Which of the following is the BEST way to ensure new systems can be adequately supported once in production?
-
A
Establish a resource management framework.
-
B
Evaluate the operational requirements of the business stakeholders.
-
C
Identify key performance indicators (KPIs).
-
D
Require operational management be identified in the business case.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe best way to ensure new systems can be adequately supported once in production is to require operational management be identified in the business case. This means that the business case should include the costs, benefits, risks and resources associated with the operation and maintenance of the new system, as well as the roles and responsibilities of the operational staff. By doing so, the business case can ensure that the new system is aligned with the business objectives and can deliver value to the stakeholders. Additionally, the business case can help to secure the commitment and support of the operational management for the new system. References: CGEIT Exam Content Outline, Domain 3: Benefits Realization1 COBIT 5: Enabling Processes, chapter 4, section 4.2.22 Building A Governance System: A Review of Information Flow and Items Component
IT management has reported difficulty retaining qualified IT personnel to support the organization's new strategy. Given that outsourcing is not a viable approach, which of the following would be the BEST way for IT governance to address this situation?
-
A
Implement an incentive-based employee referral program
-
B
Direct the development of a strategic HR plan for IT
-
C
Recommend enhancements to the online recruiting platform specific to IT
-
D
Work with HR to enhance compensation packages for IT personnel
Reveal answer details
Close answer details
Correct answerB
ExplanationA strategic HR plan is a document that drives the business forward by evaluating where the workforce is at and comparing it to future needs. It sets out the organizational goals and outlines how the HR team will help achieve them. A strategic HR plan for IT would help to identify and address the gaps, challenges, and opportunities in the IT talent management, such as recruitment, retention, development, engagement, and succession. A strategic HR plan for IT would also help to align the IT workforce with the IT strategy and objectives, and to ensure that the IT personnel have the skills, competencies, and motivation to support the organization's new strategy. A strategic HR plan for IT would also help to communicate and collaborate with the IT personnel and other stakeholders, and to foster a positive and supportive IT culture.
The PRIMARY benefit of using an IT service catalog as part of the IT governance program is that it.
-
A
ensures IT effectively meets future business needs,
-
B
provides a foundation for measuring IT performance,
-
C
improves the ability to allocate IT resources
-
D
establishes enterprise performance metrics per service
Reveal answer details
Close answer details
Correct answerB
ExplanationAn IT service catalog is a comprehensive list of all of the services an IT organization offers, such as IT support, IT operations, or IT projects. It usually includes a description of the service, its features, costs, and response and delivery times, as well as a method for requesting the service. An IT service catalog is part of the IT governance program, which is a framework that provides a formal structure for aligning IT investments and activities with business objectives and ensuring IT effectiveness and efficiency. The primary benefit of using an IT service catalog as part of the IT governance program is that it provides a foundation for measuring IT performance. By defining and documenting the IT services and their expected outcomes, an IT service catalog enables the IT organization to establish and monitor key performance indicators (KPIs) and service level agreements (SLAs) for each service. These metrics can help evaluate how well the IT services meet the customer needs and expectations, as well as the business goals and priorities. They can also help identify and address any gaps or issues in the IT service delivery and quality, and support continuous improvement and optimization. The other options are not the primary benefit of using an IT service catalog as part of the IT governance program, although they may be related or secondary benefits. Ensuring IT effectively meets future business needs, improving the ability to allocate IT resources, and establishingenterprise performance metrics per service are all desirable outcomes of using an IT service catalog, but they are not the main purpose or benefit. They are dependent or derived from the primary benefit of providing a foundation for measuring IT performance. By measuring IT performance, the IT organization can better understand the current and future business needs, allocate IT resources more efficiently and effectively, and align enterprise performance metrics with IT service outcomes. References: 4: (https://www.cio.com/article/272051/governanceit-governance-definition-and-solutions.html) 2: (https://www.atlassian.com/itsm/service-request-management/service-catalog) 5: (https://www.connectwise.com/blog/managed-services/it-service-catalog) 1: (https://www.servicenow.com/products/itsm/what-is-it-service-catalog.html) 3: (https://www.gartner.com/en/information-technology/glossary/it-governance)
Which of the following is the MOST appropriate mechanism for measuring overall IT organizational performance?
-
A
IT portfolio return on investment (ROI)
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationAn IT balanced scorecard is the most appropriate mechanism for measuring overall IT organizational performance, because it is a framework that translates the enterprise's vision and strategy into a set of performance measures that cover four perspectives: financial, customer, internal business process, and learning and growth. An IT balanced scorecard can help to communicate and monitor the IT strategy and goals, and align the IT activities and resources with the business needs and expectations. An IT balanced scorecard can also provide a balanced and comprehensive view of the IT performance and value delivery, and highlight the strengths, weaknesses, opportunities, and threats for improvement. References: ISACA, CGEIT Review Manual, 7th Edition, 2019, page 43- 44.
Which of the following roles is directly responsible for information quality?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationThis is because an information steward is a person or group who is accountable for the quality, integrity, and usability of the information assets within a specific domain or function. The responsibilities of an information steward include the following: Defining and enforcing data quality standards, policies, and procedures Monitoring and measuring data quality performance and outcomes Identifying and resolving data quality issues and errors Collaborating with data owners, custodians, analysts, and users to ensure data quality alignment and improvement. Educating and training data stakeholders on data quality best practices and tools. An information steward plays a key role in ensuring that the information assets are accurate, complete, consistent, reliable, and fit for purpose. The other options, information custodian, information analyst, and information owner are not directly responsible for information quality. They are more involved in the creation, storage, access, and use of information assets, rather than their quality. They may also have different perspectives and interests than the information steward regarding the information quality. For example, the information custodian may focus on the security and availability of information assets, while the information analyst may focus on the analysis and interpretation of information assets. The information owner may focus on the value and benefits of information assets. Therefore, they may not have the same authority or responsibility as the information steward for ensuring information quality. References: What Is an Information Steward? | Informatica, Data Roles: Data Owner vs Data Steward vs Data Custodian
When considering an IT change that would enable a potential new line of business, the FIRST strategic step for IT governance would be to ensure agreement among the stakeholders regarding:
-
A
objectives to achieve goals
-
B
metrics to measure effectiveness
-
C
a vision for the future state
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationWhen considering an IT change that would enable a potential new line of business, the first strategic step for IT governance would be to ensure agreement among the stakeholders regarding a vision for the future state, because this would provide a clear direction and purpose for the change, and align the IT strategy with the business strategy. A vision statement should describe the desired outcomes and benefits of the change, and reflect the enterprise's mission, values, and goals. References: ISACA, CGEIT Review Manual, 7th Edition, 2019, page 23-24.
Which of the following is the MOST effective way to manage risks within the enterprise?
-
A
Assign individuals responsibilities and accountabilities for management of risks.
-
B
Make staff aware of the risks in their area and risk management techniques.
-
C
Provide financial resources for risk management systems.
-
D
Document procedures and reporting processes.
Reveal answer details
Close answer details
Correct answerA
ExplanationAssigning individuals responsibilities and accountabilities for management of risks is the most effective way to manage risks within the enterprise, as it ensures that the risk owners and stakeholders are clearly identified, involved, and accountable for the risk management activities and outcomes. Assigning responsibilities and accountabilities also helps to establish roles and expectations, delegate authority, and monitor performance and compliance. References: CGEIT Exam Content Outline, Domain 4, Subtopic B: IT Risk Management, Task 2: Ensure that appropriate senior level management sponsorship for IT risk management exists.
An organization requires updates to their IT infrastructure to meet business needs. Which of the following will provide the MOST useful information when planning for the necessary IT investments?
-
A
Enterprise architecture (EA)
-
B
-
C
Business user satisfaction metrics
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationThis is because enterprise architecture (EA) is a practice that helps organizations align their IT systems and processes with their business objectives. EA provides a holistic and integrated viewof the current and future state of the organization's IT infrastructure, as well as the gaps, issues, and opportunities for improvement. By using EA, the organization can: Identify and prioritize the IT investments that support the business strategy, goals, and needs Optimize the IT spending and maximize the IT value1 Ensure the IT quality, security, and compliance Avoid IT duplication, waste, and inefficiency Define IT roles and responsibilities and assign accountability1 EA can help the organization plan for the necessary IT investments in a systematic and structured way, and ensure that they are aligned with the business vision and value. The other options, risk assessment report, business user satisfaction metrics, and audit findings are not as useful as enterprise architecture (EA) for planning for the necessary IT investments. They are more related to the evaluation and monitoring of the IT performance, rather than the planning and alignment of the IT strategy. They may also provide limited or partial information about the IT infrastructure, rather than a comprehensive and integrated view. They may also depend on external factors or standards that may not be relevant or applicable to the organization's specific context and needs.
Which of the following is MOST important for an enterprise to review when classifying information assets?
-
A
Procedures for information handling
-
B
Requirements for information retention.
-
C
Media used for storage and backup
-
D
Impact of information exposure
Reveal answer details
Close answer details
Correct answerD
ExplanationThe impact of information exposure is the most important factor for an enterprise to review when classifying information assets, because it helps to determine the level of sensitivity and protection that the information assets require. Information assets are classified according to their confidentiality, integrity, and availability, which reflect the potential harm or loss that could result from unauthorized disclosure, modification, or destruction of the information assets. The impact of information exposure can be assessed in terms of financial, reputational, legal, operational, or strategic consequences for the enterprise and its stakeholders. The impact of information exposure can also vary depending on the context, scope, and duration of the exposure. Therefore, by reviewing the impact of information exposure, an enterprise can assign appropriate labels and controls to its information assets, and ensure that they are handled and stored securely and appropriately. References: Information classification according to ISO27001, Information Asset and Security Classification Procedure, Information Classification Standard.
Question 10
Single choice
An enterprise has a zero-tolerance policy regarding security. This policy is causing a large number of email attachments to be blocked and is a disruption to enterprise. Which of the following should be the FIRST governance step to address this email issue?
-
A
Direct the development of an email usage policy.
-
B
Obtain senior management input based on identified risk.
-
C
Recommend business sign-off on the zero-tolerance policy.
-
D
Introduce an exception process.
Reveal answer details
Close answer details
Correct answerB
ExplanationAccording to the CGEIT certification guide, the first governance step to address the email issue caused by the zero-tolerance policy regarding security is to obtain senior management inputbased on identified risk. This is because senior management is ultimately responsible for setting the risk appetite and tolerance of the enterprise, and for balancing the security and business needs. The zero-tolerance policy may be too restrictive and may not align with the enterprise's risk profile and objectives. Therefore, senior management input is needed to review and adjust the policy according to the risk assessment and analysis 1. The other options are less appropriate as the first governance step, as they do not involve senior management input or risk-based decision making. References: CGEIT certification guide, domain 3: Risk Optimization, section 3.1: Risk Governance, page 87.
Question 11
Single choice
Which of the following should be the FIRST action taken by a newly formed IT governance committee to ensure reports are compliant with regulations and identify key IT risks?
-
A
Direct the development of a reporting communication plan.
-
B
Develop and monitor IT key risk indicator (KRI) triggers.
-
C
Train end users on regulation requirements.
-
D
Implement a mechanism to ensure reporting escalation.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe first action taken by a newly formed IT governance committee to ensure reports are compliant with regulations and identify key IT risks should be to develop and monitor IT key risk indicator (KRI) triggers. IT KRIs are metrics that measure the likelihood and impact of IT-related risks on the enterprise's objectives and goals. IT KRI triggers are thresholds or values that indicate when a risk is approaching or exceeding an acceptable level, requiring attention or action from the IT governance committee. Developing and monitoring IT KRI triggers can help the committee to identify, prioritize, and manage IT risks, as well as to ensure compliance with regulations and policies. Directing the development of a reporting communication plan, training end users on regulation requirements, and implementing a mechanism to ensure reporting escalation are also important actions for the IT governance committee, but they are not the first step. A reporting communication plan is a document that defines the purpose, scope, format, frequency, audience, and distribution of IT reports, as well as the roles and responsibilities of the report creators and recipients. A reporting communication plan can help the committee to communicate effectively and efficiently with the stakeholders about IT performance, issues, and risks. Training end users on regulation requirements is a process that educates the end users on the rules and standards that apply to their use of IT systems and data, as well as the consequences of non-compliance. Training end users can help the committee to raise awareness and ensure adherence to regulations and policies. Implementing a mechanism to ensure reporting escalation is a procedure that defines the criteria, process, and channels for escalating IT reports to higher levels of authority or responsibility when necessary. Implementing a reporting escalation mechanism can help the committee to ensure timely and appropriate response and resolution of IT issues or risks. References: Integrating KRIs and KPIs for Effective Technology Risk Management Performance Measurement Metrics for IT Governance State and Impact of Governance of Enterprise IT in Organizations: Key Findings of an International Study.
Question 12
Single choice
Which of the following is the MOST effective approach to ensure senior management sponsorship of IT risk management?
-
A
Benchmark risk framework against best practices.
-
B
Calculate financial impact for each IT risk finding.
-
C
Periodically review the IT risk register entries.
-
D
Integrate IT risk into enterprise risk management (ERM).
Reveal answer details
Close answer details
Correct answerD
ExplanationAccording to the CGEIT certification guide, the most effective approach to ensure senior management sponsorship of IT risk management is to integrate IT risk into enterprise risk management (ERM). This is because ERM is a holistic and strategic approach that considers all types of risks that may affect the achievement of the enterprise's objectives. By integrating IT risk into ERM, senior management can better understand the impact and interdependencies of IT risks on the enterprise's performance and value, and can provide more effective oversight and guidance to the IT risk management processes. The other options are less effective than option D, as they do not address the alignment and integration of IT risk with the enterprise's strategy and objectives. References: CGEIT certification guide, domain 3: Risk Optimization, section 3.1: Risk Governance, page 86.
Question 13
Single choice
A large financial institution is considering outsourcing customer call center operations which will allow the chosen vendor to access systems from offshore locations. Which of the following represents the GREATEST risk?
-
A
Inconsistent customer service and reporting
-
B
Loss of data confidentiality
-
C
Lack of network availability
-
D
Inadequate business continuity planning
Reveal answer details
Close answer details
Correct answerB
ExplanationLoss of data confidentiality represents the greatest risk for a large financial institution that is considering outsourcing customer call center operations, as it would expose sensitive customer and business information to unauthorized access, disclosure, or misuse by the chosen vendor or other third parties. Data confidentiality is especially important for financial institutions, as they deal with personal, financial, and transactional data that are subject to strict regulatory and legal requirements, such as the General Data Protection Regulation (GDPR) and the Payment Card Industry Data Security Standard (PCI DSS). A breach of data confidentiality could result in reputational damage, customer dissatisfaction, legal liability, and financial loss for the financial institution. The other options are not as great, as they are more related to the operational or performance aspects of outsourcing, rather than the security or compliance aspects of it. References: : CGEIT Review Manual (Digital Version), Chapter 4: Risk Optimization, Section 4.3: IT Risk Management, Subsection 4.3.1: IT Risk Management Overview, Page 153 : CGEIT Review Manual (Digital Version), Chapter 5: Resource Optimization, Section 5.3: Security Resource Management, Subsection 5.3.1: Security Resource Management Overview, Page 192 : Offshore bank call centers face risks around privacy, resilience amid COVID-191 : Call Center Outsourcing Risks and How to Mitigate Them
Question 14
Single choice
An enterprise is required to implement several regulatory requirements. Which of the following functions is BEST suited to determine compliance priorities?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 15
Single choice
An enterprise has established a new department to oversee the life cycle of activities that support data management objectives. Which of the following should be done NEXT?
-
A
Develop a business continuity plan (BCP).
-
B
Assess the current data business model.
-
C
Review data privacy requirements.
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationA RACI chart is a tool that defines the roles and responsibilities of different stakeholders in a project or a process. RACI stands for Responsible, Accountable, Consulted, and Informed. A RACI chart can help to clarify who is responsible for performing the tasks, who is accountable for the outcomes, who is consulted for input or feedback, and who is informed of the progress or results. A RACI chart can help to improve communication, collaboration, and coordination among the stakeholders, as well as to avoid confusion, duplication, or conflict of work. If an enterprise has established a new department to oversee the life cycle of activities that support data management objectives, the next step should be to establish a RACI chart for the data management process. This can help to define the roles and responsibilities of the new department and other existing departments or units that are involved in the data management process, such as IT, business, security, compliance, etc. A RACI chart can also help to align the data management process with the enterprise's strategy and goals, and to ensure that the data management objectives are met effectively and efficiently. References: What is a RACI Chart? Definition & Example. How to Use a RACI Matrix: Everything You Need to Know. Data Management Process: Definition & Best Practices. Data Lifecycle Management: A 2023 Guide for Your Business.
Question 16
Single choice
Acceptance of an enterprise's newly implemented IT governance initiatives has been resisted by a functional group requesting more autonomy over technology choices. Which of the following is MOST important to accommodate this need for autonomy?
-
A
Continuous improvement processes
-
B
Documentation of key management practices
-
C
An exception management process
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationAn exception management process is a method for documenting and approving an exception to compliance with established IT governance policies, standards, and practices. An exception management process can accommodate the need for autonomy over technology choices by allowing a functional group to request and justify a deviation from the IT governance requirements, based on the business needs, risks, costs, and benefits. An exception management process can also help to ensure that the exceptions are reviewed and approved by the appropriate authorities, that the exceptions are monitored and reported, and that the exceptions are aligned with the IT strategy and objectives. References: Exception Management Process Flow. IT/Information Security Exception Request Process. Strategies, Governance, Policies, Standards and Resources.
Question 17
Single choice
Which of the following would provide the MOST useful information to measure the alignment of IT with the enterprise?
-
A
-
B
Control self-assessment (CSA)
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationA balanced scorecard is a strategic management tool that measures the alignment of IT with the enterprise by using four perspectives: financial, customer, internal process, and learning and growth. A balanced scorecard helps to translate the enterprise vision and strategy into IT objectives, measures, targets, and initiatives. It also helps to monitor and evaluate the IT performance and value delivery in relation to the enterprise goals and stakeholder expectations. A balanced scorecard provides a comprehensive and balanced view of the IT contribution to the enterprise success. The other options are not as useful as a balanced scorecard for measuring the alignment of IT with the enterprise, because they are either too narrow or too subjective. A control self-assessment (CSA) is a technique that involves the participation of staff in assessing the effectiveness of internal controls and risk management processes. A CSA can provide some insights into the IT alignment with the enterprise, but it is not a systematic or holistic approach. A gap analysis is a method that compares the current state and the desired state of a process or a system and identifies the gaps or discrepancies that need to be addressed. A gap analysis can help to improve the IT alignment with the enterprise, but it is not a measurement tool. Audit reports are documents that present the findings and opinions of an independent auditor on the adequacy and compliance of an audited entity. Audit reports can provide some evidence of the IT alignment with the enterprise, but they are not a comprehensive or consistent measure. References: The art of measurement in enterprise and business architecture, Benchmarking strategic alignment of business and IT strategies, The Importance of Business & IT Alignment, 7 ways to effectively ensure IT-business alignment
Question 18
Single choice
Which of the following is an ADVANTAGE of using strategy mapping?
-
A
It provides effective indicators of productivity and growth.
-
B
It depicts the maturity levels of processes that support organizational strategy.
-
C
It identifies barriers to strategic alignment and links them to specific outcomes.
-
D
It depicts the cause-and-effect linked relationships between strategic objectives.
Reveal answer details
Close answer details
Correct answerD
ExplanationStrategy mapping is an advantage of using strategy mapping, as it helps to visualize and communicate how the enterprise can create value by achieving its strategic objectives. Strategy mapping also helps to align the IT goals and activities with the enterprise strategy, and to measure and monitor the IT performance and outcomes. References: CGEIT Exam Content Outline, Domain 3, Subtopic A: Performance Management, Task 2: Ensure that IT performance measurement supports IT performance management by providing relevant, complete, reliable, timely and consistent information.
Question 19
Single choice
An enterprise is initiating efforts to improve system availability to mitigate IT risk to the business. Which of the following results would be MOST important to report to the CIO to measure progress?
-
A
Incident severity and downtime trend analysis
-
B
Probability and seventy of each IT risk
-
C
Financial losses and bad press releases
-
D
Customer and stakeholder complaints over time
Reveal answer details
Close answer details
Correct answerA
ExplanationIncident severity and downtime trend analysis is the most important result to report to the CIO to measure progress in improving system availability to mitigate IT risk to the business, because it directly reflects the impact and frequency of system failures or disruptions on the business operations, processes, and functions. By analyzing the severity and duration of incidents over time, the CIO can evaluate the effectiveness of the IT risk management and system availability strategies, and identify any gaps, issues, or opportunities for improvement. Incident severity and downtime trend analysis can also help the CIO to communicate the value and performance of the IT risk management and system availability initiatives to the business stakeholders, and justify any further investment or action required to achieve the desired outcomes. The other options are not as important as incident severity and downtime trend analysis, because they are either too indirect or too subjective to measure progress in improving system availability to mitigate IT risk to the business. Probability and severity of each IT risk is a useful input for IT risk management, but it does not necessarily reflect the actual occurrence or impact of system failures or disruptions on the business. Financial losses and bad press releases are possible consequences of system failures or disruptions, but they may not capture the full extent or root causes of the IT risk to the business. Customer and stakeholder complaints over time are indicators of customer satisfaction and loyalty, but they may not be reliable or consistent measures of system availability or IT risk to the business
Question 20
Single choice
In which of the following situations is it acceptable to retain data beyond the stated policy?
-
A
The business created an analytics model based on historical records.
-
B
There is a high probability that the enterprise will enter into litigation.
-
C
New data privacy regulations are expected in a few months.
-
D
A core system database is going through an upgrade.
Reveal answer details
Close answer details
Question 21
Single choice
Which of the following BEST facilitates the adoption of an IT governance program in an enterprise?
-
A
Defining clear roles and responsibilities for the participants
-
B
Using a comprehensive business case for the initiative
-
C
Communicating the planned IT strategy to stakeholders
-
D
Addressing the behavioral and cultural aspects of change
Reveal answer details
Close answer details
Correct answerD
ExplanationFacilitating the adoption of an IT governance program in an enterprise requires addressing the behavioral and cultural aspects of change. This approach recognizes that the success of such a program depends not only on the structural and strategic elements but also on how well the people within the organization accept and adapt to the changes. Addressing cultural aspects involves engaging stakeholders, fostering a governance mindset, and overcoming resistance to change, thereby ensuring a smoother and more effective implementation. While defining roles, building business cases, and communicating strategies are critical, they must be complemented by efforts to manage the human side of change.
Question 22
Single choice
A CEO wants to establish a governance framework to facilitate the alignment of IT and business strategies. Which of the following should be a KEY requirement of this framework?
-
A
Defined resourcing levels
-
B
A defined enterprise architecture (EA)
-
C
-
D
A service delivery Strategy
Reveal answer details
Close answer details
Correct answerB
ExplanationA defined enterprise architecture (EA) is a key requirement of a governance framework to facilitate the alignment of IT and business strategies. An EA is a blueprint that describes the current and future state of the organization's structure, processes, information, and technology, as well as the principles and standards that guide their design and evolution. An EA helps to align IT and business strategies by providing a common vision, language, and framework for the organization, and by ensuring that the IT investments and initiatives support the business goals and objectives. An EA also helps to optimize the performance, efficiency, and effectiveness of the IT function and its services, and to manage the risks and changes associated with IT. An EA can be developed and maintained using various methodologies and frameworks, such as TOGAF, Zachman, or FEAF. References: CGEIT Exam Content Outline | ISACA1, CGEIT Review Manual (Digital Version), What is enterprise architecture? A framework for transformation | CIO2, Enterprise Architecture: Definition, Benefits & Examples3
Question 23
Single choice
Which of the following should be the MOST important consideration when establishing key performance indicators (KPIs) for IT initiatives?
-
A
-
B
Processes can be optimized
-
C
Data collection can be automated
-
D
Quality has been evaluated
Reveal answer details
Close answer details
Correct answerD
ExplanationThe quality of KPIs is the most important consideration. KPIs must be relevant, accurate, aligned with objectives, and capable of driving meaningful decision-making. Without quality evaluation, even automated or well-owned KPIs may mislead or fail to reflect performance accurately. Assignment and automation enhance implementation, but they do not ensure the KPI's value or appropriateness for measuring success. References: CGEIT Review Manual: Domain 3 ?Benefits Realization and Performance Monitoring COBIT 2019: MEA01 (Monitor, Evaluate and Assess Performance and Conformance).
Question 24
Single choice
A large bank has completed several acquisitions in the last few years that have resulted in redundant IT applications. To align with the strategic initiative of providing integrated services to customers, the IT steering committee has decided to share data and integrate applications. Which of the following would be MOST important to review in this situation?
-
A
Enterprise architecture (EA)
-
B
-
C
Balanced scorecard measures
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationEnterprise architecture (EA) is the most important thing to review in this situation, as it provides a holistic view of the current and desired state of the IT applications, data, and infrastructure, as well as the business processes, capabilities, and goals that they support. EA can help identify the redundant IT applications, the data sources and dependencies, the integration requirements and challenges, and the alignment with the strategic initiative of providing integrated services to customers. EA can also help define the roadmap, standards, and governance for achieving the desired state of IT integration. IT risk register, balanced scorecard measures, and IT strategic plan are also important things to review, but they are not as essential as EA in this situation. IT risk register is a document that records the IT risks that may affect the enterprise's objectives and operations, as well as their likelihood, impact, mitigation strategies, and status. IT risk register can help identify and manage the potential risks associated with IT integration, such as data quality, security, compatibility, performance, and compliance issues. Balanced scorecard measures are a set of metrics that track the performance of IT in relation to the enterprise's vision, strategy, and goals. Balanced scorecard measures can help evaluate the effectiveness and efficiency of IT integration, as well as its contribution to customer satisfaction, business value, and innovation. IT strategic plan is a document that outlines the vision, mission, objectives, initiatives, and actions of IT to support the enterprise's strategy and goals. IT strategic plan can help align IT integration with the business needs and expectations, as well as allocate the necessary resources and budget for it. References: Enterprise Architecture Governance - CIO Wiki Enterprise Architecture Governance | The Definitive Guide | LeanIX Enterprise Architecture Governance ?Why It Is Important (Part 2) What is IT governance? A formal way to align IT & business strategy.
Question 25
Single choice
An enterprise is determining the objectives for an IT training improvement initiative from a governance prosected. it would be MOST important to ensure that:
-
A
policies and processes address both enterprise requirements and professional growth
-
B
courses of instruction that will maximize employee productivity are identified
-
C
several different training strategies are created for final approval by the CIO
-
D
IT employees are surveyed and interviewed to identify development needs
Reveal answer details
Close answer details
Correct answerA
ExplanationAn enterprise is determining the objectives for an IT training improvement initiative from a governance perspective. Governance is the process of decision-making and implementation that involves various actors and structures, both formal and informal. Governance aims to achieve good governance, which is characterized by participation, consensus, accountability, transparency, responsiveness, effectiveness, efficiency, equity, inclusion, and rule of law. Therefore, it would be most important to ensure that the policies and processes for IT training address both the enterprise requirements and the professional growth of the IT employees. This would ensure that the IT training is aligned with the strategic goals and priorities of the enterprise, as well as the needs and expectations of the IT staff. It would also foster a culture of learning and development that enhances the performance, quality, and value of IT services. The other options are not the most important objectives for an IT training improvement initiative from a governance perspective. Identifying courses of instruction that will maximize employee productivity, creating several different training strategies for final approval by the CIO, and surveying and interviewing IT employees to identify development needs are all useful steps or methods for designing and implementing an IT training improvement initiative, but they are not the ultimate objectives or outcomes. They are subordinate or instrumental to the main objective of addressing both the enterprise requirements and the professional growth of the IT employees through policies and processes that reflect good governance principle. References: 3: (https://topworkplaces.com/improving-training-and-development-strategies/) 4: (https://shrm.org/ResourcesAndTools/hr-topics/organizational-and-employee-development/Pages/Key-) Steps-for-Better-Training-Development-Programs.aspx 5: (https://www.forbes.com/sites/forbeshumanresourcescouncil/2021/07/13/12-ways-to-implement-successful-employee-training-initiatives/) 1: (https://link.springer.com/article/10.1007/s40647-017-0197-4) 2: (https://www.unescap.org/sites/default/files/good-governance.pdf)
Question 26
Single choice
An enterprise's IT department has been operating independently without regard to business concerns, leading to misalignment between business and IT. The BEST way to establish alignment would be to require:
-
A
business to help define IT goals.
-
B
business to fund IT services.
-
C
IT to define business objectives.
-
D
IT and business to define risks.
Reveal answer details
Close answer details
Correct answerA
ExplanationRequiring the business to help define IT goals is the best way to establish alignment between business and IT when the IT department has been operating independently of business concerns. This collaborative approach ensures that IT initiatives are directly linked to business objectives, facilitating strategic alignment and ensuring that IT supports and enhances business operations. While IT defining business objectives, business funding IT services, and both defining risks are important, the foundational step for alignment is integrating business perspectives into the definition of IT goals.
Question 27
Single choice
To evaluate IT resource management, it is MOST important to define:
-
A
responsibilities for executing resource management.
-
B
-
C
principles for the IT strategy.
-
D
IT resource utilization reporting procedures.
Reveal answer details
Close answer details
Correct answerB
ExplanationAccording to the CGEIT exam guide, IT resource management is the process of planning, acquiring, allocating, monitoring and optimizing the IT resources of an enterprise to support its strategy, objectives and goals. To evaluate IT resource management, it is most important to define the applicable key goals that the IT resources are expected to achieve or contribute to. These key goals should be aligned with the enterprise's vision, mission and values, as well as the stakeholder needs and expectations. The key goals should also be specific, measurable, achievable, relevant and time-bound (SMART), and should be communicated and agreed upon by all relevant parties. Defining the applicable key goals will help to assess the performance, value and impact of IT resource management, as well as to identify the gaps, issues and opportunities for improvement. The other options are not as important as defining the applicable key goals, as they are more related to the implementation and execution of IT resourcemanagement, rather than its evaluation. References: CGEIT Exam Candidate Guide, page 14. CGEIT Certification, IT Resource Management
Question 28
Single choice
An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?
-
A
Authenticating access to information assets based on roles or business rules.
-
B
Implementing multi-factor authentication controls
-
C
Granting access to information based on information architecture
-
D
Engaging an audit of logical access controls and related security policies
Reveal answer details
Close answer details
Correct answerA
ExplanationAccording to the web search results, authenticating access to information assets based on roles or business rules is the most important way to ensure appropriate ownership of access controls to address privacy compliance. This is because role-based access control (RBAC) and attribute-based access control (ABAC) are two of the most common and effective methods for enforcing the principle of least privilege, which means granting users only the minimum level of access they need to perform their tasks. This can help to protect the confidentiality, integrity, and availability of information assets, as well as to comply with privacy regulations such as the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA). For example, one of the results1 states that "RBAC is a key component of any organization's compliance strategy, as it helps ensure that only authorized users can access sensitive data and resources". Another result2 explains that "ABAC is a logical model for access control that supports fine-grained authorization based on attributes, environment conditions, and policies". A third result3 discusses how RBAC and ABAC can help organizations achieve privacy compliance by implementing data minimization, purpose limitation, and accountability principles. References: What Is Access Control? | Microsoft Security Access Control Policy and Implementation Guides | CSRC Understanding Data Privacy ?A Compliance Strategy Can Mitigate Cyber ...
Question 29
Single choice
The CEO of an organization is concerned that there are inconsistencies in the way information assets are classified across the enterprise. Which of the following is be the BEST way for the CIO to address these concerns?
-
A
Include data assets in the IT inventory.
-
B
Identify data owners across the enterprise.
-
C
Require enterprise risk assessments.
-
D
Implement enterprise data governance.
Reveal answer details
Close answer details
Correct answerD
ExplanationEnterprise data governance is a system for defining who within an organization has authority and control over data assets and how those data assets may be used. It encompasses the people, processes, and technologies required to manage and protect data assets 1. Enterprise data governance can help address the inconsistencies in data classification by establishing a common framework, standards, and policies for data quality, security, and usage across the enterprise. It can also assign roles and responsibilities for data owners, stewards, and custodians to ensure accountability and compliance. References: 2: (https://www.ibm.com/topics/data-governance) 1: (https://www.cio.com/article/202183/what-is-data-governance-a-best-practices-framework-for-managing-data-assets.html) 3: (https://www.sailpoint.com/identity-library/enterprise-data-governance/) 4: (https://atlan.com/enterprise-data-governance/)
Question 30
Single choice
A healthcare enterprise that is subject to strict compliance requirements has decided to outsource several key IT services to third-party providers. Which of the following would be the BEST way to assess compliance and avoid reputational damage?
-
A
Require quarterly reports from the providers demonstrating compliance.
-
B
Require documentation that the providers have adequate controls in place.
-
C
Exercise the right to perform an audit.
-
D
Impose monetary penalties for noncompliance.
Reveal answer details
Close answer details
Correct answerC
ExplanationExercising the right to perform an audit is the best way to assess compliance and avoid reputational damage when outsourcing key IT services to third-party providers, especially in a highly regulated industry like healthcare. An audit is a systematic and independent examination of the provider's policies, procedures, controls, and performance related to the outsourced IT services, and it can help to verify that the provider is complying with the contractual obligations, service level agreements, and regulatory requirements. An audit can also help to identify and address any gaps, issues, or risks that may affect the quality, security, or reliability of the outsourced IT services, and to ensure that the provider is delivering value and meeting the expectations of the enterprise. An audit can also provide assurance and confidence to the enterprise's senior management, board, and stakeholders that the outsourcing arrangement is effective, efficient, and compliant. According to Outsourcing Compliance: What You Need to Know, "The right to audit clause should be included in every contract with a third-party service provider. It allows the organization to conduct an independent review of the provider's compliance with applicable laws and regulations, contractual terms and conditions, and industry standards and best practices."
Question 31
Single choice
A high-tech enterprise is concerned that leading competitors have been successfully recruiting top talent from the enterprise's research and development business unit. What should the leadership team mandate FIRST?
-
A
-
B
An incentive and retention program
-
C
-
D
An aggressive talent acquisition program
Reveal answer details
Close answer details
Correct answerC
ExplanationA root cause analysis is the first step to identify the factors that are causing the loss of top talent and to devise appropriate solutions. A SWOT analysis, an incentive and retention program, and an aggressive talent acquisition program are possible outcomes of a root cause analysis, but they are not the first action to take. References: CGEIT Review Manual, 7th Edition, page 103.
Question 32
Single choice
To benefit from economies of scale, a CIO is deciding whether to outsource some IT services. Which of the following would be the MOST important consideration during the decision-making process?
-
A
-
B
-
C
-
D
New service level agreements (SLAs)
Reveal answer details
Close answer details
Correct answerB
ExplanationThe most important consideration during the decision-making process of outsourcing some IT services is to identify the core IT processes that are critical for the organization's strategic objectives and competitive advantage. Core IT processes are those that provide unique value to the organization and differentiate it from its competitors. Outsourcing core IT processes may result in loss of control, innovation, and differentiation, as well as increased dependency and risk. Therefore, core IT processes should be retained in-house, while non-core IT processes can be outsourced to benefit from economies of scale, cost reduction, and access to specialized skills and technologies. References: CGEIT Exam Content Outline, Domain 3: Benefits Realization1 COBIT 5: Enabling Processes, chapter 4, section 4.2.32 IT governance -managing the outsourcing relationship
Question 33
Single choice
Which of the following BEST helps to ensure that IT policies are aligned with organizational strategies?
-
A
The policies are approved by the board of directors.
-
B
The policies are developed using a top-down approach.
-
C
The policies are updated annually.
-
D
The policies are periodically audited.
Reveal answer details
Close answer details
Correct answerB
ExplanationEnsuring that IT policies are aligned with organizational strategies is best achieved when the policies are developed using a top-down approach. This approach starts with strategic objectives and cascades down to operational policies, ensuring coherence and alignment with the overall direction and goals of the organization. While board approval, annual updates, and periodic audits are important for policy governance, the top-down development approach ensures that policies are inherently designed to support organizational strategies from the outset.
Question 34
Single choice
Which of the following BEST enables an enterprise to determine how business expectations should be addressed in a governance program?
-
A
Business impact analysis (BIA)
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThis is because stakeholder analysis is a process of identifying and prioritizing the people or groups who have an interest, influence, or impact on the enterprise's objectives and activities. Stakeholder analysis can help to understand the business expectations, needs, preferences, and concerns of different stakeholders, as well as their roles and responsibilities in the governance program. Stakeholder analysis can also help to engage and communicate with stakeholders effectively, and to align the governance program with the business strategy and value creation. Some of the sources that support this answer are: 1: This source explains the importance and benefits of stakeholder analysis for IT governance, and provides some tips and tools for conducting it. It suggests that stakeholder analysis can help to ensure that IT governance meets stakeholder needs, delivers value, and supports business objectives. 2: This source defines stakeholder analysis and describes its steps and techniques. It also provides some examples of stakeholder analysis templates and matrices that can be used for IT governance projects. 3: This source discusses how stakeholder analysis can be used in the TOGAF framework for enterprise architecture. It states that stakeholder analysis should be used during Phase A (Architecture Vision) to identify the key players in the engagement, and also be updated throughout each phase; different stakeholders may be uncovered as the engagement progresses through into Opportunities & Solutions, Migration Planning, and Architecture Change Management. 4: This source presents a chapter on enterprise governance of IT processes from a book titled "Enterprise Governance of Information Technology: Achieving Alignment and Value, Featuring COBIT 5". It mentions that stakeholder analysis is one of the key activities for defining the IT governance framework, as it helps to identify the relevant stakeholders and their expectations, roles, and responsibilities.
Question 35
Single choice
Which of the following BEST enables an enterprise to determine an appropriate retention policy for its information assets?
-
A
Business and compliance requirements
-
B
Business storage and processing needs
-
C
Backup and restoration capabilities
-
D
External customer data retention requirements
Reveal answer details
Close answer details
Correct answerA
ExplanationAn effective information retention policy must be based onbusiness and compliance requirements.These include legal mandates, industry regulations, and internal operational needs that dictate how long data must be retained and when it should be archived or deleted. While storage needs, backups, or customer expectations matter,only regulatory and business alignment guarantees legal compliance and operational relevance. References: CGEIT Review Manual: Domain 2 ?IT Resources (Data Governance) COBIT 2019: DSS01 (Manage Operations), DSS06 (Manage Business Process Controls).
Question 36
Single choice
An enterprise has a large backlog of IT projects. The current strategy is to execute projects as they are submitted, but executive management does not believe this method is optimal. Which of the following is the MOST important action to address this concern?
-
A
Implement stage-gating to determine the value of each project.
-
B
Establish a performance dashboard that determines business value.
-
C
Implement a methodology to prioritize projects based on resource availability.
-
D
Create a combined business/IT committee to determine project prioritization.
Reveal answer details
Close answer details
Correct answerC
ExplanationThe most important action to address the concern of executive management about the current strategy of executing projects as they are submitted is to create a combined business/IT committee to determine project prioritization. This action will help to ensure that the IT projects are aligned with the enterprise's objectives, strategies, and values, and that they deliver the highest value and impact to the business and the customers. A combined business/IT committee can also facilitate the communication, collaboration, and coordination among the stakeholders involved in the IT projects, and resolve any conflicts or issues that may arise. A combined business/IT committee can use various project prioritization methods, such as scoring models, prioritization matrices, payback periods, or portfolio dashboards, to evaluate and rank the IT projects based on criteria such as business value, urgency, feasibility, risk, and resource availability
Question 37
Single choice
An enterprise is planning a transformation initiative by leveraging emerging technology that will have a significant impact on existing products and services. Which of the following is the BEST way for IT to prepare for this change?
-
A
Use a balanced scorecard to measure IT outcomes.
-
B
Analyze emerging technology products and related training needs.
-
C
Procure appropriate resources to support emerging technology
-
D
Assess the impact on the existing IT strategy
Reveal answer details
Close answer details
Correct answerD
ExplanationThe best way for IT to prepare for a transformation initiative by leveraging emerging technology that will have a significant impact on existing products and services is to assess the impact on the existing IT strategy. An IT strategy is a plan that defines how IT will support the business strategy and objectives, and how IT will deliver value to the enterprise. By assessing the impact of the emerging technology on the existing IT strategy, IT can determine whether the current IT vision, mission, goals, and capabilities are aligned with the transformation initiative, and whether they need to be revised or updated. Assessing the impact of the emerging technology on the existing IT strategy also helps IT to identify and prioritize the opportunities, challenges, and risks that the emerging technology may bring, and to develop appropriate solutions and responses. Assessing the impact of the emerging technology on the existing IT strategy also helps IT to communicate and collaborate with the business stakeholders, and to ensure that the IT investments are aligned with the business needs and expectations. References: IT Strategy: What is it?, How to create an effective IT strategy in 2022, Emerging Technology Strategy: A Guide for CIOs, Maximizing Emerging Technology Adoption Benefits - Gartner
Question 38
Single choice
A recent benchmarking analysis has indicated an IT organization is retaining more data and spending significantly more on data retention than its competitors. Which of the following would BEST ensure the optimization of retention costs?
-
A
Requiring that all business cases contain data deletion and retention plans
-
B
Revalidating the organization's risk tolerance and re-aligning the retention policy
-
C
Moving all high-risk and medium-risk data backups to cloud storage
-
D
Redefining the retention policy to align with industry best practices
Reveal answer details
Close answer details
Correct answerB
ExplanationRevalidating the organization's risk tolerance and re-aligning the retention policy is the best option to ensure the optimization of retention costs, because it can help the organization balance the trade-off between the benefits and costs of data retention. By revalidating the risk tolerance, the organization can identify the optimal level of data retention that minimizes the exposure to legal, regulatory, and operational risks, while also reducing the storage and management costs. By re-aligning the retention policy, the organization can ensure that the data retention practices are consistent with the risk tolerance and reflect the current business needs and objectives. A re-aligned retention policy can also help the organization comply with data retention laws and regulations, avoid unnecessary data hoarding, and improve data quality and accessibility. References: Data Retention Policy 101: Best Practices, Examples & More - Intradyn, Data Retention 101: Policies and Best Practices | Egnyte, Best Practices for Data Retention and Policy Creation Will Optimize Storage Management, Data Retention Policy: Crafting Strategy for Compliance and Access
Question 39
Single choice
Which of the following is the BEST way for a CIO to ensure that IT-related training is taken seriously by the IT management team and direct employees?
-
A
Develop training programs based on results of an IT staff survey of preferences.
-
B
Embed training metrics into the annual performance appraisal process.
-
C
Promote IT-specific training awareness program.
-
D
Research and identify training needs based on industry trends.
Reveal answer details
Close answer details
Correct answerB
ExplanationThis is because training metrics are measurable values that indicate the effectiveness and impact of the training programs on the IT staff's knowledge, skills, and performance. By embedding training metrics into the annual performance appraisal process, the CIO can: Communicate the importance and value of IT-related training to the IT management team and direct employees Motivate and incentivize the IT management team and direct employees to participate in and complete the IT-related training Monitor and evaluate the IT management team and direct employees' progress, achievement, and improvement in the IT-related training. Provide feedback and recognition to the IT management team and direct employees who excel in the IT-related training. Identify and address any gaps or issues in the IT-related training or its outcomes. Embedding training metrics into the annual performance appraisal process can help to create a culture of learning, development, and accountability for IT-related training within the organization. It can also help to align the individual goals of the IT management team and direct employees with the organizational goals of IT governance. The other options, developing training programs based on results of an IT staff survey of preferences, promoting IT-specific training awareness program, and researching and identifying training needs based on industry trends are not as effective as embedding training metrics into the annual performance appraisal process for ensuring that IT-related training is taken seriously by the IT management team and direct employees. They are more related to the design and delivery of the IT-related training, rather than its integration and evaluation. They may also not have a significant impact on the behavior and attitude of the IT management team and direct employees towards IT-related training, as they may not provide sufficient motivation, feedback, or recognition for participation or completion.
Question 40
Single choice
An IT strategy committee wants to ensure stakeholders understand who owns each strategic objective. To enable this understanding, which of the following should be communicated to stakeholders?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationA RACI chart is a tool that assigns roles and responsibilities for each strategic objective, using the acronym RACI to denote who is Responsible, Accountable, Consulted, and Informed for each objective. A RACI chart can help stakeholders understand who owns each strategic objective, who is involved in its execution, and who needs to be updated on its progress and outcomes. A RACI chart can also help avoid confusion, duplication, or conflict among stakeholders, and ensure clear communication and accountability for each objective.
Question 41
Single choice
An organization is evaluating vendors to provide mobile device management (MDM) services. Which of the following is a KEY governance consideration for the IT steering committee?
-
A
Service level targets align with business requirements.
-
B
Employee-owned devices will be covered by the service.
-
C
The MDM services are delivered via a cloud.
-
D
Technology-owned devices will be covered by the service
Reveal answer details
Close answer details
Correct answerA
ExplanationA key governance consideration for the IT steering committee when evaluating vendors to provide mobile device management (MDM) services is to ensure that the service level targets align with the business requirements. Service level targets are the measurable and agreed-upon levels of performance and quality that the vendor is expected to deliver for the MDM services. These targets should reflect the business needs and expectations of the organization, such as availability, reliability, security, scalability, and functionality of the MDM services. Service level targets should also be realistic, achievable, and verifiable, and should be specified in the service level agreements (SLAs) that are part of the contract with the vendor. By ensuring that the service level targets align with the business requirements, the IT steering committee can facilitate the selection of a suitable and reliable vendor that can provide effective and efficient MDM services for the organization. References: CGEIT Exam Content Outline | ISACA, CGEIT Review Manual (Digital Version), Mobile Device Management (MDM) - Gartner, How to Set Service Level Targets for Your IT Support Team
Question 42
Single choice
Which of the following should be the PRIMARY consideration when developing an IT strategy for the global implementation of Internet of Things (IoT) solutions?
-
A
Hiring additional IT staff with IoT expertise
-
B
Addressing security and privacy
-
C
Identifying cost-effective IoT devices
-
D
Maintaining compatibility with legacy systems
Reveal answer details
Close answer details
Correct answerB
ExplanationSecurity and privacyare paramount when implementing IoT on a global scale. IoT devices often introduce vulnerabilities and handle sensitive data across diverse jurisdictions, making security controls and privacy compliance essential from the outset. While staffing, cost, and integration are important,security and privacyrepresent the greatest strategic and reputational risk if not addressed early in the strategy. References: CGEIT Review Manual: Domain 4 ?Risk Optimization COBIT 2019: DSS05 (Manage Security Services) and APO13 (Manage Security).
Question 43
Single choice
Communicating which of the following to staff BEST demonstrates senior management's commitment to IT governance?
-
A
Legal and regulatory requirements
-
B
Approved IT investment opportunities
-
C
Objectives and responsibilities
-
D
Need for enterprise architecture (EA)
Reveal answer details
Close answer details
Correct answerC
ExplanationCommunicating the objectives and responsibilities to staff is the BEST way to demonstrate senior management's commitment to IT governance. IT governance is the process of ensuring that IT supports the achievement of the organization's goals and objectives, and delivers value to its stakeholders. IT governance involves aligning the IT strategy, policies, processes, and resources with the business strategy, needs, and expectations. However, implementing and sustaining IT governance requires a significant amount of change in the organization, such as introducing new technologies, standards, roles, and responsibilities. Therefore, communicating the objectives and responsibilities to staff is essential for demonstrating senior management's commitment to IT governance, as it can: Provide the direction and mandate for the IT governance initiative on an ongoing basis Communicate the vision, mission, goals, and objectives of the IT function to all stakeholders Allocate the necessary resources and capabilities to enable the IT governance processes and activities Monitor and evaluate the performance and outcomes of the IT function and provide feedback and recognition Foster a positive and collaborative culture that values IT as a strategic partner and enabler of the business The other options are not as good as option C. While it is important to communicate the legal and regulatory requirements, the approved IT investment opportunities, and the need for enterprise architecture (EA), these are not sufficient to demonstrate senior management's commitment to IT governance. They are rather means to achieve the end goal of implementing and sustaining IT governance. They do not necessarily reflect the level of commitment, involvement, and support from the management toward IT governance. References: What is IT Governance? Definition & Examples | ASQ2 What is IT governance? A formal way to align IT & business strategy1 How to Involve Senior Management in the Information Security Governance ...3
Question 44
Single choice
Which of the following should be considered FIRST when migrating data to a cloud environment?
-
A
Disaster recovery plan (DRP).
-
B
-
C
Information architecture.
-
D
Reveal answer details
Close answer details
Question 45
Single choice
Due to budget cuts, IT has been forced to limit service offerings in the portfolio. There has been significant resistance from business leaders to this decision. Which of the following is the BEST way for the CIO to find a solution that is aligned with business objectives?
-
A
Engage an external consultant to document IT's alignment with the business.
-
B
Perform a cost-benefit analysis and communicate results.
-
C
Reallocate budget from maintenance projects in the portfolio.
-
D
Collaborate with the business to prioritize the IT portfolio.
Reveal answer details
Close answer details
Question 46
Single choice
Which of the following is the BEST way to ensure the continued usefulness of IT governance reports for stakeholders?
-
A
Conduct quarterly audits and adjust reporting based on findings.
-
B
Establish a standard process for providing feedback.
-
C
Rely on IT leaders to advise when adjustments should be made.
-
D
Issue frequent service level satisfaction surveys.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe best way to ensure the continued usefulness of IT governance reports for stakeholders is to establish a standard process for providing feedback. This means that the organization should define and communicate the purpose, scope, format, frequency, and distribution of the IT governance reports, and solicit input from the stakeholders on how well the reports meet their information needs and expectations. The feedback process should also include mechanisms for collecting, analyzing, and acting on the feedback, as well as reporting back to the stakeholders on the changes made or planned. This will help to ensure that the IT governance reports are relevant, accurate, timely, and consistent, and that they support the decision-making and accountability of the stakeholders
Question 47
Single choice
A newly hired IT director of a large international enterprise has been asked to provide periodic updates regarding IT risk to the board. Which of the following is the MOST effective way to initially address this request?
-
A
Include a complete IT risk register in the monthly letter given to each board member.
-
B
Include key IT risks in a dashboard submitted to the board quarterly.
-
C
Submit a register of all IT audit findings to board members monthly.
-
D
Schedule quarterly meetings to discuss all open IT risks.
Reveal answer details
Close answer details
Correct answerB
ExplanationAccording to the ISACA paper on Tactics for Effectively Communicating Cybersecurity Risk to Boards of Directors, the most effective way to initially address the request of providing periodic updates regarding IT risk to the board is to include key IT risks in a dashboard submitted to the board quarterly. A dashboard is a visual tool that can help the board members quickly understand the current status and trends of IT risk, as well as the actions taken or planned to mitigate them. A dashboard should be concise, clear, consistent and relevant, and should highlight the most significant IT risks that could impact the enterprise's objectives and performance. A dashboard should also align with the enterprise's risk appetite and tolerance, and provide recommendationsfor improvement or escalation. The other options are not as effective as a dashboard, as they may be too detailed, too frequent, too narrow or too reactive for the board's needs.
Question 48
Single choice
The board of directors of an enterprise has questioned whether the business is focused on optimizing value. The IT strategy committees' BEST action to address the board's concern is to:
-
A
initiate reporting and review of key IT performance metrics.
-
B
conduct a portfolio review to assess the benefits realization of IT investments.
-
C
conduct a benchmark to assess IT value relative to competitors.
-
D
form a technology council to monitor the efficiency of project implementation.
Reveal answer details
Close answer details
Correct answerB
ExplanationThis is because a portfolio review is a process of evaluating the performance and value of IT investments in relation to the business objectives and strategy. A portfolio review can help to identify the alignment, contribution, and optimization of IT investments, as well as the risks, issues, and opportunities for improvement. A portfolio review can also help to communicate and demonstrate the value of IT to the board and other stakeholders, as well as to support decision-making and prioritization of IT resources. Some of the sources that support this answer are: 1: This source explains the value of IT governance and how it can help to optimize risk and manage resources to support the organization's mission, goals, and objectives. It also discusses some of the governance enablers, such as principles, processes, and policies, that can help to align IT with the business context. 2: This source provides a research-based methodology to improve IT governance and drive business results. It suggests that conducting a portfolio review is one of the steps to redesign the governance framework and ensure that IT investments are aligned with the business strategy and deliver value. 3: This source defines IT portfolio management as a discipline that enables organizations to manage their IT investments as a collection of projects, programs, and services that contribute to the enterprise's strategic goals. It also describes some of the benefits of IT portfolio management, such as improving alignment, optimizing value, reducing risk, and enhancing transparency.
Question 49
Single choice
The use of new technology in an enterprise will require specific expertise and updated system development processes. There is concern that IT is not properly sourced. Which of the following should be the FIRST course of action?
-
A
Perform a risk assessment on potential outsourcing.
-
B
Update the enterprise architecture (EA) with the new technology.
-
C
Review the IT balanced scorecard for sourcing opportunities.
-
D
Assess the gap between current and required staff competencies.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe first course of action when the use of new technology in an enterprise will require specific expertise and updated system development processes is to assess the gap between current and required staff competencies. This course of action involves identifying the skills, knowledge, and abilities that are needed to implement and manage the new technology, and comparing them with the existing capabilities of the IT staff. By assessing the gap between current and required staff competencies, the enterprise can determine the extent and nature of the sourcing challenge, and plan for appropriate solutions, such as training, hiring, or outsourcing. According to one source1, "A competency gap analysis is a process of identifying the difference between what is required for a person to perform their role effectively and what they actually possess." The other options are not the first course of action when the use of new technology in an enterprise will require specific expertise and updated system development processes, but rather some of the steps or outcomes that can follow or result from the gap assessment. Performing a risk assessment on potential outsourcing is a step that involves evaluating the benefits and drawbacks of delegating some or all of the IT functions related to the new technology to an external service provider. This step can be done after assessing the gap between current and required staff competencies, and identifying outsourcing as a viable option. Updating the enterprise architecture (EA) with the new technology is a step that involves incorporating the new technology into the holistic view of the enterprise's IT environment, including its goals, principles, standards, policies, processes, technologies, and systems. This step can be done after assessing the gap between current and required staff competencies, and ensuring that the new technology aligns with the enterprise's strategic objectives and business requirements. Reviewing the IT balanced scorecard for sourcing opportunities is an outcome that involves measuring and reporting on the performance and value of IT sourcing activities and outcomes. This outcome can be done after assessing the gapbetween current and required staff competencies, and implementing the chosen sourcing solution. References: What is Competency Gap Analysis? Definition & Examples
Question 50
Single choice
Which of the following is MOST important to review during IT strategy development?
-
A
-
B
-
C
Current business environment
-
D
Data flows that indicate areas requiring IT support
Reveal answer details
Close answer details
Correct answerC
ExplanationThe most important thing to review during IT strategy development is the current business environment, as it reflects the internal and external factors that affect the enterprise's performance, objectives, and needs. The current business environment includes the analysis of the enterprise's strengths, weaknesses, opportunities, and threats (SWOT), as well as the assessment of the market trends, customer demands, competitor actions, and regulatory requirements. Reviewing the current business environment can help align the IT strategy with the business strategy, as well as identify and prioritize the IT initiatives and investments that can support and enable the enterprise's goals and value proposition. Industry best practices, IT balanced scorecard, and data flows that indicate areas requiring IT support are also important things to review during IT strategy development, but they are not the most important thing. Industry best practices are the methods or techniques that have been proven to be effective or efficient in achieving a desired outcome or result in a specific domain or context. Industry best practices can help benchmark and improve the IT strategy, as well as adopt or adapt the best solutions or innovations from other enterprises or sectors. IT balanced scorecard is a set of metrics that measure the performance of IT in relation to the enterprise's vision, strategy, and goals. IT balanced scorecard can help evaluate and communicate the effectiveness and efficiency of IT strategy, as well as its contribution to customer satisfaction, business value, and innovation. Data flows that indicate areas requiring IT support are the diagrams or models that show how data is collected, processed, stored, and distributed within or across the enterprise's processes or systems. Data flows can help identify and address the gaps or issues in IT service delivery or data management, as well as optimize or integrate the data systems or tools.
Question 51
Single choice
Which of the following is the BEST outcome measure to determine the effectiveness of IT nsk management processes?
-
A
Frequency of updates to the IT risk register
-
B
Time lag between when IT risk is identified and the enterprise's response
-
C
Number of events impacting business processes due to delays in responding to risks
-
D
Percentage of business users satisfied with the quality of risk training
Reveal answer details
Close answer details
Correct answerC
ExplanationThe number of events impacting business processes due to delays in responding to risks is the best outcome measure to determine the effectiveness of IT risk management processes, because it reflects the actual consequences and losses that result from inadequate or ineffective riskmanagement. Outcome measures are metrics that evaluate the results and benefits of a process or activity, rather than the inputs or outputs. Outcome measures help to assess whether the process or activity is achieving its objectives and delivering value to the organization. The number of events impacting business processes due to delays in responding to risks is an outcome measure that indicates how well the IT risk management processes are able to identify, analyze, evaluate, treat, monitor, and communicate IT risks in a timely and appropriate manner. A high number of such events would suggest that the IT risk management processes are not effective, and that they need to be improved or revised. A low number of such events would suggest that the IT risk management processes are effective, and that they are reducing the likelihood and impact of IT risks on the organization. References: How To Measure Risk Management KPI & Metrics - ERM Software
Question 52
Single choice
When developing effective metrics for the measurement of solution delivery, it is MOST important to:
-
A
establish project controls and monitoring objectives.
-
B
perform an objective analysis of the project roadmap.
-
C
establish the objectives and expected benefits.
-
D
specify quantitative measures for solution delivery.
Reveal answer details
Close answer details
Correct answerC
ExplanationEstablishing the objectives and expected benefits is the most important step when developing effective metrics for the measurement of solution delivery, because it defines the purpose, scope, and value of the solution and how it aligns with the business goals and needs. By establishing the objectives and expected benefits, IT leaders can identify the key performance indicators (KPIs) that will measure the progress, quality, and outcomes of the solution delivery. KPIs are specific, measurable, achievable, relevant, and time-bound metrics that track and evaluate the performance of the solution delivery against the objectives and expected benefits. KPIs can also help IT leaders to communicate the value proposition of the solution to the stakeholders, monitor and manage the risks and issues that may affect the solution delivery, and ensure that the solution meets or exceeds the expectations of the customers and users. References: Automation: metrics that measure success, 4 Types of Key Performance Metrics To Track (With Examples), A guide to measuring benefits effectively
Question 53
Single choice
A newly hired CIO has been told the enterprise has an established IT governance process, but finds it is not being followed. To address this problem, the CIO should FIRST
-
A
gain an understanding of the existing governance process and corporate culture.
-
B
replace the current governance process with one the CIO has successfully used before.
-
C
establish personal relationships with executive-level peers to leverage goodwill,
-
D
engage audit to review current governance processes and validate the ClO's concerns.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe first step for the newly hired CIO to address the problem of IT governance process not being followed is to gain an understanding of the existing governance process and corporateculture. This will help the CIO to identify the root causes of the problem, such as lack of awareness, commitment, alignment, communication, or accountability. It will also help the CIO to assess the strengths and weaknesses of the current process, as well as the opportunities and threats for improvement. By understanding the existing governance process and corporate culture, the CIO can also build trust and rapport with the stakeholders, and tailor the solutions to fit the specific needs and context of the enterprise. References: CGEIT Review Manual (Digital Version) or CGEIT Review Manual (Print Version), Chapter 1: Governance of Enterprise IT, Section 1.2: IT Governance Implementation, Subsection 1.2.1: IT Governance Implementation Process, Page 27-28. What is CGEIT? A certification for seasoned IT governance professionals.
Question 54
Single choice
Which of the following aspects of IT governance BEST addresses the potential intellectual property implications of a cloud service provider having a database in another country?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerC
ExplanationData management is the aspect of IT governance that BEST addresses the potential intellectual property implications of a cloud service provider having a database in another country. Data management involves defining and implementing policies and processes for the effective and efficient acquisition, storage, distribution, usage, and disposal of data in alignment with business objectives and regulatory requirements. Data management also includes ensuring the protection of data quality, integrity, availability, confidentiality, and ownership. Therefore, data management can help mitigate the risks of intellectual property infringement, theft, or misuse that may arise from storing data in a foreign jurisdiction with different legal and regulatory frameworks. References: CGEIT Review Manual (Digital Version), Chapter 4: Value Optimization, Section 4.2: IT Value Delivery, Subsection 4.2.3: IT Resource Management, Page 123 CGEIT Review Manual (Print Version), Chapter 4: Value Optimization, Section 4.2: IT Value Delivery, Subsection 4.2.3: IT Resource Management, Page 123 Cloud computing: A brief overview of intellectual property issues "in the cloud" - Lexology2 Protecting Intellectual Property in the Cloud - WIPO
Question 55
Single choice
An enterprise considering implementing IT governance should FIRST develop the scope of the IT governance program and:
-
A
initiate the program using an implementation roadmap.
-
B
establish initiatives for business and managers.
-
C
acquire the resources that will be required.
-
D
communicate the program to stakeholders to gain consensus.
Reveal answer details
Close answer details
Correct answerD
ExplanationCommunicating the program to stakeholders to gain consensus is the first step after developing the scope of the IT governance program, as it helps to ensure that the program is aligned with the enterprise goals and objectives, and that it has the support and commitment of the key parties who have an interest or influence in the IT governance. Communication also helps to overcome resistance, address concerns, and foster collaboration among the stakeholders. References: CGEIT Exam Content Outline, Domain 1, Subtopic A: Governance Framework, Task 3: Ensure that stakeholder needs, conditions and options are evaluated to determine balanced, agreed-on enterprise objectives to be achieved setting direction through prioritization and decision making and monitoring performance and compliance against agreed-on direction and objectives.
Question 56
Single choice
A rail transport company has the worst on-time arrival record in the industry due to an antiquated IT system that controls scheduling. Despite employee resistance, an initiative lo upgrade the technology and related processes has been approved. To maximize employee engagement throughout the project, which of the following should be in place prior to the start of the initiative?
-
A
Procurement management plan
-
B
Organizational change management plan
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationAn organizational change management plan is the best option to have in place prior to the start of an initiative to upgrade the technology and related processes of a rail transport company that has the worst on-time arrival record in the industry due to an antiquated IT system that controls scheduling. An organizational change management plan is a document that outlines the strategy, approach, and actions for managing and implementing a change within an organization. It helps to prepare the organization and its stakeholders for the change, communicate the vision and benefits of the change, address the potential resistance and challenges of the change, and monitorand evaluate the progress and outcomes of the change. An organizational change management plan is especially important for a project that involves a significant technological and process change that may impact the culture, performance, and satisfaction of the employees. By having an organizational change management plan in place before the start of the initiative, the rail transport company can maximize employee engagement throughout the project, and ensure a smooth and successful transition to the new IT system and processes
Question 57
Single choice
An IT steering committee wants the enterprise's mobile workforce to use cloud-based file storage to save non-sensitive corporate data, removing the need for remote access to that information. Before this change is implemented, what should be included in the data management policy?
-
A
A mandate for periodic employee training on how to classify corporate data files
-
B
A mandate for the encryption of all corporate data files at rest that contain sensitive data
-
C
A process for blocking access to cloud-based apps if inappropriate content is discovered
-
D
A requirement to scan approved cloud-based apps for inappropriate content
Reveal answer details
Close answer details
Correct answerD
ExplanationAccording to the web search results, a data management policy for cloud-based file storage should include a requirement to scan approved cloud-based apps for inappropriate content. This can help to prevent data leakage, compliance violations, and reputational damage. For example, one of the results describes how to use Microsoft Defender for Cloud Apps to create file policies that can monitor and control the data and files in your organization's cloud app use, and apply automated actions for governance and remediation. Another result explains how to use Google Cloud Storage's Bucket Lock feature to set a data retention policy for a bucket that governs how long objects in the bucket must be retained, and how to lock the policy to prevent itfrom being reduced or removed. A third result outlines the best practices and approval processes for using cloud computing services at Tufts University, and states that "the university reserves the right to scan any cloud computing service used by Tufts faculty, staff, or students for inappropriate content". References: File policies - Microsoft Defender for Cloud Apps Retention policies and retention policy locks | Cloud Storage | Google Cloud Cloud Computing Services Policy | Technology Services - Tufts University
Question 58
Single choice
An analysis of an organization's security breach is complete. The results indicate that the quality of the code used for updates to its primary customer-facing software has been declining and security flaws were introduced. The FIRST IT governance action to correct this problem should be to review:
-
A
compliance with the user testing process.
-
B
the change management control framework.
-
C
the qualifications of developers to write secure code.
-
D
the incident response plan.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe change management control framework is the first IT governance action to correct the problem of declining code quality and security flaws, as it defines and implements the policies, procedures, and standards for managing changes to the IT systems and software. The change management control framework also ensures that changes are authorized, tested, documented, and deployed in a consistent and secure manner. A review of the change management control framework can help to identify and address the root causes of the security breach, and to prevent or mitigate similar incidents in the future. References: CGEIT Exam Content Outline, Domain 1, Subtopic C: Technology Governance, Task 3: Ensure that IT processes are compliant with relevant laws, regulations and contractual requirements.
Question 59
Single choice
Which of the following is the BEST way for an organization to minimize the difference between expected and delivered services when acquiring resources?
-
A
Negotiate service level agreements (SLAs)
-
B
Measure service delivery using industry benchmarks
-
C
Require quarterly benefits realization reporting
-
D
Include a right-to-audit clause in the contract.
Reveal answer details
Close answer details
Correct answerA
ExplanationNegotiating service level agreements (SLAs) is the best way for an organization to minimize the difference between expected and delivered services when acquiring resources, because SLAs define the scope, quality, availability, performance, and security of the services that the provider will deliver to the customer. SLAs also specify the roles and responsibilities, escalation procedures, and penalties for non-compliance of both parties. By negotiating SLAs, the organization can ensure that its expectations and requirements are clearly communicated and agreed upon by the provider, and that there are mechanisms to measure and monitor the service delivery and outcomes. Negotiating SLAs also helps to prevent or resolve any disputes or issues that may arise from the service provision, and to ensure that the organization receives the value and benefits that it expects from the provider. One of the sources that supports this answer is Service-level Agreement: 3 Types And Templates - Contract Lawyers, which states that "A service-level agreement is important because it: Protects both parties: The SLA sets standards for the service, ensuring both the service provider and end user are on the same page with expectations."
Question 60
Single choice
Due to the recent introduction of personal data protection regulations, an enterprise is required to maintain its employee data in production systems only for a limited time. Which of the following is MOST important to review?
-
A
-
B
Information retention policies
-
C
-
D
Data backup and restoration policies
Reveal answer details
Close answer details
Correct answerB
ExplanationInformation retention policies are the most important to review, because they define the rules and procedures for retaining, disposing, and destroying information in accordance with the legal, regulatory, and business requirements. Information retention policies can help the enterprise to comply with the personal data protection regulations, and to ensure the privacy, security, and availability of the employee data in production systems. References: ISACA, CGEIT Review Manual, 7th Edition, 2019, page 57-58.
Question 61
Single choice
New legislation requires an enterprise to report cybersecurity incidents to a government agency within a defined timeline. Which of the following should be the FIRST course of action?
-
A
Establish an incident reporting system and hotline.
-
B
Require automation of incident reporting to agencies.
-
C
Establish a cybersecurity incident manager role.
-
D
Understand requirements and definitions for reportable incidents.
Reveal answer details
Close answer details
Question 62
Single choice
An enterprise is developing an ethics program, and the ethical standards have been defined. Which of the following should the enterprise do NEXT?
-
A
Establish a training and awareness program focused on ethics.
-
B
Implement an enterprise-wide employee monitoring program.
-
C
Develop key performance indicators (KPIs) for program implementation.
-
D
Outline and document consequences for noncompliance.
Reveal answer details
Close answer details
Correct answerA
ExplanationAfter defining the ethical standards for an ethics program, the next step for the enterprise should be to establish a training and awareness program focused on ethics. A training and awareness program can help to communicate the ethical standards to all employees and stakeholders, and educate them on the importance, benefits, and expectations of ethical behavior. A training and awareness program can also help to foster a culture of ethics within the enterprise, and encourage employees to apply the ethical standards in their daily work and decision making. According to ISACA's article on Ethics in IT, "training is essential to ensure that all staff understand what is expected of them and how to apply ethical principles in their work." Furthermore, according to ISACA's CGEIT Domain 1: Framework for the Governance of Enterprise IT, "training and awareness are key enablers for embedding an appropriate culture throughout the enterprise." Therefore, establishing a training and awareness program focused on ethics is the best way to implement the ethical standards defined by the enterprise.
Question 63
Single choice
A CIO has recently been made aware of a new regulatory requirement that may affect IT-enabled business activities. Which of the following should be the CIO s FIRST step in deciding the appropriate response to the new requirement?
-
A
Revise initiatives that are active to reflect the new requirements.
-
B
Confirm there are adequate resources to mitigate compliance requirements.
-
C
Consult with legal and risk experts to understand the requirements.
-
D
Consult with the board for guidance on the new requirements
Reveal answer details
Close answer details
Correct answerC
ExplanationThe CIO's first step in deciding the appropriate response to the new regulatory requirement should be to consult with legal and risk experts to understand the requirements. This step is important because the legal and risk experts can provide the CIO with the relevant and accurate information about the new regulation, such as its scope, objectives, implications, and deadlines. The legal and risk experts can also advise the CIO on the potential risks and impacts of non-compliance, as well as the best practices and strategies for compliance . The other options are not the first step in deciding the appropriate response to the new regulatory requirement, but rather subsequent steps that depend on the outcome of the consultation with the legal and risk experts. Revising initiatives that are active to reflect the new requirements is a step that occurs after the CIO has understood the requirements and assessed their impact on the current IT-enabled business activities. Confirming there are adequate resources to mitigate compliance requirements is a step that occurs after the CIO has identified and prioritized theactions and tasks needed to achieve compliance. Consulting with the board for guidance on the new requirements is a step that occurs after the CIO has developed and proposed a feasible and effective compliance plan. References: How to Respond to Regulatory Changes - Smartsheet : Regulatory Change Management: A Guide for Compliance Teams | LogicGate
Question 64
Single choice
An enterprise is evaluating a possible strategic initiative for which IT would be the main driver. There are several risk scenarios associated with the initiative that have been identified. Which of the following should be done FIRST to facilitate a decision?
-
A
Define the risk mitigation strategy.
-
B
Assess the impact of each risk.
-
C
Establish a baseline for each initiative.
-
D
Select qualified personnel to manage the project.
Reveal answer details
Close answer details
Correct answerB
ExplanationBefore deciding whether to pursue a strategic initiative, it is important to understand the potential consequences of the risks involved. Assessing the impact of each risk means estimating how likely it is to occur and how severe its effects would be on the enterprise's objectives, performance, reputation, or resources. This can help to prioritize the most critical risks and compare them with the expected benefits of the initiative. According to one of the web search results1, "the impact assessment is a key element of any risk management process. It helps to evaluate the significance of each risk and determine the appropriate response strategy." Defining the risk mitigation strategy, establishing a baseline for each initiative, and selecting qualified personnel to manage the project are important steps, but they are not the first ones. They aremore likely to be part of the implementation or execution phase of the initiative, after it has been approved and funded. References: Risk Impact Assessment and Prioritization
Question 65
Single choice
An enterprise's IT department has failed to deliver required solutions on time due to insufficient resource allocation, resulting in a longer time to market. Which of the following is the BEST way for the chief information officer (CIO) to address this situation?
-
A
Implement a new IT change management procedure.
-
B
Evaluate the availability and capacity planning process.
-
C
Benchmark IT staffing levels against similar organizations in the industry.
-
D
Direct the project management office (PMO) to review and prioritize IT projects.
Reveal answer details
Close answer details
Question 66
Single choice
Which of the following is the MOST important driver of IT governance?
-
A
Effective internal controls
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationManagement transparency is the most important driver of IT governance, because it enables the alignment of IT and business goals, the accountability of IT performance and value, the communication and collaboration among stakeholders, and the compliance with laws and regulations. Management transparency refers to the degree to which information about IT decisions, processes, outcomes, and risks is shared openly and honestly with relevant parties, such as the board of directors, senior management, business units, IT staff, customers, and regulators. Management transparency can help to build trust, confidence, and support for IT initiatives, as well as to identify and address any issues or gaps in IT governance. References: What is IT governance? A formal way to align IT & business strategy. Definition of IT Governance (ITG) - IT Glossary | Gartner.
Question 67
Single choice
An independent consultant has been hired to conduct an ad hoc audit of an enterprise's information security office with results reported to the IT governance committee and the board Which of the following is MOST important to provide to the consultant before the audit begins?
-
A
Acceptance of the audit risks and opportunities
-
B
The scope and stakeholders of the audit
-
C
The organizational structure of the security office
-
D
The policies and framework used by the security office
Reveal answer details
Close answer details
Correct answerB
ExplanationThe scope and stakeholders of the audit are the most important information to provide to the consultant before the audit begins, because they define the objectives, boundaries, and expectations of the audit. The scope and stakeholders of the audit are also part of the IT governance domain: Framework for the Governance of Enterprise IT. References: 1: CGEIT Review Manual 2023, ISACA, page 23.
Question 68
Single choice
Which of the following is the BEST way for a CIO to secure support for a strategy to achieve long-term IT objectives?
-
A
Make the necessary strategic decisions and notify staff accordingly.
-
B
Develop tactics to implement the strategy and share with stakeholders.
-
C
Develop a communication plan for distribution of information to staff.
-
D
Meet with stakeholders to explain the strategy and incorporate feedback.
Reveal answer details
Close answer details
Correct answerD
ExplanationMeeting with stakeholders to explain the strategy and incorporate feedback is the best way for a CIO to secure support for a strategy to achieve long-term IT objectives, because it ensures that the strategy is aligned with the needs, expectations, and interests of the stakeholders, and that the stakeholders are engaged, informed, and committed to the strategy. By meeting with stakeholders, the CIO can communicate the vision, goals, and benefits of the strategy, andaddress any questions, concerns, or objections that the stakeholders may have. By incorporating feedback, the CIO can demonstrate respect and appreciation for the stakeholder input, and make any necessary adjustments or improvements to the strategy based on the stakeholder perspectives. Meeting with stakeholders and incorporating feedback can also foster trust, collaboration, and innovation between the CIO and the stakeholders, and enhance the value proposition and performance of the strategy. The other options are not as effective as meeting with stakeholders and incorporating feedback, because they are either too autocratic, too vague, or too passive to secure support for a strategy to achieve long-term IT objectives. Making the necessary strategic decisions and notifying staff accordingly is a top-down approach that may alienate or antagonize the stakeholders, and create resistance or conflict. Developing tactics to implement the strategy and share with stakeholders is a tactical approach that may not address the strategic alignment, integration, or evaluation of the strategy. Developing a communication plan for distribution of information to staff is a one-way approach that may not elicit stakeholder feedback, engagement, or commitment. According to Stakeholder management: Your plan for influencing project outcomes, "Stakeholder management is essentially stakeholder relationship management as it is the relationship and not the actual stakeholder groups that are managed."
Question 69
Single choice
Which of the following BEST supports an enterprise's ability to comply with privacy laws and regulations?
-
A
Complete inventory of enterprise data
-
B
Implementation of a breach notification process
-
C
Accurate classification of enterprise data
-
D
Robust enterprise policy related to data retention
Reveal answer details
Close answer details
Correct answerC
Explanationbecause this would help the enterprise to comply with privacy laws and regulations by identifying and labeling the data according to its sensitivity, confidentiality, and protection requirements. Data classification can help the enterprise to apply the appropriate security controls, access rights, retention policies, and disposal methods for the data, and to prevent unauthorized or unlawful use, disclosure, or breach of the data. Data classification can also help the enterprise to demonstrate its accountability and transparency for the data processing activities, and to meet the expectations and rights of the data subjects.
Question 70
Single choice
What is the PRIMARY benefit of aligning information architecture with enterprise architecture (EA)?
-
A
It improves communication with senior management and the business.
-
B
It ensures the adoption of enterprise data quality standards.
-
C
It enables the tracing of data to business functions.
-
D
It facilitates appropriate access to data consumers.
Reveal answer details
Close answer details
Correct answerC
ExplanationInformation architecture is the design and organization of data and information assets in an enterprise, such as databases, documents, metadata, and taxonomies. Enterprise architecture (EA) is the holistic view and planning of the business strategy, processes, systems, and technology in an enterprise, such as business architecture, application architecture, data architecture, and technology architecture. Aligning information architecture with EA means ensuring that the data and information assets are consistent, coherent, and supportive of the EA goals and objectives. The primary benefit of aligning information architecture with EA is that it enables the tracing of data to business functions, which means that the data can be linked to the business processes, activities, roles, and outcomes that use or produce it. This benefit has several advantages for the enterprise, such as: Improving data quality, accuracy, and reliability by identifying and resolving any data issues or gaps in the business functions Enhancing data governance, security, and compliance by defining and enforcing the data policies and standards for the business functions Increasing data value, usability, and accessibility by providing the data consumers with relevant and timely data for their business functions Supporting data-driven decision making and innovation by enabling the analysis and evaluation of data for the business functions The other options are not the primary benefit of aligning information architecture with EA, but rather secondary or potential benefits. Improving communication with senior management and the business is a benefit of EA in general, but not specific to information architecture alignment. Ensuring the adoption of enterprise data quality standards is a benefit of data governance, which may be facilitated by information architecture alignment, but not guaranteed. Facilitating appropriate access to data consumers is a benefit of data security and privacy, which may be improved by information architecture alignment, but not directly. References: 1: What is Enterprise Architecture? | Gartner 2: Aligning Information Architecture with Business Strategy - DATAVERSITY 3: The Benefits of Enterprise Architecture in Organizational ... 4: An Enterprise Architecture Approach for Assessing the Alignment Between
Question 71
Single choice
A board of directors wants to ensure the enterprise is responsive to changes in its environment that would directly impact critical business processes. Which of the following will BEST facilitate meeting this objective?
-
A
Scheduling frequent threat analyses
-
B
Monitoring key risk indicators (KRIs)
-
C
Regularly reviewing the enterprise risk appetite
-
D
Implementing a competitive intelligence tool
Reveal answer details
Close answer details
Correct answerB
ExplanationKey risk indicators (KRIs) are metrics that predict potential risks that can negatively impact businesses. They provide a way to quantify and monitor each risk. Think of them as change-related metrics that act as an early warning risk detection system to help companies effectively monitor, manage and mitigate risks. By monitoring KRIs, the board of directors can ensure the enterprise is responsive to changes in its environment that would directly impact critical business processes, such as market fluctuations, customer preferences, regulatory compliance, operational efficiency, or cyber threats. Monitoring KRIs can help the board of directors to identify and assess the current and emerging risks, to evaluate the effectiveness and performance of the risk management strategies and controls, to communicate and report the risk status and issues, and to take timely and appropriate actions to prevent or reduce the impact of the risks. References: How to Develop Key Risk Indicators (KRIs) to Fortify Your Business. ThePower of KRIs in Enterprise Risk Management (ERM). KRI (Key Risk Indicator): Understanding KRI and why is it important?. Key Risk Indicators (KRIs).
Question 72
Single choice
A board of directors has just received a report indicating that only a small number of IT initiatives have been completed on time and within budget, A third of the projects were cancelled prior to completion, and more than half will cost almost double their original estimates. An analysis has determined that no one is held responsible for the completion of investmentinitiatives, and there is no consistency in execution. Which of the following would BEST help the enterprise address these problems?
-
A
Establishing a project governance framework
-
B
Assigning business management to an IT investment review board
-
C
Establishing an IT risk management plan
-
D
Aligning IT investment priorities to the business
Reveal answer details
Close answer details
Correct answerA
ExplanationA project governance framework is a set of principles, policies, roles, responsibilities, and processes that guide, direct, and control the initiation, planning, execution, monitoring, and closure of IT projects. A project governance framework can help the enterprise address the problems of poor project performance, lack of accountability, and inconsistency in execution by: Providing a clear and consistent structure for managing IT projects across the enterprise Aligning IT projects with the strategic objectives and priorities of the enterprise Defining the roles and responsibilities of the project stakeholders, including the board of directors, senior management, project sponsors, project managers, project teams, and end-users Establishing the criteria and methods for selecting, prioritizing, approving, and funding IT projects Setting the standards and expectations for project planning, execution, quality, risk management, communication, and reporting Implementing the mechanisms and tools for monitoring, controlling, evaluating, and reviewing IT project performance and outcomes Ensuring the accountability and transparency of IT project decisions and results References: According to the CGEIT Review Manual 2022, "Project governance is a subset of IT governance that provides a framework for managing IT projects. Project governance ensures that IT projects are aligned with business objectives are delivered on time, within budget, and with acceptable quality and are managed in a consistent and transparent manner." According to the ISACA article on Project Governance: An Essential Element of Project Management Success, "Project governance is an empowering aspect of the project management office (PMO) infrastructure management. It enables effective decision making by providing clarity on roles and responsibilities it also provides a framework for escalation management." According to the PMI article on Project Governance: What You Need to Know, "Project governance is a critical element of any project since it provides a framework for accountabilities and responsibilities associated with an organization's capital investments (projects). It is defined as an integrated framework of processes and tools that address matters essential to successful project delivery."
Question 73
Single choice
Which of the following is the MOST important consideration when integrating a new vendor with an enterprise resource planning (ERP) system?
-
A
IT senior management selects the vendor.
-
B
A vendor risk assessment is conducted
-
C
ERP data mapping is approved by the enterprise architect.
-
D
Procurement provides the terms of the contract.
Reveal answer details
Close answer details
Correct answerB
ExplanationA vendor risk assessment is the most important consideration when integrating a new vendor with an ERP system, because it helps to identify and evaluate the potential risks or hazards associated with the vendor's operations and products and their impact on the organization. A vendor risk assessment can cover aspects such as security, compliance, quality, reliability, performance, and contingency plans. By conducting a vendor risk assessment, the organization can mitigate the risks and ensure a smooth and secure integration with the ERP system. The other options are not as important as a vendor risk assessment, because they are either dependent on or secondary to it. IT senior management selects the vendor based on the results of the vendor risk assessment and other criteria. ERP data mapping is approved by the enterprise architect afterthe vendor risk assessment confirms that the vendor's data is compatible and consistent with the ERP system. Procurement provides the terms of the contract after the vendor risk assessment validates that the vendor meets the organizational standards and obligations. References: Guide to Vendor Risk Assessment, 10 Risk Assessment Factors for ERP System Integration Projects, Ensuring Vendor Compliance and Third-Party Risk Mitigation
Question 74
Single choice
Following a re-prioritization of business objectives by management, which of the following should be performed FIRST to allocate resources to IT processes?
-
A
Perform a maturity assessment.
-
B
-
C
Refine the human resource management plan.
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationThe IT strategy is the document that defines how IT will be used to support and achieve the business objectives of the organization. It aligns the IT investments, resources, and activities with the business priorities and direction. When there is a change in the business objectives, such as a re-prioritization by management, the IT strategy should be updated accordingly to ensure that IT remains relevant and aligned with the new business goals. Updating the IT strategy should be done first before allocating resources to IT processes, because it provides the basis for determining which IT processes are most critical and valuable for the organization. The other options are not the best actions to perform first in this scenario. Performing a maturity assessment, implementing a RACI model, and refining the human resource management plan are all useful activities for improving the IT processes, but they are not directly related to the change in business objectives. They should be done after updating the IT strategy, based on the new strategic direction and priorities. References: 1: (https://www.projectpractical.com/human-resource-management-plan-template-free-download/) 2: (https://open.lib.umn.edu/humanresourcemanagement/chapter/2-2-writing-the-hrm-plan/) 3: (https://www.isixsigma.com/getting-started/are-you-ready-how-conduct-maturity-assessment/) 4: (https://www.smartsheet.com/content/organizational-maturity) 5: (https://www.process.st/maturity-model/)
Question 75
Single choice
Before establishing IT key risk indicators (KRls) which of the following should be defined FIRST?
-
A
-
B
IT risk and security framework
-
C
-
D
IT key performance indicators (KPIs)
Reveal answer details
Close answer details
Correct answerC
ExplanationIT goals and objectives are the desired outcomes and targets that IT aims to achieve in support of the business strategy and objectives. IT goals and objectives should be defined first before establishing IT key risk indicators (KRIs), because they provide the direction and scope for the IT risk management process. KRIs are metrics that measure and monitor the level and trend of risk exposure, and help to identify and manage potential threats or opportunities that could affect the achievement of IT goals and objectives. Therefore, by defining IT goals and objectives first, an enterprise can ensure that its KRIs are relevant, aligned, and consistent with its IT strategy and value delivery. References: Key Risk Indicators (KRIs) - ISACA, Integrating KRIs and KPIs for Effective Technology Risk Management - ISACA.
Question 76
Single choice
An enterprise recently experienced a major breach that was escalated effectively. However, the recovery took far longer than expected, resulting in significant financial loss. Which of the following is MOST likely the root cause of this scenario?
-
A
Key performance indicators (KPIs) were not regularly monitored
-
B
The recovery point objective (RPO) was not established
-
C
The disaster recovery plan (DRP) was not routinely updated
-
D
The business continuity plan (BCP) was not recently tested
Reveal answer details
Close answer details
Correct answerD
ExplanationThe most likely root cause in this scenario is that thebusiness continuity plan (BCP) was not recently tested.A plan may exist and be theoretically sound, but without testing, organizations cannot assess whether recovery procedures work effectively under real conditions. Testing ensures that time estimates are realistic, personnel understand their roles, and systems perform as expected. A lack of testing results in delays, confusion, and extended recovery times--even with escalation processes functioning well. References: CGEIT Review Manual: Domain 4 ?Risk Optimization, Continuity Management COBIT 2019: DSS04 (Manage Continuity).
Question 77
Single choice
When conducting a risk assessment in support of a new regulatory requirement, the IT risk committee should FIRST consider the:
-
A
disruption to normal business operations.
-
B
risk profile of the enterprise.
-
C
readiness of IT systems to address
-
D
the risk cost burden to achieve compliance.
Reveal answer details
Close answer details
Correct answerB
ExplanationThe risk profile of the enterprise is the most important thing to consider first when conducting a risk assessment in support of a new regulatory requirement, as it reflects the overall exposure and tolerance of the enterprise to various types of risks, such as strategic, operational, financial, or compliance risks. The risk profile of the enterprise can help determine the scope, objectives, and criteria of the risk assessment, as well as the prioritization and allocation of resources and efforts for risk identification, analysis, evaluation, and treatment. The risk profile of the enterprise can also help align the risk assessment with the enterprise's strategy, goals, and values, as well as ensure consistency and integration with other risk management activities or processes. Disruption to normal business operations, readiness of IT systems to address the risk, and cost burden to achieve compliance are also important things to consider when conducting a risk assessment in support of a new regulatory requirement, but they are not the first thing to consider. Disruption to normal business operations is a potential consequence or impact of the risk on the enterprise's performance, productivity, or continuity. Disruption to normal business operations can be assessed and measured during the risk analysis or evaluation stage of the risk assessment, as well as mitigated or reduced during the risk treatment or response stage. Readiness of IT systems to address the risk is a factor that affects the capability or maturity of the enterprise's IT infrastructure, applications, or services to comply with or support the new regulatory requirement. Readiness of IT systems to address the risk can be assessed and improved during the risk treatment or response stage of the risk assessment, as well as monitored and reported during the risk communication or review stage. Cost burden to achieve compliance is a factor that affects the feasibility or affordability of the enterprise's actions or investments to comply with or support the new regulatory requirement. Cost burden to achieve compliance can be estimated and optimized during the risk treatment or response stage of the risk assessment, as well as balanced with the benefits or value of compliance.
Question 78
Single choice
Which of the following roles is accountable for the confidentiality, integrity and availability of information within an enterprise?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationThe data owner is the role that is accountable for the confidentiality, integrity, and availability of information within an enterprise, because the data owner is the person who has the authority and responsibility to classify, label, and protect the information assets according to their value and sensitivity. The data owner also defines the business requirements for the information security and ensures that the data custodian implements the appropriate controls to safeguard theinformation. The data owner is also part of the IT governance domain 4: Value Delivery.
Question 79
Single choice
The BEST way for a CIO to justify maintaining and supporting social media platforms is by demonstrating:
-
A
how social media technology fits into the IT investment management process.
-
B
that service level agreements (SLAs) for social media technologies have been met.
-
C
the IT performance Of social media technologies.
-
D
the value derived from investment in social media technologies.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe best way for a CIO to justify maintaining and supporting social media platforms is by demonstrating the value derived from investment in social media technologies. Social media platforms are not just tools for communication and entertainment, but also strategic assets that can create and deliver value to the organization and its stakeholders. Some of the potential benefits of social media platforms are: Enhancing customer engagement, loyalty, and satisfaction by providing timely, personalized, and interactive content and feedback Increasing brand awareness, reputation, and trust by showcasing the organization's values, achievements, and social responsibility Improving innovation and collaboration by facilitating the exchange of ideas, knowledge, and feedback among employees, customers, partners, and experts Supporting decision making and problem solving by providing access to relevant data, insights, and analytics Reducing costs and increasing efficiency by streamlining processes, automating tasks, and optimizing resources
Question 80
Single choice
An enterprise is replacing its customer relationship management (CRM) system with a cloud-based system. Which of the following should be done FIRST when preparing for data migration?
-
A
Review the enterprise data architecture.
-
B
Establish a data quality plan
-
C
Consult the quality assurance (QA) function.
-
D
Acquire data migration tools.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe enterprise data architecture is the blueprint that defines how data is collected, stored, processed, integrated, and distributed within the enterprise. It also specifies the data standards, policies, rules, and models that govern the data lifecycle. Reviewing the enterprise data architecture is the first step when preparing for data migration, as it helps to identify the source and target systems, the data entities and attributes, the relationships and dependencies, the data quality and security requirements, and the potential challenges and risks of the migration. Reviewing the enterprise data architecture also helps to align the data migration with the business objectives and strategies, and to ensure that the migrated data supports theenterprise's information needs and decision making. References: CGEIT Exam Content Outline | ISACA1, CGEIT Review Manual (Digital Version), Data Architecture: A Primer for the Data Scientist, Data Migration: A Comprehensive Guide
Question 81
Single choice
A large enterprise is implementing an information security policy exception process. The BEST way to ensure that security risk is properly addressed is to:
-
A
confirm process owners' acceptance of residual risk.
-
B
perform an internal and external network penetration test.
-
C
obtain IT security approval on security policy exceptions.
-
D
benchmark policy against industry best practice.
Reveal answer details
Close answer details
Correct answerA
ExplanationThe best way to ensure that security risk is properly addressed when implementing an information security policy exception process is to confirm process owners' acceptance of residual risk. Residual risk is the risk that remains after applying controls or mitigating measures to reduce the original risk. Process owners are the individuals or groups that are responsible for the design, execution, and performance of a business process. By confirming process owners' acceptance of residual risk, the enterprise can ensure that the security risk associated with the policy exception is understood, acknowledged, and agreed upon by the relevant stakeholders. This can also help to assign accountability and liability for the potential consequences of the policy exception, as well as to monitor and review the risk level and the effectiveness of the controls or mitigating measures. The other options are not as effective as confirming process owners' acceptance of residual risk for ensuring that security risk is properly addressed when implementing an information security policy exception process. Performing an internal and external network penetration test is a useful technique for identifying and exploiting vulnerabilities in the network infrastructure, but it does not address the specific security risk related to the policy exception. Obtaining IT security approval on security policy exceptions is a necessary step for validating and authorizing the policy exception, but it does not ensure that the process owners are aware of and accept the residual risk. Benchmarking policy against industry best practice is a good practice for comparing and improving the policy quality and performance, but it does not address the security risk associated with the policy exception.
Question 82
Single choice
A large enterprise has decided to use an emerging technology that needs to be integrated with the current IT infrastructure. Which of the following is the BEST way to prevent adverse effects to the enterprise resulting from the new technology?
-
A
Develop key performance indicators (KPIs).
-
B
Update the risk appetite statement
-
C
Develop key risk indicators (KRIs).
-
D
Implement service level agreements (SLAs)
Reveal answer details
Close answer details
Correct answerC
ExplanationThe best way to prevent adverse effects to the enterprise resulting from the new technology is to develop key risk indicators (KRIs), because they are metrics that measure the potential impact and likelihood of the risks associated with the new technology, and provide early warning signals for taking corrective actions. KRIs can help the enterprise to monitor and manage the risks of integrating the new technology with the current IT infrastructure, and to ensure that the expected benefits and value are realized. References: ISACA, CGEIT Review Manual, 7th Edition, 2019, page 75-76.
Question 83
Single choice
An IT steering committee is concerned about staff saving data files containing sensitive corporate information on publicly available cloud file storage applications. Which of the following should be done FIRST to address this concern?
-
A
Create a secure corporate cloud file storage and sharing solution.
-
B
Block corporate access to cloud file storage applications.
-
C
Require staff training on data classification policies.
-
D
Revise the data management policy to prohibit this practice.
Reveal answer details
Close answer details
Correct answerC
ExplanationTo address concerns about staff saving sensitive corporate information on publicly available cloud file storage applications, the first step should be to require staff training on data classification policies. Educating employees about the types of data classified as sensitive and the associated handling requirements helps to raise awareness and change behavior. Training should emphasize the importance of protecting sensitive information and the proper use of approved storage solutions. While creating secure storage solutions, blocking access to certain applications, and revising policies are important measures, education and awareness are fundamental first steps to ensure compliance and mitigate risks.
Question 84
Single choice
Which of the following is MOST important to ensure when aligning IT and enterprise resource management processes?
-
A
IT sourcing processes are in place
-
B
IT provides input for business strategy development
-
C
IT resources are mapped to business priorities
-
D
IT resource monitoring and oversight is in place
Reveal answer details
Close answer details
Correct answerC
ExplanationThemost critical factor in aligning IT and enterprise resource managementis ensuring thatIT resources are mapped to business priorities. This guarantees that resource allocation supports strategic objectives and delivers maximum value. Without this alignment, IT efforts may be misdirected, underutilized, or not supporting enterprise goals--even if sourcing and monitoring are in place. References: CGEIT Review Manual: Domain 2 ?IT Resources COBIT 2019: APO07 (Manage Human Resources), BAI01 (Manage Programs and Projects).
Question 85
Single choice
Which of the following is MOST important to effectively incorporate innovation and emerging technologies into an enterprise's IT strategy?
-
A
Implementing new technologies based on maturity roadmaps according to reputable consulting entities.
-
B
Maintaining an IT strategy based on traditional technologies, supplemented by objectives for innovation.
-
C
Establishing a formal innovation management process that involves IT and business stakeholders.
-
D
Performing quarterly feedback reviews with focus groups representing the enterprise's customer base.
Reveal answer details
Close answer details
Question 86
Single choice
The CEO of a large enterprise has announced me commencement of a major business expansion that will double the size of the organization. IT will need to support the expected demand expansion. What should the CIO do FIRST?
-
A
Review the resource utilization matrix.
-
B
Recruit IT resources based on the expansion decision.
-
C
Embed IT personnel in the business units.
-
D
Update the IT strategic plan to align with the decision.
Reveal answer details
Close answer details
Correct answerD
ExplanationThe CIO should update the IT strategic plan to align with the decision of the CEO to commence a major business expansion that will double the size of the organization. This means that the CIO should review the current IT vision, mission, goals, objectives, strategies, and actions, and assess how they support the business expansion plan. The CIO should also identify the IT opportunities, challenges, risks, and gaps that may arise from the business expansion, and develop appropriate solutions and mitigation measures. The CIO should then revise the IT strategic plan to reflect the changes and ensure that IT is aligned with and contributes to the business growth and success
Question 87
Single choice
An enterprise is trying to increase the maturity of its IT process from being ad hoc to being repeatable. Which of the following is the PRIMARY benefit of this change?
-
A
Process optimization is embedded across the organization.
-
B
Required outcomes are mapped to business objectives.
-
C
Process performance is measured in business terms.
-
D
Required outcomes are more frequently achieved.
Reveal answer details
Close answer details
Correct answerD
ExplanationIncreasing the maturity of IT process from being ad hoc to being repeatable means that the process is documented and followed consistently, resulting in more predictable and reliable outcomes. According to the capability maturity model for the IT governance process, a repeatable level indicates that "required outcomes are more frequently achieved" . References: CGEIT Domain 1: Framework for the Governance of Enterprise IT
Question 88
Single choice
Of the following, who should approve the criteria for information quality within an enterprise?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
ExplanationInformation owners are responsible for defining the quality criteria for information within their domain, based on business requirements and stakeholder expectations. Information owners are also accountable for ensuring that information quality is maintained and improved. References: COBIT 5: Enabling Information, chapter 4, section 4.2.1
Question 89
Single choice
An enterprise has learned of a new regulation that may impact delivery of one of its core technology services. Which of the following should the done FIRST?
-
A
Update the risk management framework
-
B
Determine whether the board wants to comply with the regulation
-
C
Assess the risk associated with the new regulation
-
D
Request an action plan from the risk team
Reveal answer details
Close answer details
Correct answerC
ExplanationThe first thing that the enterprise should do after learning of a new regulation that may impact delivery of one of its core technology services is to assess the risk associated with the new regulation. A risk assessment is a process of identifying, analyzing, and evaluating the potential threats and impacts of a risk event on the enterprise's objectives, processes, and resources. A risk assessment can help the enterprise understand the nature, scope, and severity of the new regulation, as well as its compliance requirements, costs, and benefits. A risk assessment can also help the enterprise prioritize and implement the appropriate risk responses, such as avoiding, reducing, transferring, or accepting the risk. According to COBIT 5, one of the seven enablers of IT governance is risk management, which includes assessing IT-related risks and aligning them with enterprise risks. The risk assessment is also part of the IT governance domain: Risk Management. The other options are not the first things that the enterprise should do after learning of a new regulation. Updating the risk management framework is a step that may be done after assessing the risk associated with the new regulation, as it involves reviewing and improving the policies, procedures, and practices for managing IT risks in the enterprise. Determining whether the board wants to comply with the regulation is a step that may be done after assessing the risk associated with the new regulation, as it involves consulting with the board and other stakeholders on the strategic and ethical implications of complying or not complying with the regulation. Requesting an action plan from the risk team is a step that may be done after assessing the risk associated with the new regulation, as it involves defining and executing the tasks and activities for achieving compliance and mitigating risk.
Question 90
Single choice
Which of the following is the MOST important attribute of an information steward?
-
A
The information steward manages the systems that process the relevant data.
-
B
The information steward has expertise in managing data quality systems.
-
C
The information steward is closely aligned with the business function.
-
D
The information steward is part of the information architecture group.
Reveal answer details
Close answer details
Correct answerC
ExplanationAn information steward is a person who is responsible for ensuring the quality, accuracy, consistency, and usability of the data in an organization. An information steward works with the business users and stakeholders to understand their data needs, requirements, and expectations, and to define and implement the data policies, standards, and rules that govern the data lifecycle. An information steward also monitors and reports on the data quality issues and trends, and initiates and coordinates the data improvement actions and projects. The most important attribute of an information steward is to be closely aligned with the business function, because this can help to ensure that the data supports the business goals and objectives, that the data meets the business expectations and requirements, that the data is relevant and useful for the business decisions and actions, and that the data is aligned with the business processes and workflows. The information steward does not necessarily manage the systems that process the relevant data, as this may be done by other IT roles, such as data engineers, data analysts, or data administrators. The information steward does not need to have expertise in managing data quality systems, as this may be a technical skill that can be acquired or supported by other IT roles or tools. The information steward does not need to be part of the information architecture group, as this may be a separate function that focuses on designing and maintaining the data structures, models, and standards. References: Information Steward settings option descriptions - SAP Online Help. What is an Information Steward, and Why You Should Care?. 6 Key Responsibilities of the Invaluable Data Steward - Dun & Bradstreet.
Question 91
Single choice
Which of the following would be MOST helpful to review when determining how to allocate IT resources during a resource shortage?
-
A
-
B
-
C
IT organizational structure
-
D
IT skill development plan
Reveal answer details
Close answer details
Correct answerB
ExplanationAn IT skills inventory is a list of the skills, competencies, and qualifications of the IT staff in an organization. It can help to identify the current and potential capabilities of the IT workforce, as well as the gaps and needs for improvement. An IT skills inventory would be most helpful to review when determining how to allocate IT resources during a resource shortage, because it canhelp to match the right people with the right tasks, optimize the utilization and productivity of the existing IT staff, and prioritize the critical and urgent IT activities. The other options are not as helpful as an IT skills inventory for allocating IT resources during a resource shortage. An IT strategic plan is a document that defines the vision, mission, goals, and objectives of the IT function and how they align with the business strategy. It can help to guide the direction and scope of the IT activities and investments, but it does not provide detailed information on the availability and suitability of the IT resources. An IT organizational structure is a diagram that shows the hierarchy, roles, and responsibilities of the IT staff in an organization. It can help to clarify the reporting lines and communication channels of the IT function, but it does not reflect the skills and competencies of the IT staff. An IT skill development plan is a document that outlines the learning and training opportunities for the IT staff to enhance their skills and competencies. It can help to improve the performance and career progression of the IT staff, but it does not address the immediate needs and challenges of allocating IT resources during a resource shortage. References: What is an IT Skills Inventory?, How to Conduct an Effective Skills Gap Analysis, Resource allocation 101: How to manage your team's resources | Planio
Question 92
Single choice
Which of the following is the PRIMARY responsibility of a data steward?
-
A
Ensuring the appropriate users have access to the right data
-
B
Developing policies for data governance
-
C
Reporting data analysis to the board
-
D
Classifying and labeling organizational data assets
Reveal answer details
Close answer details
Correct answerD
ExplanationOne of the primary responsibilities of a data steward is to classify and label organizational data assets, which means to assign categories and tags to the data based on its characteristics, such as type, source, sensitivity, quality, or purpose. Classifying and labeling data helps to organize, manage, and protect the data assets, as well as to facilitate their discovery, access, and usage. Data stewards are also responsible for defining and maintaining the data classification and labeling standards and policies, and ensuring their compliance across the organization. References: What Is a Data Steward? Roles & Responsibilities | Zuar1, Data Stewards: Who They Are & Why Data Stewardship Matters - HubSpot Blog2, Data Steward: Roles, Responsibilities, and Certification3
Question 93
Single choice
Which of the following is the MOST significant challenge faced by an enterprise when establishing information stewardship?
-
A
Lack of documented policies and procedures
-
B
Information requirements of regulatory authorities
-
C
Insufficient knowledge of IT practices and controls
-
D
Lack of role clarity and specific responsibilities
Reveal answer details
Close answer details
Correct answerD
ExplanationThe most significant challenge faced by an enterprise when establishing information stewardship is the lack of role clarity and specific responsibilities, as this can lead to confusion, duplication, inconsistency, or omission of tasks and activities related to information governance. Information stewardship is the role of providing day-to-day operational support using data, such as defining and implementing data policies, standards, and procedures; monitoring and reporting on data compliance and performance; and collaborating with other stakeholders to ensure data quality, integrity, and security. Information stewardship requires clear and consistent definition of the scope, objectives, and expectations of the role, as well as the roles and responsibilities of the information stewards and their relationship with other data owners, users, or scientists. Withoutrole clarity and specific responsibilities, information stewardship may not be effective or efficient in achieving the desired outcomes or benefits of information governance. Lack of documented policies and procedures, information requirements of regulatory authorities, and insufficient knowledge of IT practices and controls are also challenges faced by an enterprise when establishing information stewardship, but they are not the most significant challenge. Lack of documented policies and procedures is a challenge that can affect the standardization and improvement of information governance processes and activities, as well as the communication and enforcement of data rules and expectations. Information requirements of regulatory authorities are a challenge that can affect the compliance and accountability of information governance, as well as the protection and privacy of data. Insufficient knowledge of IT practices and controls is a challenge that can affect the technical skills and capabilities of information stewards, as well as their ability to use or integrate data systems or tools. References: What is an Information Steward? | Informatica What is an Information Steward, and Why You Should Care What is an Information Steward, and Why You Should Care?.
Question 94
Single choice
A board of directors is concerned that a major IT implementation has the potential to significantly disrupt enterprise operations. Which of the following would be MOST helpful in identifying the extent of the potential impact of the disruption?
-
A
An analysis of the current enterprise risk appetite
-
B
An earned value analysis (EVA) of the implementation
-
C
A risk assessment of the implementation
-
D
A review of lessons learned from previous implementations
Reveal answer details
Close answer details
Correct answerC
ExplanationA risk assessment of the implementation would be most helpful in identifying the extent of the potential impact of the disruption, as it would evaluate the likelihood and consequences of various scenarios that could affect the enterprise operations. A risk assessment would also help to identify and prioritize the mitigation strategies and contingency plans for the implementation. References: CGEIT Exam Content Outline, Domain 4, Subtopic B: IT Risk Management, Task 1: Ensure that an IT risk management framework exists to identify, analyze, mitigate, manage, monitor, and communicate IT-related business risk, and that the framework for IT risk management is in alignment with the enterprise risk management (ERM) framework 1.
Question 95
Single choice
Which of the following is a PRIMARY responsibility of the CIO when an enterprise plans to replace its enterprise resource applications?
-
A
Reviewing the IT application portfolio
-
B
Evaluating and selecting application vendors
-
C
Ensuring IT architecture requirements are considered
-
D
Establishing software quality criteria
Reveal answer details
Close answer details
Correct answerC
ExplanationThe CIO is the chief information officer of an enterprise, who oversees and optimizes the use of information technology (IT) to achieve the business objectives and strategy. One of the primary responsibilities of the CIO is to ensure that IT architecture requirements are considered when an enterprise plans to replace its enterprise resource applications (ERAs). ERAs are integrated software systems that support various business functions, such as finance, accounting, human resources, supply chain, etc. IT architecture requirements are the specifications and standards that define how the IT systems and platforms should be designed, developed, deployed, and maintained to support the ERAs and their users. IT architecture requirements include aspects such as performance, scalability, security, reliability, interoperability, usability, etc. The CIO should ensure that IT architecture requirements are considered when an enterprise plans to replace its ERAs, because they can affect the quality, efficiency, and effectiveness of the ERAs and their alignment with the business needs and goals. The CIO should also ensure that the IT architecture requirements are consistent with the enterprise's IT strategy and vision, and that they comply with the relevant policies, regulations, and best practices.
Question 96
Single choice
When implementing an IT governance framework, which of the following would BEST ensure acceptance of the framework?
-
A
Factoring in the effects of enterprise culture
-
B
Using subject matter experts
-
C
Using industry-accepted practices
-
D
Complying with regulatory requirements
Reveal answer details
Close answer details
Correct answerA
ExplanationWhen implementing an IT governance framework, it is important to consider the effects of enterprise culture on the acceptance and adoption of the framework. Enterprise culture is the set of values, beliefs, norms, and behaviors that shape how an organization operates and interacts with its stakeholders. A mismatch between the IT governance framework and the enterprise culture can lead to resistance, conflict, or failure of the framework. Therefore, it is best to factor in the effects of enterprise culture and tailor the framework to suit the specific context and needs of the organization. The other options are not the best way to ensure acceptance of the framework, but rather some of the factors that can influence the design and implementation of the framework. Using subject matter experts, industry-accepted practices, and complying with regulatory requirements can help to ensure the quality, relevance, and compliance of the framework, but they do not necessarily guarantee its acceptance by the organization. References: ISACA, CGEIT Review Manual, 27th Edition, 2020, page 12 Implementing Good Governance Principles for the Public Sector in Information Technology Governance Frameworks
Question 97
Single choice
Which of the following is MOST important to consider when planning to implement a cloud-based application for sharing documents with internal and external parties?
-
A
Cloud implementation model
-
B
-
C
-
D
Third-party access rights
Reveal answer details
Close answer details
Correct answerC
ExplanationInformation ownership is the right and responsibility to define, classify, protect, and manage the data assets of an enterprise. When using a cloud-based application, the enterprise should ensure that it retains the ownership and control of its information, and that it complies with the relevant laws and regulations regarding data privacy, security, and sovereignty. The enterprise should also establish clear policies and agreements with the cloud service provider and the internal and external parties regarding the access, usage, storage, transfer, retention, and disposal of the information. By considering information ownership, the enterprise can mitigate the risks and challenges of using a cloud-based application, such as data breaches, unauthorized access, vendor lock-in, legal disputes, or reputational damage. The other options are not as important as information ownership, as they are secondary or dependent factors. Cloud implementation model is the type of cloud service that the enterprise chooses to use, such as software as a service (SaaS), platform as a service (PaaS), or infrastructure as a service (IaaS)3. Cloud implementation model can affect the cost, performance, scalability, and flexibility of the cloud-based application, but it does not directly affect the ownership and governance of the information. User experience is the perception and satisfaction of the users when interacting with the cloud-based application. User experience can affect the adoption, engagement, and productivity of the users, but it does not directly affect the ownership and governance of the information. Third-party access rights are the permissions and restrictions that the enterprise grants to external parties to access and use its information through the cloud-based application. Third-party access rights can affect the security and privacy of the information, but they are determined by the information ownership policies and agreements that the enterprise establishes with the cloud service provider and the external parties.
Question 98
Single choice
Which of the following is MOST important to consider when monitoring the performance of IT resources?
-
A
Business impact analysis (BIA)
-
B
-
C
-
D
Service level requirements
Reveal answer details
Close answer details
Question 99
Single choice
In a large enterprise, which of the following is the MOST effective way to understand the business activities associated with the enterprise's information architecture?
-
A
Reviewing IT design with business process managers
-
B
Reviewing business strategy with senior management
-
C
Mapping business processes within a framework
-
D
Aligning business objectives to organizational strategy
Reveal answer details
Close answer details
Correct answerC
ExplanationMapping business processes within a framework is the most effective way to understand the business activities associated with the enterprise's information architecture, as it provides a clear and comprehensive view of how information flows and supports the businessobjectives. References: CGEIT Exam Content Outline, Domain 1, Subtopic C: Information Governance, Task 1: Define and implement information governance processes to ensure alignment with enterprise goals and objectives.
Question 100
Single choice
It has been discovered that multiple business units across an enterprise are using duplicate IT applications and services to fulfill their individual needs. Which of the following would be MOST helpful to address this concern?
-
A
Enterprise architecture (EA)
-
B
Enterprise risk framework
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
ExplanationEnterprise architecture (EA) is a discipline that defines and organizes the components, relationships, principles, and standards of an organization's IT environment. EA can help to align IT with business strategy and objectives, optimize IT performance and value, and manage IT complexity and change. One of the benefits of EA is that it can help to address the concern of duplicate IT applications and services across an enterprise. EA can help to identify and eliminate the redundancies, inconsistencies, and inefficiencies in the IT landscape, by providing a holistic and integrated view of the current and future state of IT. EA can also help to rationalize and consolidate the IT applications and services, by establishing a common framework, taxonomy, and governance for IT decision making. EA can also help to improve the integration and interoperability of IT applications and services, by defining the interfaces, protocols, and standards for data exchange. Some examples of how EA can help to address the concern of duplicate IT applications and services are: EA can help to conduct an inventory and assessment of the existing IT applications and services, to determine their purpose, scope, functionality, quality, cost, and value. EA can also help to compare and contrast the IT applications and services across different business units, to identify the overlaps, gaps, or conflicts among them 4. EA can help to define and prioritize the business needs and requirements for IT applications and services, to ensure that they support the business goals and processes. EA can also help to evaluate and select the best IT solutions for each business need, based on criteria such as feasibility, suitability, scalability, security, compliance, etc 5. EA can help to design and implement a target IT architecture that eliminates or minimizes the duplicate IT applications and services, by using approaches such as application portfolio management (APM), service-oriented architecture (SOA), or cloud computing. EA can also help to plan and execute a migration strategy that ensures a smooth transition from the current to the target state . EA can help to monitor and control the IT applications and services, by using metrics, indicators, and reports to measure their performance, availability, reliability, quality, and value. EA can also help to review and update the IT applications and services regularly, by using feedback mechanisms and continuous improvement practices. References: What is Enterprise Architecture? Definition & Frameworks. Enterprise Architecture: Definition & Best Practices. How Enterprise Architecture Can Help You Eliminate Technical Debt. Application Inventory: Definition & Best Practices. Business Requirements: Definition & Best Practices. [Application Portfolio Management: Definition & Best Practices]. [Service-Oriented Architecture: Definition & Benefits]. [IT Performance Management: Definition & Best Practices]. [Continuous Improvement: Definition & Best Practices].
|