In a large enterprise, which of the following should be responsible for the implementation of an IT balanced scorecard?
When developing a business case for an enterprise resource planning (ERP) implementation, which of the following, if overlooked, causes the GREATEST impact to the enterprise?
Which of the following provides the BEST evidence of effective IT governance?
Which of the following would be MOST helpful to an enterprise that wants to standardize how sensitive corporate data is handled?
An IT steering committee wants to select a disaster recovery site based on available risk data Which of the following would BE ST enable the mapping of cost to risk?
Reviewing which of the following should be the FIRST step when evaluating the possibility of outsourcing an IT system?
When assessing the impact of a new regulatory requirement, which of the following should be the FIRST course of action?
An enterprise has decided to implement an IT risk management program After establishing stakeholder desired outcomes, the MAIN goal of the IT strategy committee should be to:
The MAIN responsibility of the board of directors regarding the management of enterprise risk is to:
When establishing an enterprise data model, the BEST way to ensure the integrity of data is to:
When preparing a new IT strategic plan for board approval, the MOST important consideration is to ensure the plan identifies:
Which of the following is MOST important to review during IT strategy development?
A data governance strategy has been defined by the IT strategy committee which includes privacy objectives related to access controls, authorized use. and data collection. Which of the following should the committee do NEXT?
Which of the following should be the PRIMARY goal of implementing service level agreements (SLAs) with an outsourcing vendor?
Which of the following would be the BEST long-term solution to address the concern regarding loss of experienced staff?
Which of the following is MOST critical to support IT governance cultural changes within an organization?
Which aspect of information governance BEST enables an enterprise to avoid duplication of records and promote consistency of data?
An enterprise is replacing its customer relationship management (CRM) system with a cloud-based system. Which of the following should be done FIRST when preparing for data migration"*
To evaluate IT resource management, it is MOST important to define:
An enterprise has entered into a new market which brings additional regulatory compliance requirements. What should be done FIRST to address these requirements?
Which of the following should be established FIRST so that data owners can consistently assess the level of data protection needed across the enterprise?
An enterprise is planning a transformation initiative by leveraging emerging technology that will have a significant impact on existing products and services Which of the following is the BEST way for IT to prepare for this change?
An enterprise is considering outsourcing non-core IT processes Which of the following should be the FIRST step?
As part of the implementation of IT governance, the board of an enterprise should establish an IT strategy committee to:
An enterprise has made the strategic decision to reduce operating costs for the next year and is taking advantage of cost reductions offered by an external cloud service provider. Which of the following should be the IT steering committee's PRIMARY concern?
Which of the following IT governance actions would be the BEST way to minimize the likelihood of IT failures jeopardizing the corporate value of an IT-dependent organization?
A CEO wants to establish a governance framework to facilitate the alignment of IT and business strategies. Which of the following should be a KEY requirement of this framework?
A large bank has completed several acquisitions in the last few years that have resulted in redundant IT applications. To align with the strategic initiative of providing integrated services to customers, the IT steering committee has decided to share data and integrate applications. Which of the following would be MOST important to review in this situation?
From an IT governance perspective, establishing performance measurements is PRIMARILY the responsibility of:
Which of the following is the BEST indication that enterprise value is being derived from IT?
An enterprise wishes to establish key risk indicators (KRIs) in an effort to better manage IT risk. Which of the following should be identified FIRST?
An enterprise has developed a new digital strategy to improve fraud detection. Which of the following is MOST important to consider when updating the information architecture?
Which of the following should a new CIO do FIRST to ensure information assets are effectively governed?
Facing financial struggles, a CEO mandated severe budget cuts. A decision was also made to immediately change the enterprise strategic focus to put more reliance on mobile, cloud, and wireless services in an effort to boost revenue. The IT steering committee has asked the CIO tosuggest adjustments to the current IT project portfolio to allow support for the new direction despite fewer funds. What should the CIO advise the committee to do FIRST?
Which of the following should be management's GREATEST consideration when trying to optimize the use of benefits from IT?
Which of the following is a PRIMARY responsibility of the CIO when an enterprise plans to replace its enterprise resource applications?
Which of the following should be the PRIMARY consideration for an enterprise when prioritizing IT projects?
In an enterprise that has worldwide business units and a centralized financial control model, which of the following is a barrier to strategic alignment of business and IT?
The PRIMARY reason for using quantitative criteria in developing business cases for IT projects is to:
A project sponsor has circumvented the request for proposal (RFP) selection process. Which of the following is the MOST likely reason for this control gap?
An IT manager is trying to determine optimal IT service levels. Which of the following should be the PRIMARY consideration?
Which of the following are the MOST important processes for information asset life cycle management?
Which of the following BEST indicates that a change management process has been implemented successfully?
To enable IT to deliver adequate services and maintain availability of a web-facing infrastructure, an IT governance committee should FIRST establish:
An enterprise is developing an ethics program, and the ethical standards have been defined. Which of the following should the enterprise do NEXT?
Which of the following BEST indicates the success of an enterprise's IT governance framework after implementation?
An enterprise is determining the objectives for an IT training improvement initiative from a governance prosected. it would be MOST important to ensure that:
A business is considering a policy to anonymize personal data in enterprise systems. Before making a decision, which of the following is MOST important for the IT steering committee to consider?
The board of directors of a large organization has directed IT senior management to improve IT governance within the organization. IT senior management's MOST important course of action should be to:
IT maturity models measure:
Before establishing IT key nsk indicators (KRls) which of the following should be defined FIRST?
The CEO of an organization is concerned that there are inconsistencies in the way information assets are classified across the enterprise. Which of the following is be the BEST way for the CIO to address these concerns?
Which of the following would be the MOST effective way to ensure IT capabilities are appropriately aligned with business requirements for specific business processes?
Once the strategic vision has been established, which of the following would be the BEST activity for supporting the implementation of performance measures?
An assessment reveals that enterprise risk management (ERM) practices are being applied inconsistently by IT staff. Which of the following would be the MOST effective corrective action?
Which of the following metrics would provide senior management with the BEST indication of the success of IT investments?
Which of the following is a responsibility of an IT strategy committee?
Which of the following is the BEST justification for a procurement manager to agree to purchase IT equipment from a specific vendor during a sales promotion?
Of the following, who is PRIMARILY responsible for applying frameworks for the governance of IT to balance the need for security controls with business requirements?
An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?
An enterprise is adopting a new governance framework. Of the following, the MOST effective method to help ensure that key activities are performed by appropriate resources is through the use of:
Which of the following would be the BEST way to facilitate the successful adoption of a new technology across the enterprise?
A newly appointed CIO has been tasked with the responsibility of developing an effective IT enterprise roadmap that meets business requirements. Which of the following is the BEST way to ensure that the business needs have been taken into consideration?
An enterprise's global IT program management office (PMO) has recently discovered that several IT projects are being run within a specific region without knowledge of the PMO. The projects are on time, on budget, and will deliver the proposed benefits to the specific region. Which of the following should be the PRIMARY concern of the PMO?
Due to the recent introduction of personal data protection regulations, an enterprise is required to maintain its employee data in production systems only for a limited time. Which of the following is MOST important to review?
IT management has reported difficulty retaining qualified IT personnel to support the organization's new strategy Given that outsourcing is not a viable approach, which of the following would be the BEST way for IT governance to address this situation?
Which of the following provides the BEST evidence of an IT risk-aware culture across an enterprise?
The board of directors of an enterprise has questioned whether the business is focused on optimizing value. The IT strategy committees’ BEST action to address the board's concern is to:
An enterprise embarked on an aggressive strategy requiring the implementation of several large IT projects impacting multiple business processes across all departments. Initially employees were supportive of the strategy, but there is growing fatigue and frustration with the ongoing newcapabilities which must be learned. Which of the following would be the BEST action performed by senior management?
Which of the following is the PRIMARY ongoing responsibility of the IT governance function related to risk?
Results of an enterprise's customer survey indicate customers prefer using mobile applications. However, this same survey shows the enterprise's mobile applications are considered inferior compared to legacy browser-based applications. Which of the following should be the FIRST step in creating an effective long-term mobile application strategy?
A rail transport company has the worst on-time arrival record in the industry due to an antiquated IT system that controls scheduling. Despite employee resistance, an initiative lo upgrade the technology and related processes has been approved. To maximize employee engagement throughout the project, which of the following should be in place prior to the start of the initiative?
Which of the following is the BEST way to ensure the continued usefulness of IT governance reports for stakeholders?
Which of the following is the BEST way to ensure new systems can be adequately supported once in production?
When implementing an IT governance framework, which of the following would BEST ensure acceptance of the framework?
From a governance perspective, the PRIMARY goal of an IT risk optimization process should be to ensure:
Due to continually missed service level agreements (SLAs), an enterprise plans to terminate its contract with a vendor providing IT help desk services. The enterprise s IT department willassume the help desk-related responsibilities. Which of the following would BEST facilitate this transition?
An organization's board of directors has questioned the value provided by IT key performance indicators (KPIs). Which of the following is the BEST way to determine whether the KPIs adequately support organizational objectives?
An enterprise has been focused on establishing an IT risk management framework. Which of the following should be the PRIMARY motivation behind this objective?
Which of the following would be MOST important to update if a decision is made to ban end user-owned devices in the workplace?
Which of the following is the BEST IT architecture concept to ensure consistency, interoperability, and agility for infrastructure capabilities?
An enterprise has a large backlog of IT projects. The current strategy is to execute projects as they are submitted, but executive management does not believe this method is optimal. Which of the following is the MOST important action to address this concern?
A marketing enterprise is considering procuring customer information to more accurately target customer communications and increase sales. The data has a very high cost to the enterprise. Which of the following would provide the MOST comprehensive view into the potential value to the organization?
An enterprise learns that a new privacy regulation was recently published to protect customers in the event of a breach involving personally identifiable information (Pll). The IT risk management team's FIRST course of action should be to:
Which of the following MUST be established before implementing an information architecture that restricts access to data based on sensitivity?
Who is PRIMARILY accountable for delivering the benefits of an IT-enabled investment program to the enterprise?
The IT program manager does not see the value of conducting risk assessments for a new major IT project. The manager is reluctant to cooperate with internal auditors and the newly formed steering committee. Midway through the project, program requirements were changed because the CEO is a friend of a vendor and wants to implement this vendor's new technology. This decision will cause the current IT program budget to be insufficient and will be shown as overspending.
After the requirement change request, the IT program manager should FIRST:
The BEST way to manage an outsourced vendor relationship is by:
Which of the following would BEST help to improve an enterprise's ability to manage large IT investment projects?
An enterprise is implementing a new IT governance program. Which of the following is the BEST way to increase the likelihood of its success?
Which of the following is MOST important to effectively initiate IT-enabled change?
An IT steering committee is presented with an audit finding that new software applications are delivered on time but consistently have unacceptable levels of defects. Which of the following would be the BEST direction from the committee?
While monitoring an enterprise's IT projects portfolio, it is discovered that a project is 75% complete, but all budgeted resources have been expended. Which of the following is the MOST important task to perform?
A new CIO has been charged with updating the IT governance structure. Which of the following is the MOST important consideration to effectively influence organizational and process change?
A regulatory audit assessed an enterprise's main transactional application as noncompliant. In addition to fines and required corrections, an agreement was reached to implement a set of governance controls over IT. Accountability for these controls is BEST assigned to which of the following?
The use of an IT balanced scorecard enables the realization of business value of IT through:
The MOST successful IT performance metrics are those that:
Which of the following is MOST important for the effective design of an IT balanced scorecard?
Which of the following MOST effectively prevents an IT system from becoming technologically obsolete before its planned return on investment (ROi)?
Which of the following would BEST enable business innovation through IT?
A CIO believes that a recent mission-critical IT decision by the board of directors is not in the best financial interest of all stakeholders. Which of the following is the MOST ethical course of action?
An enterprise is initiating efforts to improve system availability to mitigate IT risk to the business. Which of the following results would be MOST important to report to the CIO to measure progress?
A company is considering selling products online, and the CIO has been asked to advise the board of directors of potential problems with this strategy. Which of the following is the ClO's BEST course of action?
To generate value for the enterprise, it is MOST important that IT investments are:
A new and expanding enterprise has recently received a report indicating 90% of its data has been collected in just the last six months, triggering data breach and privacy concerns. What should be the IT steering committee's FIRST course of action to ensure new data is managed effectively?
A large organization with branches across many countries is in the midst of an enterprise resource planning (ERP) transformation. The IT organization receives news that the branches in a country where the impact to the enterprise is to be greatest are being sold. What should be the NEXT step?
Which of the following is the MOST important driver of IT governance?
A CIO has been asked to modify an organization's IT performance measurement system to reflect recent changes in technology, including the movement of some data processing to a cloud solution. Which of the following is the PRIMARY consideration when designing such a measurement system?
Which of the following is the BEST method for making a strategic decision to invest in cloud services?
Prior to decommissioning an IT system, it is MOST important to:
Best practice states that IT governance MUST:
An enterprise has had the same IT governance framework in place for several years. Currently, large and small capital projects go through the same architectural governance reviews. Despite repeated requests to streamline the review process for small capital projects, business units have received no response from IT. The business units have recently escalated this issue to the newly appointed GO. Which of the following should be done FIRST to begin addressing business needs?
An enterprise plans to implement a business intelligence (Bl) tool with data sources from various enterprise applications. Which of the following is the GREATEST challenge to implementation?
Which of the following is the MOST comprehensive method to report on overall IT performance to the board of directors?
Of the following, who should be responsible for ensuring the regular review of quality management performance against defined quality metrics?
A CIO must determine if IT staff have adequate skills to deliver on key strategic objectives. Which of the following will provide the MOST useful information?
A financial institution with a highly regarded reputation for protecting customer interests has recently deployed a mobile payments program. Which of the following key risk indicators (KRIs) would be of MOST interest to the CIO?
Which of the following aspects of the transition from X-rays to digital images would be BEST addressed by implementing information security policy and procedures?
The board of directors of an enterprise has approved a three-year IT strategic program to centralize the core business processes of its global entities into one core system. Which of the following should be the ClO's NEXT step?
Which of the following would be of MOST concern regarding the effectiveness of risk management processes?
A board of directors is concerned that a major IT implementation has the potential to significantly disrupt enterprise operations. Which of the following would be MOST helpful in identifying the extent of the potential impact of the disruption?
An IT audit reveals inconsistent maintenance of data privacy in enterprise systems primarily due to a lack of data sensitivity categorizations. Once the categorizations are defined, what is the BEST long-term strategic response by IT governance to address this problem?
The BEST way to ensure an IT steering committee meets enterprise objectives is to:
A recent benchmarking analysis has indicated an IT organization is retaining more data and spending significantly more on data retention than its competitors. Which of the following would BEST ensure the optimization of retention costs?
A CIO is concerned with the potential of vendor system failures that could cause a large amount of unintended system downtime. To determine how to prepare for this concern, what is MOST important for the CIO to review?
An enterprise has a zero-tolerance policy regarding security. This policy is causing a large number of email attachments to be blocked and is a disruption to enterprise. Which of the following should be the FIRST governance step to address this email issue?
IT has launched new portfolio management policies and processes to improve the alignment of IT projects with enterprise goals. The latest audit report indicates that no improvement has been made due to confusion in the decision-making process. Which of the following is the BEST course of action for the CIO?
Which of the following is an ADVANTAGE of using strategy mapping?
An IT risk assessment for a large healthcare group revealed an increased risk of unauthorized disclosure of information. Which of the following should be established FIRST to address the risk?
A strategic IT-enabled investment is failing due to unforeseen technology problems. What should be the board of directors' FIRST course of action?
Which of the following is the BEST method for determining an enterprise's current appetite for risk?
An analysis of an organization s security breach is complete. The results indicate that the quality of the code used for updates to its primary customer-facing software has been declining and security flaws were introduced. The FIRST IT governance action to correct this problem should be to review:
Which of the following roles has PRIMARY accountability for the security related to data assets?
Which of the following is the BEST way for a CIO to secure support for a strategy to achieve long-term IT objectives?
Which of the following should be the MOST important consideration when defining an information architecture?
When determining the optimal IT service levels to support business, which of the following is MOST important?
Which of the following is the GREATEST expected strategic organizational benefit from the standardization of technical platforms?
An enterprise will be adopting wearable technology to improve business performance. Which of the following is the BEST way for the CIO to validate IT’s preparedness for this initiative?
The board of an organization has been informed of possible cyberthreats. Which of the following should be the board’s NEXT course of action?
An enterprise has made the strategic decision to begin a global expansion program which will require opening sales offices in countries across the world. Which of the following should be the FIRST consideration with regard to the IT service desk which will remain centralized?
The effect of regional differences On service delivery
Identification of IT service desk functions that can be outsourced
Which of the following is MOST important to effectively incorporate innovation and emerging technologies into an enterprise’s IT strategy?
Of the following, who is responsible for the achievement of IT strategic objectives?
Which of the following is the BEST indicator for measuring performance when implementing DevSecOps in an enterprise?
Which of the following would be MOST useful in developing IT strategic plans aligned with technological needs?
What is the BEST way for IT to achieve compliance with regulatory requirements?
An enterprise’s IT director is concerned that the chair of the IT steering committee is stealing confidential company information. Which of the following is the IT director’s BEST course of action?
An internal auditor conducts an assessment of a two-year-old IT risk management program. Which of the following findings should be of MOST concern to the CIO?
From an IT governance perspective, which of the following would be the MOST significant impact of moving all IT applications to an external Software as a Service (SaaS) cloud provider?
Which of the following is the PRIMARY objective of a data protection impact assessment?
Which of the following provides an enterprise with the BEST understanding of the value proposition for employing a new cloud service?
Which of the following is the BEST way to address the risk associated with new IT investments?
An enterprise has decided to adopt cloud services. Which of the following should be established FIRST?
Which of the following should be the MOST important consideration when establishing key performance indicators (KPIs) for IT initiatives?
An enterprise's IT department has been operating independently without regard to business concerns, leading to misalignment between business and IT. The BEST way to establish alignment would be to require:
In a large enterprise, which of the following is the BEST approach to enable effective communication to senior management regarding the project status for a strategic enterprise resource management system implementation?
An IT steering committee is concerned about staff saving data files containing sensitive corporate information on publicly available cloud file storage applications. Which of the following should be done FIRST to address this concern?
IT governance within an enterprise is attempting to drive a cultural shift to enhance compliance with IT security policies. The BEST way to support this objective is to ensure that enterprise IT policies are:
Despite an adequate training budget. IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?
After experiencing poor recovery times following a catastrophic event, an enterprise is seeking to improve its disaster recovery capabilities. Which of the following would BEST enable the enterprise to accomplish this objective?
A board of directors is concerned with the total cost of IT. Which of the following is MOST important for the CIO to include in an explanation to the board?
Which of the following should be done FIRST when developing an IT strategy to support a new AI business strategy?
Which of the following is MOST important to ensure when aligning IT and enterprise resource management processes?
What should be the FIRST action of a new CIO when considering an IT governance framework for an enterprise?
Which of the following should be the CIO’s GREATEST consideration when making changes to the IT strategy?
Which of the following would BEST help to ensure the appropriate allocation of IT resources to support an enterprise's mission?
When developing IT risk management policies and standards, it is MOST important to align them with:
A CIO wants to make improvements to the enterprise's IT governance. Which of the following would BEST help to demonstrate the expected benefits from proposed changes?
Which of the following is the BEST way to express the value of financial investments in cybersecurity?
Which of the following BEST supports an IT strategy committee’s objective to align employee competencies with planned initiatives?
An IT governance committee realizes there are antiquated technologies in use throughout the enterprise. Which of the following is the BEST group to evaluate the recommendations to address these shortcomings?
From a governance perspective, which of the following functions MUST approve the agreed-upon criteria for a new technology-enabled service before submitting the final high-level design to project stakeholders?
An enterprise is implementing its first mobile sales channel. Final approval for accepting the associated IT risk should be obtained from which of the following?
Risk manager
Business sponsor
A board of directors has mandated that key performance indicators (KPIs) be developed for all IT projects that are created in support of a business objective. Which of the following MUST be reflected in the KPIs to be effective?
New legislation requires an enterprise to report cybersecurity incidents to a government agency within a defined timeline. Which of the following should be the FIRST course of action?
An enterprise is assessing whether to utilize wearable technology. The enterprise has no prior experience with this technology and has asked the chief technology officer (CTO) to assess the impact to the enterprise. The CTO should FIRST:
A regulator has expressed concerns about the timeliness of information reported from an enterprise. Which of the following should be done FIRST to address this issue?
An IT governance committee is reviewing its current risk management policy in light of increased usage of social media within an enterprise. The FIRST task for the governance committee is to:
Which of the following is the GREATEST driver of ethical decision making in an IT enterprise?
An IT team is having difficulty meeting new demands placed on the department as a result of a major and radical shift in enterprise business strategy. Which of the following is the ClO's BEST course of action to address this situation?
Which of the following is MOST helpful in determining whether an enterprise’s quality assurance (QA) program is meeting business requirements?
Which of the following has the GREATEST impact on the design of an IT governance framework?
Which of the following is the PRIMARY outcome of using a comprehensive architecture framework?
A small enterprise has just hired its first CIO, who has been tasked with making the IT department more efficient. What should be the CIO's NEXT step after identifying several new improvement initiatives?
A large enterprise is implementing an information security policy exception process. The BEST way to ensure that security risk is properly addressed is to:
confirm process owners' acceptance of residual risk.
perform an internal and external network penetration test.
obtain IT security approval on security policy exceptions.
Which of the following should be considered FIRST when assessing the implications of new external regulations on IT compliance?
The MOST appropriate method for evaluating the capability of IT governance is through the use of:
A CIO was notified that a new employee was observed wearing a headset with an optical lens at the organization's data center. The individual was entering voice commands into the device. When approached, the employee explained the device is a new personal technology serving as a hands-free version of a smart phone. The CIO is concerned with potential security vulnerabilities of allowing such devices, and whether they should be banned from the facility. What should be the NEXT course of action in response to the ClO's concern?
A CIO realizes a significant change is required in the way IT responds to key external customers and needs to gain support from the enterprise to address this situation. What should be done FIRST?
An enterprise has well-designed procurement and vendor risk management policies that are intended to prevent biased decision-making. However, a pattern of ethical violations indicates that vendor selection may have been inappropriately influenced by non-work-related incentives provided to decision makers. Which of the following should be done FIRST in response to this issue?
Which of the following BEST enables an enterprise to determine whether a current program for IT infrastructure migration to the cloud is continuing to provide benefits?
An enterprise is required to implement several regulatory requirements. Which of the following functions is BEST suited to determine compliance priorities?
Which of the following is MOST relevant to report to the board of directors regarding the execution of IT strategy?
An interna! health organization has been notified that a data breach has resulted in patient records being published online. Which of the
following is MOST important consideration when determining the process for meeting the organization's legal and regulatory obligations?
An enterprise wants to implement metrics to monitor the performance of its IT portfolio. Whose input is MOST important to consider when establishing these metrics?
Which of the following should be the FIRST step to ensure IT resources have the appropriate skills and experience level to support enterprise objectives?
To measure the value of IT-enabled investments, an enterprise needs to identify its drivers as defined by its:
An enterprise plans to implement a business intelligence tool with data sources from various enterprise applications. Which of the following is the GREATEST challenge to implementation?
The PRIMARY objective of establishing outcome measures is to:
Which of the following should be the PRIMARY consideration when implementing IT governance in a small, newly established organization?
Business management is seeking assurance from the CIO that IT has a plan in place for early identification of potential issues that could impact the delivery of a new application. Which of the following is the BEST way to increase the chances of a successful delivery?
The BEST way for a CIO to justify maintaining and supporting social media platforms is by demonstrating:
Despite an adequate training budget, IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?
An enterprise's current business continuity plan (BCP) fails to consider many common crisis events. What would be MOST helpful to address this situation?
Which of the following would BEST help to prevent an IT system from becoming obsolete before its planned return on investment (ROI)?