Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free Isaca Certified in the Governance of Enterprise IT CGEIT Exam Questions

Page: 1 / 47 Total 692 questions

Want more questions? Get Premium Access.

Question 1

In which of the following situations is it MOST appropriate to use a quantitative risk assessment?

Correct Answer: C. The objectivity of the risk assessment is of primary importance.
Explanation:

Quantitative risk assessment is more objective than qualitative risk assessment because it uses numeric values and calculations to estimate the likelihood and impact of risks. Quantitative risk assessment is more appropriate when the risk assessment needs to be unbiased and consistent.Reference:= ISACA, CGEIT Review Manual, 7th Edition, 2019, p. 90-91.


Question 2

Which of the following roles has PRIMARY accountability for the security related to data assets?

Correct Answer: B. Data owner
Explanation:

The role that has primary accountability for the security related to data assets is the data owner.A data owner is a person who is generally in a senior company position, responsible for the categorization, protection, usage, and quality of one or more data sets1.The data owner must ensure that the information within their domain is correctly maintained across various platforms and business processes, and that it is secured from unauthorized access and misuse2.The data owner also has the authority to grant or revoke access rights to the data, and to define and enforce data security policies and standards3. Therefore, the data owner is the primary accountable role for the security related to data assets.Reference: Data Owners vs. Data Stewards vs.Data Custodians - CPO Magazine2, CISSP domain 2: Asset security - Infosec Resources


Question 3

IT security is concerned with employees' increasing use of personal equipment for work-related purposes, while employees claim it allows them to be more productive. A decision on whether to modify the enterprise information security policy should be based on:

Correct Answer: D. a risk and benefit evaluation.
Explanation:

A risk and benefit evaluation is a method of weighing the pros and cons of an action or decision, such as modifying the enterprise information security policy to allow the use of personal equipment for work-related purposes.A risk and benefit evaluation can help identify the potential risks and benefits of such a change, assess their likelihood and impact, and compare them with the current situation or alternative options1.A risk and benefit evaluation can provide a systematic and objective basis for making a decision that balances the needs and interests of different stakeholders, such as IT security, employees, and the organization2. The other options are not the best basis for making a decision on whether to modify the enterprise information security policy.Audit findings are reports that evaluate the compliance and effectiveness of an existing policy or process, but they do not necessarily address the potential risks and benefits of changing it3.User access approval procedures are steps that authorize or deny users to access certain resources or systems, but they do not reflect the overall impact of using personal equipment for work-related purposes4. The impact to security is an important factor to consider, but it is not the only one.There may be other benefits or risks that need to be taken into account, such as productivity, cost, user satisfaction, etc.5Reference:

5: https://www.osha.gov/personal-protective-equipment

4: https://www.ato.gov.au/Individuals/Income-deductions-offsets-and-records/Deductions-you-can-claim/Tools-computers-and-items-you-use-for-work/Tools-and-equipment-to-perform-your-work/

3: https://www.ema.europa.eu/en/documents/presentation/presentation-periodic-safety-update-report-procedure-concept-benefit-risk-evaluation-r-postigo_en.pdf

2: https://safetyculture.com/topics/risk-analysis/

1: https://pestleanalysis.com/risk-benefit-analysis/


Question 4

Which of the following is the BEST way for a CIO to assess the consistency of IT processes against industry benchmarks to determine where to focus improvement initiatives?

Correct Answer: A. Utilizing a capability maturity model
Explanation:

Utilizing a capability maturity model is the best way for a CIO to assess the consistency of IT processes against industry benchmarks and determine where to focus improvement initiatives. Capability maturity models provide a structured framework for evaluating the maturity of an organization's processes in comparison to industry best practices. This approach helps identify areas of strength and opportunities for improvement, guiding strategic decisions on where to allocate resources for process enhancements. While balanced scorecards, key performance measures, and IT process audit results are useful, a capability maturity model offers a comprehensive assessment specifically designed for process improvement.


Question 5

Which of the following presents the GREATEST challenge for a large-scale enterprise when procuring Infrastructure as a Service (IaaS)?

Correct Answer: C. Ensuring the vendor meets corporate requirements
Explanation:

For large enterprises, the greatest challenge when procuring IaaS is ensuring the vendor meets corporate requirements, including compliance, integration standards, security, scalability, and service levels. The complexity of aligning cloud capabilities with internal policies and operational needs can create governance gaps.

Other options represent necessary practices, but the alignment of vendor capabilities with enterprise standards is foundational to long-term success and risk mitigation.


CGEIT Review Manual: Domain 2 -- IT Resources and Third-Party Risk

COBIT 2019: APO03 (Manage Enterprise Architecture), APO10 (Manage Suppliers).

Question 6

Of the following, who should be responsible for ensuring the regular review of quality management performance against defined quality metrics?

Correct Answer: A. Process owners
Explanation:

Process owners are responsible for ensuring the regular review of quality management performance against defined quality metrics, as they are accountable for the design, implementation and improvement of the processes they own. Risk management team, internal auditors and executive management have other roles and responsibilities in relation to quality management, such as providing assurance, oversight and direction.Reference: : CGEIT Review Manual (Digital Version), Chapter 3: Benefits Realization, Section 3.2: IT Investment Management, Subsection 3.2.4: IT Investment Management Process, Page 104 : CGEIT Review Manual (Digital Version), Chapter 3: Benefits Realization, Section 3.4: Quality Management, Subsection 3.4.1: Quality Management Overview, Page 120


Question 7

Which of the following is MOST important for the effective design of an IT balanced scorecard?

Correct Answer: D. Identifying appropriate key performance indicators (KPls)
Explanation:

The most important factor for the effective design of an IT balanced scorecard is identifying appropriate key performance indicators (KPIs). KPIs are the measures that reflect the critical success factors of the IT strategy and goals, and that help to monitor and evaluate the IT performance and value. KPIs should be aligned with the four perspectives of the balanced scorecard: financial, customer, internal process, and learning and growth. KPIs should also be SMART: specific, measurable, achievable, relevant, and time-bound.By choosing the right KPIs, the IT balanced scorecard can provide a comprehensive and balanced view of the IT contribution to the business, and support the decision-making and improvement processes


Question 8

An enterprise is exploring a new business opportunity. Which of the following is the BEST way to help ensure related IT projects deliver the business requirements?

Correct Answer: C. Implement stage-gate reviews that require business sign-off.
Explanation:

To help ensure that IT projects related to a new business opportunity deliver the required business outcomes, the best approach is to implement stage-gate reviews that require business sign-off at each critical phase of the project. This process provides structured checkpoints where project progress, alignment with business requirements, and expected outcomes can be evaluated and validated by business stakeholders. This ensures ongoing alignment between IT project execution and business objectives, allowing for timely adjustments as needed. Hiring consultants, developing policies, and focusing on process maturity are supportive actions, but stage-gate reviews with business sign-off directly link project progression to business expectations.


Question 9

An IT department outsourced application support and negotiated service level agreements (SLAs) directly with the vendor Although the vendor met the SLAs business owner expectations are not met and senior management cancels the contract This situation can be avoided in the future by:

Correct Answer: D. assigning responsibility for vendor management
Explanation:

Assigning responsibility for vendor management is the best way to avoid the situation where the IT department outsourced application support and negotiated service level agreements (SLAs) directly with the vendor, but the business owner expectations were not met and senior management cancelled the contract.Vendor management is the process of managing the relationship with a supplier, also known as a vendor or a third party1.Vendor management involves selecting, contracting, monitoring, evaluating, and communicating with vendors to ensure that they deliver the goods and services that meet the business needs and objectives1.Assigning responsibility for vendor management helps to ensure that there is a clear and consistent governance structure, strategy, and policy for working with vendors2.It also helps to align the expectations and interests of all the stakeholders involved, such as the IT department, the business owners, and the senior management2.Assigning responsibility for vendor management also helps to avoid duplication of efforts, conflicts of interest, or gaps in oversight that could result in poor vendor performance, dissatisfaction, or risk exposure2.


Question 10

Which of the following BEST reflects mature risk management in an enterprise?

Correct Answer: D. Responsive risk awareness culture
Explanation:

A responsive risk awareness culture is the best reflection of mature risk management in an enterprise, because it implies that the organization has a high level of risk maturity that enables it to reduce noise and focus more effectively on truly high-risk concerns, choose cost-effective solutions for the risk management priorities, and execute reliably1.A responsive risk awareness culture also means that the organization has a clear and consistent risk appetite and tolerance, and that the employees are cognizant of the relevant risks as part of their actions2.A responsive risk awareness culture also fosters trust, collaboration, and innovation among the stakeholders, and helps the organization to adapt to changing business environments and emerging risks3.

The other options are not as indicative of mature risk management in an enterprise, because they are either too narrow or too reactive.A regularly updated risk register is a useful tool forcataloguing, tracking, and mitigating risks, but it does not necessarily reflect the strategic alignment, integration, or performance of the risk management process4.Ongoing risk assessment is an essential activity for identifying and evaluating risks, but it does not guarantee that the risks are prioritized, communicated, or managed effectively5.Ongoing investment in risk mitigation is a sign of commitment to risk management, but it does not ensure that the investment is aligned with the risk appetite and tolerance, or that it delivers value to the organization5.


Question 11

Which of the following provides the BEST information to assess the effective alignment of IT investments?

Correct Answer: A. IT balanced scorecard
Explanation:

An IT balanced scorecard is the best information source to assess the effective alignment of IT investments, because it provides a comprehensive and balanced view of the IT performance and value from four perspectives: financial, customer, internal process, and learning and growth1.An IT balanced scorecard helps to translate the IT strategy and objectives into measurable indicators that reflect the contribution of IT to the business strategy and goals2.An IT balanced scorecard also helps to monitor and evaluate the IT investments based on their benefits, costs, and risks, and to identify and address any gaps or issues in the IT alignment2.An IT balanced scorecard also helps to communicate and report the IT value and outcomes to the stakeholders, and to foster a continuous improvement culture within the organization2.


Question 12

Which of the following should be the ClO's GREATEST consideration when making changes to the IT strategy'?

Correct Answer: C. Have key stakeholders been consulted?
Explanation:

The CIO's greatest consideration when making changes to the IT strategy should be whether key stakeholders have been consulted, because they are the ones who are affected by and involved in the IT strategy.Key stakeholders include the business functions, customers, suppliers, partners, regulators, and employees who depend on or contribute to the IT value delivery1.Consulting key stakeholders helps to ensure that the IT strategy is aligned with the business strategy and objectives, and that it meets the needs and expectations of the stakeholders2.Consulting key stakeholders also helps to solicit feedback and suggestions for improvement, and to gain buy-in and support for the IT strategy3.Consulting key stakeholders also helps to identify and manage any risks, issues, or opportunities that may arise from the IT strategy changes4.


Question 13

From a governance perspective, which of the following roles is MOST important for an enterprise to keep in-house?

Correct Answer: C. Information steward
Explanation:

An information steward is a person who is responsible for ensuring the quality, accuracy, consistency, and usability of the data in an organization. An information steward works with the business users and stakeholders to understand their data needs, requirements, and expectations, and to define and implement the data policies, standards, and rules that govern the data lifecycle.An information steward also monitors and reports on the data quality issues and trends, and initiates and coordinates the data improvement actions and projects12.

From a governance perspective, the role of an information steward is most important for an enterprise to keep in-house, because it requires a close alignment with the business function, adeep knowledge of the data sources and systems, and a high level of trust and accountability. An information steward is the guardian of the business data, which is a valuable asset and a competitive advantage for any organization.Outsourcing the role of an information steward may pose significant risks to the data security, privacy, quality, and compliance12.

An information auditor is a person who performs independent and objective assessments of the data quality, integrity, and compliance in an organization. An information auditor evaluates the data governance policies, standards, and processes, as well as the data controls and safeguards.An information auditor also provides recommendations for improving the data management practices and mitigating the data risks3. An information auditor can be outsourced to provide an external and unbiased perspective on the data governance performance and issues.

An information architect is a person who designs and maintains the data structures, models, and standards in an organization. An information architect ensures that the data is organized, integrated, accessible, and consistent across different systems and platforms.An information architect also supports the data analysis, reporting, and visualization needs of the organization4. An information architect can be outsourced to leverage the expertise and experience of external consultants or vendors.

An information analyst is a person who collects, processes, analyzes, and interprets the data in an organization. An information analyst uses various tools and techniques to extract insights and value from the data. An information analyst also communicates and presents the data findings and recommendations to support decision making and problem solving in the organization. An information analyst can be outsourced to access specialized skills or technologies that may not be available in-house.Reference:What is Information Audit? Definition & Process.What is Information Architecture? Definition & Examples.What is an Information Steward? Definition & Role.6 Key Responsibilities of the Invaluable Data Steward - Dun & Bradstreet. [What is an Information Analyst? Definition & Skills].


Question 14

When developing a framework to implement IT governance, which of the following BEST contributes to the successful implementation?

Correct Answer: A. Practical and enforceable policies
Explanation:

Practical and enforceable policies are the best way to contribute to the successful implementation of a framework to implement IT governance, as they provide clear and consistent guidance and direction for IT activities, processes, and decisions. Practical and enforceable policies are based on the enterprise's strategy, goals, and values, as well as the relevant regulations and standards. Practical and enforceable policies also define the roles, responsibilities, and authorities of the IT stakeholders, as well as the mechanisms for monitoring, measuring, and reporting on IT performance and compliance. Practical and enforceable policies can help ensure that IT governance is effective, efficient, and aligned with the business needs and expectations.

Automated compliance tracking, comprehensive and timely audit reviews, and periodic peer reviews are also useful ways to support the implementation of a framework to implement IT governance, but they are not the best way. Automated compliance tracking is a process that uses software tools or systems to collect, analyze, and report on IT compliance data, such as policies, standards, controls, risks, incidents, or issues. Automated compliance tracking can help reduce the time and effort required for IT compliance management, as well as improve the accuracy and reliability of IT compliance information. Comprehensive and timely audit reviews are assessments that evaluate the adequacy and effectiveness of IT governance, management, and operations. Comprehensive and timely audit reviews can help identify and address any weaknesses or gaps in IT governance, as well as provide recommendations for improvement. Periodic peer reviews are evaluations that compare the IT governance practices of an enterprise with those of its peers or competitors. Periodic peer reviews can help benchmark and improve the IT governance performance of an enterprise, as well as identify best practices or opportunities for innovation.


Question 15

An IT governance committee realizes there are antiquated technologies in use throughout the enterprise. Which of the following is the BEST group to evaluate the recommendations to address these shortcomings?

Correct Answer: A. Enterprise architecture (EA) review board
Explanation:

The best group to evaluate recommendations to address the use of antiquated technologies throughout the enterprise is the Enterprise Architecture (EA) review board. This group is responsible for overseeing the architectural framework and ensuring that IT systems and technologies align with the enterprise's strategic objectives. The EA review board has the expertise to assess the impact of current technologies on the business and recommend modernization strategies that align with the enterprise architecture. While business process improvement workgroups, audit committees, and risk management committees play important roles, the EA review board is specifically equipped to address technological shortcomings and alignment with business goals.