Skip to main content

CGEIT Real Exam Questions

Certified in the Governance of Enterprise IT

666 questions available · Page 1 of 67

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

An enterprise experiencing issues with data protection and least privilege is implementing enterprise-wide data encryption in response.

Which of the following is the BEST approach to ensure all business units work toward remediating these issues?

  1. A

    Develop key performance indicators (KPIs) to measure enterprise adoption.

  2. B

    Integrate data encryption requirements into existing and planned projects.

  3. C

    Assign owners for data governance initiatives.

  4. D

    Mandate the creation of a data governance framework.

Show answer and explanation

Correct answer: D

Explanation

A data governance framework is a set of policies, standards, roles, and processes that define how data is collected, stored, accessed, and used within an enterprise. A data governance framework can help address data protection and least privilege issues by establishing clear rules and responsibilities for data owners, custodians, and users. A data governance framework can also enable data encryption as a key control to protect sensitive data from unauthorized access or disclosure. Therefore, mandating the creation of a data governance framework is the best approach to ensure all business units work toward remediating these issues.
References:
CGEIT Review Manual (Digital Version), Chapter 4: Risk Optimization, Section 4.3: IT Risk Management,
Subsection 4.3.2: IT Risk Management Process, Page 156 : CGEIT Review Manual (Digital Version),
Chapter 5:
Resource Optimization, Section 5.2: Information Resource Management, Subsection 5.2.1:
Information Resource Management Overview, Page 183 : A Guide to Selecting and Adopting a Privacy Framework1

Question 2 Single choice

An internal audit revealed a widespread perception that the enterprise's IT governance reporting lacks transparency.

Which of the following should the CIO do FIRST?

  1. A

    Add stakeholder transparency metrics to the balanced scorecard

  2. B

    Develop a communication and awareness strategy

  3. C

    Meet with key stakeholders to understand their concerns

  4. D

    Adopt an industry-recognized template to standardize reports.

Show answer and explanation

Correct answer: C

Explanation

The CIO should first meet with key stakeholders to understand their concerns about the IT governance reporting transparency. This will help the CIO to identify the root causes of the perception, the expectations and needs of the stakeholders, and the gaps and issues in the current reporting process. Meeting with key stakeholders will also help to build trust and rapport, and to solicit feedback and suggestions for improvement. The CIO can then use this information to develop a communication and awareness strategy, adopt a standard template, and add transparency metrics to the balanced scorecard. These actions will help to enhance the transparency, consistency, and quality of the IT governance reporting, and to address the stakeholder concerns effectively.
References:
How Boards Realise IT Governance Transparency: A Study Into Current Practice of the COBIT EDM05
Process, Page 1.

Question 3 Single choice

Which of the following should be done FIRST when designing an IT balanced scorecard?

  1. A

    Develop key performance indicators (KPIs).

  2. B

    Communicate to stakeholders

  3. C

    Analyze the business strategy.

  4. D

    Review the IT resource plan.

Show answer and explanation

Correct answer: C

Explanation

An IT balanced scorecard (BSC) is a tool that helps align IT goals and performance with the business strategy and vision. The first step in designing an IT BSC is to analyze the business strategy and understand its objectives, priorities, and challenges. This will help identify the key stakeholders, customers, and value propositions of the IT function, as well as the critical success factors and risks that affect IT performance. Analyzing the business strategy will also help define the scope and purpose of the IT BSC, and establish the linkages between the IT goals and the business goals. Analyzing the business strategy should be done before developing key performance indicators (KPIs), communicating to stakeholders, or reviewing the IT resource plan, as these steps depend on the clarity and alignment of the business strategy.

Question 4 Single choice

An enterprise has decided to utilize a cloud vendor for the first time to provide email as a service, eliminating in-house email capabilities.

Which of the following IT strategic actions should be triggered by this decision?

  1. A

    Develop a data protection awareness education training program.

  2. B

    Monitor outgoing email traffic for malware.

  3. C

    Implement a data classification and storage management tool.

  4. D

    Update and communicate data storage and transmission policies.

Show answer and explanation

Correct answer: D

Explanation

Data storage and transmission policies are documents that define the rules and guidelines for how data is stored, accessed, shared, and transmitted within and outside an organization. Data storage and transmission policies can help to ensure the security, privacy, compliance, and quality of the data, as well as to prevent data loss, leakage, or breach.
If an enterprise has decided to utilize a cloud vendor for the first time to provide email as a service, eliminating in-house email capabilities, one of the IT strategic actions that should be triggered by this decision is to update and communicate data storage and transmission policies. This is because using a cloud vendor for email as a service may introduce new risks and challenges for data storage and transmission, such as data sovereignty, data ownership, data encryption, data backup, data retention, data deletion, data access control, data audit, data breach notification, etc. Therefore, it is important to update the data storage and transmission policies to reflect the changes in the email environment and the cloud vendor's responsibilities and obligations. It is also important to communicate the updated policies to all relevant stakeholders, such as employees, customers, partners, regulators, etc., to ensure their awareness and compliance.
References:
Data Storage Policy: Definition & Best Practices. Data Transmission Policy: Definition & Best Practices.
Cloud Email Security: Definition & Best Practices. Cloud Data Protection:
Definition & Best Practices.

Question 5 Single choice

A board of directors is concerned with the total cost of IT.

Which of the following is MOST important for the CIO to include in an explanation to the board?

  1. A

    A summary of benefits that will be achieved once key IT initiatives are completed.

  2. B

    A mapping of IT employee roles to the balanced scorecard.

  3. C

    A benchmark of IT employee salary costs against comparable organizations.

  4. D

    A breakdown of operational versus capital expenditures.

Show answer and explanation

Correct answer: D

Question 6 Single choice

Following a strategic planning session, new IT objectives were announced.

Which of the following is the MOST effective way for the CIO to ensure these objectives are cascaded to IT personnel?

  1. A

    Communicate the new IT objectives during a staff meeting.

  2. B

    Define individual performance measures related to the IT objectives.

  3. C

    Establish IT management's performance measures based on the IT objectives.

  4. D

    Update the IT balanced scorecard to align with the new IT objectives.

Show answer and explanation

Correct answer: B

Explanation

The MOST effective way for the CIO to ensure that the new IT objectives are cascaded to IT personnel is to define individual performance measures related to the IT objectives. Cascading goals is a framework to get everyone in an organization aligned with the big picture organizational goal, and to make sure they know what to do by breaking strategy into clear tasks and deliverables. By defining individual performance measures related to the IT objectives, the CIO can: Communicate the expectations and priorities of the IT function to each IT staff member Link the individual goals and activities to the IT objectives and the organizational strategy. Motivate and empower the IT staff to take ownership and responsibility for their work Monitor and evaluate the progress and performance of the IT staff and provide feedback and recognition. The other options are not as effective as option B. While it is important to communicate the new IT objectives, establish IT management's performance measures, and update the IT balanced scorecard, these are not sufficient to ensure that the IT objectives are cascaded to IT personnel. They are rather means to achieve the end goal of aligning and measuring the IT objectives at different levels of the organization. They do not necessarily translate into clear and specific actions and outcomes for each individual IT staff member.

Question 7 Single choice

Which of the following is the BEST IT architecture concept to ensure consistency, interoperability, and agility for infrastructure capabilities?

  1. A

    Establishment of an IT steering committee

  2. B

    Standards-based reference architecture and design specifications

  3. C

    Establishment of standard vendor and technology designations

  4. D

    Design of policies and procedures

Show answer and explanation

Correct answer: B

Explanation

Standards-based reference architecture and design specifications. A reference architecture is a set of principles, patterns, standards, and best practices that guide the design and implementation of IT solutions. A design specification is a detailed document that describes the technical requirements, features, and functionalities of an IT solution. By using standards-based reference architecture and design specifications, an enterprise can ensure that its IT infrastructure is aligned with its business needs and goals, and that it can support the integration, compatibility, and scalability of its IT systems and services.
Some examples of standards-based reference architectures are: The Open Group Architecture Framework (TOGAF) , The Federal Enterprise Architecture Framework (FEAF) , and The Cloud Computing Reference Architecture (CCRA) .

Question 8 Single choice

Which of the following is the BEST way to encourage employees to raise ethics concerns in full confidence?

  1. A

    Publish and enforce a code of conduct policy.

  2. B

    Provide access to legal resource benefits.

  3. C

    Establish and communicate a whistle-blower policy.

  4. D

    Provide protection language in employment contracts.

Show answer and explanation

Correct answer: C

Explanation

A whistle-blower policy is a document that defines how ethics violations should be reported and how the whistle-blowers should be protected from retaliation. A whistle-blower policy is the best way to encourage employees to raise ethics concerns in full confidence, as it provides them with a clear, safe, and confidential channel to voice their concerns and seek resolution. A whistle-blower policy also demonstrates the organization's commitment to ethical conduct and accountability, and fosters a culture of trust and openness. The other options are not as effective as establishing and communicating a whistle-blower policy. Publishing and enforcing a code of conduct policy is important for defining the ethical standards and expectations for the organization, but it does not necessarily encourage employees to raise ethics concerns, unless it is accompanied by a whistle-blower policy that ensures their protection and support.
Providing access to legal resource benefits is helpful for employees who need legal advice or assistance, but it does not guarantee their confidence or safety in reporting ethics violations, especially if they fear retaliation from their employer or co-workers. Providing protection language in employment contracts is useful for safeguarding the rights and interests of employees, but it may not be sufficient or specific enough to address the issues and challenges faced by whistle-blowers, such as harassment, discrimination, or termination.
References:
1: Here's What You Need in Your Whistleblower Policy (and Why) - Case IQ
2: Whistle Blowing in the Public Sector - Markkula Center for Applied Ethics
3: Ethics Policies vs. Whistleblower Policies - What's the Difference? - CMS
4: Legal Resources | Employee Benefits | The Hartford
5: Whistleblower Protection: Overview of Federal Laws | Congressional Research Service

Question 9 Single choice

An enterprise plans to implement a business intelligence (Bl) tool with data sources from various enterprise applications.

Which of the following is the GREATEST challenge to implementation?

  1. A

    Interface issues between enterprise and Bl applications

  2. B

    Large volumes of data fed from enterprise applications

  3. C

    The need for staff to be trained on the new Bl tool

  4. D

    Data definition and mapping sources from applications

Show answer and explanation

Correct answer: D

Explanation

Data definition and mapping sources from applications is the greatest challenge to implementing a business intelligence (BI) tool with data sources from various enterprise applications because it involves ensuring the consistency, accuracy, and quality of data across different systems and formats. Data definition and mapping requires defining common data elements, identifying data sources and targets, establishing data transformation rules, and resolving data conflicts and discrepancies. This is a complex and time-consuming process that requires a high level of coordination and collaboration among different stakeholders and data owners.
References:
According to ISACA's CGEIT Review Manual 2021, one of the key activities for ensuring effective IT-enabled business innovation is to "define and map data sources from various enterprise applications to the
BI tool."
According to ISACA's COBIT 2019 Framework, one of the governance objectives for managing data is to "ensure that data are defined consistently across the enterprise and that data quality issues are identified and resolved." According to ISACA's Business Intelligence: Governance and Analytics guide, one of the challenges for BI governance is to "ensure that data are properly defined, mapped, transformed, integrated, and validated across different sources and systems."

Question 10 Single choice

Which of the following is the PRIMARY benefit to an enterprise when risk management is practiced effectively throughout the organization?

  1. A

    Decisions are made with an awareness of probability and impact.

  2. B

    IT objectives and goals are aligned to business objectives and goals.

  3. C

    Business opportunity losses are minimized.

  4. D

    Innovative strategic initiatives are encouraged.

Show answer and explanation

Correct answer: A

Explanation

Risk management is the process of identifying, analyzing, evaluating, and treating the uncertainties that may affect the achievement of objectives. Risk management helps to ensure that decisions are made with an awareness of probability and impact, which means that the likelihood and consequences of potential events are considered and weighed against the benefits and costs of the actions. This can help to optimize the risk-reward balance, enhance the quality and consistency of decision-making, and support the achievement of desired outcomes.