk appetite

B.

Enterprise project management framework

C.

IT investment portfolio

D.

Information systems architecture

Buy Now
Questions 16

When developing effective metrics for the measurement of solution delivery, it is MOST important to:

Options:

A.

establish project controls and monitoring objectives.

B.

perform an objective analysis of the project roadmap.

C.

establish the objectives and expected benefits.

D.

specify quantitative measures for solution delivery.

Buy Now
Questions 17

The PRIMARY reason for an enterprise to adopt an IT governance framework is to:

Options:

A.

assure IT sustains and extends the enterprise strategies and objectives.

B.

expedite IT investments among other competing business investments.

C.

establish IT initiatives focused on the business strategy.

D.

allow IT to optimize confidentiality, integrity, and availability of information assets.

Buy Now
Questions 18

An IT steering committee wants the enterprise's mobile workforce to use cloud-based file storage to save non-sensitive corporate data, removing the need for remote access to that information. Before this change is implemented, what should be included in the data management policy?

Options:

A.

A mandate for periodic employee training on how to classify corporate data files

B.

A mandate for the encryption of all corporate data files at rest that contain sensitive data

C.

A process for blocking access to cloud-based apps if inappropriate content is discovered

D.

A requirement to scan approved cloud-based apps for inappropriate content

Buy Now
Questions 19

Which of the following is the BEST method for determining an enterprise's current appetite for risk?

Options:

A.

Interviewing senior management

B.

Evaluating the balanced scorecard

C.

Reviewing recent audit findings

D.

Assessing social media adoption

Buy Now
Questions 20

An IT director is negotiating a contract with a vendor for application management services. There is concern by other departments that the outsourced services may not be delivered successfully. Which of the following is the BEST way for the IT director to address this concern?

Options:

A.

Implement a communication management plan.

B.

Develop a comprehensive vendor management plan.

C.

Review the IT service risk management plan.

D.

Establish a policy on operational level agreements with vendors.

Buy Now
Questions 21

The CIO in a large enterprise is seeking assurance that significant IT risk is being proactively monitored and does not exceed agreed risk tolerance levels. The BEST way to provide this ongoing assurance is to require the development of:

Options:

A.

an IT risk appetite statement.

B.

a risk management policy.

C.

key risk indicators (KRIs).

D.

a risk register.

Buy Now
Questions 22

An audit report has revealed that data scientists are analyzing sensitive "big data" files using an offsite cloud because corporate servers do not have the necessary processing capabilities. A review of policies indicates this practice is not prohibited. Which of the following should be the FIRST strategic action to address the report?

Options:

A.

Authorize a risk analysis of the practice.

B.

Update data governance practices.

C.

Revise the information security policy.

D.

Recommend the use of a private cloud.

Buy Now
Questions 23

An enterprise's CIO requires all IT processes within the enterprise to be clearly defined. Which of the following would be the MOST immediate outcome?

Options:

A.

Performance

B.

Repeatability

C.

Scalability

D.

Optimization

Buy Now
Questions 24

The board and senior management of a new enterprise recently met to formalize an IT governance framework. The board of directors' FIRST step in implementing IT governance is to ensure that:

Options:

A.

an IT balanced scorecard is implemented.

B.

a portfolio of IT-enabled investments is developed.

C.

IT roles and responsibilities are established.

D.

IT policies and procedures are defined.

Buy Now
Questions 25

An enterprise is initiating efforts to improve system availability to mitigate IT risk to the business. Which of the following results would be MOST important to report to the CIO to measure progress?

Options:

A.

Incident severity and downtime trend analysis

B.

Probability and seventy of each IT risk

C.

Financial losses and bad press releases

D.

Customer and stakeholder complaints over time

Buy Now
Questions 26

Two large financial institutions with different corporate cultures are engaged in a merger. From a governance perspective, which of the following should be the GREATEST concern?

Options:

A.

Technology infrastructure

B.

Risk appetite

C.

Combined cost of operations

D.

Enterprise architecture (EA) integration

Buy Now
Questions 27

Six months ago, an enterprise's CIO reorganized IT to improve service delivery to the business. Which of the following would BEST demonstrate the effectiveness of the reorganization?

Options:

A.

The number of help desk calls

B.

A balanced scorecard

C.

A survey of IT staff

D.

IT cost reduction

Buy Now
Questions 28

A global enterprise is experiencing an economic downturn and is rapidly losing market share. IT senior management is reassessing the core activities of the business, including IT, and the associated resource implications. Management has decided to focus on its local market and to close international operations. A critical issue from a resource management perspective is to retain the most capable staff. This is BEST achieved by:

Options:

A.

reviewing current goals-based performance appraisals across the enterprise.

B.

ranking employees across the enterprise based on their compensation.

C.

ranking employees across the enterprise based on length of service.

D.

retaining capable staff exclusively from the local market.

Buy Now
Questions 29

Which of the following represents the GREATEST challenge to implementing IT governance?

Options:

A.

Determining the best practice to follow

B.

Planning the project itself

C.

Developing a business case

D.

Applying behavioral change management

Buy Now
Questions 30

Which of the following groups should approve the implementation of new technology?

Options:

A.

IT steering committee

B.

IT audit department

C.

Portfolio management office

D.

Program management office

Buy Now
Questions 31

Which of the following is an ADVANTAGE of using strategy mapping?

Options:

A.

It provides effective indicators of productivity and growth.

B.

It depicts the maturity levels of processes that support organizational strategy.

C.

It identifies barriers to strategic alignment and links them to specific outcomes.

D.

It depicts the cause-and-effect linked relationships between strategic objectives.

Buy Now
Questions 32

A CEO determines the enterprise is lagging behind its competitors in consumer mobile offerings, and mandates an aggressive rollout of several new mobile services within the next 12 months. To ensure the IT organization is capable of supporting this business objective, what should the CIO do FIRST?

Options:

A.

Request an assessment of current in-house mobile technology skills.

B.

Create a sense of urgency with the IT team that mobile knowledge is mandatory.

C.

Procure contractors with experience in mobile application development.

D.

Task direct reports with creating training plans for their teams.

Buy Now
Questions 33

Which of the following is the MOST important benefit of developing an information architecture model consistent with enterprise strategy?

Options:

A.

It identifies information architecture priorities.

B.

It support and facilitates decision making.

C.

It enables information architecture roadmap updates.

D.

It optimizes information delivery and storage costs.

Buy Now
Questions 34

An enterprise is planning to replace multiple enterprise resource planning (ERP) systems at various regions with one company-wide ERP system. The main objective of this change is to achieve economies of scale efficiencies resulting in cost reductions. To meet this objective, what is the BEST approach in the planning phase of the project?

Options:

A.

Implement an ERP system on shared resources with the lowest cost.

B.

Minimize customization by standardizing ERP processes across regions.

C.

Adopt a best in breed web-based architecture for the ERP system.

D.

Use a service provider to evaluate and implement the new ERP processes.

Buy Now
Questions 35

IT has launched new portfolio management policies and processes to improve the alignment of IT projects with enterprise goals. The latest audit report indicates that no improvement has been made due to confusion in the decision-making process. Which of the following is the BEST course of action for the CIO?

Options:

A.

Deliver prioritization and facilitation training.

B.

Implement a performance management framework.

C.

Create an IT portfolio management risk framework.

D.

Develop and communicate an accountability matrix.

Buy Now
Questions 36

An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?

Options:

A.

Authenticating access to information assets based on roles or business rules.

B.

Implementing multi-factor authentication controls

C.

Granting access to information based on information architecture

D.

Engaging an audit of logical access controls and related security policies

Buy Now
Questions 37

The MOST successful IT performance metrics are those that:

Options:

A.

measure financial results.

B.

measure all areas.

C.

are approved by the stakeholders.

D.

contain objective measures.

Buy Now
Questions 38

An IT strategy committee wants to ensure that a risk program is successfully implemented throughout the enterprise. Which of the following would BEST support this goal?

Options:

A.

A risk management framework

B.

Mandatory risk awareness courses for staff

C.

A risk recognition and reporting policy

D.

Commitment from senior management

Buy Now
Questions 39

Senior management wants to promote investment in IT, but is uncertain that associated risks are being properly identified. The BEST way to address this concern is to:

Options:

A.

engage an external consultant to develop risk scenarios.

B.

appoint an IT representative to the business risk committee.

C.

assign an IT cost controller to the finance department.

D.

ensure business cases are developed by IT.

Buy Now
Questions 40

Which of the following should be the MOST important consideration when defining an information architecture?

Options:

A.

Frequency and quantity of information updates

B.

Information to justify business cases

C.

Incorporation of emerging technologies

D.

Access to and exchange of information

Buy Now
Questions 41

Which of the following would BEST help to improve an enterprise's ability to manage large IT investment projects?

Options:

A.

Creating a change management board

B.

Reviewing and evaluating existing business cases

C.

Implementing a review and approval process for each phase

D.

Publishing the IT approval process online for wider scrutiny

Buy Now
Questions 42

Which of the following is the PRIMARY ongoing responsibility of the IT governance function related to risk?

Options:

A.

Responding to and controlling all IT risk events

B.

Communicating the enterprise risk management plan

C.

Ensuring IT risk management is aligned with business risk appetite

D.

Verifying that all business units have staff skilled at assessing risk

Buy Now
Questions 43

An enterprise experiencing issues with data protection and least privilege is implementing enterprise-wide data encryption in response. Which of the following is the BEST approach to ensure all business units work toward remediating these issues?

Options:

A.

Develop key performance indicators (KPIs) to measure enterprise adoption.

B.

Integrate data encryption requirements into existing and planned projects.

C.

Assign owners for data governance initiatives.

D.

Mandate the creation of a data governance framework.

Buy Now
Questions 44

Which of the following is the MOST effective approach to ensure senior management sponsorship of IT risk management?

Options:

A.

Benchmark risk framework against best practices.

B.

Calculate financial impact for each IT risk finding.

C.

Periodically review the IT risk register entries.

D.

Integrate IT risk into enterprise risk management (ERM).

Buy Now
Questions 45

The BEST way to manage continuous improvement of governance-related processes is to:

Options:

A.

assess existing process resource capacities.

B.

define accountability based on roles and responsibilities.

C.

apply effective quality management practices.

D.

require third-party independent reviews.

Buy Now
Questions 46

An enterprise learns that a new privacy regulation was recently published to protect customers in the event of a breach involving personally identifiable information (Pll). The IT risk management team's FIRST course of action should be to:

Options:

A.

evaluate the risk appetite for the new regulation.

B.

define the risk tolerance for the new regulation.

C.

determine if the new regulation introduces new risk.

D.

assign a risk owner for the new regulation.

Buy Now
Questions 47

Which of the following is the MOST comprehensive method to report on overall IT performance to the board of directors?

Options:

A.

Balanced scorecard

B.

Net present value (NPV)

C.

Performance-based payments

D.

Return on investment (ROI)

Buy Now
Questions 48

A CIO must determine if IT staff have adequate skills to deliver on key strategic objectives. Which of the following will provide the MOST useful information?

Options:

A.

Employee performance metrics

B.

Project risk reports

C.

Gap analysis results

D.

Training program statistics

Buy Now
Questions 49

Which of the following is the MOST valuable input when quantifying the loss associated with a major risk event?

Options:

A.

Key risk indicators (KRIs)

B.

IT environment threat modeling

C.

Business impact analysis (BIA) report

D.

Recovery time objectives (RTOs)

Buy Now
Questions 50

Of the following, who should approve the criteria for information quality within an enterprise?

Options:

A.

Information architect

B.

Information analyst

C.

Information steward

D.

Information owner

Buy Now
Questions 51

An enterprise is planning a change in business direction. As a result, IT risk will significantly increase. Which of the following should be the GO'S FIRST course of action?

Options:

A.

Recommend delaying the business change.

B.

Implement IT changes to align with the plan.

C.

Report the risk to executive management

D.

Plan for the corresponding IT reorganization.

Buy Now
Questions 52

A marketing enterprise is considering procuring customer information to more accurately target customer communications and increase sales. The data has a very high cost to the enterprise. Which of the following would provide the MOST comprehensive view into the potential value to the organization?

Options:

A.

Investment services board review

B.

Net present value {NPV) calculation

C.

Risk assessment results

D.

Cost-benefit analysis results

Buy Now
Questions 53

Which of the following is the MOST effective way for a CIO to govern business unit deployment of shadow IT applications in a cloud environment?

Options:

A.

Implement controls to block the installation of unapproved applications.

B.

Educate the executive team about the risk associated with shadow IT applications.

C.

Provide training to the help desk to identify shadow IT applications.

D.

Review and update the application implementation process.

Buy Now
Questions 54

Which of the following BEST lowers costs and improves scalability from an IT enterprise architecture (EA) perspective?

Options:

A.

Cost management

B.

IT strategic sourcing

C.

Standardization

D.

Business agility

Buy Now
Questions 55

Prior to setting IT objectives, an enterprise MUST have established its:

Options:

A.

architecture.

B.

policies.

C.

strategies.

D.

controls.

Buy Now
Questions 56

The MOST important aspect of an IT governance framework to ensure that IT supports repeatable business processes is:

Options:

A.

earned value management.

B.

quality management,

C.

resource management.

D.

risk management

Buy Now
Questions 57

Enterprise IT has overseen the implementation of an array of data services with overlapping functionality leading to business inefficiencies. Which of the following is the MOST likely cause of this situation?

Options:

A.

insufficient information architecture

B.

Ineffective project management

C.

An outdated service level agreement (SLA)

D.

An incomplete cost-benefit analysis

Buy Now
Questions 58

An organization is evaluating vendors to provide mobile device management (MDM) services. Which of the following is a KEY governance consideration for the IT steering committee?

Options:

A.

Service level targets align with business requirements.

B.

Employee-owned devices will be covered by the service.

C.

The MDM services are delivered via a cloud.

D.

Technology-owned devices will be covered by the service

Buy Now
Questions 59

An IT strategy committee wants to ensure stakeholders understand who owns each strategic objective. To enable this understanding, which of the following should be communicated to stakeholders?

Options:

A.

A RACI chart

B.

The strategic plan

C.

Performance measure

D.

Risk owners

Buy Now
Questions 60

An IT risk committee is trying to mitigate the risk associated with a newly implemented bring your own device (BYOD) policy and supporting mobile device management (MDM) tools. Which of the following would be the BEST way to ensure employees understand how to protect sensitive corporate data on their mobile devices?

Options:

A.

Require staff to complete security awareness training

B.

Develop security procedures for mobile devices.

C.

Distribute the BYOD policy on the company Intranet.

D.

Require staff to review and sign nondisclosure agreements (NDAs)

Buy Now
Questions 61

To evaluate IT resource management, it is MOST important to define:

Options:

A.

responsibilities for executing resource management.

B.

applicable key goals.

C.

principles for the IT strategy.

D.

IT resource utilization reporting procedures.

Buy Now
Questions 62

Which of the following BEST demonstrates the effectiveness of enterprise IT governance?

Options:

A.

An IT balanced scorecard is used.

B.

Business objectives are achieved.

C.

Business objectives are defined.

D.

IT processes are measured.

Buy Now
Questions 63

Which of the following should be established FIRST so that data owners can consistently assess the level of data protection needed across the enterprise?

Options:

A.

Data encryption program

B.

Data risk management program

C.

Data retention policy

D.

Data classification policy

Buy Now
Questions 64

Due to the recent introduction of personal data protection regulations, an enterprise is required to maintain its employee data in production systems only for a limited time. Which of the following is MOST important to review?

Options:

A.

Asset retention policies

B.

Information retention policies

C.

Data archival policies

D.

Data backup and restoration policies

Buy Now
Questions 65

A multinational enterprise is planning to migrate to cloud-based systems. Which of the following should be of MOST concern to the risk management committee?

Options:

A.

Cost considerations

B.

Regulatory compliance

C.

Resource alignment

D.

Security breaches

Buy Now
Questions 66

Which of the following is the BEST approach when reviewing The security status of a new business acquisition?

Options:

A.

Embed IT risk management strategies in service level agreements (SLAs).

B.

Establish a committee to oversee the alignment of IT security in new businesses.

C.

Incorporate IT security objectives to cover additional risks associated with new businesses.

D.

Integrate IT risk assessment into the overall due diligence process.

Buy Now
Questions 67

Which of the following is the MOST significant challenge faced by an enterprise when establishing information stewardship?

Options:

A.

Lack of documented policies and procedures

B.

Information requirements of regulatory authorities

C.

Insufficient knowledge of IT practices and controls

D.

Lack of role clarity and specific responsibilities

Buy Now
Questions 68

A project sponsor has circumvented the request for proposal (RFP) selection process. Which of the following is the MOST likely reason for this control gap?

Options:

A.

Inadequate stage-gate reviews

B.

Inadequate board oversight

C.

Lack of accountability for policy adherence

D.

Lack of a legal and regulatory review process

Buy Now
Questions 69

To minimize the potential mishandling of customer personal information in a system located in a country with strict privacy regulations which of the following is the BEST action to take?

Options:

A.

Update the information architecture

B.

Revise the IT strategic plan

C.

Implement data loss prevention (DLP)

D.

Establish new IT key risk indicators (KRIs)

Buy Now
Questions 70

Which of the following should be management's GREATEST consideration when trying to optimize the use of benefits from IT?

Options:

A.

Value delivery

B.

Quality management

C.

Process improvement

D.

Alignment of business to IT

Buy Now
Questions 71

The PRIMARY reason for periodically evaluating IT resource staffing requirements is to:

Options:

A.

ascertain the IT function has sufficient skilled staff to maintain daily operations.

B.

ensure the enterprise has sufficient resources to address changing business and IT needs.

C.

verify that human resource recruitment and retention processes meet enterprise IT objectives.

D.

confirm IT-related responsibilities are defined for the enterprise's business and IT staff.

Buy Now
Questions 72

Which of the following should be the PRIMARY consideration for an enterprise when prioritizing IT projects?

Options:

A.

Technical capability of the enterprise to execute the projects

B.

Process owner expectations based on operational benefits

C.

Results of IT performance benchmarks against competitors

D.

Impact on the business due to expected project outcomes

Buy Now
Questions 73

Which of the following is the PRIMARY consideration when developing an information asset management program?

Options:

A.

Operational requirements

B.

Industry best practice

C.

Cost benefit

D.

Regulatory requirements

Buy Now
Questions 74

Reviewing which of the following should be the FIRST step when evaluating the possibility of outsourcing an IT system?

Options:

A.

Outsourcing strategy

B.

Outsourced business processes

C.

Service level agreements (SLAs)

D.

IT staff skill sets

Buy Now
Questions 75

An enterprise is trying to increase the maturity of its IT process from being ad hoc to being repeatable. Which of the following is the PRIMARY benefit of this change?

Options:

A.

Process optimization is embedded across the organization.

B.

Required outcomes are mapped to business objectives.

C.

Process performance is measured in business terms.

D.

Required outcomes are more frequently achieved.

Buy Now
Questions 76

Which of the following is the BEST way to address an IT audit finding that many enterprise application updates lack appropriate documentation?

Options:

A.

Enforce change control procedures.

B.

Conduct software quality audits

C.

Review the application development life cycle.

D.

Add change control to the risk register.

Buy Now
Questions 77

An IT department outsourced application support and negotiated service level agreements (SLAs) directly with the vendor Although the vendor met the SLAs business owner expectations are not met and senior management cancels the contract This situation can be avoided in the future by:

Options:

A.

improving the business requirements gathering process

B.

improving the negotiation process for service level agreements (SLAs)

C.

implementing a vendor performance scorecard

D.

assigning responsibility for vendor management

Buy Now
Questions 78

Which of the following should occur FIRST in the IT investment process?

Options:

A.

Assess each project's impact on the enterprise's investment plan.

B.

Select IT projects that will best support the enterprise's mission.

C.

Analyze IT investments based on past data.

D.

Analyze the risks and benefits of the investment for each IT project.

Buy Now
Questions 79

The PRIMARY objective of IT resource planning within an enterprise should be to:

Options:

A.

determine risk associated with IT resources.

B.

maximize value received from IT.

C.

determine IT outsourcing options.

D.

finalize service level agreements (SLAs) for IT

Buy Now
Questions 80

Following the rollout of an enterprise IT software solution that hosts sensitive data it was discovered that the application's role-based access control was not functioning as specified Which of the following is the BEST way to prevent reoccurrence in the future?

Options:

A.

Ensure supplier contracts include penalties if solutions do not meet functional requirements

B.

Ensure the evaluation process requires independent assessment of solutions prior to implementation

C.

Ensure supplier contracts include a provision for the right to audit on an annual basis

D.

Ensure procurement processes require the identification of alternate vendors to ensure business continuity.

Buy Now
Questions 81

Which of the following is the BEST outcome measure to determine the effectiveness of IT nsk management processes?

Options:

A.

Frequency of updates to the IT risk register

B.

Time lag between when IT risk is identified and the enterprise's response

C.

Number of events impacting business processes due to delays in responding to risks

D.

Percentage of business users satisfied with the quality of risk training

Buy Now
Questions 82

Which of the following BEST facilitates governance oversight of data protection measures?

Options:

A.

Information ownership

B.

Information classification

C.

Information custodianship

D.

Information life cycle management

Buy Now
Questions 83

Which of the following is the PRIMARY responsibility of a data steward?

Options:

A.

Ensuring the appropriate users have access to the right data

B.

Developing policies for data governance

C.

Reporting data analysis to the board

D.

Classifying and labeling organizational data assets

Buy Now
Questions 84

Which of the following roles should approve major IT purchases to help prevent conflicts of interest?

Options:

A.

IT steering committee

B.

Chief information officer (CIO)

C.

Chief compliance officer

D.

Project management office (PMO)

Buy Now
Questions 85

To successfully implement enterprise IT governance, which of the following should be the MAIN focus of IT policies?

Options:

A.

Providing business value

B.

Optimizing operational benefits

C.

Enhancing organizational capability

D.

Limiting IT costs

Buy Now
Questions 86

Which of the following BEST facilitates the standardization of IT vendor selection?

Options:

A.

Cost-benefit analysis

B.

Contract management office

C.

Service level agreements (SLAs)

D.

Procurement framework

Buy Now
Questions 87

To meet the growing demands of a newly established business unit, IT senior management has been tasked with changing the current IT organization model to

service-oriented. With significant growth expected of the IT organization, which of the following is the MOST important consideration when planning for long-term IT

service delivery?

Options:

A.

The IT service delivery model is approved by the business.

B.

An IT risk management process is in place.

C.

IT is able to provide a comprehensive service catalog to the business.

D.

The IT organization is able to sustain business requirements.

Buy Now
Questions 88

What is the BEST way for an IT governance board to establish standards of behavior for the adoption of artificial intelligence (Al)?

Options:

A.

Direct the creation and approval of an ethical use policy.

B.

Review and update the data privacy policy to align with industry standards.

C.

Include specific ethics clauses in vendor agreements and contracts.

D.

Include ethics topics within onboarding and awareness training.

Buy Now
Questions 89

Which of the following should IT governance mandate before any transition of data from a legacy system to a new technology platform?

Options:

A.

Data conversion has documented approvals from business process data owners.

B.

Data conversion is performed in a test environment to confirm correctness

C.

Control totals of key transaction values are matched with data converted for migration.

D.

A crisis management plan has been approved by the IT steering committee

Buy Now
Questions 90

An enterprise's executive team has recently released a new IT strategy and related objectives. Which of the following would be the MOST effective way for the CIO to ensure IT personnel are supporting the new strategy's objectives?

Options:

A.

Measure progress towards IT objectives and communicate the results to IT staff.

B.

Incorporate IT objectives into individual performance evaluations.

C.

Develop communication materials to promote the new IT strategy and objectives.

D.

Require IT managers to assign activities aligned to the IT objectives.

Buy Now
Questions 91

The CIO of a global technology company is considering introducing a bring your own device (BYOD) program. What should the CIO do FIRST?

Options:

A.

Ensure the infrastructure can meet BYOD requirements.

B.

Establish a business case.

C.

Define a clear and inclusive BYOD policy.

D.

Focus on securing data and access to data.

Buy Now
Questions 92

Which of the following is MOST important to document for a business ethics program?

Options:

A.

Guiding principles and best practices

B.

Violation response matrix

C.

Whistle-blower protection protocols.

D.

Employee awareness and training content

Buy Now
Questions 93

A CIO is concerned with the potential of vendor system failures that could cause a large amount of unintended system downtime. To determine how to prepare for this concern, what is MOST important for the CIO to review?

Options:

A.

IT balanced scorecard

B.

Service-level metrics

C.

IT procurement policy

D.

Business impact analysis (BIA)

Buy Now
Questions 94

Which of the following is (he GREATEST benefit of using the life cycle approach to govern information assets?

Options:

A.

Overall costs are optimized

B.

Operational costs are maintained

C.

Information availability is improved

D.

Compliance with regulatory requirements is ensured

Buy Now
Questions 95

Which of the following should be the PRIMARY governance objective for selecting key risk indicators (KRIs) related to legal and regulatory compliance?

Options:

A.

Identifying the risk of noncompliance

B.

Demonstrating sound risk management practices

C.

Measuring IT alignment with enterprise risk management (ERM)

D.

Ensuring the effectiveness of IT compliance controls

Buy Now
Questions 96

Which of the following decisions would be made by the IT strategy committee?

Options:

A.

Communication plan for a major IT initiative

B.

Cloud implementation and support plan

C.

Enterprise risk management (ERM) framework

D.

Composition of the investment portfolio

Buy Now
Questions 97

Individual business units within an enterprise have been designing their own IT solutions without consulting the IT department. From a governance perspective, what is the GREATEST issue associated with this situation?

Options:

A.

Security controls may not meet IT requirements.

B.

The enterprise does not have the skills to manage the solutions.

C.

The solutions conflict with IT goals and objectives.

D.

The solution may conflict with existing enterprise goals.

Buy Now
Questions 98

Enterprise leadership is concerned with the potential for discrimination against certain demographic groups resulting from the use of machine learning models What should be done FIRST to address this concern?

Options:

A.

Obtain stakeholders' input regarding the ethics associated with machine learning

B.

Revise the code of conduct to discourage bias within automated processes

C.

Develop a machine learning policy articulating guidelines for machine learning use

D.

Assess recent case law related to the enterprise's machine learning business strategy

Buy Now
Questions 99

Which of the following is the GREATEST benefit of using a quantitative risk assessment method?

Options:

A.

It uses resources more efficiently

B.

It can be used to assess risks against non-tangible assets

C.

It reduces subjectivity

D.

It helps in prioritizing risk response action plans

Buy Now
Questions 100

An enterprise has made the strategic decision to reduce operating costs for the next year and is taking advantage of cost reductions offered by an external cloud service provider. Which of the following should be the IT steering committee's PRIMARY concern?

Options:

A.

Calculating the cost of the current solution

B.

Updating the business risk profile

C.

Changing the IT steering committee charter

D.

Revising the business's balanced scorecard

Buy Now
Questions 101

A root-cause analysis indicates a major service disruption due to a lack of competency of newly hired IT system administrators. Who should be accountable for resolving the situation?

Options:

A.

HR training director

B.

HR recruitment manager

C.

Chief information officer

D.

(CIO) Business process owner

Buy Now
Questions 102

A large enterprise has decided to use an emerging technology that needs to be integrated with the current IT infrastructure. Which of the following is the BEST way to prevent adverse effects to the enterprise resulting from the new technology?

Options:

A.

Develop key performance indicators (KPIs).

B.

Update the risk appetite statement

C.

Develop key risk indicators (KRIs).

D.

Implement service level agreements (SLAs)

Buy Now
Questions 103

Which of the following is the BEST way to maximize the value of an enterprise’s information asset base?

Options:

A.

Seek additional opportunities to leverage existing information assets.

B.

Facilitate widespread user access to all information assets

C.

Regularly purge information assets to minimize maintenance costs

D.

Implement an automated information management platform

Buy Now
Questions 104

A CEO wants to establish a governance framework to facilitate the alignment of IT and business strategies. Which of the following should be a KEY requirement of this framework?

Options:

A.

Defined resourcing levels

B.

A defined enterprise architecture (EA)

C.

An outsourcing strategy

D.

A service delivery Strategy

Buy Now
Questions 105

Which of the following are the MOST important processes for information asset life cycle management?

Options:

A.

Procurement management and third-party management

B.

Configuration management and financial management

C.

Vulnerability management and network management

D.

Business continuity management and disaster recovery management

Buy Now
Questions 106

Which of the following would be MOST useful for prioritizing IT improvement initiatives to achieve desired business outcomes?

Options:

A.

Budget variance analysis

B.

Enterprise architecture (EA)

C.

IT skills matrix

D.

Portfolio management

Buy Now
Questions 107

Which of the following should be the PRIMARY goal of implementing service level agreements (SLAs) with an outsourcing vendor?

Options:

A.

Gaining a competitive advantage

B.

Establishing penalties for not meeting service levels

C.

Achieving operational objectives

D.

Complying with regulatory requirements

Buy Now
Questions 108

An enterprise's decision to move to a virtualized architecture will have the GREATEST impact on:

Options:

A.

system life cycle management.

B.

asset classification.

C.

vendor management

D.

vulnerability management.

Buy Now
Questions 109

An enterprise is planning a transformation initiative by leveraging emerging technology that will have a significant impact on existing products and services Which of the following is the BEST way for IT to prepare for this change?

Options:

A.

Use a balanced scorecard to measure IT outcomes.

B.

Analyze emerging technology products and related training needs.

C.

Procure appropriate resources to support emerging technology

D.

Assess the impact on the existing IT strategy

Buy Now
Questions 110

When developing an IT training plan, which of the following is the BEST way to ensure that resource skills requirements are identified?

Options:

A.

Extract training requirements from deficiencies reported in customer service satisfaction surveys.

B.

Ask managers to determine IT training requirements annually.

C.

Determine training needs based on the capabilities to support the IT strategy.

D.

Survey employees for IT skills requirements based upon technology trends.

Buy Now
Questions 111

Which of the following should be the PRIMARY input when developing IT strategy?

Options:

A.

Vision statement

B.

Process and capability maturity

C.

Governance objectives

D.

Balanced scorecard

Buy Now
Questions 112

An enterprise is conducting a SWOT analysis as part of IT strategy development. Which of the following would be MOST helpful to identify opportunities and threats?

Options:

A.

Risk appetite

B.

Internal framework assessment

C.

Competitor analysis

D.

Critical success factors (CSF)

Buy Now
Questions 113

Which of the following BEST indicates that a change management process has been implemented successfully?

Options:

A.

Maturity levels

B.

Degree of control

C.

Process performance

D.

Outcome measures

Buy Now
Questions 114

From an IT governance perspective, establishing performance measurements is PRIMARILY the responsibility of:

Options:

A.

the IT architecture review board.

B.

senior management.

C.

the board of directors.

D.

enterprise risk management (ERM).

Buy Now
Questions 115

An IT manager is trying to determine optimal IT service levels. Which of the following should be the PRIMARY consideration?

Options:

A.

Internal rate of return

B.

Recovery time objective (RTO)

C.

Cost-benefit analysis

D.

Resource utilization analysis

Buy Now
Questions 116

To ensure IT risk is managed in a consistent manner, it is MOST important for IT governance to establish a:

Options:

A.

risk management committee to identify IT-related risks.

B.

risk management framework.

C.

balanced scorecard that includes IT risks.

D.

risk management reporting tool to ensure compliance.

Buy Now
Questions 117

A CIO just received a final audit report that indicates there is inconsistent enforcement of the enterprise's mobile device acceptable use policy throughout all business units. Which of the following should be the FIRST step to address this issue?

Options:

A.

Incorporate compliance metrics into performance goals.

B.

Review the relevance of existing policy.

C.

Mandate awareness training for all mobile device users.

D.

Implement controls to enforce the policy.

Buy Now
Questions 118

Which of the following IT governance actions would be the BEST way to minimize the likelihood of IT failures jeopardizing the corporate value of an IT-dependent organization?

Options:

A.

Implement an IT risk management framework.

B.

Install an IT continuous monitoring solution.

C.

Define IT performance management measures.

D.

Benchmark IT strategy against industry peers.

Buy Now
Questions 119

Which of the following is the PRIMARY purpose of information governance?

Options:

A.

To develop control procedures that help ensure information is adequately protected throughout its life cycle

B.

To monitor the processes that deliver and enhance the value of information assets

C.

To set direction for information management capabilities through prioritization and decision making

D.

To ensure regulatory compliance is maintained while optimizing the utilization of information

Buy Now
Questions 120

An enterprise is developing an ethics program, and the ethical standards have been defined. Which of the following should the enterprise do NEXT?

Options:

A.

Establish a training and awareness program focused on ethics.

B.

Implement an enterprise-wide employee monitoring program.

C.

Develop key performance indicators (KPIs) for program implementation.

D.

Outline and document consequences for noncompliance.

Buy Now
Questions 121

When establishing an enterprise data model, the BEST way to ensure the integrity of data is to:

Options:

A.

classify information using an agreed-upon schema.

B.

implement the highest level of protection to data across the enterprise.

C.

establish a privileged access management platform.

D.

implement a data loss prevention (DLP) program.

Buy Now
Questions 122

Following a re-prioritization of business objectives by management, which of the following should be performed FIRST to allocate resources to IT processes?

Options:

A.

Perform a maturity assessment.

B.

Implement a RACI model.

C.

Refine the human resource management plan.

D.

Update the IT strategy.

Buy Now
Questions 123

A newly appointed CIO has issued a new IT strategic plan. Which of the following is the MOST effective way for the CIO to ensure the IT management team is held accountable for the delivery of the plan?

Options:

A.

Update the IT balanced scorecard with key objectives.

B.

Enforce disciplinary action for managers if the plan is not delivered.

C.

Revise the managers' performance goals to include key objectives.

D.

Provide management training on IT Strategic Objectives

Buy Now
Questions 124

When establishing a comprehensive approach for analyzing IT risk in an international, multi-division enterprise, it is MOST important to ensure:

Options:

A.

Risk management methodologies are aligned with local best practices.

B.

IT senior managers perform the analysis.

C.

Risk scenarios are compartmentalized by division.

D.

A consistent risk management methodology is used.

Buy Now
Questions 125

Which strategic planning approach would be MOST appropriate for a large enterprise to follow when revamping its IT services?

Options:

A.

Addressing gaps within the management of IT-related risk

B.

Focusing on business innovation through knowledge, expertise, and initiatives

C.

Calibrating and scaling delivery Of IT services in line with business requirements

D.

Adhering to on-time and on-budget IT service delivery

Buy Now
Questions 126

Within a governance structure for risk management, which of the following activities should be performed by the second line of defense?

Options:

A.

Conducting internal and external audits

B.

Implementing controls to manage risk

C.

Monitoring risk and controls

D.

Identifying and assessing risk

Buy Now
Questions 127

An enterprise plans to implement a business intelligence tool with data sources from various enterprise applications. Which of the following is the GREATEST challenge to implementation?

Options:

A.

Interface issues between enterprise and business intelligence applications.

B.

The need for staff to be trained on the new business intelligence tool.

C.

Large volumes of data fed from enterprise applications.

D.

Data definition and mapping sources from applications.

Buy Now
Questions 128

Which of the following BEST enables effective enterprise risk management (ERM)?

Options:

A.

Risk register

B.

Risk ownership

C.

Risk tolerance

D.

Risk training

Buy Now
Questions 129

Which of the following would be the PRIMARY impact on IT governance when a business strategy is changed?

Options:

A.

Performance outcomes of IT objectives

B.

IT governance structure

C.

Maturity level of IT processes

D.

Relationship level with IT outsourcers

Buy Now
Questions 130

A new CIO has been charged with updating the IT governance structure. Which of the following is the MOST important consideration to effectively influence organizational and process change?

Options:

A.

Obtaining guidance from consultants

B.

Aligning IT services to business processes

C.

Redefining the IT risk appetite

D.

Ensuring the commitment of stakeholders

Buy Now
Questions 131

An enterprise has decided to create its first mobile application. The IT director is concerned about the potential impact of this initiative. Which of the following is the MOST important input for managing the risk associated with this initiative?

Options:

A.

Enterprise architecture (EA)

B.

IT risk scorecard

C.

Enterprise risk appetite

D.

Business requirements

Buy Now
Questions 132

Which of the following roles has PRIMARY accountability for the security related to data assets?

Options:

A.

Database administrator

B.

Data owner

C.

Data analyst

D.

Security architect

Buy Now
Questions 133

Of the following, who should be responsible for ensuring the regular review of quality management performance against defined quality metrics?

Options:

A.

Process owners

B.

Risk management team

C.

Internal auditors

D.

Executive management

Buy Now
Questions 134

Which of the following is the MOST important driver of IT governance?

Options:

A.

Effective internal controls

B.

Management transparency

C.

Quality measurement

D.

Technical excellence

Buy Now
Questions 135

The use of an IT balanced scorecard enables the realization of business value of IT through:

Options:

A.

business value and control mechanisms.

B.

outcome measures and performance drivers.

C.

financial measures and investment management.

D.

vision and alignment with corporate programs.

Buy Now
Questions 136

Due to continually missed service level agreements (SLAs), an enterprise plans to terminate its contract with a vendor providing IT help desk services. The enterprise s IT department willassume the help desk-related responsibilities. Which of the following would BEST facilitate this transition?

Options:

A.

Requiring the enterprise architecture (EA) be updated

B.

Validating that the balanced scorecard is still meaningful

C.

Ensuring IT will operate at a lower cost than the vendor

D.

Ensuring a change management plan is in place

Buy Now
Questions 137

Which of the following is the PRIMARY element in sustaining an effective governance framework?

Options:

A.

Identification of optimal business resources

B.

Establishment of a performance metric system

C.

Ranking of critical business risks

D.

Assurance of the execution of business controls

Buy Now
Questions 138

An enterprise considers implementing a system that uses a technology that is not in line with its IT strategy. The business case indicates significant benefit to the enterprise. Which of the following is the BEST way to manage this situation within an IT governance framework?

Options:

A.

Update the IT strategy to align with the new technology.

B.

Initiate an operational change request.

C.

Reject based on non-alignment.

D.

Address as part of an architecture exception process.

Buy Now
Questions 139

Which of the following is the BEST method to monitor IT governance effectiveness?

Options:

A.

Service level management

B.

Balanced scorecard

C.

Risk control self-assessment (CSA)

D.

SWOT analysis

Buy Now
Questions 140

An enterprise has made the strategic decision to reduce operating costs for the next year and is taking advantage of cost reductions offered by an external cloud service provider. Which of the following should be the IT steering committee's PRIMARY concern?

Options:

A.

Revising the business $ balanced store card

B.

Updating the business risk profile

C.

Changing the IT steering committee charter

D.

Calculating the cost of the current solution

Buy Now
Questions 141

The CIO of an enterprise learns the payroll server of a competitor has been the victim of ransomware. To help plan for the possibility of ransomed corporate data, what should be the ClO's FIRST course of action?

Options:

A.

Require development of key risk indicators (KRls).

B.

Develop a policy to address ransomware.

C.

Request a targeted risk assessment.

D.

Back up corporate data to a secure location.

Buy Now
Questions 142

An enterprise plans to implement a business intelligence (Bl) tool with data sources from various enterprise applications. Which of the following is the GREATEST challenge to implementation?

Options:

A.

Interface issues between enterprise and Bl applications

B.

Large volumes of data fed from enterprise applications

C.

The need for staff to be trained on the new Bl tool

D.

Data definition and mapping sources from applications

Buy Now
Questions 143

A CEO is concerned that IT costs have significantly exceeded budget without resulting benefits. The root causes are an overlap of IT projects and a lack of alignment with business demands. Which of the following would BEST enable remediation of this situation?

Options:

A.

Require IT business cases be approved by the board of directors.

B.

Assign a set of key risk indicators (KRIs) to each new IT project.

C.

Conduct a performance assessment of IT projects.

D.

Implement an IT portfolio management policy.

Buy Now
Questions 144

An enterprise has decided to utilize a cloud vendor for the first time to provide email as a service, eliminating in-house email capabilities. Which of the following IT strategic actions should be triggered by this decision?

Options:

A.

Develop a data protection awareness education training program.

B.

Monitor outgoing email traffic for malware.

C.

Implement a data classification and storage management tool.

D.

Update and communicate data storage and transmission policies.

Buy Now
Questions 145

Which of the following is MOST important for the effective design of an IT balanced scorecard?

Options:

A.

On-demand reporting and continuous monitoring

B.

Consulting with the CIO

C.

Emphasizing the financial results

D.

Identifying appropriate key performance indicators (KPls)

Buy Now
Questions 146

An enterprise has a large backlog of IT projects. The current strategy is to execute projects as they are submitted, but executive management does not believe this method is optimal. Which of the following is the MOST important action to address this concern?

Options:

A.

Implement stage-gating to determine the value of each project.

B.

Establish a performance dashboard that determines business value.

C.

Implement a methodology to prioritize projects based on resource availability.

D.

Create a combined business/IT committee to determine project prioritization.

Buy Now
Questions 147

Which of the following BEST enables an enterprise to determine whether a current program for IT infrastructure migration to the cloud is continuing to provide benefits?

Options:

A.

Key performance indicators (KPls)

B.

Total cost of ownership (TCO)

C.

Key risk indicators (KRIS)

D.

Net present value (NPV)

Buy Now
Questions 148

Which of the following is the PRIMARY outcome of using a comprehensive architecture framework?

Options:

A.

Key third-party relationships are supported.

B.

Business goal conflicts are identified.

C.

Relevant controls are identified.

D.

Organizational management policies are developed.

Buy Now
Questions 149

An interna! health organization has been notified that a data breach has resulted in patient records being published online. Which of the

following is MOST important consideration when determining the process for meeting the organization's legal and regulatory obligations?

Options:

A.

Organizational structure, including accountable partes

B.

Data classification and related security policy

C.

Context of the breach, including data ownership and location

D.

Details of how the breach occurred and related incident response efforts

Buy Now
Questions 150

Which of the following is the BEST indication that an implementation plan for a new governance initiative will be successful?

Options:

A.

Staff have been trained on the new initiative.

B.

External consultants created the plan.

C.

The plan assigns responsibility for completing milestones.

D.

The plan is designed to engage employees across the enterprise.

Buy Now
Questions 151

An enterprise recently acquired technology that will enable it to offer products to customers through a mobile device application. The business is eager to use this technology as soon as possible for products currently offered through legacy IT systems. What is the CIO's MAIN responsibility?

Options:

A.

Ensure proper metrics are established to measure technology usage throughout the enterprise.

B.

Ensure business units are aware of new opportunities available with the acquired technology.

C.

Ensure the enterprise architecture (EA) is reviewed and updated.

D.

Ensure risk associated with implementation and support of the new technology is properly managed.

Buy Now
Questions 152

Which of the following would be the GREATEST obstacle for effective implementation of an enterprise's information security policy?

Options:

A.

Corporate culture

B.

Threats to corporate information

C.

Utilization of cloud-based applications

D.

Geographically dispersed staff

Buy Now
Questions 153

An enterprise has decided to use third-party software for a business process which is hosted and supported by the same third party. The BEST way to provide quality of service oversight would be to establish a process:

Options:

A.

for robust change management.

B.

for periodic service provider audits.

C.

for enterprise architecture (EA) updates.

D.

to qualify service providers.

Buy Now
Questions 154

Which of the following BEST enables the alignment of user access rights with business requirements?

Options:

A.

Data classification policy

B.

Maturity model

C.

System design

D.

Data architecture model

Buy Now
Questions 155

Which of the following is the BEST way for a CIO to assess the consistency of IT processes against industry benchmarks to determine where to focus improvement initiatives?

Options:

A.

Utilizing a capability maturity model

B.

Evaluating the current balanced scorecard

C.

Reviewing key performance measures

D.

Reviewing IT process audit results

Buy Now
Questions 156

An enterprise recently approved a bring your own device (BYOD) policy. The IT steering committee has directed IT management to develop a communication plan to disseminate information regarding the associated technical risks. Which of the following is MOST important to include in this communication plan?

Options:

A.

A link on the corporate intranet to the BYOD policy

B.

Potential exposures and impacts using common terms

C.

Schedule and content for mandatory training

D.

Disciplinary actions for violation of the BYOD policy

Buy Now
Questions 157

The board of directors of an enterprise has approved a three-year IT strategic program to centralize the core business processes of its global entities into one core system. Which of the following should be the ClO's NEXT step?

Options:

A.

Engage a team to perform a business impact analysis (BIA).

B.

Require the development of a risk management plan.

C.

Determine resource requirements for program implementation.

D.

Require the development of a program roadmap.

Buy Now
Questions 158

An IT steering committee has received a report that supports the economic and service benefits of moving infrastructure hosting to an external cloud provider. Business leadership is very concerned about the security risk and potential loss of customer data. What is the BEST way for the committee to address these concerns?

Options:

A.

Mandate there will be no customer data at rest stored on cloud servers used by the vendor.

B.

Include compliance with the enterprise's data governance policy in the contract.

C.

Ensure reporting and penalty clauses are included in the contract for any loss of data.

D.

Require an encrypted connection between the cloud and enterprise servers.

Buy Now
Questions 159

Which of the following should be the MOST important consideration when designing an implementation plan for IT governance?

Options:

A.

Principles and policies

B.

Roles and responsibilities

C.

Risk tolerance levels

D.

Organizational culture

Buy Now
Questions 160

Which of the following is the BEST justification for a procurement manager to agree to purchase IT equipment from a specific vendor during a sales promotion?

Options:

A.

The IT benefit surpasses the business benefit from the purchase.

B.

The equipment adds value to the enterprise.

C.

The business profit surpasses the IT cost for the equipment.

D.

The product is offered at the lowest price.

Buy Now
Questions 161

Which of the following is necessary for effective risk management in IT governance?

Options:

A.

Risk evaluation is embedded in the management processes.

B.

IT risk management is separate from enterprise risk management (ERM).

C.

Local managers are solely responsible for risk evaluation.

D.

Risk management strategy is approved by the audit committee.

Buy Now
Questions 162

An enterprise has established a goal of leveraging AI as a source of strategic advantage. Which of the following should be done FIRST when developing the related IT strategy?

Options:

A.

Document requirements mapped to each business function.

B.

Benchmark how other IT organizations are leveraging AI.

C.

Define the IT infrastructure requirements for AI implementation.

D.

Define an operational level agreement (OLA) between IT and business functions.

Buy Now
Questions 163

A CIO is planning to interview enterprise stakeholders to assess whether the IT strategic plan is continuing to support enterprise business objectives. The CIO would be MOST effective by starting the interview process with:

Options:

A.

the executive team.

B.

the internal auditors.

C.

senior IT managers.

D.

business process owners.

Buy Now
Questions 164

Despite an adequate training budget. IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?

Options:

A.

Provide incentives for IT staff to attend outside conferences and training

B.

Create a standard-setting center of excellence for IT.

C.

Require human resources (HR) to recruit new talent using an established IT skills matrix.

D.

Establish an agreed-upon skills development plan with each employee

Buy Now
Questions 165

An enterprise wants to implement metrics to monitor the performance of its IT portfolio. Whose input is MOST important to consider when establishing these metrics?

Options:

A.

Project management office (PMO).

B.

IT executives.

C.

The chief executive officer (CEO).

D.

Business unit stakeholders.

Buy Now
Questions 166

Which of the following is the BEST critical success factor (CSF) to use when changing an IT value management program in an enterprise?

Options:

A.

Documenting the process for the board of directors' approval

B.

Adopting the program by using an incremental approach

C.

Implementing the program through the enterprise's change plan

D.

Aligning the program to the business requirements

Buy Now
Questions 167

Which of the following is the BEST indication of an effective information governance model?

Options:

A.

Senior management ensures quality goals are defined for information.

B.

The CIO defines information accountability, quality criteria, and criticality.

C.

Enterprise architects define information protection attributes.

D.

Process owners determine which information assets will be managed.

Buy Now
Questions 168

When developing IT risk management policies and standards, it is MOST important to align them with:

Options:

A.

The corporate risk culture

B.

The enterprise risk management (ERM) framework

C.

Enterprise goals and objectives

D.

Best practices for IT risk management

Buy Now
Questions 169

An enterprise's IT department has been operating independently without regard to business concerns, leading to misalignment between business and IT. The BEST way to establish alignment would be to require:

Options:

A.

business to help define IT goals.

B.

business to fund IT services.

C.

IT to define business objectives.

D.

IT and business to define risks.

Buy Now
Questions 170

Which of the following should be done FIRST when developing an IT strategy to support a new AI business strategy?

Options:

A.

Assess current AI capabilities and infrastructure

B.

Establish guidelines and policies for responsible use of AI

C.

Create use cases to understand the impact of AI

D.

Build a team of AI professionals

Buy Now
Questions 171

Following a recent change to enterprise strategy, which of the following would be MOST important for the CIO to review?

Options:

A.

Existing performance and capacity plans

B.

A list of current and planned IT projects

C.

Historical IT budget allocations

D.

The enterprise SWOT analysis

Buy Now
Questions 172

Which of the following is the MOST efficient way for an IT transformation project manager to communicate the project progress with stakeholders?

Establish governance forums within project management.

Options:

A.

Include key performance indicators (KPls) in a monthly newsletter.

B.

Share the business case with stakeholders.

C.

Post the project management report to the enterprise intranet site.

Buy Now
Questions 173

Which of the following should be the PRIMARY consideration when implementing an emerging technology with unclear regulatory and compliance requirements?

Options:

A.

Enterprise strategic plan

B.

Enterprise architecture (EA) alignment

C.

Enterprise risk appetite

D.

Business impact analysis (BIA) results

Buy Now
Questions 174

A CIO is planning to implement an enterprise resource planning (ERP) system at the request of the business. Of the following, who is accountable for providing sponsorship for the IT-enabled change across the enterprise?

Options:

A.

CEO

B.

Human resource (HR) director

C.

IT strategy committee

D.

CIO

Buy Now
Questions 175

A CIO observes that many information assets are hosted on legacy technology that can no longer be patched or updated. The systems are not currently in use, but business units are reluctant to decommission assets due to information retention requirements. Which of the following is the BEST strategic response to this situation?

Options:

A.

Ensure the legacy systems are behind a secure firewall

B.

Isolate the legacy systems and disconnect them from the internet

C.

Apply legacy system surcharges to the business units

D.

Develop and enforce life cycle policies in consultation with business

Buy Now
Questions 176

Which of the following BEST provides an enterprise with greater insight into its environmental, social, and governance (ESG) metrics?

Options:

A.

Audit committee oversight

B.

Benchmarking against similar industries

C.

Collaborative tools and approaches

D.

Customer satisfaction surveys

Buy Now
Questions 177

An IT governance committee realizes there are antiquated technologies in use throughout the enterprise. Which of the following is the BEST group to evaluate the recommendations to address these shortcomings?

Options:

A.

Enterprise architecture (EA) review board

B.

Business process improvement workgroup

C.

Audit committee

D.

Risk management committee

Buy Now
Questions 178

An enterprise will be adopting wearable technology to improve business performance. Which of the following is the BEST way for the CIO to validate IT’s preparedness for this initiative?

Options:

A.

Request an enterprise architecture (EA) review.

B.

Perform a baseline business value assessment.

C.

Request reprioritization of the IT portfolio.

D.

Identify the penalties for noncompliance.

Buy Now
Questions 179

Which of the following should be considered FIRST when assessing the implications of new external regulations on IT compliance?

Options:

A.

IT policies and procedures that need revision

B.

Resource burden for implementation

C.

Gaps in skills and experience of IT employees

D.

Impact on contracts with service providers

Buy Now
Questions 180

Which of the following is the BEST indicator for measuring performance when implementing DevSecOps in an enterprise?

Options:

A.

Mean time to repair

B.

Percentage of automated tests

C.

Deployments per day

D.

Number of defects released per day

Buy Now
Questions 181

Despite an adequate training budget, IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?

Options:

A.

Provide incentives for IT staff to attend outside conferences and training.

B.

Require human resources (HR) to recruit new talent using an established IT skills matrix.

C.

Create a standard-setting center of excellence for IT.

D.

Establish an agreed-upon skills development plan with each employee.

Buy Now
Questions 182

Executive management is concerned that IT has not achieved its performance targets. At the end of the fiscal year, it was noted the reason was largely due to insufficient spending on key IT initiatives. Which of the following would help to alleviate the issue for the coming year?

Options:

A.

Key risk indicators (KRIs)

B.

Stage gate reviews

C.

Lag indicators

D.

Lead indicators

Buy Now
Questions 183

The GREATEST benefit associated with a decision to implement performance metrics for key IT assets is the ability to:

Options:

A.

establish the span of control during the life cycle of IT assets.

B.

determine the average cost of controls for protection of IT assets.

C.

compare the performance Of IT assets against industry best practices.

D.

determine the contribution of IT assets in achievement of IT goals.

Buy Now
Questions 184

Which of the following provides the STRONGEST indication that IT governance is well established within an organizational culture?

Options:

A.

Benefits of IT governance are realized throughout the organization.

B.

There is awareness of IT metrics throughout the organization.

C.

IT governance defines how IT projects should be assessed.

D.

IT performance metrics are defined in the balanced scorecard.

Buy Now
Questions 185

When developing IT risk management policies and standards, it is MOST important to align them with:

Options:

A.

Best practices for IT risk management.

B.

The corporate risk culture.

C.

Enterprise goals and objectives.

D.

The enterprise risk management (ERM) framework.

Buy Now
Questions 186

ACIO determines IT investment management processes are not fully realizing the benefits identified in business cases. Which of the following would be the BEST way to prevent this issue?

Options:

A.

Establish a requirement for ClO review and approval of each business case.

B.

Evaluate the delegation of investment approval authorities.

C.

Perform stage-gate reviews throughout the life cycle of each project.

D.

Document lessons learned throughout the investment life cycle.

Buy Now
Questions 187

To help ensure the IT portfolio provides maximum value to an organization, IT projects are BEST prioritized based on:

cost-benefit analysis results.

alignment with business strategy.

Options:

A.

recommendation Of business owners.

B.

alignment with IT architecture.

Buy Now
Questions 188

Which of the following BEST enables an enterprise to determine an appropriate retention policy for its information assets?

Options:

A.

Business and compliance requirements

B.

Business storage and processing needs

C.

Backup and restoration capabilities

D.

External customer data retention requirements

Buy Now
Questions 189

Which of the following would be MOST helpful to review when determining how to allocate IT resources during a resource shortage?

Options:

A.

IT strategic plan

B.

IT skills inventory

C.

IT organizational structure

D.

IT skill development plan

Buy Now
Questions 190

An enterprise is exploring a new business opportunity. Which of the following is the BEST way to help ensure related IT projects deliver the business requirements?

Options:

A.

Hire a business consultant to manage the projects.

B.

Develop a policy to enforce the processes and procedures.

C.

Implement stage-gate reviews that require business sign-off.

D.

Focus on maturing processes and developing procedures.

Buy Now
Questions 191

An enterprise has well-designed procurement and vendor risk management policies that are intended to prevent biased decision-making. However, a pattern of ethical violations indicates that vendor selection may have been inappropriately influenced by non-work-related incentives provided to decision makers. Which of the following should be done FIRST in response to this issue?

Options:

A.

Revise the procurement and vendor risk management policies.

B.

Conduct a root cause analysis and remediate based on findings.

C.

Document the critical success factors (CSFs) for the procurement policies.

D.

Establish and communicate strict penalties for biased vendor selection.

Buy Now
Questions 192

Which of the following would BEST help to prevent an IT system from becoming obsolete before its planned return on investment (ROI)?

Options:

A.

Obtaining independent assurance that the IT system conforms to business requirements

B.

Defining IT and business goals to ensure value delivery as required

C.

Managing the benefit realization through the entire life cycle

D.

Ordering an external audit for the IT system early in the roll out

Buy Now
Questions 193

A regulator has expressed concerns about the timeliness of information reported from an enterprise. Which of the following should be done FIRST to address this issue?

Options:

A.

Assess the reporting delivery process.

B.

Negotiate an exception process with the regulator.

C.

Automate the reporting process.

D.

Evaluate the implications of risk acceptance.

Buy Now
Questions 194

An enterprise wants to establish key risk indicators (KRIs) in an effort to better manage IT risk. Which of the following should be identified FIRST?

Options:

A.

The enterprise risk appetite

B.

Key performance metrics

C.

Risk mitigation strategies

D.

Enterprise architecture (EA) components

Buy Now
Questions 195

Which of the following BEST supports an IT strategy committee’s objective to align employee competencies with planned initiatives?

Options:

A.

Set management goals to hire cooperative work experience students.

B.

Specify minimum training hours required for continuing professional education.

C.

Require balanced scorecard concepts training of all employees.

D.

Add achievement of competencies to employee performance goals.

Buy Now
Questions 196

What should be the FIRST action of a new CIO when considering an IT governance framework for an enterprise?

Options:

A.

Understand corporate culture and IT'S role in providing business value.

B.

Understand critical IT processes to define the scope of the IT governance framework.

C.

Verify stakeholder sponsorship of the IT governance initiative.

D.

Develop an IT balanced scorecard to monitor and track IT performance.

Buy Now
Questions 197

Which of the following is the MOST important course of action when initiating a procurement process for a Zero Trust solution?

Options:

A.

Develop a contracting template for solution procurement.

B.

Conduct a thorough assessment of the vendor's security practices.

C.

Select an industry-recognized solution used by a benchmarked enterprise.

D.

Develop a comprehensive list of required features.

Buy Now
Questions 198

An enterprise has launched a critical new IT initiative that is expected to produce substantial value. Which of the following would BEST facilitate the reporting of benefits realized by the IT investment to the board?

Options:

A.

Balanced scorecard

B.

Milestone chart

C.

Performance management

D.

Critical risk and issue walk through

Buy Now
Questions 199

The MOST appropriate method for evaluating the capability of IT governance is through the use of:

Options:

A.

a maturity assessment.

B.

benchmarking.

C.

a cost-benefit analysis.

D.

a risk assessment.

Buy Now
Questions 200

An enterprise's current business continuity plan (BCP) fails to consider many common crisis events. What would be MOST helpful to address this situation?

Options:

A.

Engage stakeholders in scenario development

B.

Review the root cause analysis

C.

Require further walk-through tests

D.

Review and update the crisis communication plan

Buy Now
Questions 201

Which of the following should be the PRIMARY consideration when developing an IT strategy for the global implementation of Internet of Things (IoT) solutions?

Options:

A.

Hiring additional IT staff with IoT expertise

B.

Addressing security and privacy

C.

Identifying cost-effective IoT devices

D.

Maintaining compatibility with legacy systems

Buy Now
Questions 202

When an enterprise is evaluating potential IT service vendors, which of the following BEST enables a clear understanding of the vendor's capabilities that will be critical to the enterprise's strategy?

Due diligence process

Options:

A.

Independent audit results

B.

Historical service level agreements (SLAs)

C.

Benchmarking analysis results

Buy Now
Questions 203

An IT governance committee is defining a risk management policy for a portfolio of IT-enabled investments. Which of the following should be the PRIMARY consideration when developing the policy?

Options:

A.

Risk appetite of the enterprise.

B.

Possible investment failures.

C.

Risk management framework.

D.

Value obtained with minimum risk.

Buy Now
Questions 204

The accountability for a business continuity program for business-critical systems is BEST assigned to the:

Options:

A.

enterprise risk manager.

B.

chief executive officer (CEO).

C.

director of internal audit.

D.

chief information officer (CIO).

Buy Now
Exam Code: CGEIT
Exam Name: Certified in the Governance of Enterprise IT Exam
Last Update: Jun 24, 2025
Questions: 682

PDF + Testing Engine

$72.6  $181.49

Testing Engine

$57.8  $144.49
buy now CGEIT testing engine

PDF (Q&A)

$49.8  $124.49
buy now CGEIT pdf