Month End Sale - Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 65percent

Welcome To DumpsPedia

CGEIT Sample Questions Answers

Questions 4

Which of the following BEST lowers costs and improves scalability from an IT enterprise architecture (EA) perspective?

Options:

A.

Cost management

B.

IT strategic sourcing

C.

Standardization

D.

Business agility

Buy Now
Questions 5

A rail transport company has the worst on-time arrival record in the industry due to an antiquated IT system that controls scheduling. Despite employee resistance, an initiative lo upgrade the technology and related processes has been approved. To maximize employee engagement throughout the project, which of the following should be in place prior to the start of the initiative?

Options:

A.

Procurement management plan

B.

Organizational change management plan

C.

Risk response plan

D.

Resource management plan

Buy Now
Questions 6

An enterprise has decided to create its first mobile application. The IT director is concerned about the potential impact of this initiative. Which of the following is the MOST important input for managing the risk associated with this initiative?

Options:

A.

Enterprise architecture (EA)

B.

IT risk scorecard

C.

Enterprise risk appetite

D.

Business requirements

Buy Now
Questions 7

An enterprise made a significant change to its business operating model that resulted in a new strategic direction. Which of the following should be reviewed FIRST to ensure IT congruence with the new business strategy?

Options:

A.

IT risk appetite

B.

Enterprise project management framework

C.

IT investment portfolio

D.

Information systems architecture

Buy Now
Questions 8

An IT risk assessment for a large healthcare group revealed an increased risk of unauthorized disclosure of information. Which of the following should be established FIRST to address the risk?

Options:

A.

Data encryption tools

B.

Data loss prevention tools

C.

Data classification policy

D.

Data retention policy

Buy Now
Questions 9

Which of the following would be the PRIMARY impact on IT governance when a business strategy is changed?

Options:

A.

Performance outcomes of IT objectives

B.

IT governance structure

C.

Maturity level of IT processes

D.

Relationship level with IT outsourcers

Buy Now
Questions 10

Which of the following is the MOST important consideration for data classification to be successfully implemented?

Options:

A.

Users should be provided with clear instructions that are easy to follow and understand.

B.

The data classification tools integrate with other tools that help manage the data.

C.

The classification scheme should be closely aligned with the IT strategic plan.

D.

Senior management should be properly trained in monitoring compliance.

Buy Now
Questions 11

An organization's board of directors has questioned the value provided by IT key performance indicators (KPIs). Which of the following is the BEST way to determine whether the KPIs adequately support organizational objectives?

Options:

A.

Define a strategy for IT measurement.

B.

Define policies and procedures around current KPIs.

C.

Review the KPIs with key business executives.

D.

Work directly with the CEO to identify what measures should be used.

Buy Now
Questions 12

An enterprise has a zero-tolerance policy regarding security. This policy is causing a large number of email attachments to be blocked and is a disruption to enterprise. Which of the following should be the FIRST governance step to address this email issue?

Options:

A.

Direct the development of an email usage policy.

B.

Obtain senior management input based on identified risk.

C.

Recommend business sign-off on the zero-tolerance policy.

D.

Introduce an exception process.

Buy Now
Questions 13

A large financial institution is considering outsourcing customer call center operations which will allow the chosen vendor to access systems from offshore locations. Which of the following represents the GREATEST risk?

Options:

A.

Inconsistent customer service and reporting

B.

Loss of data confidentiality

C.

Lack of network availability

D.

Inadequate business continuity planning

Buy Now
Questions 14

Which of the following is an ADVANTAGE of using strategy mapping?

Options:

A.

It provides effective indicators of productivity and growth.

B.

It depicts the maturity levels of processes that support organizational strategy.

C.

It identifies barriers to strategic alignment and links them to specific outcomes.

D.

It depicts the cause-and-effect linked relationships between strategic objectives.

Buy Now
Questions 15

Which of the following would be of MOST concern regarding the effectiveness of risk management processes?

Options:

A.

Key risk indicators (KRIs) are not established.

B.

Risk management requirements are not included in performance reviews.

C.

The plans and procedures are not updated on an annual basis.

D.

There is no framework to ensure effective reporting of risk events.

Buy Now
Questions 16

A retail enterprise has cost reduction as its top priority. From a governance perspective, which of the following should be the MOST important consideration when evaluating different IT investment options?

Options:

A.

Support for increased sales

B.

Risk associated with each option

C.

Industry best practices

D.

Business value impact

Buy Now
Questions 17

A review of the effectiveness of IT governance within an enterprise has revealed that several innovation improvement initiatives are failing. An analysis shows a lack of stakeholder buy-in to the improvements. Implementing which of the following would have prevented this problem?

Options:

A.

An IT project roadmap

B.

An IT risk management program

C.

A change management program

D.

A service delivery framework

Buy Now
Questions 18

Senior management wants to promote investment in IT, but is uncertain that associated risks are being properly identified. The BEST way to address this concern is to:

Options:

A.

engage an external consultant to develop risk scenarios.

B.

appoint an IT representative to the business risk committee.

C.

assign an IT cost controller to the finance department.

D.

ensure business cases are developed by IT.

Buy Now
Questions 19

An enterprise's information security function is making changes to its data retention and backup policies. Which of the following presents the GREATEST risk?

Options:

A.

Business data owners were not consulted.

B.

The new policies Increase the cost of data backups.

C.

Data backups will be hosted at third-party locations.

D.

The retention period for data backups is Increased.

Buy Now
Questions 20

The CIO of a financial services company is tasked with ensuring IT processes are in compliance with recently instituted regulatory changes. The FIRST course of action should be to:

Options:

A.

align IT project portfolio with regulatory requirements.

B.

create an IT balanced scorecard.

C.

identify the penalties for noncompliance.

D.

perform a current state assessment.

Buy Now
Questions 21

The BEST way to manage continuous improvement of governance-related processes is to:

Options:

A.

assess existing process resource capacities.

B.

define accountability based on roles and responsibilities.

C.

apply effective quality management practices.

D.

require third-party independent reviews.

Buy Now
Questions 22

An IT audit reveals inconsistent maintenance of data privacy in enterprise systems primarily due to a lack of data sensitivity categorizations. Once the categorizations are defined, what is the BEST long-term strategic response by IT governance to address this problem?

Options:

A.

Standardize data classification processes throughout the enterprise.

B.

Incorporate enterprise privacy categorizations into contracts.

C.

Require business impact analyses (BIAs) for enterprise systems.

D.

Reassess the data governance policy.

Buy Now
Questions 23

Which of the following is MOST important when an IT-enabled business initiative involves multiple business functions?

Options:

A.

Defining cross-departmental budget allocation

B.

Conducting a systemic risk assessment

C.

Developing independent business cases

D.

Establishing a steering committee with business representation

Buy Now
Questions 24

An IT governance committee wants to ensure there is a clear description of the "data owner" in the enterprise data policy. Which of the following would BEST define the owner of data stored in an external cloud?

Options:

A.

The business leader who is most impacted by the loss of data.

B.

The risk manager who is responsible for protecting data stored in the cloud.

C.

The contract manager who monitors the security of the cloud provider.

D.

The vendor who submits the data to the organization via online forms

Buy Now
Questions 25

What is the PRIMARY objective for performing an IT due diligence review prior to the acquisition of a competitor?

Options:

A.

Document the competitor's governance structure.

B.

Ensure that the competitor understands significant IT risks.

C.

Assess the status of the risk profile of the competitor.

D.

Determine whether the competitor is using industry-accepted practices.

Buy Now
Questions 26

Who is PRIMARILY accountable for delivering the benefits of an IT-enabled investment program to the enterprise?

Options:

A.

Program manager

B.

IT steering committee chair

C.

CIO

D.

Business sponsor

Buy Now
Questions 27

Which of the following is the BEST way to demonstrate that IT strategy supports a new enterprise strategy?

Options:

A.

Monitor new key risk indicators (KRIs).

B.

Measure return on IT investments against balanced scorecards.

C.

Review and update the portfolio management process.

D.

Map IT programs to business goals.

Buy Now
Questions 28

An enterprise plans to implement a business intelligence (Bl) tool with data sources from various enterprise applications. Which of the following is the GREATEST challenge to implementation?

Options:

A.

Interface issues between enterprise and Bl applications

B.

Large volumes of data fed from enterprise applications

C.

The need for staff to be trained on the new Bl tool

D.

Data definition and mapping sources from applications

Buy Now
Questions 29

A global financial institution has decided to integrate data from branch locations into a common database to address regulatory reporting requirements. Analysis of data flows and the full data life cycle should be conducted at which level?

Options:

A.

Transaction level

B.

Enterprise level

C.

Branch level

D.

Department level

Buy Now
Questions 30

Which of the following is the MOST effective way of assessing enterprise risk?

Options:

A.

Business impact analysis (BIA)

B.

Business vulnerability assessment

C.

Likelihood of threat analysis

D.

Operational risk assessment

Buy Now
Questions 31

Which of the following is the BEST way for a CIO to secure support for a strategy to achieve long-term IT objectives?

Options:

A.

Make the necessary strategic decisions and notify staff accordingly.

B.

Develop tactics to implement the strategy and share with stakeholders.

C.

Develop a communication plan for distribution of information to staff.

D.

Meet with stakeholders to explain the strategy and incorporate feedback.

Buy Now
Questions 32

Which of the following is MOST important to effectively initiate IT-enabled change?

Options:

A.

Establish a change management process.

B.

Obtain top management support and ownership.

C.

Ensure compliance with corporate policy.

D.

Benchmark against best practices.

Buy Now
Questions 33

A new CIO has been charged with updating the IT governance structure. Which of the following is the MOST important consideration to effectively influence organizational and process change?

Options:

A.

Obtaining guidance from consultants

B.

Aligning IT services to business processes

C.

Redefining the IT risk appetite

D.

Ensuring the commitment of stakeholders

Buy Now
Questions 34

Which of the following BEST reflects the ethical values adopted by an IT organization?

Options:

A.

IT principles and policies

B.

IT balanced scorecard

C.

IT governance framework

D.

IT goals and objectives

Buy Now
Questions 35

To reduce the risk of reputational damage through inappropriate use of social media by employees outside of the workplace, the enterprise approach regarding social media should PRIMARILY focus on;

Options:

A.

implementing preventative controls.

B.

developing policies on social media.

C.

implementing a review of processes utilizing social media.

D.

ensuring each use of social media is approved by management.

Buy Now
Questions 36

A healthcare enterprise that is subject to strict compliance requirements has decided to outsource several key IT services to third-party providers. Which of the following would be the BEST way to assess compliance and avoid reputational damage?

Options:

A.

Require quarterly reports from the providers demonstrating compliance.

B.

Require documentation that the providers have adequate controls in place.

C.

Exercise the right to perform an audit.

D.

Impose monetary penalties for noncompliance.

Buy Now
Questions 37

The results of an internal audit show that the business and IT acquire resources differently, which causes duplicate purchases. Which of the following is the BEST way to address this issue?

Options:

A.

Align IT objectives to the business procurement process.

B.

Involve business in IT procurement decisions.

C.

Establish a centralized procurement approval process.

D.

Define roles and responsibilities through a RAG chart

Buy Now
Questions 38

Which of the following would BEST enable business innovation through IT?

Options:

A.

Outsourcing of IT to a strategic business partner

B.

Business participation in IT strategy development

C.

Adoption of a standardized business development life cycle

D.

IT participation in business strategy development

Buy Now
Questions 39

An enterprise's board of directors can BEST manage enterprise risk by:

Options:

A.

mandating board-approved enterprise risk management (ERM) modifications.

B.

requiring the establishment of an enterprise risk management (ERM) framework.

C.

requiring the establishment of an enterprise-wide program management office.

D.

ensuring the cost-effectiveness of the internal control system.

Buy Now
Questions 40

Which of the following is the BEST method for making a strategic decision to invest in cloud services?

Options:

A.

Prepare a business case.

B.

Prepare a request for information (RFI),

C.

Benchmarking.

D.

Define a balanced scorecard.

Buy Now
Questions 41

Which of the following is MOST important for the effective design of an IT balanced scorecard?

Options:

A.

On-demand reporting and continuous monitoring

B.

Consulting with the CIO

C.

Emphasizing the financial results

D.

Identifying appropriate key performance indicators (KPls)

Buy Now
Questions 42

A large organization with branches across many countries is in the midst of an enterprise resource planning (ERP) transformation. The IT organization receives news that the branches in a country where the impact to the enterprise is to be greatest are being sold. What should be the NEXT step?

Options:

A.

Update the ERP business case and re-evaluate the ROI.

B.

Cancel the ERP transformation and re-allocate project funds.

C.

Adjust the ERP implementation plan and budget.

D.

Continue with the ERP migration according to plan.

Buy Now
Questions 43

Which of the following is the PRIMARY element in sustaining an effective governance framework?

Options:

A.

Identification of optimal business resources

B.

Establishment of a performance metric system

C.

Ranking of critical business risks

D.

Assurance of the execution of business controls

Buy Now
Questions 44

Which of the following components of a policy BEST enables the governance of enterprise IT?

Options:

A.

Disciplinary actions

B.

Regulatory requirements

C.

Roles and responsibilities

D.

Terms and definitions

Buy Now
Questions 45

The IT program manager does not see the value of conducting risk assessments for a new major IT project. The manager is reluctant to cooperate with internal auditors and the newly formed steering committee. Midway through the project, program requirements were changed because the CEO is a friend of a vendor and wants to implement this vendor's new technology. This decision will cause the current IT program budget to be insufficient and will be shown as overspending.

After the requirement change request, the IT program manager should FIRST:

Options:

A.

obtain confirmation from the business and a decision by the steering committee.

B.

request additional funding from the business owner to cover the additional scope.

C.

report the matter to internal audit as a program deviation to be reviewed.

D.

align IT with the business and agree to the business request.

Buy Now
Questions 46

Which of the following should be the PRIMARY consideration when developing an IT strategy for the global implementation of Internet of Things (IoT) solutions?

Options:

A.

Hiring additional IT staff with IoT expertise

B.

Addressing security and privacy

C.

Identifying cost-effective IoT devices

D.

Maintaining compatibility with legacy systems

Buy Now
Questions 47

Which of the following is the PRIMARY benefit of communicating the IT strategy across the enterprise?

Options:

A.

On-time and on-budget delivery of strategic projects

B.

Improvement in IT balanced scorecard performance

C.

Optimization of IT investment in supporting business objectives

D.

Reduced organizational resistance during strategy execution

Buy Now
Questions 48

Which of the following is the PRIMARY ongoing responsibility of the IT governance function related to risk?

Options:

A.

Responding to and controlling all IT risk events

B.

Communicating the enterprise risk management plan

C.

Ensuring IT risk management is aligned with business risk appetite

D.

Verifying that all business units have staff skilled at assessing risk

Buy Now
Questions 49

Which of the following would be the BEST way to facilitate the adoption of strong IT governance practices throughout a multi-divisional enterprise?

Options:

A.

Ensuring each divisional policy is consistent with corporate policy

B.

Ensuring divisional governance fosters continuous improvement processes

C.

Mandating data standardization across the distributed enterprise

D.

Documenting and communicating key management practices across divisions

Buy Now
Questions 50

Which of the following BEST enables the alignment of user access rights with business requirements?

Options:

A.

Data classification policy

B.

Maturity model

C.

System design

D.

Data architecture model

Buy Now
Questions 51

Which of the following is MOST important for a data steward to verify when a system's data is edited by an automated tool to fix an incident?

Options:

A.

The change has been requested by the business department and approved by the data owner.

B.

The change is documented in preparation for future audits.

C.

The change maintains consistency among databases and has no other impacts.

D.

The change is a temporary fix for the incident, and the permanent solution is addressed by problem management.

Buy Now
Questions 52

An enterprise has established a new department to oversee the life cycle of activities that support data management objectives. Which of the following should be done NEXT?

Options:

A.

Develop a business continuity plan (BCP).

B.

Assess the current data business model.

C.

Review data privacy requirements.

D.

Establish a RACI chart

Buy Now
Questions 53

Which of the following groups should approve the implementation of new technology?

Options:

A.

IT steering committee

B.

IT audit department

C.

Portfolio management office

D.

Program management office

Buy Now
Questions 54

A large enterprise that is diversifying its business will be transitioning to a new software platform, which is expected to cause data changes. Which of the following should be done FIRST when developing the related metadata management process?

Options:

A.

Require an update to enterprise data policies.

B.

Request an impact analysis.

C.

Review documented data interdependence.

D.

Validate against existing architecture.

Buy Now
Questions 55

Despite an adequate training budget. IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?

Options:

A.

Provide incentives for IT staff to attend outside conferences and training

B.

Create a standard-setting center of excellence for IT.

C.

Require human resources (HR) to recruit new talent using an established IT skills matrix.

D.

Establish an agreed-upon skills development plan with each employee

Buy Now
Questions 56

A CIO engages a consulting firm to conduct a benchmark analysis of the organization’s IT governance framework against industry best practices. Several recommendations to improve the maturity of the framework are identified. Which of the following should be the CIO's NEXT course of action?

Options:

A.

Develop a plan to integrate the recommendations

B.

Appoint a project manager to implement the recommendations

C.

Obtain approval from the IT steering committee to implement the recommendations

D.

Evaluate the feasibility of the recommendations

Buy Now
Questions 57

While monitoring an enterprise's IT projects portfolio, it is discovered that a project is 75% complete, but all budgeted resources have been expended. Which of the following is the MOST important task to perform?

Options:

A.

Review the IT investments.

B.

Reorganize the IT projects portfolio.

C.

Re-evaluate the business case.

D.

Review the IT governance structure.

Buy Now
Questions 58

When an enterprise is evaluating potential IT service vendors, which of the following BEST enables a clear understanding of the vendor's capabilities that will be critical to the enterprise's strategy?

Due diligence process

Options:

A.

Independent audit results

B.

Historical service level agreements (SLAs)

C.

Benchmarking analysis results

Buy Now
Questions 59

Following a recent change to enterprise strategy, which of the following would be MOST important for the CIO to review?

Options:

A.

Existing performance and capacity plans

B.

A list of current and planned IT projects

C.

Historical IT budget allocations

D.

The enterprise SWOT analysis

Buy Now
Questions 60

An enterprise plans to migrate its applications and data to an external cloud environment. Which of the following should be the ClO's PRIMARY focus before the migration?

Options:

A.

Reviewing the information governance framework

B.

Selecting best-of-breed cloud offerings

C.

Updates the enterprise architecture (EA) repository

D.

Conducting IT staff training to manage cloud workloads

Buy Now
Questions 61

A CIO believes that a recent mission-critical IT decision by the board of directors is not in the best financial interest of all stakeholders. Which of the following is the MOST ethical course of action?

Options:

A.

Share concerns with the legal department.

B.

Request a meeting with the board.

C.

Engage an independent cost-benefit analysis.

D.

Request an internal audit review of the board's decision.

Buy Now
Questions 62

To measure the value of IT-enabled investments, an enterprise needs to identify its drivers as defined by its:

Options:

A.

technology strategy.

B.

value statements.

C.

service level agreements (SLAs).

D.

business strategy.

Buy Now
Questions 63

The PRIMARY objective of establishing outcome measures is to:

Options:

A.

Clarify the cause-and-effect relationship of the strategy

B.

Monitor whether the chosen strategy is successful

C.

Understand how the strategy will be achieved

D.

Demonstrate commitment to IT governance

Buy Now
Questions 64

Which of the following is the FIRST step when developing an IT risk management framework?

Options:

A.

Promoting a culture of risk awareness

B.

Establishing a risk control library

C.

Aligning to enterprise risk management (ERM)

D.

Establishing risk appetite

Buy Now
Questions 65

Which of the following presents the GREATEST challenge for a large-scale enterprise when procuring Infrastructure as a Service (IaaS)?

Options:

A.

Testing the vendor resiliency plan annually

B.

Protecting the enterprise from labor liability

C.

Ensuring the vendor meets corporate requirements

D.

Monitoring key performance indicators (KPIs)

Buy Now
Questions 66

Which of the following is MOST likely to have a negative impact on

accountability for information risk ownership?

Options:

A.

The risk owner is a department manager, and the control owner is a member of the risk owner's staff.

B.

Information risk is assigned to a department, and an individual owner has not been assigned.

C.

The risk owner and the control owner of the information do not work in the same department.

D.

The same person is listed as both the control owner and the risk owner for the information.

Buy Now
Questions 67

An enterprise has decided to use third-party software for a business process which is hosted and supported by the same third party. The BEST way to provide quality of service oversight would be to establish a process:

Options:

A.

for robust change management.

B.

for periodic service provider audits.

C.

for enterprise architecture (EA) updates.

D.

to qualify service providers.

Buy Now
Questions 68

A high-tech enterprise is concerned that leading competitors have been successfully recruiting top talent from the enterprise's research and development business unit.

What should the leadership team mandate FIRST?

Options:

A.

A SWOT analysis

B.

An incentive and retention program

C.

A root cause analysis

D.

An aggressive talent acquisition program

Buy Now
Questions 69

Which of the following would be MOST helpful to review when determining how to allocate IT resources during a resource shortage?

Options:

A.

IT strategic plan

B.

IT skills inventory

C.

IT organizational structure

D.

IT skill development plan

Buy Now
Questions 70

An enterprise recently implemented a significant change in its business strategy by moving to a technologically advanced product with considerable impact on the business. What should be the FINAL step in completing the changes to IT processes?

Options:

A.

Updating the configuration management database (CMDB)

B.

Empowering the business to embrace the changes

C.

Ensuring a return to stabilized business operations

D.

Updating the enterprise architecture (EA)

Buy Now
Questions 71

When determining the desired maturity levels for IT governance processes, it is MOST important to:

Options:

A.

Focus on existing strengths as key drivers for the target levels

B.

Ensure target levels are in line with external competitor benchmarks

C.

Agree on target levels in response to need

D.

Ensure that maturity can be achieved at the lowest cost

Buy Now
Questions 72

A global organization has noticed a significant decrease in the return on IT investments in a particular region. To enhance project governance in this region, the CEO should FIRST

Options:

A.

Perform a program benefit calculation and review the project selection methodology

B.

Suspend funding until project managers from better-performing regions can be assigned

C.

Perform an independent review of business cases for each current and proposed project in the region

D.

Work with the region's leadership to better understand why the situation has occurred

Buy Now
Questions 73

Which of the following is the BEST indicator of the effectiveness of IT governance in an enterprise?

Options:

A.

Value delivery

B.

Resource utilization

C.

Residual risk

D.

Project delivery

Buy Now
Questions 74

An enterprise's current business continuity plan (BCP) fails to consider many common crisis events. What would be MOST helpful to address this situation?

Options:

A.

Engage stakeholders in scenario development

B.

Review the root cause analysis

C.

Require further walk-through tests

D.

Review and update the crisis communication plan

Buy Now
Questions 75

Which of the following is the PRIMARY responsibility of a data steward at an enterprise with mature data management programs?

Options:

A.

Implementing processes for data collection and use

B.

Ensuring compliance with data privacy laws and regulations

C.

Establishing data quality requirements and metrics

D.

Developing data-related policies and procedures

Buy Now
Questions 76

Which of the following is the BEST way for a CIO to provide progress updates on a newly implemented IT strategic plan to the board of directors?

Present an IT summary dashboard.

Present IT critical success factors (CSFs).

Report results Of key risk indicators (KRIs).

Options:

A.

Report results of stage-gate reviews.

Buy Now
Questions 77

When establishing a methodology for business cases, it would be MOST beneficial for an enterprise to include procedures for:

Options:

A.

updating the business case throughout its life cycle.

B.

addressing required changes outside the business case.

C.

identifying metrics post-implementation to measure project success.

D.

entering the business case into the enterprise architecture (EA).

Buy Now
Questions 78

An enterprise has decided to adopt cloud services. Which of the following should be established FIRST?

Options:

A.

Service level agreements (SLAs)

B.

Business continuity plan (BCP)

C.

Risk tolerance levels

D.

Third-party management framework

Buy Now
Questions 79

Which of the following should be considered FIRST when assessing the implications of new external regulations on IT compliance?

Options:

A.

IT policies and procedures that need revision

B.

Resource burden for implementation

C.

Gaps in skills and experience of IT employees

D.

Impact on contracts with service providers

Buy Now
Questions 80

A CIO is planning to interview enterprise stakeholders to assess whether the IT strategic plan is continuing to support enterprise business objectives. The CIO would be MOST effective by starting the interview process with:

Options:

A.

the executive team.

B.

the internal auditors.

C.

senior IT managers.

D.

business process owners.

Buy Now
Questions 81

A board of directors has mandated that key performance indicators (KPIs) be developed for all IT projects that are created in support of a business objective. Which of the following MUST be reflected in the KPIs to be effective?

Options:

A.

Future-state architecture

B.

Critical success factors (CSFs)

C.

Portfolio management principles

D.

Key risk indicators (KRIs)

Buy Now
Questions 82

Which of the following is MOST important to ensure when aligning IT and enterprise resource management processes?

Options:

A.

IT sourcing processes are in place

B.

IT provides input for business strategy development

C.

IT resources are mapped to business priorities

D.

IT resource monitoring and oversight is in place

Buy Now
Questions 83

A CIO was notified that a new employee was observed wearing a headset with an optical lens at the organization's data center. The individual was entering voice commands into the device. When approached, the employee explained the device is a new personal technology serving as a hands-free version of a smart phone. The CIO is concerned with potential security vulnerabilities of allowing such devices, and whether they should be banned from the facility. What should be the NEXT course of action in response to the ClO's concern?

Options:

A.

Define a risk mitigation strategy.

B.

Update the acceptable use policy.

C.

Research competitor usage of similar devices.

D.

Assess the risk associated with the device.

Buy Now
Questions 84

An enterprise learns that some of its business divisions have been approaching technology vendors for cloud services, resulting in duplicate support contracts and underutilization of IT services. Which of the following should be done FIRST to address this issue?

Options:

A.

Review the enterprise IT procurement policy.

B.

Re-negotiate contracts with vendors to request discounts.

C.

Require updates to the IT procurement process.

D.

Conduct an audit to investigate utilization of cloud services.

Buy Now
Questions 85

An enterprise has a centralized IT function but also allows business units to have their own technology operations, resulting in duplicate technologies and conflicting priorities. Which of the following should be done FIRST to reduce the complexity of the IT landscape?

Promote automation tools used by the business units.

Options:

A.

Conduct strategic planning with business units.

B.

Migrate all in-house systems to an external cloud environment.

C.

Standardize technology architecture on common products.

Buy Now
Questions 86

An enterprise is concerned about the community impact of its data center noise levels. Which of the following is the enterprise’s BEST course of action?

Options:

A.

Proactively reduce after-hours operations

B.

Pursue acquisition of surrounding properties

C.

Wait for a formal complaint to be filed

D.

Seek input from appropriate stakeholders

Buy Now
Questions 87

Which of the following is the GREATEST consideration when evaluating whether to comply with the new carbon footprint regulations impacted by blockchain technology?

Options:

A.

The enterprise's organizational structure

B.

The enterprise's risk appetite

C.

The current IT process capability maturity

D.

The IT strategic plan

Buy Now
Questions 88

An enterprise recently approved a bring your own device (BYOD) policy. The IT steering committee has directed IT management to develop a communication plan to disseminate information regarding the associated technical risks. Which of the following is MOST important to include in this communication plan?

Options:

A.

A link on the corporate intranet to the BYOD policy

B.

Potential exposures and impacts using common terms

C.

Schedule and content for mandatory training

D.

Disciplinary actions for violation of the BYOD policy

Buy Now
Questions 89

An enterprise has made the strategic decision to begin a global expansion program which will require opening sales offices in countries across the world. Which of the following should be the FIRST consideration with regard to the IT service desk which will remain centralized?

The effect of regional differences On service delivery

Identification of IT service desk functions that can be outsourced

Options:

A.

Enforcement Of a standardized policy across all regions

B.

Availability of adequate resources to provide support for new users

Buy Now
Questions 90

An enterprise is implementing its first mobile sales channel. Final approval for accepting the associated IT risk should be obtained from which of the following?

Risk manager

Business sponsor

Options:

A.

Chief information officer (CIO)

B.

IT steering committee

Buy Now
Questions 91

A large enterprise is implementing an information security policy exception process. The BEST way to ensure that security risk is properly addressed is to:

confirm process owners' acceptance of residual risk.

perform an internal and external network penetration test.

obtain IT security approval on security policy exceptions.

Options:

A.

benchmark policy against industry best practice.

Buy Now
Questions 92

Which of the following is the MOST efficient approach for using risk scenarios to evaluate a new business opportunity?

Options:

A.

Related risks are consolidated into one scenario for analysis.

B.

Risk events are identified bottom-up and top-down.

C.

Risk identification leverages past audit and compliance reports.

D.

Risk scenario narratives are summarized and limited in length.

Buy Now
Questions 93

After experiencing poor recovery times following a catastrophic event, an enterprise is seeking to improve its disaster recovery capabilities. Which of the following would BEST enable the enterprise to accomplish this objective?

Options:

A.

Continuous testing of disaster recovery capabilities with implementation of lessons learned

B.

Increased training and monitoring for disaster recovery personnel who perform below expectations

C.

Annual review and updates to the disaster recovery plan (DRP)

D.

Increased outsourcing of disaster recovery capabilities to ensure reliability

Buy Now
Questions 94

When reporting key risk indicators (KRIs) to the board, what information BEST enables risk-based decision-making?

Options:

A.

Risk appetite, risk threshold, and risk tolerance

B.

Classification of current business risk

C.

Emerging industry risk trends and benchmarks

D.

Costs and resource needs related to risk mitigation measures

Buy Now
Questions 95

Which strategic planning approach would be MOST appropriate for a large enterprise to follow when revamping its IT services?

Options:

A.

Addressing gaps within the management of IT-related risk

B.

Focusing on business innovation through knowledge, expertise, and initiatives

C.

Calibrating and scaling delivery Of IT services in line with business requirements

D.

Adhering to on-time and on-budget IT service delivery

Buy Now
Questions 96

The MOST appropriate method for evaluating the capability of IT governance is through the use of:

Options:

A.

a maturity assessment.

B.

benchmarking.

C.

a cost-benefit analysis.

D.

a risk assessment.

Buy Now
Questions 97

Which of the following is MOST important to include in the customer dimension of an IT balanced scorecard?

Options:

A.

Business value creation

B.

Stakeholder satisfaction

C.

Maintenance of IT operations

D.

Support for corporate customers

Buy Now
Questions 98

Which of the following situations provides the BEST justification for considering the adoption of a qualitative risk assessment method?

Options:

A.

Determining a quantitative risk score would require complex calculations

B.

It is cost prohibitive to obtain relevant historical quantitative data

C.

There are fewer information assets in the risk register

D.

A higher risk tolerance level has been defined by enterprise leadership

Buy Now
Questions 99

What is the BEST way for IT to achieve compliance with regulatory requirements?

Options:

A.

Enforce IT policies and procedures.

B.

Create an IT project portfolio.

C.

Review an IT performance dashboard.

D.

Report on IT audit findings and action plans.

Buy Now
Questions 100

Which of the following is the BEST way to encourage employees to raise ethics concerns in full confidence?

Options:

A.

Publish and enforce a code of conduct policy.

B.

Provide access to legal resource benefits.

C.

Establish and communicate a whistle-blower policy.

D.

Provide protection language in employment contracts.

Buy Now
Questions 101

When a shortfall of IT resources is identified, the FIRST course of action is to;

Options:

A.

perform a business impact analysis (BIA).

B.

reallocate the budget to close the gap in resources.

C.

reduce business requirements.

D.

negotiate best pricing for contracted resources.

Buy Now
Questions 102

What is the PRIMARY benefit of aligning information architecture with enterprise architecture (EA)?

Options:

A.

It improves communication with senior management and the business.

B.

It ensures the adoption of enterprise data quality standards.

C.

It enables the tracing of data to business functions.

D.

It facilitates appropriate access to data consumers.

Buy Now
Questions 103

Which of the following should a CIO review to obtain a holistic view of IT performance when identifying potential gaps in service delivery?

Options:

A.

Key performance indicators (KPIs)

B.

Return on investment (ROI) analysis

C.

Service level agreement (SLA) reporting

D.

Staff performance evaluations

Buy Now
Questions 104

A CIO wants to make improvements to the enterprise's IT governance. Which of the following would BEST help to demonstrate the expected benefits from proposed changes?

Options:

A.

RACI chart

B.

Balanced scorecard

C.

Enterprise architecture (EA)

D.

Business case

Buy Now
Questions 105

Which of the following is the BEST way for a CIO to ensure that IT-related training is taken seriously by the IT management team and direct employees?

Options:

A.

Develop training programs based on results of an IT staff survey of preferences.

B.

Embed training metrics into the annual performance appraisal process.

C.

Promote IT-specific training awareness program.

D.

Research and identify training needs based on industry trends.

Buy Now
Questions 106

When an enterprise plans to deploy mobile device technologies, it is MOST important for leadership to ensure that:

Options:

A.

Users agree to an acceptable use policy

B.

Appropriate controls are implemented

C.

The IT policy addresses mobile devices

D.

The project management office (PMO) is engaged

Buy Now
Questions 107

Which of the following BEST enables an enterprise to minimize the risks of intellectual property theft and loss of sensitive information when acquiring Internet of Things (IoT) hardware and software components?

Options:

A.

Review the data classification policy and relevant documentation

B.

Terminate contracts with suppliers from sanctioned regions of the world

C.

Require nondisclosure agreements (NDAs) from all suppliers

D.

Integrate supply chain cyber risk management processes

Buy Now
Questions 108

A CIO observes that many information assets are hosted on legacy technology that can no longer be patched or updated. The systems are not currently in use, but business units are reluctant to decommission assets due to information retention requirements. Which of the following is the BEST strategic response to this situation?

Options:

A.

Ensure the legacy systems are behind a secure firewall

B.

Isolate the legacy systems and disconnect them from the internet

C.

Apply legacy system surcharges to the business units

D.

Develop and enforce life cycle policies in consultation with business

Buy Now
Questions 109

Which of the following is MOST important for a CIO to ensure before signing a contract for a new cloud-based customer relationship management (CRM) system?

The service provider has been audited for vulnerabilities and threats.

Options:

A.

Risk management responsibilities are agreed upon and accepted.

B.

The request for proposal (RFP) has been reviewed for completeness.

C.

A full system functionality check has been completed.

Buy Now
Questions 110

Which of the following is the PRIMARY role of the governance function in enabling an enterprise to achieve its business objectives?

Options:

A.

Determining risk thresholds that the enterprise can sustain

B.

Preparing business continuity and resiliency plans

C.

Providing a means to effectively manage stakeholders

D.

Monitoring strategic plans to reach the desired target state

Buy Now
Questions 111

Which of the following has the GREATEST impact on the design of an IT governance framework?

Options:

A.

IT performance metrics

B.

Resource allocation

C.

Business leadership

D.

Business risk

Buy Now
Questions 112

Which of the following would BEST help to ensure the appropriate allocation of IT resources to support an enterprise's mission?

Options:

A.

Develop a resource strategy as part of program management.

B.

Prioritize program requirements based on existing resources.

C.

Implement resource planning for each IT project.

D.

Manage resources as part of the portfolio strategy.

Buy Now
Questions 113

An IT steering committee is concerned about staff saving data files containing sensitive corporate information on publicly available cloud file storage applications. Which of the following should be done FIRST to address this concern?

Options:

A.

Create a secure corporate cloud file storage and sharing solution.

B.

Block corporate access to cloud file storage applications.

C.

Require staff training on data classification policies.

D.

Revise the data management policy to prohibit this practice.

Buy Now
Questions 114

Which of the following is the BEST way for a CIO to ensure that the work of IT employees is aligned with approved IT directives?

Options:

A.

Mandate technical training related to the IT objectives.

B.

Have business leaders present their departments' objectives.

C.

Include relevant IT goals in individual performance objectives.

D.

Request a progress review of IT objectives by internal audit.

Buy Now
Questions 115

Which of the following is MOST important to document for a business ethics program?

Options:

A.

Guiding principles and best practices

B.

Violation response matrix

C.

Whistle-blower protection protocols.

D.

Employee awareness and training content

Buy Now
Questions 116

When evaluating the process for acquiring third-party IT resources, management identified several suppliers with repeated downtime issues impacting the enterprise. Which of the following is the BEST approach to help ensure future service delivery in accordance with business objectives?

Options:

A.

Establish key performance indicators (KPls)

B.

Appoint a procurement oversight committee

C.

Establish key risk indicators (KRIs).

D.

Implement contract monitoring.

Buy Now
Questions 117

An enterprise has committed to the implementation of a new IT governance model. The BEST way to begin this implementation is to:

Options:

A.

identify IT services that currently support the enterprise’s capability.

B.

define policies for data, applications, and organization of infrastructure.

C.

identify the role of IT in supporting the business.

D.

prioritize how much and where to invest in IT.

Buy Now
Questions 118

Individual business units within an enterprise have been designing their own IT solutions without consulting the IT department. From a governance perspective, what is the GREATEST issue associated with this situation?

Options:

A.

Security controls may not meet IT requirements.

B.

The enterprise does not have the skills to manage the solutions.

C.

The solutions conflict with IT goals and objectives.

D.

The solution may conflict with existing enterprise goals.

Buy Now
Questions 119

Which of the following methods is MOST likely to be used to assess plausible risk scenarios that could result in reputational risk to the enterprise?

Options:

A.

Controls gap analysis

B.

Qualitative analysis

C.

Quantitative analysis

D.

SWOT analysis

Buy Now
Questions 120

When developing an IT governance framework, it is MOST important for an enterprise to consider:

Options:

A.

information technology risk.

B.

framework development cost.

C.

information technology strategy.

D.

stakeholders' support.

Buy Now
Questions 121

An enterprise-wide strategic plan has been approved by the board of directors. Which of the following would BEST support the planning of IT investments required for the enterprise?

Options:

A.

Service-oriented architecture

B.

Enterprise architecture (EA)

C.

Contingency planning

D.

Enterprise balanced scorecard

Buy Now
Questions 122

After shifting from lease to purchase of IT infrastructure and software licenses, an enterprise has to pay for unexpected lease extensions causing significant cost overruns. The BEST direction for the IT steering committee would be to establish;

Options:

A.

an end-of-life program to remove aging infrastructure from the environment.

B.

budget cuts to compensate for the cost overruns.

C.

a program to annually review financial policy on overruns.

D.

a policy to consider total cost of ownership (TCO) in investment decisions.

Buy Now
Questions 123

A root-cause analysis indicates a major service disruption due to a lack of competency of newly hired IT system administrators. Who should be accountable for resolving the situation?

Options:

A.

HR training director

B.

HR recruitment manager

C.

Chief information officer

D.

(CIO) Business process owner

Buy Now
Questions 124

Which of the following activities MUST be completed before developing an IT strategic plan?

Options:

A.

Review the enterprise business plan

B.

Align the enterprise vision statement with business processes

C.

Develop an enterprise architecture (EA) framework

D.

Review the enterprise risk tolerance level

Buy Now
Questions 125

Which of the following is the BEST way to implement effective IT risk management?

Options:

A.

Align with business risk management processes.

B.

Establish a risk management function.

C.

Minimize the number of IT risk management decision points.

D.

Adopt risk management processes.

Buy Now
Questions 126

Which of the following provides the BEST evidence of effective IT governance?

Options:

A.

Cost savings and human resource optimization

B.

Business value and customer satisfaction

C.

IT risk identification and mitigation

D.

Comprehensive IT policies and procedures

Buy Now
Questions 127

Enterprise leadership is concerned with the potential for discrimination against certain demographic groups resulting from the use of machine learning models What should be done FIRST to address this concern?

Options:

A.

Obtain stakeholders' input regarding the ethics associated with machine learning

B.

Revise the code of conduct to discourage bias within automated processes

C.

Develop a machine learning policy articulating guidelines for machine learning use

D.

Assess recent case law related to the enterprise's machine learning business strategy

Buy Now
Questions 128

Which of the following is the MOST important aspect of business ethics?

Options:

A.

Ensuring fair and consistent vendor management practices

B.

Providing equal opportunities to employees

C.

Protecting stakeholders' interests

D.

Complying with legal and regulatory requirements

Buy Now
Questions 129

Which of the following should be the PRIMARY consideration for an enterprise when prioritizing IT projects?

Options:

A.

Technical capability of the enterprise to execute the projects

B.

Process owner expectations based on operational benefits

C.

Results of IT performance benchmarks against competitors

D.

Impact on the business due to expected project outcomes

Buy Now
Questions 130

Which of the following should a new CIO do FIRST to ensure information assets are effectively governed?

Options:

A.

Quantify the business value of information assets

B.

Perform an information gap analysis

C.

Review information classification procedures

D.

Evaluate information access methods

Buy Now
Questions 131

An enterprise is replacing its customer relationship management (CRM) system with a cloud-based system. Which of the following should be done FIRST when preparing for data migration"*

Options:

A.

Review the enterprise data architecture.

B.

Establish a data quality plan

C.

Consult the quality assurance (QA) function.

D.

Acquire data migration tools.

Buy Now
Questions 132

Which of the following should be the PRIMARY goal of implementing service level agreements (SLAs) with an outsourcing vendor?

Options:

A.

Gaining a competitive advantage

B.

Establishing penalties for not meeting service levels

C.

Achieving operational objectives

D.

Complying with regulatory requirements

Buy Now
Questions 133

A major data leakage incident at an enterprise has resulted in a mandate to strengthen and enforce current data governance practices. Which of the following should be done FIRST to achieve this objective?

Options:

A.

Assess data security controls.

B.

Review data logs.

C.

Analyze data quality.

D.

Verify data owners.

Buy Now
Questions 134

Which of the following is the MOST important input for the development of a human resources strategy to address IT skill gaps?

Options:

A.

Training budget allocated for IT staff

B.

Training effectiveness reports

C.

Technology direction of the enterprise

D.

A recent IT skills matrix

Buy Now
Questions 135

An enterprise's board of directors has determined that IT is not sufficiently supporting its corporate objectives, and has established a committee to address this problem. Which of the following should be the committees FIRST action?

Options:

A.

Implement a continuous improvement plan.

B.

Specify IT human resource performance measures.

C.

Create an IT strategic plan.

D.

Develop a service level management plan.

Buy Now
Questions 136

To ensure that information can be traced to the originating event and accountable parties, an enterprise should FIRST:

Options:

A.

capture source information and supporting evidence.

B.

improve business process controls.

C.

review information event logs tor potential incidents.

D.

review retention requirements for source information.

Buy Now
Questions 137

An enterprise is determining the objectives for an IT training improvement initiative from a governance prosected. it would be MOST important to ensure that:

Options:

A.

policies and processes address both enterprise requirements and professional growth

B.

courses of instruction that will maximize employee productivity are identified

C.

several different training strategies are created for final approval by the CIO

D.

IT employees are surveyed and interviewed to identify development needs

Buy Now
Questions 138

Which of the following should occur FIRST in the IT investment process?

Options:

A.

Assess each project's impact on the enterprise's investment plan.

B.

Select IT projects that will best support the enterprise's mission.

C.

Analyze IT investments based on past data.

D.

Analyze the risks and benefits of the investment for each IT project.

Buy Now
Questions 139

Which of the following is the BEST method to confirm whether a pilot project was successful?

Options:

A.

Determine whether the pilot aligns with the as-is enterprise architecture (EA).

B.

Evaluate whether the pilot project achieved planned schedule and cost.

C.

Assess the results of the pilot project against the expected performance outcomes.

D.

Review the metrics recorded in the IT balanced scorecard.

Buy Now
Questions 140

Which of the following would be the MOST effective way to ensure IT capabilities are appropriately aligned with business requirements for specific business processes?

Options:

A.

Establishing key performance indicators {KPIs)

B.

Requiring Internal IT architecture and design reviews

C.

Requiring architecture and design reviews with business process stakeholders

D.

Issuing a management mandate that IT and business process stakeholders work together

Buy Now
Questions 141

A data governance strategy has been defined by the IT strategy committee which includes privacy objectives related to access controls, authorized use. and data collection. Which of the following should the committee do NEXT?

Options:

A.

Mandate data privacy training for employees.

B.

Establish a data privacy budget

C.

Perform a data privacy impact assessment.

D.

Mandate the creation of a data privacy policy.

Buy Now
Questions 142

Which of the following is the MOST appropriate mechanism for measuring overall IT organizational performance?

Options:

A.

IT portfolio return on investment (ROI)

B.

Maturity model

C.

IT balanced scorecard

D.

Service level metrics

Buy Now
Questions 143

Which of the following is the BEST outcome measure to determine the effectiveness of IT nsk management processes?

Options:

A.

Frequency of updates to the IT risk register

B.

Time lag between when IT risk is identified and the enterprise's response

C.

Number of events impacting business processes due to delays in responding to risks

D.

Percentage of business users satisfied with the quality of risk training

Buy Now
Questions 144

Which of the following is MOST critical to support IT governance cultural changes within an organization?

Options:

A.

Established IT monitoring and measuring

B.

Regularly scheduled governance training

C.

Demonstrated management commitment

D.

IT governance process manuals

Buy Now
Questions 145

Which of the following is the BEST justification for a procurement manager to agree to purchase IT equipment from a specific vendor during a sales promotion?

Options:

A.

The IT benefit surpasses the business benefit from the purchase.

B.

The equipment adds value to the enterprise.

C.

The business profit surpasses the IT cost for the equipment.

D.

The product is offered at the lowest price.

Buy Now
Questions 146

Which of the following would a CIO use to present the overall view of IT performance to the board of directors?

Options:

A.

Balanced scorecard

B.

Key risk indicators (KRIs)

C.

Maturity model

D.

Key performance indicators (KPIs)

Buy Now
Questions 147

Which of the following is the MOST important reason to include internal audit as a stakeholder when establishing clear roles for the governance of IT?

Options:

A.

Internal audit has knowledge and technical expertise to advise on IT infrastructure.

B.

Internal audit is accountable for the overall enterprise governance of IT.

C.

Internal audit implements controls over IT risks and security.

D.

Internal audit provides input on relevant issues and control processes.

Buy Now
Questions 148

An internal audit revealed a widespread perception that the enterprise's IT governance reporting lacks transparency Which of the following should the CIO do FIRST?

Options:

A.

Add stakeholder transparency metrics to the balanced scorecard

B.

Develop a communication and awareness strategy

C.

Meet with key stakeholders to understand their concerns

D.

Adopt an industry-recognized template to standardize reports.

Buy Now
Questions 149

A financial services company has implemented the use of a cloud-based centralized customer relationship management (CRM) system. The company has decided to go multi-national. Which of the following should be the enterprise risk management (ERM) committee's PRIMARY consideration?

Options:

A.

Security issues

B.

Vendor capability

C.

Return on investment (ROI)

D.

Compliance issues

Buy Now
Questions 150

An enterprise has made the strategic decision to reduce operating costs for the next year and is taking advantage of cost reductions offered by an external cloud service provider. Which of the following should be the IT steering committee's PRIMARY concern?

Options:

A.

Calculating the cost of the current solution

B.

Updating the business risk profile

C.

Changing the IT steering committee charter

D.

Revising the business's balanced scorecard

Buy Now
Questions 151

An enterprise wants to address the human factors of social engineering risk within the organization. From a governance perspective, which of the following is the BEST way to mitigate this risk?

Options:

A.

Distribute the social media information security policy to staff.

B.

Mandate annual security awareness training.

C.

Restrict access to social media.

D.

Mandate security requirements be included in employee contracts.

Buy Now
Questions 152

The PRIMARY objective of building outcome measures is to:

Options:

A.

monitor whether the chosen strategy is successful

B.

visualize how the strategy will be achieved.

C.

demonstrate commitment to IT governance.

D.

clarify the cause-and-effect relationship of the strategy.

Buy Now
Questions 153

An IT steering committee wants to select a disaster recovery site based on available risk data Which of the following would BE ST enable the mapping of cost to risk?

Options:

A.

Key risk indicators (KRIs)

B.

Scenario-based assessment

C.

Business impact analysis (BIA)

D.

Qualitative forecasting

Buy Now
Questions 154

An enterprise's global IT program management office (PMO) has recently discovered that several IT projects are being run within a specific region without knowledge of the PMO. The projects are on time, on budget, and will deliver the proposed benefits to the specific region. Which of the following should be the PRIMARY concern of the PMO?

Options:

A.

Inability to reduce the impact to the risk level of the global portfolio

B.

Projects may not follow system development life cycle (SDLC)

C.

Lack of control and impact to the overall PMO budget

Buy Now
Questions 155

Which of the following is the MOST comprehensive method to report on overall IT performance to the board of directors?

Options:

A.

Balanced scorecard

B.

Net present value (NPV)

C.

Performance-based payments

D.

Return on investment (ROI)

Buy Now
Questions 156

An enterprise has developed a new digital strategy to improve fraud detection. Which of the following is MOST important to consider when updating the information architecture?

Options:

A.

Resource constraints related to implementing the digital strategy.

B.

The business use cases supporting the digital strategy

C.

Changes to the legacy business and data architectures

D.

The history of fraud incidents and their root causes

Buy Now
Questions 157

Which of the following is MOST important for IT governance to have in place to ensure the enterprise can maintain operations during extensive system downtime?

Options:

A.

Fault-tolerant hardware

B.

An incident response plan

C.

A crisis communications plan

D.

A business continuity plan (BCP)

Buy Now
Questions 158

The board of directors of a large organization has directed IT senior management to improve IT governance within the organization. IT senior management's MOST important course of action should be to:

Options:

A.

understand the driver that led to a desire to change.

B.

assess the current slate of IT governance within the organization.

C.

review IT strategy and direction.

D.

analyze IT service levels and performance.

Buy Now
Questions 159

When assessing the impact of a new regulatory requirement, which of the following should be the FIRST course of action?

Options:

A.

Update affected IT policies.

B.

Assess the budget impact of the new regulation.

C.

Map the regulation to business processes.

D.

Implement new regulatory requirements.

Buy Now
Questions 160

What is the BEST way for an IT governance board to establish standards of behavior for the adoption of artificial intelligence (Al)?

Options:

A.

Direct the creation and approval of an ethical use policy.

B.

Review and update the data privacy policy to align with industry standards.

C.

Include specific ethics clauses in vendor agreements and contracts.

D.

Include ethics topics within onboarding and awareness training.

Buy Now
Questions 161

An enterprise is adopting a new governance framework. Of the following, the MOST effective method to help ensure that key activities are performed by appropriate resources is through the use of:

Options:

A.

a RACI chart.

B.

an organizational breakdown structure.

C.

a work breakdown structure.

Buy Now
Questions 162

An enterprise is planning a transformation initiative by leveraging emerging technology that will have a significant impact on existing products and services Which of the following is the BEST way for IT to prepare for this change?

Options:

A.

Use a balanced scorecard to measure IT outcomes.

B.

Analyze emerging technology products and related training needs.

C.

Procure appropriate resources to support emerging technology

D.

Assess the impact on the existing IT strategy

Buy Now
Questions 163

Which of the following provides the BEST evidence of an IT risk-aware culture across an enterprise?

Options:

A.

Business staff report identified IT risks.

B.

IT risks are communicated to the business.

C.

IT risk-related policies are published.

D.

The IT infrastructure is resilient.

Buy Now
Questions 164

An enterprise is trying to increase the maturity of its IT process from being ad hoc to being repeatable. Which of the following is the PRIMARY benefit of this change?

Options:

A.

Process optimization is embedded across the organization.

B.

Required outcomes are mapped to business objectives.

C.

Process performance is measured in business terms.

D.

Required outcomes are more frequently achieved.

Buy Now
Questions 165

Which of the following would be the BEST way for an IT steering committee to monitor the adoption of a new enterprise IT strategy?

Options:

A.

Establish key performance indicators (KPIs).

B.

Establish key risk indicators (KRIs).

C.

Schedule ongoing audit reviews.

D.

Implement service level agreements (SLAs)

Buy Now
Questions 166

To enable the development of required IT skill sets for the enterprise, it is MOST important to define skill requirements based on:

Options:

A.

training needs.

B.

one set of skills applicable to all IT staff.

C.

a best practices framework.

D.

each role within the IT department.

Buy Now
Questions 167

Which of the following will BEST enable an IT steering committee to monitor the achievement of overall IT objectives on a continuous basis?

Options:

A.

Defined service level agreements (SLAs)

B.

Project portfolio dashboards

C.

Key performance indicators (KPIs)

D.

IT user survey results

Buy Now
Questions 168

What is the BEST criterion for prioritizing IT risk remediation when resource requirements are equal?

Options:

A.

Deviation from IT standards

B.

IT strategy alignment

C.

IT audit recommendations

D.

Impact on business

Buy Now
Questions 169

Which of the following should be done FIRST when defining responsibilities for ownership of information and systems?

Options:

A.

Require an information risk assessment.

B.

Identify systems that are outsourced.

C.

Ensure information is classified.

D.

Require an inventory of information assets.

Buy Now
Questions 170

Communicating which of the following to staff BEST demonstrates senior management's commitment to IT governance?

Options:

A.

Legal and regulatory requirements

B.

Approved IT investment opportunities

C.

Objectives and responsibilities

D.

Need for enterprise architecture (EA)

Buy Now
Questions 171

To ensure IT risk is managed in a consistent manner, it is MOST important for IT governance to establish a:

Options:

A.

risk management committee to identify IT-related risks.

B.

risk management framework.

C.

balanced scorecard that includes IT risks.

D.

risk management reporting tool to ensure compliance.

Buy Now
Questions 172

As part of the implementation of IT governance, the board of an enterprise should establish an IT strategy committee to:

Options:

A.

provide input to and ensure alignment of the enterprise and IT strategies.

B.

ensure IT risks inherent in the enterprise strategy implementation are managed

C.

drive IT strategy development and take responsibility for implementing the IT strategy.

D.

assume governance accountability for the business strategy on behalf of the board

Buy Now
Questions 173

When establishing an enterprise data model, the BEST way to ensure the integrity of data is to:

Options:

A.

classify information using an agreed-upon schema.

B.

implement the highest level of protection to data across the enterprise.

C.

establish a privileged access management platform.

D.

implement a data loss prevention (DLP) program.

Buy Now
Questions 174

When developing an IT strategic plan that supports an enterprise's business goals which of the following should be done FIRST?

Options:

A.

Ensure that IT drives business goals

B.

Analyze benchmarking data

C.

Understand the current vision

D.

Perform a business impact analysis (BIA)

Buy Now
Questions 175

A board of directors has just received a report indicating that only a small number of IT initiatives have been completed on time and within budget, A third of the projects were cancelled prior to completion, and more than half will cost almost double their original estimates. An analysis has determined that no one is held responsible for the completion of investmentinitiatives, and there is no consistency in execution. Which of the following would BEST help the enterprise address these problems?

Options:

A.

Establishing a project governance framework

B.

Assigning business management to an IT investment review board

C.

Establishing an IT risk management plan

D.

Aligning IT investment priorities to the business

Buy Now
Questions 176

A business is considering a policy to anonymize personal data in enterprise systems. Before making a decision, which of the following is MOST important for the IT steering committee to consider?

Options:

A.

Business impact analysis (BIA) results

B.

Regulatory requirements

C.

Sustainability costs to the enterprise

D.

Potential implementation barriers

Buy Now
Questions 177

Which of the following would provide the BEST input for prioritizing strategic IT improvement initiatives?

Options:

A.

Business dependency assessment

B.

Business process analysis

C.

Business case evaluation

D.

Business impact analysis (BIA)

Buy Now
Questions 178

Before an IT strategy committee can approve an IT risk assessment framework, which of the following is MOST important to have established?

Options:

A.

An enterprise risk mitigation strategy

B.

Leading and lagging risk indicators

C.

IT performance metrics and standards

D.

Enterprise definitions for risk impact and probability

Buy Now
Questions 179

Which of the following is the MOST important driver of IT governance?

Options:

A.

Effective internal controls

B.

Management transparency

C.

Quality measurement

D.

Technical excellence

Buy Now
Questions 180

IT has launched new portfolio management policies and processes to improve the alignment of IT projects with enterprise goals. The latest audit report indicates that no improvement has been made due to confusion in the decision-making process. Which of the following is the BEST course of action for the CIO?

Options:

A.

Deliver prioritization and facilitation training.

B.

Implement a performance management framework.

C.

Create an IT portfolio management risk framework.

D.

Develop and communicate an accountability matrix.

Buy Now
Questions 181

A regulatory audit assessed an enterprise's main transactional application as noncompliant. In addition to fines and required corrections, an agreement was reached to implement a set of governance controls over IT. Accountability for these controls is BEST assigned to which of the following?

Options:

A.

CIO

B.

Internal audit director

C.

Application users

D.

The board of directors

Buy Now
Questions 182

An enterprise has had the same IT governance framework in place for several years. Currently, large and small capital projects go through the same architectural governance reviews. Despite repeated requests to streamline the review process for small capital projects, business units have received no response from IT. The business units have recently escalated this issue to the newly appointed GO. Which of the following should be done FIRST to begin addressing business needs?

Options:

A.

Create a central repository for the business to submit requests.

B.

Explain the importance of the IT governance framework.

C.

Assess the impact of the proposed change.

D.

Assign a project team to implement necessary changes.

Buy Now
Questions 183

Establishing a uniform definition for likelihood and impact through risk management standards PRIMARILY addresses which of the following concerns?

Options:

A.

Inconsistent categories of vulnerabilities

B.

Conflicting interpretations of risk levels

C.

Inconsistent data classification

D.

Lack of strategic IT alignment

Buy Now
Exam Code: CGEIT
Exam Name: Certified in the Governance of Enterprise IT Exam
Last Update: May 23, 2025
Questions: 612
$57.75  $164.99
$43.75  $124.99
$36.75  $104.99
buy now CGEIT