The board and senior management of a new enterprise recently met to formalize an IT governance framework. The board of directors' FIRST step in implementing IT governance is to ensure that:
An enterprise experiencing issues with data protection and least privilege is implementing enterprise-wide data encryption in response. Which of the following is the BEST approach to ensure all business units work toward remediating these issues?
An enterprise has a large backlog of IT projects. The current strategy is to execute projects as they are submitted, but executive management does not believe this method is optimal. Which of the following is the MOST important action to address this concern?
A board of directors is concerned that a major IT implementation has the potential to significantly disrupt enterprise operations. Which of the following would be MOST helpful in identifying the extent of the potential impact of the disruption?
A large organization with branches across many countries is in the midst of an enterprise resource planning (ERP) transformation. The IT organization receives news that the branches in a country where the impact to the enterprise is to be greatest are being sold. What should be the NEXT step?
The CIO in a large enterprise is seeking assurance that significant IT risk is being proactively monitored and does not exceed agreed risk tolerance levels. The BEST way to provide this ongoing assurance is to require the development of:
Before an IT strategy committee can approve an IT risk assessment framework, which of the following is MOST important to have established?
An enterprise is evaluating a Software as a Service (SaaS) solution to support a core business process. There is no outsourcing governance or vendor management in place. What should be the CEO's FIRST course of action?
Which of the following is the PRIMARY benefit of communicating the IT strategy across the enterprise?
A chief technology officer (CTO) wants to ensure IT governance practices adequately address risk management specific to mobile applications. To create the appropriate risk policies for IT, it is MOST important for the CTO to:
An enterprise's information security function is making changes to its data retention and backup policies. Which of the following presents the GREATEST risk?
An audit department recently uncovered a series of security breaches. It was determined that network intrusion detection logs were recording the suspicious activity, but IT staff were not reviewing logs due to competing business demands. To address this situation, the IT steering committee’s FIRST priority should be:
Which of the following should be the MOST important consideration when defining an information architecture?
The PRIMARY benefit of using an IT service catalog as part of the IT governance program is that it.
An IT investment review board wants to ensure that IT will be able to support business initiatives. Each initiative is comprised of several interrelated IT projects. Which of the following would help ensure that the initiatives meet their goals?
An IT strategy committee wants to ensure that a risk program is successfully implemented throughout the enterprise. Which of the following would BEST support this goal?
Which of the following is the MOST appropriate mechanism for measuring overall IT organizational performance?
Which of the following is the BEST way to ensure all enterprise employees understand the corporate code of business conduct?
An enterprise wants to address the human factors of social engineering risk within the organization. From a governance perspective, which of the following is the BEST way to mitigate this risk?
An enterprise's board of directors has determined that IT is not sufficiently supporting its corporate objectives, and has established a committee to address this problem. Which of the following should be the committees FIRST action?
When updating an IT governance framework to support an outsourcing strategy, which of the following is MOST important?
An IT governance committee is defining a risk management policy for a portfolio of IT-enabled investments Which of the following should be the PRIMARY consideration when developing the policy?
An enterprise has performed a business impact analysis (BIA) considering a number of risk scenarios Which of the following should the enterprise do NEXT?
An IT steering committee has received a report that supports the economic and service benefits of moving infrastructure hosting to an external cloud provider. Business leadership is very concerned about the security risk and potential loss of customer data. What is the BEST way for the committee to address these concerns?
When developing an IT training plan, which of the following is the BEST way to ensure that resource skills requirements are identified?
An enterprise has committed to the implementation of a new IT governance model. The BEST way to begin this implementation is to:
Which of the following BEST facilitates governance oversight of data protection measures?
Which of the following is MOST important for IT governance to have in place to ensure the enterprise can maintain operations during extensive system downtime?
The PRIMARY reason for implementing an IT governance program in an enterprise is to
IT management has reported difficulty retaining qualified IT personnel to support the organization's new strategy Given that outsourcing is not a viable approach, which of the following would be the BEST way for IT governance to address this situation?
Which of the following BEST supports the implementation of an effective data classification policy?
An enterprise has identified potential environmental disasters that could occur in the area where its data center is located. Which of the following should be done NEXT?
The PRIMARY objective of IT resource planning within an enterprise should be to:
A board of directors has just received a report indicating that only a small number of IT initiatives have been completed on time and within budget, A third of the projects were cancelled prior to completion, and more than half will cost almost double their original estimates. An analysis has determined that no one is held responsible for the completion of investmentinitiatives, and there is no consistency in execution. Which of the following would BEST help the enterprise address these problems?
To successfully implement enterprise IT governance, which of the following should be the MAIN focus of IT policies?
Which of the following is (he GREATEST benefit of using the life cycle approach to govern information assets?
A project sponsor has circumvented the request for proposal (RFP) selection process. Which of the following is the MOST likely reason for this control gap?
An independent consultant has been hired to conduct an ad hoc audit of an enterprise’s information security office with results reported to the IT governance committee and the board Which of the following is MOST important to provide to the consultant before the audit begins?
The BEST way to decide how to prioritize issues identified in an IT risk and control self-assessment (CSA) is to understand the risk and:
In which of the following situations is it MOST appropriate to use a quantitative risk assessment?
Which of the following would be the MOST effective way to ensure IT capabilities are appropriately aligned with business requirements for specific business processes?
An enterprise is conducting a SWOT analysis as part of IT strategy development. Which of the following would be MOST helpful to identify opportunities and threats?
A CIO of an enterprise is concerned that IT and the business have different priorities. Which of the following would BEST demonstrate the current state of strategic alignment?
An IT strategy committee has reviewed an audit report indicating sales employees are using personal smartphones to conduct corporate business. Although the committee appreciates the business benefits, it is also concerned with the security risk. To deliver the business benefit, what should be the committee's FIRST recommendation?
An enterprise has entered into a new market which brings additional regulatory compliance requirements. What should be done FIRST to address these requirements?
A CIO just received a final audit report that indicates there is inconsistent enforcement of the enterprise's mobile device acceptable use policy throughout all business units. Which of the following should be the FIRST step to address this issue?
Which of the following is the MOST important benefit of effective IT governance reporting?
From an IT governance perspective, establishing performance measurements is PRIMARILY the responsibility of:
An enterprise has lost an unencrypted backup tape of archived customer data. A data breach report is not mandatory in the relevant jurisdiction. From an ethical standpoint, what should the enterprise do NEXT?
Of the following, who should approve the criteria for information quality within an enterprise?
Communicating which of the following to staff BEST demonstrates senior management's commitment to IT governance?
Which of the following will BEST enable an IT steering committee to monitor the achievement of overall IT objectives on a continuous basis?
An enterprise is concerned with the potential for data leakage as a result of increased use of social media in the workplace, and wishes to establish a social media strategy. Which of the following should be the MOST important consideration in developing this strategy?
A business is considering a policy to anonymize personal data in enterprise systems. Before making a decision, which of the following is MOST important for the IT steering committee to consider?
Which of the following is MOST critical to support IT governance cultural changes within an organization?
Which of the following should be the PRIMARY input when developing IT strategy?
Which of the following would provide the MOST useful information to understand the associated risks when implementing a new digital transformation strategy?
In a successful enterprise that is profitable in its marketplace and consistently growing in size, the non-IT workforce has grown by 50% in the last two years. The demand for IT staff in the marketplace is more than the supply, and the enterprise is losing staff to rival organizations. Due to the rapid growth. IT has struggled to keep up with the enterprise, and IT procedures and associated job roles are not well-defined. The MOST critical activity for reducing the impact caused by IT staff turnover is to:
Which of the following would be MOST useful for prioritizing IT improvement initiatives to achieve desired business outcomes?
Which of the following is the PRIMARY purpose of an effective set of key risk indicators (KRIs)?
Which of the following BEST demonstrates the effectiveness of enterprise IT governance?
When developing an IT strategic plan that supports an enterprise's business goals which of the following should be done FIRST?
An IT steering committee wants to select a disaster recovery site based on available risk data Which of the following would BE ST enable the mapping of cost to risk?
Which of the following activities MUST be completed before developing an IT strategic plan?
Which of the following should be the FIRST step for executive management to take in communicating what is considered acceptable use with regard to personally owned devices for company business?
Which of the following methods is MOST likely to be used to assess plausible risk scenarios that could result in reputational risk to the enterprise?
Which of the following should be the MOST important consideration when designing an implementation plan for IT governance?
Which of the following should be the PRIMARY goal of implementing an IT strategic planning process?
What is the BEST way for an IT governance board to establish standards of behavior for the adoption of artificial intelligence (Al)?
Which of the following is the BEST indication that information security requirements are taken into consideration when developing IT processes?
A multinational enterprise is planning to migrate to cloud-based systems. Which of the following should be of MOST concern to the risk management committee?
Which of the following would a CIO use to present the overall view of IT performance to the board of directors?
Which of the following is the MOST important reason to include internal audit as a stakeholder when establishing clear roles for the governance of IT?
An IT strategy committee wants to evaluate how well the IT department supports the business strategy. Which of the following is the BEST method for making this determination?
The risk committee is overwhelmed by the number of false positives included in risk reports. What action would BEST address this situation?
An enterprise wishes to establish key risk indicators (KRIs) in an effort to better manage IT risk. Which of the following should be identified FIRST?
When preparing a new IT strategic plan for board approval, the MOST important consideration is to ensure the plan identifies:
Which of the following is the MOST important consideration when developing a new IT service'?
Which of the following should a CIO review to obtain a holistic view of IT performance when identifying potential gaps in service delivery?
A large enterprise has decided to use an emerging technology that needs to be integrated with the current IT infrastructure. Which of the following is the BEST way to prevent adverse effects to the enterprise resulting from the new technology?
An IT governance committee realizes there are antiquated technologies in use throughout the enterprise. Which of the following is the BEST group to evaluate the recommendations to address these shortcomings?
When establishing a comprehensive approach for analyzing IT risk in an international, multi-division enterprise, it is MOST important to ensure:
Which of the following would BEST help assess the effectiveness of a newly established IT governance framework?
When conducting a risk assessment in support of a new regulatory
requirement, the IT risk committee should FIRST consider the:
Which of the following is the BEST way to express the value of financial investments in cybersecurity?
Which of the following is the MOST efficient approach for using risk scenarios to evaluate a new business opportunity?
Which of the following is the GREATEST consideration when evaluating whether to comply with the new carbon footprint regulations impacted by blockchain technology?
Which of the following is MOST helpful in determining whether an enterprise’s quality assurance (QA) program is meeting business requirements?
A CIO engages a consulting firm to conduct a benchmark analysis of the organization’s IT governance framework against industry best practices. Several recommendations to improve the maturity of the framework are identified. Which of the following should be the CIO’s NEXT course of action?
A regulatory audit of an IT department has identified discrepancies between processes described in the procedures and what is actually done by system administrators.
The discrepancies were caused by recent IT application changes. Which of the following would be the BEST way to prevent the recurrence of similar findings in the future?
Which of the following is MOST important to ensure when aligning IT and enterprise resource management processes?
An enterprise is required to implement several regulatory requirements. Which of the following functions is BEST suited to determine compliance priorities?
From an IT governance perspective, which of the following would be the MOST significant impact of moving all IT applications to an external Software as a Service (SaaS) cloud provider?
Which of the following is the BEST way for an IT steering committee to determine the benefits of an IT investment?
Which of the following is the MOST efficient way for an IT transformation project manager to communicate the project progress with stakeholders?
Establish governance forums within project management.
Which of the following BEST facilitates the adoption of an IT governance program in an enterprise?
Despite an adequate training budget, IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?
An enterprise is assessing whether to utilize wearable technology. The enterprise has no prior experience with this technology and has asked the chief technology officer (CTO) to assess the impact to the enterprise. The CTO should FIRST:
When an enterprise is evaluating potential IT service vendors, which of the following BEST enables a clear understanding of the vendor's capabilities that will be critical to the enterprise's strategy?
Due diligence process
Which of the following provides the STRONGEST indication that IT governance is well established within an organizational culture?
An enterprise’s IT director is concerned that the chair of the IT steering committee is stealing confidential company information. Which of the following is the IT director’s BEST course of action?
Which of the following should be done FIRST when developing an IT strategy to support a new AI business strategy?
Which of the following is MOST important for a data steward to verify when a system's data is edited by an automated tool to fix an incident?
An IT governance committee is defining a risk management policy for a portfolio of IT-enabled investments. Which of the following should be the PRIMARY consideration when developing the policy?
Upcoming IT-related regulations carry costly penalties for an enterprise. The issuing regulatory agency has a history of weak enforcement. The IT steering committee should FIRST direct management to:
To define the risk management strategy, which of the following MUST be set by the board of directors?
Which of the following is MOST important for the successful establishment of an ethics program?
When reporting key risk indicators (KRIs) to the board, what information BEST enables risk-based decision-making?
Which of the following is the BEST indication of an effective information governance model?
Which of the following is the MOST important consideration when integrating a new vendor with an enterprise resource planning (ERP) system?
Which of the following should be the PRIMARY consideration when developing an IT strategy for the global implementation of Internet of Things (IoT) solutions?
An enterprise is implementing its first mobile sales channel. Final approval for accepting the associated IT risk should be obtained from which of the following?
Risk manager
Business sponsor
A regulator has expressed concerns about the timeliness of information reported from an enterprise. Which of the following should be done FIRST to address this issue?
An organization has decided to integrate IT risk with the enterprise risk management (ERM) framework. The FIRST step to enable this integration is to establish:
Which of the following is the GREATEST advantage of earned value management when used for evaluating benefits from the implementation of blockchain projects for IT contracts management?
An enterprise plans to migrate its applications and data to an external cloud environment. Which of the following should be the ClO's PRIMARY focus before the migration?
An ongoing project is on track according to project plan. However, a recent regulation change will have a major impact to the project. The project sponsor's NEXT step should be to:
Which of the following is the BEST approach to ensure global regulatory compliance when implementing a new business process?
Which of the following is MOST likely to have a negative impact on
accountability for information risk ownership?
Which of the following should be the PRIMARY consideration when implementing IT governance in a small, newly established organization?
A publicly traded enterprise wants to demonstrate that its board of directors is providing adequate strategic oversight of IT. Which of the following BEST supports this objective?
Which of the following should be the PRIMARY goal of implementing service level agreements (SLAs) with an outsourcing vendor?
A CIO observes that many information assets are hosted on legacy technology that can no longer be patched or updated. The systems are not currently in use, but business units are reluctant to decommission assets due to information retention requirements. Which of the following is the BEST strategic response to this situation?
A global organization has noticed a significant decrease in the return on IT investments in a particular region. To enhance project governance in this region, the CEO should FIRST
Within a governance structure for risk management, which of the following activities should be performed by the second line of defense?
An enterprise recently implemented a significant change in its business strategy by moving to a technologically advanced product with considerable impact on the business. What should be the FINAL step in completing the changes to IT processes?
Despite an adequate training budget. IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?
Which of the following is a CIO's BEST approach to ensure IT executes against an approved strategy?
Which of the following is the FIRST consideration for a CISO when implementing Zero Trust architecture?
An enterprise recently approved a bring your own device (BYOD) policy. The IT steering committee has directed IT management to develop a communication plan to disseminate information regarding the associated technical risks. Which of the following is MOST important to include in this communication plan?
When identifying improvements focused on the information asset life cycle, which of the following is CRITICAL for enabling data interoperability?
A high-tech enterprise is concerned that leading competitors have been successfully recruiting top talent from the enterprise's research and development business unit.
What should the leadership team mandate FIRST?
A small enterprise has just hired its first CIO, who has been tasked with making the IT department more efficient. What should be the CIO's NEXT step after identifying several new improvement initiatives?
When developing IT risk management policies and standards, it is MOST important to align them with:
Which of the following is the PRIMARY objective of a data protection impact assessment?
An enterprise wants to implement metrics to monitor the performance of its IT portfolio. Whose input is MOST important to consider when establishing these metrics?
Which of the following should be the MOST important consideration when establishing key performance indicators (KPIs) for IT initiatives?
Which of the following is the BEST way to encourage employees to raise ethics concerns in full confidence?
Which of the following BEST enables an enterprise to determine whether a current program for IT infrastructure migration to the cloud is continuing to provide benefits?
An enterprise plans to implement a business intelligence tool with data sources from various enterprise applications. Which of the following is the GREATEST challenge to implementation?
Executive management is concerned that IT has not achieved its performance targets. At the end of the fiscal year, it was noted the reason was largely due to insufficient spending on key IT initiatives. Which of the following would help to alleviate the issue for the coming year?
Following a recent change to enterprise strategy, which of the following would be MOST important for the CIO to review?
An enterprise has launched a digitization effort requiring a single view of customer information across all product lines. Which of the following should be done FIRST to enable this initiative?
Which of the following has the GREATEST impact on the design of an IT governance framework?
An enterprise plans to implement a business intelligence (Bl) tool with data sources from various enterprise applications. Which of the following is the GREATEST challenge to implementation?
As the required core competencies of the IT workforce are anticipated and identified, what is the NEXT step in strengthening the department's human resource assets?
Which of the following should be the MAIN reason for an enterprise to implement an IT risk management framework?
An IT steering committee wants the enterprise's mobile workforce to use cloud-based file storage to save non-sensitive corporate data, removing the need for remote access to that information. Before this change is implemented, what should be included in the data management policy?
The CEO of a large enterprise has announced me commencement of a major business expansion that will double the size of the organization. IT will need to support the expected demand expansion. What should the CIO do FIRST?
Which of the following is the MOST comprehensive method to report on overall IT performance to the board of directors?
The BEST way to ensure an IT steering committee meets enterprise objectives is to:
Which of the following is the MOST effective approach to ensure senior management sponsorship of IT risk management?
An enterprise has decided to utilize a cloud vendor for the first time to provide email as a service, eliminating in-house email capabilities. Which of the following IT strategic actions should be triggered by this decision?
Which of the following is the BEST approach when reviewing The security status of a new business acquisition?
A review of the effectiveness of IT governance within an enterprise has revealed that several innovation improvement initiatives are failing. An analysis shows a lack of stakeholder buy-in to the improvements. Implementing which of the following would have prevented this problem?
Which of the following components of a policy BEST enables the governance of enterprise IT?
While monitoring an enterprise's IT projects portfolio, it is discovered that a project is 75% complete, but all budgeted resources have been expended. Which of the following is the MOST important task to perform?
While assessing the feasibility of introducing new IT practices and standards into the IT governance framework, it is CRITICAL to understand an organization's:
Which of the following BEST lowers costs and improves scalability from an IT enterprise architecture (EA) perspective?
An IT governance committee wants to ensure there is a clear description of the "data owner" in the enterprise data policy. Which of the following would BEST define the owner of data stored in an external cloud?
An IT audit reveals inconsistent maintenance of data privacy in enterprise systems primarily due to a lack of data sensitivity categorizations. Once the categorizations are defined, what is the BEST long-term strategic response by IT governance to address this problem?
An enterprise is initiating efforts to improve system availability to mitigate IT risk to the business. Which of the following results would be MOST important to report to the CIO to measure progress?
Which of the following is the BEST method for making a strategic decision to invest in cloud services?
Which of the following is the BEST indication of effective IT-business strategic alignment?
A CIO believes that a recent mission-critical IT decision by the board of directors is not in the best financial interest of all stakeholders. Which of the following is the MOST ethical course of action?
Which of the following is the MOST important attribute of an information steward?
An enterprise's service center is experiencing long delays in fulfilling! T service requests and very low customer satisfaction. The BEST way to determine if staff competency is the root cause of these performance problems is to compare required staff competencies with:
An enterprise learns that a new privacy regulation was recently published to protect customers in the event of a breach involving personally identifiable information (Pll). The IT risk management team's FIRST course of action should be to:
A retail enterprise has cost reduction as its top priority. From a governance perspective, which of the following should be the MOST important consideration when evaluating different IT investment options?
A rail transport company has the worst on-time arrival record in the industry due to an antiquated IT system that controls scheduling. Despite employee resistance, an initiative lo upgrade the technology and related processes has been approved. To maximize employee engagement throughout the project, which of the following should be in place prior to the start of the initiative?
Senior management wants to promote investment in IT, but is uncertain that associated risks are being properly identified. The BEST way to address this concern is to:
A new and expanding enterprise has recently received a report indicating 90% of its data has been collected in just the last six months, triggering data breach and privacy concerns. What should be the IT steering committee's FIRST course of action to ensure new data is managed effectively?
An organization's board of directors has questioned the value provided by IT key performance indicators (KPIs). Which of the following is the BEST way to determine whether the KPIs adequately support organizational objectives?
An enterprise is planning to replace multiple enterprise resource planning (ERP) systems at various regions with one company-wide ERP system. The main objective of this change is to achieve economies of scale efficiencies resulting in cost reductions. To meet this objective, what is the BEST approach in the planning phase of the project?
The board of directors of an enterprise has approved a three-year IT strategic program to centralize the core business processes of its global entities into one core system. Which of the following should be the ClO's NEXT step?
Which of the following is the MOST effective way for a CIO to govern business unit deployment of shadow IT applications in a cloud environment?
Due to continually missed service level agreements (SLAs), an enterprise plans to terminate its contract with a vendor providing IT help desk services. The enterprise s IT department willassume the help desk-related responsibilities. Which of the following would BEST facilitate this transition?
A CIO has been asked to modify an organization's IT performance measurement system to reflect recent changes in technology, including the movement of some data processing to a cloud solution. Which of the following is the PRIMARY consideration when designing such a measurement system?
A CEO determines the enterprise is lagging behind its competitors in consumer mobile offerings, and mandates an aggressive rollout of several new mobile services within the next 12 months. To ensure the IT organization is capable of supporting this business objective, what should the CIO do FIRST?
Which of the following roles has PRIMARY accountability for the security related to data assets?
An enterprise considers implementing a system that uses a technology that is not in line with its IT strategy. The business case indicates significant benefit to the enterprise. Which of the following is the BEST way to manage this situation within an IT governance framework?
Of the following, who should be responsible for ensuring the regular review of quality management performance against defined quality metrics?
An enterprise has established a new department to oversee the life cycle of activities that support data management objectives. Which of the following should be done NEXT?
Which of the following is the MOST important consideration for data classification to be successfully implemented?
Which of the following is the BEST way to ensure new systems can be adequately supported once in production?
An enterprise is evaluating a possible strategic initiative for which IT would be the main driver. There are several risk scenarios associated with the initiative that have been identified. Which of the following should be done FIRST to facilitate a decision?
A large retail chain realizes that while there has not been any loss of data, IT security has not been a priority and should become a key goal for the enterprise. What should be the FIRST high-level initiative for a newly created IT strategy committee in order to support this business goal?
What is the PRIMARY objective for performing an IT due diligence review prior to the acquisition of a competitor?
IT has launched new portfolio management policies and processes to improve the alignment of IT projects with enterprise goals. The latest audit report indicates that no improvement has been made due to confusion in the decision-making process. Which of the following is the BEST course of action for the CIO?