Summer Sale- Special Discount Limited Time 65% Offer - Ends in 0d 00h 00m 00s - Coupon code: netdisc

Isaca CGEIT Certified in the Governance of Enterprise IT Exam Exam Practice Test

Page: 1 / 68
Total 682 questions

Certified in the Governance of Enterprise IT Exam Questions and Answers

Question 1

In a large enterprise, which of the following should be responsible for the implementation of an IT balanced scorecard?

Options:

A.

Project management office

B.

Chief information officer (CIO)

C.

IT steering committee

D.

Chief risk officer (CRO)

Question 2

When developing a business case for an enterprise resource planning (ERP) implementation, which of the following, if overlooked, causes the GREATEST impact to the enterprise?

Options:

A.

Vendor selection

B.

Salvage value of legacy hardware

C.

Interdependent systems

D.

IT best practices

Question 3

Which of the following provides the BEST evidence of effective IT governance?

Options:

A.

Cost savings and human resource optimization

B.

Business value and customer satisfaction

C.

IT risk identification and mitigation

D.

Comprehensive IT policies and procedures

Question 4

Which of the following would be MOST helpful to an enterprise that wants to standardize how sensitive corporate data is handled?

Options:

A.

Information classification framework

B.

Enterprise risk policy

C.

Enterprise risk management (ERM) framework

D.

Information security policy

Question 5

An IT steering committee wants to select a disaster recovery site based on available risk data Which of the following would BE ST enable the mapping of cost to risk?

Options:

A.

Key risk indicators (KRIs)

B.

Scenario-based assessment

C.

Business impact analysis (BIA)

D.

Qualitative forecasting

Question 6

Reviewing which of the following should be the FIRST step when evaluating the possibility of outsourcing an IT system?

Options:

A.

Outsourcing strategy

B.

Outsourced business processes

C.

Service level agreements (SLAs)

D.

IT staff skill sets

Question 7

When assessing the impact of a new regulatory requirement, which of the following should be the FIRST course of action?

Options:

A.

Update affected IT policies.

B.

Assess the budget impact of the new regulation.

C.

Map the regulation to business processes.

D.

Implement new regulatory requirements.

Question 8

An enterprise has decided to implement an IT risk management program After establishing stakeholder desired outcomes, the MAIN goal of the IT strategy committee should be to:

Options:

A.

identify business data that requires protection.

B.

perform a risk analysis on key IT processes

C.

implement controls to address high risk areas

D.

ensure IT risk alignment with enterprise risk

Question 9

The MAIN responsibility of the board of directors regarding the management of enterprise risk is to:

Options:

A.

ensure a risk process exists which addresses the risk appetite.

B.

sustain investment in staff training regarding IT risk.

C.

promote a benefits-driven culture throughout the enterprise.

D.

maintain awareness of IT risk to the business.

Question 10

When establishing an enterprise data model, the BEST way to ensure the integrity of data is to:

Options:

A.

classify information using an agreed-upon schema.

B.

implement the highest level of protection to data across the enterprise.

C.

establish a privileged access management platform.

D.

implement a data loss prevention (DLP) program.

Question 11

When preparing a new IT strategic plan for board approval, the MOST important consideration is to ensure the plan identifies:

Options:

A.

roles and responsibilities that link to IT objectives.

B.

specific resourcing requirements for identified IT projects.

C.

frameworks that will be aligned to IT programs.

D.

implications of the strategy on the procurement process.

Question 12

Which of the following is MOST important to review during IT strategy development?

Options:

A.

Industry best practices

B.

IT balanced scorecard

C.

Current business environment

D.

Data flows that indicate areas requiring IT support

Question 13

A data governance strategy has been defined by the IT strategy committee which includes privacy objectives related to access controls, authorized use. and data collection. Which of the following should the committee do NEXT?

Options:

A.

Mandate data privacy training for employees.

B.

Establish a data privacy budget

C.

Perform a data privacy impact assessment.

D.

Mandate the creation of a data privacy policy.

Question 14

Which of the following should be the PRIMARY goal of implementing service level agreements (SLAs) with an outsourcing vendor?

Options:

A.

Gaining a competitive advantage

B.

Establishing penalties for not meeting service levels

C.

Achieving operational objectives

D.

Complying with regulatory requirements

Question 15

Which of the following would be the BEST long-term solution to address the concern regarding loss of experienced staff?

Options:

A.

implement knowledge management practices

B.

Establish a mentoring program for IT staff

C.

Determine key risk indicators (KRIs)

D.

Retain key staff as consultants.

Question 16

Which of the following is MOST critical to support IT governance cultural changes within an organization?

Options:

A.

Established IT monitoring and measuring

B.

Regularly scheduled governance training

C.

Demonstrated management commitment

D.

IT governance process manuals

Question 17

Which aspect of information governance BEST enables an enterprise to avoid duplication of records and promote consistency of data?

Options:

A.

Data loss prevention (DLP)

B.

Data modeling

C.

Blockchain management

D.

Enterprise architecture (EA)

Question 18

An enterprise is replacing its customer relationship management (CRM) system with a cloud-based system. Which of the following should be done FIRST when preparing for data migration"*

Options:

A.

Review the enterprise data architecture.

B.

Establish a data quality plan

C.

Consult the quality assurance (QA) function.

D.

Acquire data migration tools.

Question 19

To evaluate IT resource management, it is MOST important to define:

Options:

A.

responsibilities for executing resource management.

B.

applicable key goals.

C.

principles for the IT strategy.

D.

IT resource utilization reporting procedures.

Question 20

An enterprise has entered into a new market which brings additional regulatory compliance requirements. What should be done FIRST to address these requirements?

Options:

A.

Outsource the compliance process.

B.

Appoint a compliance officer.

C.

Update the organization's risk profile.

D.

Have executive management monitor compliance.

Question 21

Which of the following should be established FIRST so that data owners can consistently assess the level of data protection needed across the enterprise?

Options:

A.

Data encryption program

B.

Data risk management program

C.

Data retention policy

D.

Data classification policy

Question 22

An enterprise is planning a transformation initiative by leveraging emerging technology that will have a significant impact on existing products and services Which of the following is the BEST way for IT to prepare for this change?

Options:

A.

Use a balanced scorecard to measure IT outcomes.

B.

Analyze emerging technology products and related training needs.

C.

Procure appropriate resources to support emerging technology

D.

Assess the impact on the existing IT strategy

Question 23

An enterprise is considering outsourcing non-core IT processes Which of the following should be the FIRST step?

Options:

A.

Update resource allocation policies

B.

Conduct a cost-benefit analysis for outsourcing.

C.

Issue a formal request for proposal to outsourcing vendors.

D.

Establish service level metrics for outsourced activities

Question 24

As part of the implementation of IT governance, the board of an enterprise should establish an IT strategy committee to:

Options:

A.

provide input to and ensure alignment of the enterprise and IT strategies.

B.

ensure IT risks inherent in the enterprise strategy implementation are managed

C.

drive IT strategy development and take responsibility for implementing the IT strategy.

D.

assume governance accountability for the business strategy on behalf of the board

Question 25

An enterprise has made the strategic decision to reduce operating costs for the next year and is taking advantage of cost reductions offered by an external cloud service provider. Which of the following should be the IT steering committee's PRIMARY concern?

Options:

A.

Calculating the cost of the current solution

B.

Updating the business risk profile

C.

Changing the IT steering committee charter

D.

Revising the business's balanced scorecard

Question 26

Which of the following IT governance actions would be the BEST way to minimize the likelihood of IT failures jeopardizing the corporate value of an IT-dependent organization?

Options:

A.

Implement an IT risk management framework.

B.

Install an IT continuous monitoring solution.

C.

Define IT performance management measures.

D.

Benchmark IT strategy against industry peers.

Question 27

A CEO wants to establish a governance framework to facilitate the alignment of IT and business strategies. Which of the following should be a KEY requirement of this framework?

Options:

A.

Defined resourcing levels

B.

A defined enterprise architecture (EA)

C.

An outsourcing strategy

D.

A service delivery Strategy

Question 28

A large bank has completed several acquisitions in the last few years that have resulted in redundant IT applications. To align with the strategic initiative of providing integrated services to customers, the IT steering committee has decided to share data and integrate applications. Which of the following would be MOST important to review in this situation?

Options:

A.

Enterprise architecture (EA)

B.

IT risk register

C.

Balanced scorecard measures

D.

IT strategic plan

Question 29

From an IT governance perspective, establishing performance measurements is PRIMARILY the responsibility of:

Options:

A.

the IT architecture review board.

B.

senior management.

C.

the board of directors.

D.

enterprise risk management (ERM).

Question 30

Which of the following is the BEST indication that enterprise value is being derived from IT?

Options:

A.

IT strategy supports continuous improvement initiatives

B.

Metrics are established for IT performance.

C.

Rate of return for projects is achieved.

D.

IT services enable business strategy.

Question 31

An enterprise wishes to establish key risk indicators (KRIs) in an effort to better manage IT risk. Which of the following should be identified FIRST?

Options:

A.

Risk mitigation strategies

B.

Enterprise architecture (EA) components

C.

The enterprise risk appetite

D.

Key performance metrics

Question 32

An enterprise has developed a new digital strategy to improve fraud detection. Which of the following is MOST important to consider when updating the information architecture?

Options:

A.

Resource constraints related to implementing the digital strategy.

B.

The business use cases supporting the digital strategy

C.

Changes to the legacy business and data architectures

D.

The history of fraud incidents and their root causes

Question 33

Which of the following should a new CIO do FIRST to ensure information assets are effectively governed?

Options:

A.

Quantify the business value of information assets

B.

Perform an information gap analysis

C.

Review information classification procedures

D.

Evaluate information access methods

Question 34

Facing financial struggles, a CEO mandated severe budget cuts. A decision was also made to immediately change the enterprise strategic focus to put more reliance on mobile, cloud, and wireless services in an effort to boost revenue. The IT steering committee has asked the CIO tosuggest adjustments to the current IT project portfolio to allow support for the new direction despite fewer funds. What should the CIO advise the committee to do FIRST?

Options:

A.

Ask business stakeholders to discuss their vision for the new strategy.

B.

Cancel projects with a net present value (NPV) below a defined threshold.

C.

Conduct a risk assessment against the potential new services.

D.

Start re-allocating budget to projects involving mobile or cloud.

Question 35

Which of the following should be management's GREATEST consideration when trying to optimize the use of benefits from IT?

Options:

A.

Value delivery

B.

Quality management

C.

Process improvement

D.

Alignment of business to IT

Question 36

Which of the following is a PRIMARY responsibility of the CIO when an enterprise plans to replace its enterprise resource applications?

Options:

A.

Reviewing the IT application portfolio

B.

Evaluating and selecting application vendors

C.

Ensuring IT architecture requirements are considered

D.

Establishing software quality criteria

Question 37

Which of the following should be the PRIMARY consideration for an enterprise when prioritizing IT projects?

Options:

A.

Technical capability of the enterprise to execute the projects

B.

Process owner expectations based on operational benefits

C.

Results of IT performance benchmarks against competitors

D.

Impact on the business due to expected project outcomes

Question 38

In an enterprise that has worldwide business units and a centralized financial control model, which of the following is a barrier to strategic alignment of business and IT?

Options:

A.

Each business unit has its own steering committee for IT investment and prioritization.

B.

Uniform portfolio management is in place throughout the business units.

C.

IT is the exclusive provider of IT services to the business units.

D.

The enterprise's CIO is a member of the executive committee.

Question 39

The PRIMARY reason for using quantitative criteria in developing business cases for IT projects is to:

Options:

A.

improve the process of evaluating returns after implementation.

B.

benchmark project success with similar enterprises.

C.

learn lessons from errors made in past projects.

D.

apply other corporate standards to the development project.

Question 40

A project sponsor has circumvented the request for proposal (RFP) selection process. Which of the following is the MOST likely reason for this control gap?

Options:

A.

Inadequate stage-gate reviews

B.

Inadequate board oversight

C.

Lack of accountability for policy adherence

D.

Lack of a legal and regulatory review process

Question 41

An IT manager is trying to determine optimal IT service levels. Which of the following should be the PRIMARY consideration?

Options:

A.

Internal rate of return

B.

Recovery time objective (RTO)

C.

Cost-benefit analysis

D.

Resource utilization analysis

Question 42

Which of the following are the MOST important processes for information asset life cycle management?

Options:

A.

Procurement management and third-party management

B.

Configuration management and financial management

C.

Vulnerability management and network management

D.

Business continuity management and disaster recovery management

Question 43

Which of the following BEST indicates that a change management process has been implemented successfully?

Options:

A.

Maturity levels

B.

Degree of control

C.

Process performance

D.

Outcome measures

Question 44

To enable IT to deliver adequate services and maintain availability of a web-facing infrastructure, an IT governance committee should FIRST establish:

Options:

A.

web operations procedures.

B.

business continuity plans (BCPs).

C.

key performance indicators (KPIs).

D.

customer survey processes.

Question 45

An enterprise is developing an ethics program, and the ethical standards have been defined. Which of the following should the enterprise do NEXT?

Options:

A.

Establish a training and awareness program focused on ethics.

B.

Implement an enterprise-wide employee monitoring program.

C.

Develop key performance indicators (KPIs) for program implementation.

D.

Outline and document consequences for noncompliance.

Question 46

Which of the following BEST indicates the success of an enterprise's IT governance framework after implementation?

Options:

A.

A high percentage of business owners involved with the approval of the IT strategic plan

B.

A high percentage of IT systems complying with corporate information security standards

C.

A high percentage of IT projects delivered on time and on budget

D.

A high percentage of IT investments delivering expected benefits

Question 47

An enterprise is determining the objectives for an IT training improvement initiative from a governance prosected. it would be MOST important to ensure that:

Options:

A.

policies and processes address both enterprise requirements and professional growth

B.

courses of instruction that will maximize employee productivity are identified

C.

several different training strategies are created for final approval by the CIO

D.

IT employees are surveyed and interviewed to identify development needs

Question 48

A business is considering a policy to anonymize personal data in enterprise systems. Before making a decision, which of the following is MOST important for the IT steering committee to consider?

Options:

A.

Business impact analysis (BIA) results

B.

Regulatory requirements

C.

Sustainability costs to the enterprise

D.

Potential implementation barriers

Question 49

The board of directors of a large organization has directed IT senior management to improve IT governance within the organization. IT senior management's MOST important course of action should be to:

Options:

A.

understand the driver that led to a desire to change.

B.

assess the current slate of IT governance within the organization.

C.

review IT strategy and direction.

D.

analyze IT service levels and performance.

Question 50

IT maturity models measure:

Options:

A.

performance.

B.

value.

C.

capabilities.

D.

outcome.

Question 51

Before establishing IT key nsk indicators (KRls) which of the following should be defined FIRST?

Options:

A.

IT resource strategy

B.

IT risk and security framework

C.

IT goals and objectives

D.

IT key performance indicators (KPIs)

Question 52

The CEO of an organization is concerned that there are inconsistencies in the way information assets are classified across the enterprise. Which of the following is be the BEST way for the CIO to address these concerns?

Options:

A.

Include data assets in the IT inventory.

B.

Identify data owners across the enterprise.

C.

Require enterprise risk assessments.

D.

Implement enterprise data governance.

Question 53

Which of the following would be the MOST effective way to ensure IT capabilities are appropriately aligned with business requirements for specific business processes?

Options:

A.

Establishing key performance indicators {KPIs)

B.

Requiring Internal IT architecture and design reviews

C.

Requiring architecture and design reviews with business process stakeholders

D.

Issuing a management mandate that IT and business process stakeholders work together

Question 54

Once the strategic vision has been established, which of the following would be the BEST activity for supporting the implementation of performance measures?

Options:

A.

Monitor service level performance.

B.

Document strengths, weaknesses, opportunities, and threats.

C.

Document policy requirements

D.

Identify key performance indicators (KPIs).

Question 55

An assessment reveals that enterprise risk management (ERM) practices are being applied inconsistently by IT staff. Which of the following would be the MOST effective corrective action?

Options:

A.

Require ERM orientation sessions

B.

Request the development of an IT risk register template.

C.

Request a complete skills reassessment for all IT staff.

D.

Update the ERM framework.

Question 56

Which of the following metrics would provide senior management with the BEST indication of the success of IT investments?

Options:

A.

Number of IT investments tracked in the balanced scorecard

B.

Percentage of IT investments recorded in the enterprise architecture (EA)

C.

Number of IT investments impacted by business-related incidents

D.

Percentage of IT investments that meet expected benefits

Question 57

Which of the following is a responsibility of an IT strategy committee?

Options:

A.

Providing oversight on enterprise strategy implementation

B.

Approving the business strategy and its IT implications

C.

Advising the board on the development of IT goals

D.

Tracking projects in the IT investment portfolio

Question 58

Which of the following is the BEST justification for a procurement manager to agree to purchase IT equipment from a specific vendor during a sales promotion?

Options:

A.

The IT benefit surpasses the business benefit from the purchase.

B.

The equipment adds value to the enterprise.

C.

The business profit surpasses the IT cost for the equipment.

D.

The product is offered at the lowest price.

Question 59

Of the following, who is PRIMARILY responsible for applying frameworks for the governance of IT to balance the need for security controls with business requirements?

Options:

A.

Data scientists

B.

Data stewards

C.

Data analysts

D.

Data processors

Question 60

An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?

Options:

A.

Granting access to information based on information architecture

B.

Engaging an audit of logical access controls and related security policies

C.

Implementing multi-factor authentication controls

D.

Authenticating access to information assets based on roles or business rules

Question 61

An enterprise is adopting a new governance framework. Of the following, the MOST effective method to help ensure that key activities are performed by appropriate resources is through the use of:

Options:

A.

a RACI chart.

B.

an organizational breakdown structure.

C.

a work breakdown structure.

Question 62

Which of the following would be the BEST way to facilitate the successful adoption of a new technology across the enterprise?

Options:

A.

Ensure the use of a business case

B.

Review business goals.

C.

Establish an IT balanced scorecard.

D.

Highlight the risk the new technology will address.

Question 63

A newly appointed CIO has been tasked with the responsibility of developing an effective IT enterprise roadmap that meets business requirements. Which of the following is the BEST way to ensure that the business needs have been taken into consideration?

Options:

A.

Involve process owners in requirements gathering.

B.

Implement a balanced scorecard.

C.

Include user acceptance testing (UAT) as part of the resulting IT solutions.

Question 64

An enterprise's global IT program management office (PMO) has recently discovered that several IT projects are being run within a specific region without knowledge of the PMO. The projects are on time, on budget, and will deliver the proposed benefits to the specific region. Which of the following should be the PRIMARY concern of the PMO?

Options:

A.

Inability to reduce the impact to the risk level of the global portfolio

B.

Projects may not follow system development life cycle (SDLC)

C.

Lack of control and impact to the overall PMO budget

Question 65

Due to the recent introduction of personal data protection regulations, an enterprise is required to maintain its employee data in production systems only for a limited time. Which of the following is MOST important to review?

Options:

A.

Asset retention policies

B.

Information retention policies

C.

Data archival policies

D.

Data backup and restoration policies

Question 66

IT management has reported difficulty retaining qualified IT personnel to support the organization's new strategy Given that outsourcing is not a viable approach, which of the following would be the BEST way for IT governance to address this situation?

Options:

A.

Implement an incentive-based employee referral program

B.

Direct the development of a strategic HR plan for IT

C.

Recommend enhancements to the online recruiting platform specific to IT

D.

Work with HR to enhance compensation packages for IT personnel

Question 67

Which of the following provides the BEST evidence of an IT risk-aware culture across an enterprise?

Options:

A.

Business staff report identified IT risks.

B.

IT risks are communicated to the business.

C.

IT risk-related policies are published.

D.

The IT infrastructure is resilient.

Question 68

The board of directors of an enterprise has questioned whether the business is focused on optimizing value. The IT strategy committees’ BEST action to address the board's concern is to:

Options:

A.

initiate reporting and review of key IT performance metrics.

B.

conduct a portfolio review to assess the benefits realization of IT investments.

C.

conduct a benchmark to assess IT value relative to competitors.

D.

form a technology council to monitor the efficiency of project implementation.

Question 69

An enterprise embarked on an aggressive strategy requiring the implementation of several large IT projects impacting multiple business processes across all departments. Initially employees were supportive of the strategy, but there is growing fatigue and frustration with the ongoing newcapabilities which must be learned. Which of the following would be the BEST action performed by senior management?

Options:

A.

Incorporate an organizational change management program.

B.

Establish "Reward and Recognition" efforts to boost employee morale.

C.

Improve the system development life cycle (SDLC) process.

D.

Assess current business and IT competencies.

Question 70

Which of the following is the PRIMARY ongoing responsibility of the IT governance function related to risk?

Options:

A.

Responding to and controlling all IT risk events

B.

Communicating the enterprise risk management plan

C.

Ensuring IT risk management is aligned with business risk appetite

D.

Verifying that all business units have staff skilled at assessing risk

Question 71

Results of an enterprise's customer survey indicate customers prefer using mobile applications. However, this same survey shows the enterprise's mobile applications are considered inferior compared to legacy browser-based applications. Which of the following should be the FIRST step in creating an effective long-term mobile application strategy?

Options:

A.

Establish service level agreements (SLAs) with the development team.

B.

Identify key risks and mitigation strategies for mobile applications.

C.

Implement key performance indicators (KPIs) that include application quality.

D.

Identify business requirements concerning mobile applications.

Question 72

A rail transport company has the worst on-time arrival record in the industry due to an antiquated IT system that controls scheduling. Despite employee resistance, an initiative lo upgrade the technology and related processes has been approved. To maximize employee engagement throughout the project, which of the following should be in place prior to the start of the initiative?

Options:

A.

Procurement management plan

B.

Organizational change management plan

C.

Risk response plan

D.

Resource management plan

Question 73

Which of the following is the BEST way to ensure the continued usefulness of IT governance reports for stakeholders?

Options:

A.

Conduct quarterly audits and adjust reporting based on findings.

B.

Establish a standard process for providing feedback.

C.

Rely on IT leaders to advise when adjustments should be made.

D.

Issue frequent service level satisfaction surveys.

Question 74

Which of the following is the BEST way to ensure new systems can be adequately supported once in production?

Options:

A.

Establish a resource management framework.

B.

Evaluate the operational requirements of the business stakeholders.

C.

Identify key performance indicators (KPIs).

D.

Require operational management be identified in the business case.

Question 75

When implementing an IT governance framework, which of the following would BEST ensure acceptance of the framework?

Options:

A.

Factoring in the effects of enterprise culture

B.

Using subject matter experts

C.

Using industry-accepted practices

D.

Complying with regulatory requirements

Question 76

From a governance perspective, the PRIMARY goal of an IT risk optimization process should be to ensure:

Options:

A.

IT risk thresholds are defined in the enterprise architecture (EA).

B.

the IT risk mitigation strategy is approved by management.

C.

IT risk is mapped to the balanced scorecard.

D.

the impact of IT risk to the enterprise is managed.

Question 77

Due to continually missed service level agreements (SLAs), an enterprise plans to terminate its contract with a vendor providing IT help desk services. The enterprise s IT department willassume the help desk-related responsibilities. Which of the following would BEST facilitate this transition?

Options:

A.

Requiring the enterprise architecture (EA) be updated

B.

Validating that the balanced scorecard is still meaningful

C.

Ensuring IT will operate at a lower cost than the vendor

D.

Ensuring a change management plan is in place

Question 78

An organization's board of directors has questioned the value provided by IT key performance indicators (KPIs). Which of the following is the BEST way to determine whether the KPIs adequately support organizational objectives?

Options:

A.

Define a strategy for IT measurement.

B.

Define policies and procedures around current KPIs.

C.

Review the KPIs with key business executives.

D.

Work directly with the CEO to identify what measures should be used.

Question 79

An enterprise has been focused on establishing an IT risk management framework. Which of the following should be the PRIMARY motivation behind this objective?

Options:

A.

Promoting responsibility throughout the enterprise for managing IT risk.

B.

Increasing the enterprise's risk tolerance level and risk appetite.

C.

Engaging executives in examining IT risk when developing policies.

D.

Maintaining a complete and accurate risk registry to belief manage IT risk

Question 80

Which of the following would be MOST important to update if a decision is made to ban end user-owned devices in the workplace?

Options:

A.

Employee nondisclosure agreement

B.

Enterprise risk appetite statement

C.

Enterprise acceptable use policy

D.

Orientation training materials

Question 81

Which of the following is the BEST IT architecture concept to ensure consistency, interoperability, and agility for infrastructure capabilities?

Options:

A.

Establishment of an IT steering committee

B.

Standards-based reference architecture and design specifications

C.

Establishment of standard vendor and technology designations

D.

Design of policies and procedures

Question 82

An enterprise has a large backlog of IT projects. The current strategy is to execute projects as they are submitted, but executive management does not believe this method is optimal. Which of the following is the MOST important action to address this concern?

Options:

A.

Implement stage-gating to determine the value of each project.

B.

Establish a performance dashboard that determines business value.

C.

Implement a methodology to prioritize projects based on resource availability.

D.

Create a combined business/IT committee to determine project prioritization.

Question 83

A marketing enterprise is considering procuring customer information to more accurately target customer communications and increase sales. The data has a very high cost to the enterprise. Which of the following would provide the MOST comprehensive view into the potential value to the organization?

Options:

A.

Investment services board review

B.

Net present value {NPV) calculation

C.

Risk assessment results

D.

Cost-benefit analysis results

Question 84

An enterprise learns that a new privacy regulation was recently published to protect customers in the event of a breach involving personally identifiable information (Pll). The IT risk management team's FIRST course of action should be to:

Options:

A.

evaluate the risk appetite for the new regulation.

B.

define the risk tolerance for the new regulation.

C.

determine if the new regulation introduces new risk.

D.

assign a risk owner for the new regulation.

Question 85

Which of the following MUST be established before implementing an information architecture that restricts access to data based on sensitivity?

Options:

A.

Risk and control frameworks

B.

Probability and impact analysis

C.

Classification and ownership

D.

Security and privacy policies

Question 86

Who is PRIMARILY accountable for delivering the benefits of an IT-enabled investment program to the enterprise?

Options:

A.

Program manager

B.

IT steering committee chair

C.

CIO

D.

Business sponsor

Question 87

The IT program manager does not see the value of conducting risk assessments for a new major IT project. The manager is reluctant to cooperate with internal auditors and the newly formed steering committee. Midway through the project, program requirements were changed because the CEO is a friend of a vendor and wants to implement this vendor's new technology. This decision will cause the current IT program budget to be insufficient and will be shown as overspending.

After the requirement change request, the IT program manager should FIRST:

Options:

A.

obtain confirmation from the business and a decision by the steering committee.

B.

request additional funding from the business owner to cover the additional scope.

C.

report the matter to internal audit as a program deviation to be reviewed.

D.

align IT with the business and agree to the business request.

Question 88

The BEST way to manage an outsourced vendor relationship is by:

Options:

A.

conducting periodic risk assessments.

B.

reviewing annual independent third-party reports.

C.

providing clear objectives and transparency.

D.

analyzing performance statistics from the vendor.

Question 89

Which of the following would BEST help to improve an enterprise's ability to manage large IT investment projects?

Options:

A.

Creating a change management board

B.

Reviewing and evaluating existing business cases

C.

Implementing a review and approval process for each phase

D.

Publishing the IT approval process online for wider scrutiny

Question 90

An enterprise is implementing a new IT governance program. Which of the following is the BEST way to increase the likelihood of its success?

Options:

A.

The IT steering committee approves the implementation efforts.

B.

The CIO communicates why IT governance is important to the enterprise.

C.

Implementation follows an IT audit recommendation.

D.

The CIO issues a mandate for adherence to the program.

Question 91

Which of the following is MOST important to effectively initiate IT-enabled change?

Options:

A.

Establish a change management process.

B.

Obtain top management support and ownership.

C.

Ensure compliance with corporate policy.

D.

Benchmark against best practices.

Question 92

An IT steering committee is presented with an audit finding that new software applications are delivered on time but consistently have unacceptable levels of defects. Which of the following would be the BEST direction from the committee?

Options:

A.

Implement performance indicators.

B.

Evaluate the change management process.

C.

Establish code peer reviews.

D.

Evaluate the quality assurance process.

Question 93

While monitoring an enterprise's IT projects portfolio, it is discovered that a project is 75% complete, but all budgeted resources have been expended. Which of the following is the MOST important task to perform?

Options:

A.

Review the IT investments.

B.

Reorganize the IT projects portfolio.

C.

Re-evaluate the business case.

D.

Review the IT governance structure.

Question 94

A new CIO has been charged with updating the IT governance structure. Which of the following is the MOST important consideration to effectively influence organizational and process change?

Options:

A.

Obtaining guidance from consultants

B.

Aligning IT services to business processes

C.

Redefining the IT risk appetite

D.

Ensuring the commitment of stakeholders

Question 95

A regulatory audit assessed an enterprise's main transactional application as noncompliant. In addition to fines and required corrections, an agreement was reached to implement a set of governance controls over IT. Accountability for these controls is BEST assigned to which of the following?

Options:

A.

CIO

B.

Internal audit director

C.

Application users

D.

The board of directors

Question 96

The use of an IT balanced scorecard enables the realization of business value of IT through:

Options:

A.

business value and control mechanisms.

B.

outcome measures and performance drivers.

C.

financial measures and investment management.

D.

vision and alignment with corporate programs.

Question 97

The MOST successful IT performance metrics are those that:

Options:

A.

measure financial results.

B.

measure all areas.

C.

are approved by the stakeholders.

D.

contain objective measures.

Question 98

Which of the following is MOST important for the effective design of an IT balanced scorecard?

Options:

A.

On-demand reporting and continuous monitoring

B.

Consulting with the CIO

C.

Emphasizing the financial results

D.

Identifying appropriate key performance indicators (KPls)

Question 99

Which of the following MOST effectively prevents an IT system from becoming technologically obsolete before its planned return on investment (ROi)?

Options:

A.

Requesting periodic third-party assessments of the system throughout its life

B.

Obtaining long-term support commitments from the system platform vendors)

C.

Obtaining independent assurance that the system will conform to future business requirements

D.

Ensuring that the system is maintained in compliance with enterprise architecture (EA) standards

Question 100

Which of the following would BEST enable business innovation through IT?

Options:

A.

Outsourcing of IT to a strategic business partner

B.

Business participation in IT strategy development

C.

Adoption of a standardized business development life cycle

D.

IT participation in business strategy development

Question 101

A CIO believes that a recent mission-critical IT decision by the board of directors is not in the best financial interest of all stakeholders. Which of the following is the MOST ethical course of action?

Options:

A.

Share concerns with the legal department.

B.

Request a meeting with the board.

C.

Engage an independent cost-benefit analysis.

D.

Request an internal audit review of the board's decision.

Question 102

An enterprise is initiating efforts to improve system availability to mitigate IT risk to the business. Which of the following results would be MOST important to report to the CIO to measure progress?

Options:

A.

Incident severity and downtime trend analysis

B.

Probability and seventy of each IT risk

C.

Financial losses and bad press releases

D.

Customer and stakeholder complaints over time

Question 103

A company is considering selling products online, and the CIO has been asked to advise the board of directors of potential problems with this strategy. Which of the following is the ClO's BEST course of action?

Options:

A.

Review the security framework.

B.

Conduct a return on investment (ROI) analysis.

C.

Review the enterprise architecture (EA).

D.

Perform a risk assessment.

Question 104

To generate value for the enterprise, it is MOST important that IT investments are:

Options:

A.

aligned with the IT strategic objectives.

B.

approved by the CFO.

C.

consistent with the enterprise's business objectives.

D.

included in the balanced scorecard.

Question 105

A new and expanding enterprise has recently received a report indicating 90% of its data has been collected in just the last six months, triggering data breach and privacy concerns. What should be the IT steering committee's FIRST course of action to ensure new data is managed effectively?

Options:

A.

Mitigate and track data-related issues and risks.

B.

Modify legal and regulatory data requirements.

C.

Define data protection and privacy practices.

D.

Assess the information governance framework.

Question 106

A large organization with branches across many countries is in the midst of an enterprise resource planning (ERP) transformation. The IT organization receives news that the branches in a country where the impact to the enterprise is to be greatest are being sold. What should be the NEXT step?

Options:

A.

Update the ERP business case and re-evaluate the ROI.

B.

Cancel the ERP transformation and re-allocate project funds.

C.

Adjust the ERP implementation plan and budget.

D.

Continue with the ERP migration according to plan.

Question 107

Which of the following is the MOST important driver of IT governance?

Options:

A.

Effective internal controls

B.

Management transparency

C.

Quality measurement

D.

Technical excellence

Question 108

A CIO has been asked to modify an organization's IT performance measurement system to reflect recent changes in technology, including the movement of some data processing to a cloud solution. Which of the following is the PRIMARY consideration when designing such a measurement system?

Options:

A.

Ensuring that cost of measurement and reporting is minimized

B.

Ensuring the measurement system maps to the enterprise architecture (EA)

C.

Adequately defining the scope of services moved to the cloud

D.

Correctly understanding stakeholder needs for IT-related measurement

Question 109

Which of the following is the BEST method for making a strategic decision to invest in cloud services?

Options:

A.

Prepare a business case.

B.

Prepare a request for information (RFI),

C.

Benchmarking.

D.

Define a balanced scorecard.

Question 110

Prior to decommissioning an IT system, it is MOST important to:

Options:

A.

assess compliance with environmental regulations.

B.

assess compliance with the retention policy.

C.

review the media disposal records.

D.

review the data sanitation records.

Question 111

Best practice states that IT governance MUST:

Options:

A.

enforce consistent policy across the enterprise.

B.

be applied in the same manner throughout the enterprise.

C.

apply consistent target levels of maturity to processes.

D.

be a component of enterprise governance.

Question 112

An enterprise has had the same IT governance framework in place for several years. Currently, large and small capital projects go through the same architectural governance reviews. Despite repeated requests to streamline the review process for small capital projects, business units have received no response from IT. The business units have recently escalated this issue to the newly appointed GO. Which of the following should be done FIRST to begin addressing business needs?

Options:

A.

Create a central repository for the business to submit requests.

B.

Explain the importance of the IT governance framework.

C.

Assess the impact of the proposed change.

D.

Assign a project team to implement necessary changes.

Question 113

An enterprise plans to implement a business intelligence (Bl) tool with data sources from various enterprise applications. Which of the following is the GREATEST challenge to implementation?

Options:

A.

Interface issues between enterprise and Bl applications

B.

Large volumes of data fed from enterprise applications

C.

The need for staff to be trained on the new Bl tool

D.

Data definition and mapping sources from applications

Question 114

Which of the following is the MOST comprehensive method to report on overall IT performance to the board of directors?

Options:

A.

Balanced scorecard

B.

Net present value (NPV)

C.

Performance-based payments

D.

Return on investment (ROI)

Question 115

Of the following, who should be responsible for ensuring the regular review of quality management performance against defined quality metrics?

Options:

A.

Process owners

B.

Risk management team

C.

Internal auditors

D.

Executive management

Question 116

A CIO must determine if IT staff have adequate skills to deliver on key strategic objectives. Which of the following will provide the MOST useful information?

Options:

A.

Employee performance metrics

B.

Project risk reports

C.

Gap analysis results

D.

Training program statistics

Question 117

A financial institution with a highly regarded reputation for protecting customer interests has recently deployed a mobile payments program. Which of the following key risk indicators (KRIs) would be of MOST interest to the CIO?

Options:

A.

Number of failed software updates on mobile devices

B.

Percentage of incomplete transactions

C.

Failure rate of point-of-sale systems

D.

Total volume of suspicious transactions

Question 118

Which of the following aspects of the transition from X-rays to digital images would be BEST addressed by implementing information security policy and procedures?

Options:

A.

Establishing data retention procedures

B.

Training technicians on acceptable use policy

C.

Minimizing the impact of hospital operation disruptions on patient care

D.

Protecting personal health information

Question 119

The board of directors of an enterprise has approved a three-year IT strategic program to centralize the core business processes of its global entities into one core system. Which of the following should be the ClO's NEXT step?

Options:

A.

Engage a team to perform a business impact analysis (BIA).

B.

Require the development of a risk management plan.

C.

Determine resource requirements for program implementation.

D.

Require the development of a program roadmap.

Question 120

Which of the following would be of MOST concern regarding the effectiveness of risk management processes?

Options:

A.

Key risk indicators (KRIs) are not established.

B.

Risk management requirements are not included in performance reviews.

C.

The plans and procedures are not updated on an annual basis.

D.

There is no framework to ensure effective reporting of risk events.

Question 121

A board of directors is concerned that a major IT implementation has the potential to significantly disrupt enterprise operations. Which of the following would be MOST helpful in identifying the extent of the potential impact of the disruption?

Options:

A.

An analysis of the current enterprise risk appetite

B.

An earned value analysis (EVA) of the implementation

C.

A risk assessment of the implementation

D.

A review of lessons learned from previous implementations

Question 122

An IT audit reveals inconsistent maintenance of data privacy in enterprise systems primarily due to a lack of data sensitivity categorizations. Once the categorizations are defined, what is the BEST long-term strategic response by IT governance to address this problem?

Options:

A.

Standardize data classification processes throughout the enterprise.

B.

Incorporate enterprise privacy categorizations into contracts.

C.

Require business impact analyses (BIAs) for enterprise systems.

D.

Reassess the data governance policy.

Question 123

The BEST way to ensure an IT steering committee meets enterprise objectives is to:

Options:

A.

require a member of the committee to have IT governance expertise.

B.

benchmark against industry best practices.

C.

establish key performance indicators (KPIs).

D.

have key business stakeholders represented on the committee.

Question 124

A recent benchmarking analysis has indicated an IT organization is retaining more data and spending significantly more on data retention than its competitors. Which of the following would BEST ensure the optimization of retention costs?

Options:

A.

Requiring that all business cases contain data deletion and retention plans

B.

Revalidating the organization's risk tolerance and re-aligning the retention policy

C.

Moving all high-risk and medium-risk data backups to cloud storage

D.

Redefining the retention policy to align with industry best practices

Question 125

A CIO is concerned with the potential of vendor system failures that could cause a large amount of unintended system downtime. To determine how to prepare for this concern, what is MOST important for the CIO to review?

Options:

A.

IT balanced scorecard

B.

Service-level metrics

C.

IT procurement policy

D.

Business impact analysis (BIA)

Question 126

An enterprise has a zero-tolerance policy regarding security. This policy is causing a large number of email attachments to be blocked and is a disruption to enterprise. Which of the following should be the FIRST governance step to address this email issue?

Options:

A.

Direct the development of an email usage policy.

B.

Obtain senior management input based on identified risk.

C.

Recommend business sign-off on the zero-tolerance policy.

D.

Introduce an exception process.

Question 127

IT has launched new portfolio management policies and processes to improve the alignment of IT projects with enterprise goals. The latest audit report indicates that no improvement has been made due to confusion in the decision-making process. Which of the following is the BEST course of action for the CIO?

Options:

A.

Deliver prioritization and facilitation training.

B.

Implement a performance management framework.

C.

Create an IT portfolio management risk framework.

D.

Develop and communicate an accountability matrix.

Question 128

Which of the following is an ADVANTAGE of using strategy mapping?

Options:

A.

It provides effective indicators of productivity and growth.

B.

It depicts the maturity levels of processes that support organizational strategy.

C.

It identifies barriers to strategic alignment and links them to specific outcomes.

D.

It depicts the cause-and-effect linked relationships between strategic objectives.

Question 129

An IT risk assessment for a large healthcare group revealed an increased risk of unauthorized disclosure of information. Which of the following should be established FIRST to address the risk?

Options:

A.

Data encryption tools

B.

Data loss prevention tools

C.

Data classification policy

D.

Data retention policy

Question 130

A strategic IT-enabled investment is failing due to unforeseen technology problems. What should be the board of directors' FIRST course of action?

Options:

A.

Terminate the investment.

B.

Assess the business risk and options.

C.

Approve an investment budget increase.

D.

Revise the investment selection process.

Question 131

Which of the following is the BEST method for determining an enterprise's current appetite for risk?

Options:

A.

Interviewing senior management

B.

Evaluating the balanced scorecard

C.

Reviewing recent audit findings

D.

Assessing social media adoption

Question 132

An analysis of an organization s security breach is complete. The results indicate that the quality of the code used for updates to its primary customer-facing software has been declining and security flaws were introduced. The FIRST IT governance action to correct this problem should be to review:

Options:

A.

compliance with the user testing process.

B.

the change management control framework.

C.

the qualifications of developers to write secure code.

D.

the incident response plan.

Question 133

Which of the following roles has PRIMARY accountability for the security related to data assets?

Options:

A.

Database administrator

B.

Data owner

C.

Data analyst

D.

Security architect

Question 134

Which of the following is the BEST way for a CIO to secure support for a strategy to achieve long-term IT objectives?

Options:

A.

Make the necessary strategic decisions and notify staff accordingly.

B.

Develop tactics to implement the strategy and share with stakeholders.

C.

Develop a communication plan for distribution of information to staff.

D.

Meet with stakeholders to explain the strategy and incorporate feedback.

Question 135

Which of the following should be the MOST important consideration when defining an information architecture?

Options:

A.

Frequency and quantity of information updates

B.

Information to justify business cases

C.

Incorporation of emerging technologies

D.

Access to and exchange of information

Question 136

When determining the optimal IT service levels to support business, which of the following is MOST important?

Options:

A.

IT capacity utilization and availability.

B.

Cost/benefit to the business.

C.

Available IT budget.

D.

Business user requests

Question 137

Which of the following is the GREATEST expected strategic organizational benefit from the standardization of technical platforms?

Options:

A.

Reduces IT operational training costs

B.

Reduces response time

C.

Optimizes infrastructure investments

D.

Meets regulatory compliance requirements

Question 138

An enterprise will be adopting wearable technology to improve business performance. Which of the following is the BEST way for the CIO to validate IT’s preparedness for this initiative?

Options:

A.

Request an enterprise architecture (EA) review.

B.

Perform a baseline business value assessment.

C.

Request reprioritization of the IT portfolio.

D.

Identify the penalties for noncompliance.

Question 139

The board of an organization has been informed of possible cyberthreats. Which of the following should be the board’s NEXT course of action?

Options:

A.

Evaluate the security incident response process

B.

Reevaluate the risk tolerance of the organization

C.

Ask the CIO to report on a risk response

D.

Engage the CIO to evaluate the risk

Question 140

An enterprise has made the strategic decision to begin a global expansion program which will require opening sales offices in countries across the world. Which of the following should be the FIRST consideration with regard to the IT service desk which will remain centralized?

The effect of regional differences On service delivery

Identification of IT service desk functions that can be outsourced

Options:

A.

Enforcement Of a standardized policy across all regions

B.

Availability of adequate resources to provide support for new users

Question 141

Which of the following is MOST important to effectively incorporate innovation and emerging technologies into an enterprise’s IT strategy?

Options:

A.

Implementing new technologies based on maturity roadmaps according to reputable consulting entities.

B.

Maintaining an IT strategy based on traditional technologies, supplemented by objectives for innovation.

C.

Establishing a formal innovation management process that involves IT and business stakeholders.

D.

Performing quarterly feedback reviews with focus groups representing the enterprise’s customer base.

Question 142

Of the following, who is responsible for the achievement of IT strategic objectives?

Options:

A.

IT steering committee

B.

Business process owners

C.

Chief information officer (CIO)

D.

Board of directors

Question 143

Which of the following is the BEST indicator for measuring performance when implementing DevSecOps in an enterprise?

Options:

A.

Mean time to repair

B.

Percentage of automated tests

C.

Deployments per day

D.

Number of defects released per day

Question 144

Which of the following would be MOST useful in developing IT strategic plans aligned with technological needs?

Options:

A.

Business impact analysis (BIA)

B.

Business case

C.

Enterprise architecture (EA)

D.

Benchmark analysis

Question 145

What is the BEST way for IT to achieve compliance with regulatory requirements?

Options:

A.

Enforce IT policies and procedures.

B.

Create an IT project portfolio.

C.

Review an IT performance dashboard.

D.

Report on IT audit findings and action plans.

Question 146

An enterprise’s IT director is concerned that the chair of the IT steering committee is stealing confidential company information. Which of the following is the IT director’s BEST course of action?

Options:

A.

File a report with the local law enforcement agency.

B.

Report the concern to the ethics hotline.

C.

Discuss the concern with the chair directly.

D.

Conduct an investigation to substantiate the chair’s activities.

Question 147

An internal auditor conducts an assessment of a two-year-old IT risk management program. Which of the following findings should be of MOST concern to the CIO?

Options:

A.

Organizational responsibility for IT risk management is not clearly defined.

B.

None of the members of the IT risk management team have risk management-related certifications.

C.

Only a few key risk indicators (KRIs) identified by the IT risk management team are being monitored and the rest will be on a phased schedule.

D.

IT risk training records are not properly retained in accordance with established schedules

Question 148

From an IT governance perspective, which of the following would be the MOST significant impact of moving all IT applications to an external Software as a Service (SaaS) cloud provider?

Options:

A.

The integration of the IT department with business lines

B.

The shift from service delivery to service management

C.

The improvement Of IT service alignment with business

D.

The necessity to update key risk indicators (KRIs)

Question 149

Which of the following is the PRIMARY objective of a data protection impact assessment?

Options:

A.

To identify and analyze how data privacy might be affected by business processes.

B.

To evaluate the quality and integrity of personal data stored in an enterprise.

C.

To estimate the value created by personal data as it progresses through its life cycle.

D.

To ensure key business processes and related data interfaces are documented.

Question 150

Which of the following provides an enterprise with the BEST understanding of the value proposition for employing a new cloud service?

Options:

A.

Key risk indicators (KRIs).

B.

Service level agreements (SLAs).

C.

Return on investment (ROI).

D.

Customer satisfaction surveys.

Question 151

Which of the following is the BEST way to address the risk associated with new IT investments?

Options:

A.

Develop security best practices to protect applications.

B.

Integrate security requirements at the beginning of projects

C.

Establish an enterprise-wide incident response process.

D.

Implement an enterprise-wide security awareness program.

Question 152

An enterprise has decided to adopt cloud services. Which of the following should be established FIRST?

Options:

A.

Service level agreements (SLAs)

B.

Business continuity plan (BCP)

C.

Risk tolerance levels

D.

Third-party management framework

Question 153

Which of the following should be the MOST important consideration when establishing key performance indicators (KPIs) for IT initiatives?

Options:

A.

An owner can be assigned

B.

Processes can be optimized

C.

Data collection can be automated

D.

Quality has been evaluated

Question 154

An enterprise's IT department has been operating independently without regard to business concerns, leading to misalignment between business and IT. The BEST way to establish alignment would be to require:

Options:

A.

business to help define IT goals.

B.

business to fund IT services.

C.

IT to define business objectives.

D.

IT and business to define risks.

Question 155

In a large enterprise, which of the following is the BEST approach to enable effective communication to senior management regarding the project status for a strategic enterprise resource management system implementation?

Options:

A.

Project management office with business and IT representatives

B.

Weekly project reports reviewed by business and IT management

C.

Project status updates on the intranet

D.

A steering committee involving business and IT

Question 156

An IT steering committee is concerned about staff saving data files containing sensitive corporate information on publicly available cloud file storage applications. Which of the following should be done FIRST to address this concern?

Options:

A.

Create a secure corporate cloud file storage and sharing solution.

B.

Block corporate access to cloud file storage applications.

C.

Require staff training on data classification policies.

D.

Revise the data management policy to prohibit this practice.

Question 157

IT governance within an enterprise is attempting to drive a cultural shift to enhance compliance with IT security policies. The BEST way to support this objective is to ensure that enterprise IT policies are:

Options:

A.

communicated on a regular basis.

B.

acknowledged and signed by each employee.

C.

centrally posted and contain detailed instructions.

D.

integrated into individual performance objectives.

Question 158

Despite an adequate training budget. IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?

Options:

A.

Provide incentives for IT staff to attend outside conferences and training

B.

Create a standard-setting center of excellence for IT.

C.

Require human resources (HR) to recruit new talent using an established IT skills matrix.

D.

Establish an agreed-upon skills development plan with each employee

Question 159

After experiencing poor recovery times following a catastrophic event, an enterprise is seeking to improve its disaster recovery capabilities. Which of the following would BEST enable the enterprise to accomplish this objective?

Options:

A.

Continuous testing of disaster recovery capabilities with implementation of lessons learned

B.

Increased training and monitoring for disaster recovery personnel who perform below expectations

C.

Annual review and updates to the disaster recovery plan (DRP)

D.

Increased outsourcing of disaster recovery capabilities to ensure reliability

Question 160

A board of directors is concerned with the total cost of IT. Which of the following is MOST important for the CIO to include in an explanation to the board?

Options:

A.

A summary of benefits that will be achieved once key IT initiatives are completed.

B.

A mapping of IT employee roles to the balanced scorecard.

C.

A benchmark of IT employee salary costs against comparable organizations.

D.

A breakdown of operational versus capital expenditures.

Question 161

Which of the following should be done FIRST when developing an IT strategy to support a new AI business strategy?

Options:

A.

Assess current AI capabilities and infrastructure

B.

Establish guidelines and policies for responsible use of AI

C.

Create use cases to understand the impact of AI

D.

Build a team of AI professionals

Question 162

Which of the following is MOST important to ensure when aligning IT and enterprise resource management processes?

Options:

A.

IT sourcing processes are in place

B.

IT provides input for business strategy development

C.

IT resources are mapped to business priorities

D.

IT resource monitoring and oversight is in place

Question 163

What should be the FIRST action of a new CIO when considering an IT governance framework for an enterprise?

Options:

A.

Understand corporate culture and IT'S role in providing business value.

B.

Understand critical IT processes to define the scope of the IT governance framework.

C.

Verify stakeholder sponsorship of the IT governance initiative.

D.

Develop an IT balanced scorecard to monitor and track IT performance.

Question 164

Which of the following should be the CIO’s GREATEST consideration when making changes to the IT strategy?

Options:

A.

Have key stakeholders been consulted?

B.

Has the impact to the enterprise architecture (EA) been assessed?

C.

Have IT risk metrics been adjusted?

D.

Has the investment portfolio been revised?

Question 165

Which of the following would BEST help to ensure the appropriate allocation of IT resources to support an enterprise's mission?

Options:

A.

Develop a resource strategy as part of program management.

B.

Prioritize program requirements based on existing resources.

C.

Implement resource planning for each IT project.

D.

Manage resources as part of the portfolio strategy.

Question 166

When developing IT risk management policies and standards, it is MOST important to align them with:

Options:

A.

The corporate risk culture

B.

The enterprise risk management (ERM) framework

C.

Enterprise goals and objectives

D.

Best practices for IT risk management

Question 167

A CIO wants to make improvements to the enterprise's IT governance. Which of the following would BEST help to demonstrate the expected benefits from proposed changes?

Options:

A.

RACI chart

B.

Balanced scorecard

C.

Enterprise architecture (EA)

D.

Business case

Question 168

Which of the following is the BEST way to express the value of financial investments in cybersecurity?

Options:

A.

Payback period

B.

Cost-benefit analysis

C.

Net present value (NPV)

D.

Internal rate of return (IRR)

Question 169

Which of the following BEST supports an IT strategy committee’s objective to align employee competencies with planned initiatives?

Options:

A.

Set management goals to hire cooperative work experience students.

B.

Specify minimum training hours required for continuing professional education.

C.

Require balanced scorecard concepts training of all employees.

D.

Add achievement of competencies to employee performance goals.

Question 170

An IT governance committee realizes there are antiquated technologies in use throughout the enterprise. Which of the following is the BEST group to evaluate the recommendations to address these shortcomings?

Options:

A.

Enterprise architecture (EA) review board

B.

Business process improvement workgroup

C.

Audit committee

D.

Risk management committee

Question 171

From a governance perspective, which of the following functions MUST approve the agreed-upon criteria for a new technology-enabled service before submitting the final high-level design to project stakeholders?

Options:

A.

Information security

B.

Project management office (PMO)

C.

Quality assurance (QA)

D.

Internal audit

Question 172

An enterprise is implementing its first mobile sales channel. Final approval for accepting the associated IT risk should be obtained from which of the following?

Risk manager

Business sponsor

Options:

A.

Chief information officer (CIO)

B.

IT steering committee

Question 173

A board of directors has mandated that key performance indicators (KPIs) be developed for all IT projects that are created in support of a business objective. Which of the following MUST be reflected in the KPIs to be effective?

Options:

A.

Future-state architecture

B.

Critical success factors (CSFs)

C.

Portfolio management principles

D.

Key risk indicators (KRIs)

Question 174

New legislation requires an enterprise to report cybersecurity incidents to a government agency within a defined timeline. Which of the following should be the FIRST course of action?

Options:

A.

Establish an incident reporting system and hotline.

B.

Require automation of incident reporting to agencies.

C.

Establish a cybersecurity incident manager role.

D.

Understand requirements and definitions for reportable incidents.

Question 175

An enterprise is assessing whether to utilize wearable technology. The enterprise has no prior experience with this technology and has asked the chief technology officer (CTO) to assess the impact to the enterprise. The CTO should FIRST:

Options:

A.

understand the enterprise’s risk tolerance.

B.

create an IT risk scorecard.

C.

prioritize wearable technology risk.

Question 176

A regulator has expressed concerns about the timeliness of information reported from an enterprise. Which of the following should be done FIRST to address this issue?

Options:

A.

Assess the reporting delivery process.

B.

Negotiate an exception process with the regulator.

C.

Automate the reporting process.

D.

Evaluate the implications of risk acceptance.

Question 177

An IT governance committee is reviewing its current risk management policy in light of increased usage of social media within an enterprise. The FIRST task for the governance committee is to:

Options:

A.

recommend blocking access to social media.

B.

review current level of social media usage.

C.

initiate an assessment of the impact on the business.

D.

reassess the enterprise's bring your own device (BYOD) policy.

Question 178

Which of the following is the GREATEST driver of ethical decision making in an IT enterprise?

Options:

A.

Corporate culture

B.

Process and control environment

C.

Code of conduct

D.

Training and awareness programs

Question 179

An IT team is having difficulty meeting new demands placed on the department as a result of a major and radical shift in enterprise business strategy. Which of the following is the ClO's BEST course of action to address this situation?

Options:

A.

Utilize third parties for non-value-added processes.

B.

Align the business strategy with the IT strategy.

C.

Review the current IT strategy.

D.

Review the IT risk appetite.

Question 180

Which of the following is MOST helpful in determining whether an enterprise’s quality assurance (QA) program is meeting business requirements?

Options:

A.

Review the quality framework.

B.

Perform a SWOT analysis.

C.

Review service outage reports.

D.

Perform a quality audit.

Question 181

Which of the following has the GREATEST impact on the design of an IT governance framework?

Options:

A.

IT performance metrics

B.

Resource allocation

C.

Business leadership

D.

Business risk

Question 182

Which of the following is the PRIMARY outcome of using a comprehensive architecture framework?

Options:

A.

Key third-party relationships are supported.

B.

Business goal conflicts are identified.

C.

Relevant controls are identified.

D.

Organizational management policies are developed.

Question 183

A small enterprise has just hired its first CIO, who has been tasked with making the IT department more efficient. What should be the CIO's NEXT step after identifying several new improvement initiatives?

Options:

A.

Mandate IT staff training.

B.

Request an IT balanced scorecard.

C.

Require a cost-benefit analysis.

D.

Allocate funding for the initiatives.

Question 184

A large enterprise is implementing an information security policy exception process. The BEST way to ensure that security risk is properly addressed is to:

confirm process owners' acceptance of residual risk.

perform an internal and external network penetration test.

obtain IT security approval on security policy exceptions.

Options:

A.

benchmark policy against industry best practice.

Question 185

Which of the following should be considered FIRST when assessing the implications of new external regulations on IT compliance?

Options:

A.

IT policies and procedures that need revision

B.

Resource burden for implementation

C.

Gaps in skills and experience of IT employees

D.

Impact on contracts with service providers

Question 186

The MOST appropriate method for evaluating the capability of IT governance is through the use of:

Options:

A.

a maturity assessment.

B.

benchmarking.

C.

a cost-benefit analysis.

D.

a risk assessment.

Question 187

A CIO was notified that a new employee was observed wearing a headset with an optical lens at the organization's data center. The individual was entering voice commands into the device. When approached, the employee explained the device is a new personal technology serving as a hands-free version of a smart phone. The CIO is concerned with potential security vulnerabilities of allowing such devices, and whether they should be banned from the facility. What should be the NEXT course of action in response to the ClO's concern?

Options:

A.

Define a risk mitigation strategy.

B.

Update the acceptable use policy.

C.

Research competitor usage of similar devices.

D.

Assess the risk associated with the device.

Question 188

A CIO realizes a significant change is required in the way IT responds to key external customers and needs to gain support from the enterprise to address this situation. What should be done FIRST?

Options:

A.

Empower key IT staff to implement a solution.

B.

Establish new customer service policies.

C.

Engage customer service training providers.

D.

Engage the IT steering committee.

Question 189

An enterprise has well-designed procurement and vendor risk management policies that are intended to prevent biased decision-making. However, a pattern of ethical violations indicates that vendor selection may have been inappropriately influenced by non-work-related incentives provided to decision makers. Which of the following should be done FIRST in response to this issue?

Options:

A.

Revise the procurement and vendor risk management policies.

B.

Conduct a root cause analysis and remediate based on findings.

C.

Document the critical success factors (CSFs) for the procurement policies.

D.

Establish and communicate strict penalties for biased vendor selection.

Question 190

Which of the following BEST enables an enterprise to determine whether a current program for IT infrastructure migration to the cloud is continuing to provide benefits?

Options:

A.

Key performance indicators (KPls)

B.

Total cost of ownership (TCO)

C.

Key risk indicators (KRIS)

D.

Net present value (NPV)

Question 191

An enterprise is required to implement several regulatory requirements. Which of the following functions is BEST suited to determine compliance priorities?

Options:

A.

Legal counsel

B.

The IT risk department

C.

The audit department

D.

Business units

Question 192

Which of the following is MOST relevant to report to the board of directors regarding the execution of IT strategy?

Options:

A.

Service level agreements (SLAs) for outsourced IT initiatives

B.

Total IT spend from all current IT initiatives

C.

Realization of benefits in the business case

D.

IT strategy risk metrics related to critical services and projects

Question 193

An interna! health organization has been notified that a data breach has resulted in patient records being published online. Which of the

following is MOST important consideration when determining the process for meeting the organization's legal and regulatory obligations?

Options:

A.

Organizational structure, including accountable partes

B.

Data classification and related security policy

C.

Context of the breach, including data ownership and location

D.

Details of how the breach occurred and related incident response efforts

Question 194

An enterprise wants to implement metrics to monitor the performance of its IT portfolio. Whose input is MOST important to consider when establishing these metrics?

Options:

A.

Project management office (PMO).

B.

IT executives.

C.

The chief executive officer (CEO).

D.

Business unit stakeholders.

Question 195

Which of the following should be the FIRST step to ensure IT resources have the appropriate skills and experience level to support enterprise objectives?

Options:

A.

Determining the required competencies.

B.

Providing training to IT personnel.

C.

Developing an IT skills matrix.

D.

Monitoring resource performance.

Question 196

To measure the value of IT-enabled investments, an enterprise needs to identify its drivers as defined by its:

Options:

A.

technology strategy.

B.

value statements.

C.

service level agreements (SLAs).

D.

business strategy.

Question 197

An enterprise plans to implement a business intelligence tool with data sources from various enterprise applications. Which of the following is the GREATEST challenge to implementation?

Options:

A.

Interface issues between enterprise and business intelligence applications.

B.

The need for staff to be trained on the new business intelligence tool.

C.

Large volumes of data fed from enterprise applications.

D.

Data definition and mapping sources from applications.

Question 198

The PRIMARY objective of establishing outcome measures is to:

Options:

A.

Clarify the cause-and-effect relationship of the strategy

B.

Monitor whether the chosen strategy is successful

C.

Understand how the strategy will be achieved

D.

Demonstrate commitment to IT governance

Question 199

Which of the following should be the PRIMARY consideration when implementing IT governance in a small, newly established organization?

Options:

A.

Assigning a budget for IT governance applications.

B.

Defining IT project management methodology.

C.

Approving enterprise architecture (EA) and standards.

D.

Assigning IT roles and responsibilities.

Question 200

Business management is seeking assurance from the CIO that IT has a plan in place for early identification of potential issues that could impact the delivery of a new application. Which of the following is the BEST way to increase the chances of a successful delivery?

Options:

A.

Implement a release and deployment plan

B.

Ask the application owner to update the risk register

C.

Create a baseline configuration of the new application

D.

Perform user acceptance testing (UAT)

Question 201

The BEST way for a CIO to justify maintaining and supporting social media platforms is by demonstrating:

Options:

A.

how social media technology fits into the IT investment management process.

B.

that service level agreements (SLAs) for social media technologies have been met.

C.

the IT performance Of social media technologies.

D.

the value derived from investment in social media technologies.

Question 202

Despite an adequate training budget, IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?

Options:

A.

Provide incentives for IT staff to attend outside conferences and training.

B.

Require human resources (HR) to recruit new talent using an established IT skills matrix.

C.

Create a standard-setting center of excellence for IT.

D.

Establish an agreed-upon skills development plan with each employee.

Question 203

An enterprise's current business continuity plan (BCP) fails to consider many common crisis events. What would be MOST helpful to address this situation?

Options:

A.

Engage stakeholders in scenario development

B.

Review the root cause analysis

C.

Require further walk-through tests

D.

Review and update the crisis communication plan

Question 204

Which of the following would BEST help to prevent an IT system from becoming obsolete before its planned return on investment (ROI)?

Options:

A.

Obtaining independent assurance that the IT system conforms to business requirements

B.

Defining IT and business goals to ensure value delivery as required

C.

Managing the benefit realization through the entire life cycle

D.

Ordering an external audit for the IT system early in the roll out

Page: 1 / 68
Total 682 questions