Which of the following BEST lowers costs and improves scalability from an IT enterprise architecture (EA) perspective?
A rail transport company has the worst on-time arrival record in the industry due to an antiquated IT system that controls scheduling. Despite employee resistance, an initiative lo upgrade the technology and related processes has been approved. To maximize employee engagement throughout the project, which of the following should be in place prior to the start of the initiative?
An enterprise has decided to create its first mobile application. The IT director is concerned about the potential impact of this initiative. Which of the following is the MOST important input for managing the risk associated with this initiative?
An enterprise made a significant change to its business operating model that resulted in a new strategic direction. Which of the following should be reviewed FIRST to ensure IT congruence with the new business strategy?
An IT risk assessment for a large healthcare group revealed an increased risk of unauthorized disclosure of information. Which of the following should be established FIRST to address the risk?
Which of the following would be the PRIMARY impact on IT governance when a business strategy is changed?
Which of the following is the MOST important consideration for data classification to be successfully implemented?
An organization's board of directors has questioned the value provided by IT key performance indicators (KPIs). Which of the following is the BEST way to determine whether the KPIs adequately support organizational objectives?
An enterprise has a zero-tolerance policy regarding security. This policy is causing a large number of email attachments to be blocked and is a disruption to enterprise. Which of the following should be the FIRST governance step to address this email issue?
A large financial institution is considering outsourcing customer call center operations which will allow the chosen vendor to access systems from offshore locations. Which of the following represents the GREATEST risk?
Which of the following would be of MOST concern regarding the effectiveness of risk management processes?
A retail enterprise has cost reduction as its top priority. From a governance perspective, which of the following should be the MOST important consideration when evaluating different IT investment options?
A review of the effectiveness of IT governance within an enterprise has revealed that several innovation improvement initiatives are failing. An analysis shows a lack of stakeholder buy-in to the improvements. Implementing which of the following would have prevented this problem?
Senior management wants to promote investment in IT, but is uncertain that associated risks are being properly identified. The BEST way to address this concern is to:
An enterprise's information security function is making changes to its data retention and backup policies. Which of the following presents the GREATEST risk?
The CIO of a financial services company is tasked with ensuring IT processes are in compliance with recently instituted regulatory changes. The FIRST course of action should be to:
The BEST way to manage continuous improvement of governance-related processes is to:
An IT audit reveals inconsistent maintenance of data privacy in enterprise systems primarily due to a lack of data sensitivity categorizations. Once the categorizations are defined, what is the BEST long-term strategic response by IT governance to address this problem?
Which of the following is MOST important when an IT-enabled business initiative involves multiple business functions?
An IT governance committee wants to ensure there is a clear description of the "data owner" in the enterprise data policy. Which of the following would BEST define the owner of data stored in an external cloud?
What is the PRIMARY objective for performing an IT due diligence review prior to the acquisition of a competitor?
Who is PRIMARILY accountable for delivering the benefits of an IT-enabled investment program to the enterprise?
Which of the following is the BEST way to demonstrate that IT strategy supports a new enterprise strategy?
An enterprise plans to implement a business intelligence (Bl) tool with data sources from various enterprise applications. Which of the following is the GREATEST challenge to implementation?
A global financial institution has decided to integrate data from branch locations into a common database to address regulatory reporting requirements. Analysis of data flows and the full data life cycle should be conducted at which level?
Which of the following is the BEST way for a CIO to secure support for a strategy to achieve long-term IT objectives?
Which of the following is MOST important to effectively initiate IT-enabled change?
A new CIO has been charged with updating the IT governance structure. Which of the following is the MOST important consideration to effectively influence organizational and process change?
Which of the following BEST reflects the ethical values adopted by an IT organization?
To reduce the risk of reputational damage through inappropriate use of social media by employees outside of the workplace, the enterprise approach regarding social media should PRIMARILY focus on;
A healthcare enterprise that is subject to strict compliance requirements has decided to outsource several key IT services to third-party providers. Which of the following would be the BEST way to assess compliance and avoid reputational damage?
The results of an internal audit show that the business and IT acquire resources differently, which causes duplicate purchases. Which of the following is the BEST way to address this issue?
Which of the following is the BEST method for making a strategic decision to invest in cloud services?
Which of the following is MOST important for the effective design of an IT balanced scorecard?
A large organization with branches across many countries is in the midst of an enterprise resource planning (ERP) transformation. The IT organization receives news that the branches in a country where the impact to the enterprise is to be greatest are being sold. What should be the NEXT step?
Which of the following is the PRIMARY element in sustaining an effective governance framework?
Which of the following components of a policy BEST enables the governance of enterprise IT?
The IT program manager does not see the value of conducting risk assessments for a new major IT project. The manager is reluctant to cooperate with internal auditors and the newly formed steering committee. Midway through the project, program requirements were changed because the CEO is a friend of a vendor and wants to implement this vendor's new technology. This decision will cause the current IT program budget to be insufficient and will be shown as overspending.
After the requirement change request, the IT program manager should FIRST:
Which of the following should be the PRIMARY consideration when developing an IT strategy for the global implementation of Internet of Things (IoT) solutions?
Which of the following is the PRIMARY benefit of communicating the IT strategy across the enterprise?
Which of the following is the PRIMARY ongoing responsibility of the IT governance function related to risk?
Which of the following would be the BEST way to facilitate the adoption of strong IT governance practices throughout a multi-divisional enterprise?
Which of the following BEST enables the alignment of user access rights with business requirements?
Which of the following is MOST important for a data steward to verify when a system's data is edited by an automated tool to fix an incident?
An enterprise has established a new department to oversee the life cycle of activities that support data management objectives. Which of the following should be done NEXT?
Which of the following groups should approve the implementation of new technology?
A large enterprise that is diversifying its business will be transitioning to a new software platform, which is expected to cause data changes. Which of the following should be done FIRST when developing the related metadata management process?
Despite an adequate training budget. IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?
A CIO engages a consulting firm to conduct a benchmark analysis of the organization’s IT governance framework against industry best practices. Several recommendations to improve the maturity of the framework are identified. Which of the following should be the CIO's NEXT course of action?
While monitoring an enterprise's IT projects portfolio, it is discovered that a project is 75% complete, but all budgeted resources have been expended. Which of the following is the MOST important task to perform?
When an enterprise is evaluating potential IT service vendors, which of the following BEST enables a clear understanding of the vendor's capabilities that will be critical to the enterprise's strategy?
Due diligence process
Following a recent change to enterprise strategy, which of the following would be MOST important for the CIO to review?
An enterprise plans to migrate its applications and data to an external cloud environment. Which of the following should be the ClO's PRIMARY focus before the migration?
A CIO believes that a recent mission-critical IT decision by the board of directors is not in the best financial interest of all stakeholders. Which of the following is the MOST ethical course of action?
To measure the value of IT-enabled investments, an enterprise needs to identify its drivers as defined by its:
Which of the following is the FIRST step when developing an IT risk management framework?
Which of the following presents the GREATEST challenge for a large-scale enterprise when procuring Infrastructure as a Service (IaaS)?
Which of the following is MOST likely to have a negative impact on
accountability for information risk ownership?
An enterprise has decided to use third-party software for a business process which is hosted and supported by the same third party. The BEST way to provide quality of service oversight would be to establish a process:
A high-tech enterprise is concerned that leading competitors have been successfully recruiting top talent from the enterprise's research and development business unit.
What should the leadership team mandate FIRST?
Which of the following would be MOST helpful to review when determining how to allocate IT resources during a resource shortage?
An enterprise recently implemented a significant change in its business strategy by moving to a technologically advanced product with considerable impact on the business. What should be the FINAL step in completing the changes to IT processes?
When determining the desired maturity levels for IT governance processes, it is MOST important to:
A global organization has noticed a significant decrease in the return on IT investments in a particular region. To enhance project governance in this region, the CEO should FIRST
Which of the following is the BEST indicator of the effectiveness of IT governance in an enterprise?
An enterprise's current business continuity plan (BCP) fails to consider many common crisis events. What would be MOST helpful to address this situation?
Which of the following is the PRIMARY responsibility of a data steward at an enterprise with mature data management programs?
Which of the following is the BEST way for a CIO to provide progress updates on a newly implemented IT strategic plan to the board of directors?
Present an IT summary dashboard.
Present IT critical success factors (CSFs).
Report results Of key risk indicators (KRIs).
When establishing a methodology for business cases, it would be MOST beneficial for an enterprise to include procedures for:
An enterprise has decided to adopt cloud services. Which of the following should be established FIRST?
Which of the following should be considered FIRST when assessing the implications of new external regulations on IT compliance?
A CIO is planning to interview enterprise stakeholders to assess whether the IT strategic plan is continuing to support enterprise business objectives. The CIO would be MOST effective by starting the interview process with:
A board of directors has mandated that key performance indicators (KPIs) be developed for all IT projects that are created in support of a business objective. Which of the following MUST be reflected in the KPIs to be effective?
Which of the following is MOST important to ensure when aligning IT and enterprise resource management processes?
A CIO was notified that a new employee was observed wearing a headset with an optical lens at the organization's data center. The individual was entering voice commands into the device. When approached, the employee explained the device is a new personal technology serving as a hands-free version of a smart phone. The CIO is concerned with potential security vulnerabilities of allowing such devices, and whether they should be banned from the facility. What should be the NEXT course of action in response to the ClO's concern?
An enterprise learns that some of its business divisions have been approaching technology vendors for cloud services, resulting in duplicate support contracts and underutilization of IT services. Which of the following should be done FIRST to address this issue?
An enterprise has a centralized IT function but also allows business units to have their own technology operations, resulting in duplicate technologies and conflicting priorities. Which of the following should be done FIRST to reduce the complexity of the IT landscape?
Promote automation tools used by the business units.
An enterprise is concerned about the community impact of its data center noise levels. Which of the following is the enterprise’s BEST course of action?
Which of the following is the GREATEST consideration when evaluating whether to comply with the new carbon footprint regulations impacted by blockchain technology?
An enterprise recently approved a bring your own device (BYOD) policy. The IT steering committee has directed IT management to develop a communication plan to disseminate information regarding the associated technical risks. Which of the following is MOST important to include in this communication plan?
An enterprise has made the strategic decision to begin a global expansion program which will require opening sales offices in countries across the world. Which of the following should be the FIRST consideration with regard to the IT service desk which will remain centralized?
The effect of regional differences On service delivery
Identification of IT service desk functions that can be outsourced
An enterprise is implementing its first mobile sales channel. Final approval for accepting the associated IT risk should be obtained from which of the following?
Risk manager
Business sponsor
A large enterprise is implementing an information security policy exception process. The BEST way to ensure that security risk is properly addressed is to:
confirm process owners' acceptance of residual risk.
perform an internal and external network penetration test.
obtain IT security approval on security policy exceptions.
Which of the following is the MOST efficient approach for using risk scenarios to evaluate a new business opportunity?
After experiencing poor recovery times following a catastrophic event, an enterprise is seeking to improve its disaster recovery capabilities. Which of the following would BEST enable the enterprise to accomplish this objective?
When reporting key risk indicators (KRIs) to the board, what information BEST enables risk-based decision-making?
Which strategic planning approach would be MOST appropriate for a large enterprise to follow when revamping its IT services?
The MOST appropriate method for evaluating the capability of IT governance is through the use of:
Which of the following is MOST important to include in the customer dimension of an IT balanced scorecard?
Which of the following situations provides the BEST justification for considering the adoption of a qualitative risk assessment method?
What is the BEST way for IT to achieve compliance with regulatory requirements?
Which of the following is the BEST way to encourage employees to raise ethics concerns in full confidence?
When a shortfall of IT resources is identified, the FIRST course of action is to;
What is the PRIMARY benefit of aligning information architecture with enterprise architecture (EA)?
Which of the following should a CIO review to obtain a holistic view of IT performance when identifying potential gaps in service delivery?
A CIO wants to make improvements to the enterprise's IT governance. Which of the following would BEST help to demonstrate the expected benefits from proposed changes?
Which of the following is the BEST way for a CIO to ensure that IT-related training is taken seriously by the IT management team and direct employees?
When an enterprise plans to deploy mobile device technologies, it is MOST important for leadership to ensure that:
Which of the following BEST enables an enterprise to minimize the risks of intellectual property theft and loss of sensitive information when acquiring Internet of Things (IoT) hardware and software components?
A CIO observes that many information assets are hosted on legacy technology that can no longer be patched or updated. The systems are not currently in use, but business units are reluctant to decommission assets due to information retention requirements. Which of the following is the BEST strategic response to this situation?
Which of the following is MOST important for a CIO to ensure before signing a contract for a new cloud-based customer relationship management (CRM) system?
The service provider has been audited for vulnerabilities and threats.
Which of the following is the PRIMARY role of the governance function in enabling an enterprise to achieve its business objectives?
Which of the following has the GREATEST impact on the design of an IT governance framework?
Which of the following would BEST help to ensure the appropriate allocation of IT resources to support an enterprise's mission?
An IT steering committee is concerned about staff saving data files containing sensitive corporate information on publicly available cloud file storage applications. Which of the following should be done FIRST to address this concern?
Which of the following is the BEST way for a CIO to ensure that the work of IT employees is aligned with approved IT directives?
Which of the following is MOST important to document for a business ethics program?
When evaluating the process for acquiring third-party IT resources, management identified several suppliers with repeated downtime issues impacting the enterprise. Which of the following is the BEST approach to help ensure future service delivery in accordance with business objectives?
An enterprise has committed to the implementation of a new IT governance model. The BEST way to begin this implementation is to:
Individual business units within an enterprise have been designing their own IT solutions without consulting the IT department. From a governance perspective, what is the GREATEST issue associated with this situation?
Which of the following methods is MOST likely to be used to assess plausible risk scenarios that could result in reputational risk to the enterprise?
When developing an IT governance framework, it is MOST important for an enterprise to consider:
An enterprise-wide strategic plan has been approved by the board of directors. Which of the following would BEST support the planning of IT investments required for the enterprise?
After shifting from lease to purchase of IT infrastructure and software licenses, an enterprise has to pay for unexpected lease extensions causing significant cost overruns. The BEST direction for the IT steering committee would be to establish;
A root-cause analysis indicates a major service disruption due to a lack of competency of newly hired IT system administrators. Who should be accountable for resolving the situation?
Which of the following activities MUST be completed before developing an IT strategic plan?
Which of the following is the BEST way to implement effective IT risk management?
Enterprise leadership is concerned with the potential for discrimination against certain demographic groups resulting from the use of machine learning models What should be done FIRST to address this concern?
Which of the following should be the PRIMARY consideration for an enterprise when prioritizing IT projects?
Which of the following should a new CIO do FIRST to ensure information assets are effectively governed?
An enterprise is replacing its customer relationship management (CRM) system with a cloud-based system. Which of the following should be done FIRST when preparing for data migration"*
Which of the following should be the PRIMARY goal of implementing service level agreements (SLAs) with an outsourcing vendor?
A major data leakage incident at an enterprise has resulted in a mandate to strengthen and enforce current data governance practices. Which of the following should be done FIRST to achieve this objective?
Which of the following is the MOST important input for the development of a human resources strategy to address IT skill gaps?
An enterprise's board of directors has determined that IT is not sufficiently supporting its corporate objectives, and has established a committee to address this problem. Which of the following should be the committees FIRST action?
To ensure that information can be traced to the originating event and accountable parties, an enterprise should FIRST:
An enterprise is determining the objectives for an IT training improvement initiative from a governance prosected. it would be MOST important to ensure that:
Which of the following is the BEST method to confirm whether a pilot project was successful?
Which of the following would be the MOST effective way to ensure IT capabilities are appropriately aligned with business requirements for specific business processes?
A data governance strategy has been defined by the IT strategy committee which includes privacy objectives related to access controls, authorized use. and data collection. Which of the following should the committee do NEXT?
Which of the following is the MOST appropriate mechanism for measuring overall IT organizational performance?
Which of the following is the BEST outcome measure to determine the effectiveness of IT nsk management processes?
Which of the following is MOST critical to support IT governance cultural changes within an organization?
Which of the following is the BEST justification for a procurement manager to agree to purchase IT equipment from a specific vendor during a sales promotion?
Which of the following would a CIO use to present the overall view of IT performance to the board of directors?
Which of the following is the MOST important reason to include internal audit as a stakeholder when establishing clear roles for the governance of IT?
An internal audit revealed a widespread perception that the enterprise's IT governance reporting lacks transparency Which of the following should the CIO do FIRST?
A financial services company has implemented the use of a cloud-based centralized customer relationship management (CRM) system. The company has decided to go multi-national. Which of the following should be the enterprise risk management (ERM) committee's PRIMARY consideration?
An enterprise has made the strategic decision to reduce operating costs for the next year and is taking advantage of cost reductions offered by an external cloud service provider. Which of the following should be the IT steering committee's PRIMARY concern?
An enterprise wants to address the human factors of social engineering risk within the organization. From a governance perspective, which of the following is the BEST way to mitigate this risk?
An IT steering committee wants to select a disaster recovery site based on available risk data Which of the following would BE ST enable the mapping of cost to risk?
An enterprise's global IT program management office (PMO) has recently discovered that several IT projects are being run within a specific region without knowledge of the PMO. The projects are on time, on budget, and will deliver the proposed benefits to the specific region. Which of the following should be the PRIMARY concern of the PMO?
Which of the following is the MOST comprehensive method to report on overall IT performance to the board of directors?
An enterprise has developed a new digital strategy to improve fraud detection. Which of the following is MOST important to consider when updating the information architecture?
Which of the following is MOST important for IT governance to have in place to ensure the enterprise can maintain operations during extensive system downtime?
The board of directors of a large organization has directed IT senior management to improve IT governance within the organization. IT senior management's MOST important course of action should be to:
When assessing the impact of a new regulatory requirement, which of the following should be the FIRST course of action?
What is the BEST way for an IT governance board to establish standards of behavior for the adoption of artificial intelligence (Al)?
An enterprise is adopting a new governance framework. Of the following, the MOST effective method to help ensure that key activities are performed by appropriate resources is through the use of:
An enterprise is planning a transformation initiative by leveraging emerging technology that will have a significant impact on existing products and services Which of the following is the BEST way for IT to prepare for this change?
Which of the following provides the BEST evidence of an IT risk-aware culture across an enterprise?
An enterprise is trying to increase the maturity of its IT process from being ad hoc to being repeatable. Which of the following is the PRIMARY benefit of this change?
Which of the following would be the BEST way for an IT steering committee to monitor the adoption of a new enterprise IT strategy?
To enable the development of required IT skill sets for the enterprise, it is MOST important to define skill requirements based on:
Which of the following will BEST enable an IT steering committee to monitor the achievement of overall IT objectives on a continuous basis?
What is the BEST criterion for prioritizing IT risk remediation when resource requirements are equal?
Which of the following should be done FIRST when defining responsibilities for ownership of information and systems?
Communicating which of the following to staff BEST demonstrates senior management's commitment to IT governance?
To ensure IT risk is managed in a consistent manner, it is MOST important for IT governance to establish a:
As part of the implementation of IT governance, the board of an enterprise should establish an IT strategy committee to:
When establishing an enterprise data model, the BEST way to ensure the integrity of data is to:
When developing an IT strategic plan that supports an enterprise's business goals which of the following should be done FIRST?
A board of directors has just received a report indicating that only a small number of IT initiatives have been completed on time and within budget, A third of the projects were cancelled prior to completion, and more than half will cost almost double their original estimates. An analysis has determined that no one is held responsible for the completion of investmentinitiatives, and there is no consistency in execution. Which of the following would BEST help the enterprise address these problems?
A business is considering a policy to anonymize personal data in enterprise systems. Before making a decision, which of the following is MOST important for the IT steering committee to consider?
Which of the following would provide the BEST input for prioritizing strategic IT improvement initiatives?
Before an IT strategy committee can approve an IT risk assessment framework, which of the following is MOST important to have established?
IT has launched new portfolio management policies and processes to improve the alignment of IT projects with enterprise goals. The latest audit report indicates that no improvement has been made due to confusion in the decision-making process. Which of the following is the BEST course of action for the CIO?
A regulatory audit assessed an enterprise's main transactional application as noncompliant. In addition to fines and required corrections, an agreement was reached to implement a set of governance controls over IT. Accountability for these controls is BEST assigned to which of the following?
An enterprise has had the same IT governance framework in place for several years. Currently, large and small capital projects go through the same architectural governance reviews. Despite repeated requests to streamline the review process for small capital projects, business units have received no response from IT. The business units have recently escalated this issue to the newly appointed GO. Which of the following should be done FIRST to begin addressing business needs?
Establishing a uniform definition for likelihood and impact through risk management standards PRIMARILY addresses which of the following concerns?