CGEIT Certified in the Governance of Enterprise IT Exam Questions and Answers
An enterprise is planning a transformation initiative by leveraging emerging technology that will have a significant impact on existing products and services Which of the following is the BEST way for IT to prepare for this change?
Which of the following is MOST important to include in IT governance reporting to the board of directors?
An enterprise has entered into a new market which brings additional regulatory compliance requirements. What should be done FIRST to address these requirements?
Which of the following would provide the MOST useful information to understand the associated risks when implementing a new digital transformation strategy?
The CIO of a large enterprise has taken the necessary steps to align IT objectives with business objectives. What is the BEST way for the CIO to ensure these objectives are delivered effectively by IT staff?
Which of the following should be done FIRST when designing an IT balanced scorecard?
An IT strategy committee wants to evaluate how well the IT department supports the business strategy. Which of the following is the BEST method for making this determination?
Which of the following should be the PRIMARY consideration for an enterprise when prioritizing IT projects?
An enterprise has finalized a major acquisition and a new business strategy in line with stakeholder needs has been introduced to help ensure continuous alignment of IT with the new business strategy the CiO should FIRST
Which of the following is the PRIMARY objective of a data protection impact assessment?
Which of the following is the BEST indication of an effective information governance model?
An enterprise has decided to adopt cloud services. Which of the following should be established FIRST?
Which of the following should a new CIO do FIRST to set the strategic direction for IT?
Which of the following is the BEST way to minimize the potential mishandling of customer personal information in a system that is located in a country with strict privacy regulations?
Which of the following is MOST helpful in determining whether an enterprise’s quality assurance (QA) program is meeting business requirements?
Which of the following is the PRIMARY responsibility of a data steward at an enterprise with mature data management programs?
An executive management team has determined the need to implement an IT governance framework, beginning with the maturity assessment process. The PRIMARY purpose for maturity assessment is to:
An enterprise has decided to invest in Internet of Things (IoT) technology as part of its strategic plan. Which of the following presents the GREATEST risk to consider as part of the technical risk management process?
Which of the following should a CIO review to obtain a holistic view of IT performance when identifying potential gaps in service delivery?
An enterprise has made the strategic decision to begin a global expansion program which will require opening sales offices in countries across the world. Which of the following should be the FIRST consideration with regard to the IT service desk which will remain centralized?
The effect of regional differences On service delivery
Identification of IT service desk functions that can be outsourced
Which of the following provides the STRONGEST indication that IT governance is well established within an organizational culture?
Which of the following is MOST important to have in place to ensure a business continuity plan (BCP) can be executed?
To help ensure the IT portfolio provides maximum value to an organization, IT projects are BEST prioritized based on:
cost-benefit analysis results.
alignment with business strategy.
Which of the following is the BEST way for a CIO to provide senior business management with increased visibility to the overall performance of the IT operation?
Which of the following is the MOST effective method of measuring the realization of benefits from implementing robotic process automation (RPA)?
A CIO is planning to interview enterprise stakeholders to assess whether the IT strategic plan is continuing to support enterprise business objectives. The CIO would be MOST effective by starting the interview process with:
Which of the following BEST enables an enterprise to determine whether a current program for IT infrastructure migration to the cloud is continuing to provide benefits?
Which of the following has the GREATEST impact on the design of an IT governance framework?
An enterprise has established a goal of leveraging AI as a source of strategic advantage. Which of the following should be done FIRST when developing the related IT strategy?
Which of the following should be considered FIRST when assessing the implications of new external regulations on IT compliance?
A CIO observes that many information assets are hosted on legacy technology that can no longer be patched or updated. The systems are not currently in use, but business units are reluctant to decommission assets due to information retention requirements. Which of the following is the BEST strategic response to this situation?
In a large enterprise, which of the following is the BEST approach to enable effective communication to senior management regarding the project status for a strategic enterprise resource management system implementation?
To define the risk management strategy, which of the following MUST be set by the board of directors?
An enterprise has a centralized IT function but also allows business units to have their own technology operations, resulting in duplicate technologies and conflicting priorities. Which of the following should be done FIRST to reduce the complexity of the IT landscape?
Promote automation tools used by the business units.
An enterprise wants to establish key risk indicators (KRIs) in an effort to better manage IT risk. Which of the following should be identified FIRST?
Which of the following is the BEST way to maximize the value of an enterprise’s information asset base?
Which of the following BEST enables an enterprise to achieve the benefits of implementing new Internet of Things (loT) technology?
An enterprise is considering outsourcing non-core IT processes. Which of the following should be the FIRST step?
Senior management is concerned about the unauthorized use of third-party data that is stored within the enterprise's data repositories. Which of the following is the BEST way to address this concern?
After experiencing poor recovery times following a catastrophic event, an enterprise is seeking to improve its disaster recovery capabilities. Which of the following would BEST enable the enterprise to accomplish this objective?
When conducting a risk assessment in support of a new regulatory
requirement, the IT risk committee should FIRST consider the:
Which of the following should be the MOST important consideration when establishing key performance indicators (KPIs) for IT initiatives?
Which of the following should be the FIRST step to ensure IT resources have the appropriate skills and experience level to support enterprise objectives?
An enterprise's IT department has failed to deliver required solutions on time due to insufficient resource allocation, resulting in a longer time to market. Which of the following is the BEST way for the chief information officer (CIO) to address this situation?
An organization requires updates to their IT infrastructure to meet business needs. Which of the following will provide the MOST useful information when planning for the necessary IT investments?
Which of the following is MOST important for the successful establishment of an ethics program?
An internal auditor conducts an assessment of a two-year-old IT risk management program. Which of the following findings should be of MOST concern to the CIO?
Which of the following is MOST important for a data steward to verify when a system's data is edited by an automated tool to fix an incident?
A new regulation requires enterprises to disclose when significant cyber incidents occur. Which of the following is MOST important for the enterprise to determine?
A board of directors is concerned that a major IT implementation has the potential to significantly disrupt enterprise operations. Which of the following would be MOST helpful in identifying the extent of the potential impact of the disruption?
An enterprise is initiating efforts to improve system availability to mitigate IT risk to the business. Which of the following results would be MOST important to report to the CIO to measure progress?
Which of the following is the BEST indicator of the effectiveness of IT governance in an enterprise?
What is the BEST way for a board of directors to improve its ability to identify material changes to the enterprise IT risk profile?
Which of the following is the MOST effective approach to ensure senior management sponsorship of IT risk management?
A high-tech enterprise is concerned that leading competitors have been successfully recruiting top talent from the enterprise's research and development business unit.
What should the leadership team mandate FIRST?
The board directed the CIO to ensure that required IT resources are available to execute a new enterprise strategy. Which of the following should be done FIRST to support this initiative?
Which of the following is the BEST way for a CIO to assess the consistency of IT processes against industry benchmarks to determine where to focus improvement initiatives?
Which of the following is the MOST important characteristic of a well-defined information architecture?
Which of the following would BEST help to prevent an IT system from becoming obsolete before its planned return on investment (ROI)?
Which of the following is MOST important to consider when monitoring the performance of IT resources?
The board of an organization has been informed of possible cyberthreats. Which of the following should be the board’s NEXT course of action?
Which of the following should be the PRIMARY consideration when implementing IT governance in a small, newly established organization?
An IT governance committee is defining a risk management policy for a portfolio of IT-enabled investments. Which of the following should be the PRIMARY consideration when developing the policy?
Which of the following is the MOST important course of action when initiating a procurement process for a Zero Trust solution?
The accountability for a business continuity program for business-critical systems is BEST assigned to the:
When an enterprise outsources to a third-party data center, who is accountable for the governance of data retention controls for the data that has been transferred?
An audit department recently uncovered a series of security breaches. It was determined that network intrusion detection logs were recording the suspicious activity, but IT staff were not reviewing logs due to competing business demands. To address this situation, the IT steering committee’s FIRST priority should be:
Which of the following is the PRIMARY reason to monitor data classification efforts?
Which of the following should be the PRIMARY consideration when developing an IT strategy for the global implementation of Internet of Things (IoT) solutions?
An enterprise is required to implement several regulatory requirements. Which of the following functions is BEST suited to determine compliance priorities?
Which of the following would be an IT steering committee's BEST course of action upon learning business units have been independently procuring cloud services?
A publicly traded enterprise wants to demonstrate that its board of directors is providing adequate strategic oversight of IT. Which of the following BEST supports this objective?
ACIO determines IT investment management processes are not fully realizing the benefits identified in business cases. Which of the following would be the BEST way to prevent this issue?
When selecting a cloud provider, which of the following provides the MOST comprehensive information regarding the current status and effectiveness of the provider's controls?
An interna! health organization has been notified that a data breach has resulted in patient records being published online. Which of the
following is MOST important consideration when determining the process for meeting the organization's legal and regulatory obligations?
New legislation requires an enterprise to report cybersecurity incidents to a government agency within a defined timeline. Which of the following should be the FIRST course of action?
An enterprise's global IT program management office (PMO) has recently discovered that several IT projects are being run within a specific region without knowledge of the PMO. The projects are on time, on budget, and will deliver the proposed benefits to the specific region. Which of the following should be the PRIMARY concern of the PMO?
Which of the following BEST supports enterprise decision making for IT resource allocation?
An enterprise has launched a series of critical new IT initiatives that are expected to produce substantial value Which of the following would BEST provide the board with an indication of progress of the IT initiatives?
In which of the following situations is it MOST appropriate to use a quantitative risk assessment?
An enterprise has decided to implement an IT risk management program After establishing stakeholder desired outcomes, the MAIN goal of the IT strategy committee should be to:
The board of directors of an enterprise has questioned whether the business is focused on optimizing value. The IT strategy committees’ BEST action to address the board's concern is to:
Facing financial struggles, a CEO mandated severe budget cuts. A decision was also made to immediately change the enterprise strategic focus to put more reliance on mobile, cloud, and wireless services in an effort to boost revenue. The IT steering committee has asked the CIO tosuggest adjustments to the current IT project portfolio to allow support for the new direction despite fewer funds. What should the CIO advise the committee to do FIRST?
When developing an IT governance framework, it is MOST important for an enterprise to consider:
Which of the following is MOST likely to have a negative impact on
accountability for information risk ownership?
An internal audit of a large financial institution found that financial data is being managed in a way that will negatively impact the enterprise's ability to support regulatory reporting. Which of the following should be the FIRST strategic action in addressing this situation?
Establish a data governance framework.
Assign data responsibilities through a RACI chart.
Review key risk indicators (KRIS) related to data management.
Communicating which of the following to staff BEST demonstrates senior management's commitment to IT governance?
An enterprise-wide strategic plan has been approved by the board of directors. Which of the following would BEST support the planning of IT investments required for the enterprise?
The PRIMARY reason for periodically evaluating IT resource staffing requirements is to:
Which of the following IT governance actions would be the BEST way to minimize the likelihood of IT failures jeopardizing the corporate value of an IT-dependent organization?
An enterprise is replacing its customer relationship management (CRM) system with a cloud-based system. Which of the following should be done FIRST when preparing for data migration"*
A root-cause analysis indicates a major service disruption due to a lack of competency of newly hired IT system administrators. Who should be accountable for resolving the situation?
When establishing an enterprise data model, the BEST way to ensure the integrity of data is to:
The MAIN responsibility of the board of directors regarding the management of enterprise risk is to:
Which of the following is the MOST appropriate mechanism for measuring overall IT organizational performance?
An enterprise's executive team has recently released a new IT strategy and related objectives. Which of the following would be the MOST effective way for the CIO to ensure IT personnel are supporting the new strategy's objectives?
To meet the growing demands of a newly established business unit, IT senior management has been tasked with changing the current IT organization model to
service-oriented. With significant growth expected of the IT organization, which of the following is the MOST important consideration when planning for long-term IT
service delivery?
Which of the following is the PRIMARY consideration when developing an information asset management program?
When preparing a new IT strategic plan for board approval, the MOST important consideration is to ensure the plan identifies:
An organization is evaluating vendors to provide mobile device management (MDM) services. Which of the following is a KEY governance consideration for the IT steering committee?
Which of the following is the BEST way to address an IT audit finding that many enterprise application updates lack appropriate documentation?
When developing a framework to implement IT governance, which of the following BEST contributes to the successful implementation?
Which aspect of information governance BEST enables an enterprise to avoid duplication of records and promote consistency of data?
Which of the following is the MOST important input for designing a development program to help IT employees improve their ability to respond to business needs?
When considering an IT change that would enable a potential new line of business, the FIRST strategic step for IT governance would be to ensure agreement among the stakeholders regarding:
Reviewing which of the following should be the FIRST step when evaluating the possibility of outsourcing an IT system?
The BEST way to decide how to prioritize issues identified in an IT risk and control self-assessment (CSA) is to understand the risk and:
The PRIMARY objective of promoting business ethics within the IT enterprise should be to ensure:
Which of the following BEST facilitates the standardization of IT vendor selection?
After shifting from lease to purchase of IT infrastructure and software licenses, an enterprise has to pay for unexpected lease extensions causing significant cost overruns. The BEST direction for the IT steering committee would be to establish;
A CEO wants to establish a governance framework to facilitate the alignment of IT and business strategies. Which of the following should be a KEY requirement of this framework?
Which of the following is the BEST IT architecture concept to ensure consistency, interoperability, and agility for infrastructure capabilities?
The CIO in a large enterprise is seeking assurance that significant IT risk is being proactively monitored and does not exceed agreed risk tolerance levels. The BEST way to provide this ongoing assurance is to require the development of:
Which of the following is the MOST effective way for a CIO to govern business unit deployment of shadow IT applications in a cloud environment?
A retail enterprise has cost reduction as its top priority. From a governance perspective, which of the following should be the MOST important consideration when evaluating different IT investment options?
An enterprise is developing several consumer-based services using emerging technologies involving sensitive personal data. The CIO is under pressure to ensure the enterprise is first to market, but security scan results have not been adequately addressed. Reviewing which of the following will enable the CIO to make the BEST decision for the customers?
An enterprise considers implementing a system that uses a technology that is not in line with its IT strategy. The business case indicates significant benefit to the enterprise. Which of the following is the BEST way to manage this situation within an IT governance framework?
Which of the following represents the GREATEST challenge to implementing IT governance?
An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?
From a governance perspective, the PRIMARY goal of an IT risk optimization process should be to ensure:
An IT steering committee is presented with an audit finding that new software applications are delivered on time but consistently have unacceptable levels of defects. Which of the following would be the BEST direction from the committee?
Which of the following provides the BEST assurance on the effectiveness of IT service management processes?
Which of the following is the MOST effective approach to ensure senior management sponsorship of IT risk management?
Establishing a uniform definition for likelihood and impact through risk management standards PRIMARILY addresses which of the following concerns?
A large enterprise that is diversifying its business will be transitioning to a new software platform, which is expected to cause data changes. Which of the following should be done FIRST when developing the related metadata management process?
Six months ago, an enterprise's CIO reorganized IT to improve service delivery to the business. Which of the following would BEST demonstrate the effectiveness of the reorganization?
Senior management wants to expand offshoring to include IT services as other types of business offshoring have already resulted in significant financial benefits for the enterprise. The CIO is currently midway through a successful five-year strategy that relies heavily on internal IT resources. What should the CIO do NEXT?
A business case indicates an enterprise would reduce costs by implementing a bring your own device (BYOD) program allowing employees to use personal devices for email. Which of the following should be the FIRST governance action?
An enterprise experiencing issues with data protection and least privilege is implementing enterprise-wide data encryption in response. Which of the following is the BEST approach to ensure all business units work toward remediating these issues?
A global financial enterprise has been experiencing a substantial number of information security incidents that have directly affected its business reputation. Which of the following should be the IT governance board's FIRST course of action?
The board of a start-up company has directed the CIO to develop a technology resource acquisition and management policy. Which of the following should be the MOST important consideration during the development of this policy?
Which of the following is MOST critical for the successful implementation of an IT process?
An enterprise can BEST assess the benefits of a new IT project through its life cycle by:
IT has launched new portfolio management policies and processes to improve the alignment of IT projects with enterprise goals. The latest audit report indicates that no improvement has been made due to confusion in the decision-making process. Which of the following is the BEST course of action for the CIO?
While assessing the feasibility of introducing new IT practices and standards into the IT governance framework, it is CRITICAL to understand an organization's:
Results of an enterprise's customer survey indicate customers prefer using mobile applications. However, this same survey shows the enterprise's mobile applications are considered inferior compared to legacy browser-based applications. Which of the following should be the FIRST step in creating an effective long-term mobile application strategy?
An enterprise learns that a new privacy regulation was recently published to protect customers in the event of a breach involving personally identifiable information (Pll). The IT risk management team's FIRST course of action should be to:
An enterprise's information security function is making changes to its data retention and backup policies. Which of the following presents the GREATEST risk?
Which of the following would BEST help to improve an enterprise's ability to manage large IT investment projects?
A CIO has been asked to modify an organization's IT performance measurement system to reflect recent changes in technology, including the movement of some data processing to a cloud solution. Which of the following is the PRIMARY consideration when designing such a measurement system?
Two large financial institutions with different corporate cultures are engaged in a merger. From a governance perspective, which of the following should be the GREATEST concern?
A new and expanding enterprise has recently received a report indicating 90% of its data has been collected in just the last six months, triggering data breach and privacy concerns. What should be the IT steering committee's FIRST course of action to ensure new data is managed effectively?
In a large enterprise, which of the following is the MOST effective way to understand the business activities associated with the enterprise's information architecture?
An enterprise plans to implement a business intelligence (Bl) tool with data sources from various enterprise applications. Which of the following is the GREATEST challenge to implementation?
Which of the following MOST effectively demonstrates operational readiness to address information security risk issues?
A manufacturing company has recently decided to outsource portions of its IT operations. Which of the following would BEST justify this decision?
Which of the following aspects of the transition from X-rays to digital images would be BEST addressed by implementing information security policy and procedures?
An enterprise is planning to replace multiple enterprise resource planning (ERP) systems at various regions with one company-wide ERP system. The main objective of this change is to achieve economies of scale efficiencies resulting in cost reductions. To meet this objective, what is the BEST approach in the planning phase of the project?
A global enterprise is experiencing an economic downturn and is rapidly losing market share. IT senior management is reassessing the core activities of the business, including IT, and the associated resource implications. Management has decided to focus on its local market and to close international operations. A critical issue from a resource management perspective is to retain the most capable staff. This is BEST achieved by:
Which of the following is the GREATEST impact to an enterprise that has ineffective information architecture?
A large retail chain realizes that while there has not been any loss of data, IT security has not been a priority and should become a key goal for the enterprise. What should be the FIRST high-level initiative for a newly created IT strategy committee in order to support this business goal?
Which of the following groups should approve the implementation of new technology?
Senior management is reviewing the results of a recent security incident with significant business impact. Which of the following findings should be of GREATEST concern?
An executive sponsor of a partially completed IT project has learned that the financial assumptions supporting the project have changed. Which of the following governance actions should be taken FIRST?
An enterprise's CIO requires all IT processes within the enterprise to be clearly defined. Which of the following would be the MOST immediate outcome?
Which of the following is the MOST comprehensive method to report on overall IT performance to the board of directors?
Which of the following is MOST important for the effective design of an IT balanced scorecard?
Who is PRIMARILY accountable for delivering the benefits of an IT-enabled investment program to the enterprise?
A marketing enterprise is considering procuring customer information to more accurately target customer communications and increase sales. The data has a very high cost to the enterprise. Which of the following would provide the MOST comprehensive view into the potential value to the organization?
A rail transport company has the worst on-time arrival record in the industry due to an antiquated IT system that controls scheduling. Despite employee resistance, an initiative lo upgrade the technology and related processes has been approved. To maximize employee engagement throughout the project, which of the following should be in place prior to the start of the initiative?
An enterprise has decided to utilize a cloud vendor for the first time to provide email as a service, eliminating in-house email capabilities. Which of the following IT strategic actions should be triggered by this decision?
Which of the following is the BEST indication of effective IT-business strategic alignment?
The board of directors of an enterprise has approved a three-year IT strategic program to centralize the core business processes of its global entities into one core system. Which of the following should be the ClO's NEXT step?
A healthcare enterprise that is subject to strict compliance requirements has decided to outsource several key IT services to third-party providers. Which of the following would be the BEST way to assess compliance and avoid reputational damage?
A CIO is concerned with the potential of vendor system failures that could cause a large amount of unintended system downtime. To determine how to prepare for this concern, what is MOST important for the CIO to review?
The use of new technology in an enterprise will require specific expertise and updated system development processes. There is concern that IT is not properly sourced. Which of the following should be the FIRST course of action?
Which of the following is the BEST approach when reviewing The security status of a new business acquisition?
Which of the following BEST lowers costs and improves scalability from an IT enterprise architecture (EA) perspective?
Acceptance of an enterprise's newly implemented IT governance initiatives has been resisted by a functional group requesting more autonomy over technology choices. Which of the following is MOST important to accommodate this need for autonomy?
The board and senior management of a new enterprise recently met to formalize an IT governance framework. The board of directors' FIRST step in implementing IT governance is to ensure that:
Which of the following would be of MOST concern regarding the effectiveness of risk management processes?
When implementing an IT governance framework, which of the following would BEST ensure acceptance of the framework?
Which of the following is MOST important to effectively initiate IT-enabled change?
Which of the following methods is MOST likely to be used to assess plausible risk scenarios that could result in reputational risk to the enterprise?
Following a strategic planning session, new IT objectives were announced. Which of the following is the MOST effective way for the CIO to ensure these objectives are cascaded to IT personnel?
Following a re-prioritization of business objectives by management, which of the following should be performed FIRST to allocate resources to IT processes?
Which of the following should be the FIRST action taken by a newly formed IT governance committee to ensure reports are compliant with regulations and identify key IT risks?
Which of the following is the MOST significant challenge faced by an enterprise when establishing information stewardship?
When conducting a risk assessment in support of a new regulatory requirement, the IT risk committee should FIRST consider the:
Which of the following should be done FIRST when defining responsibilities for ownership of information and systems?
When selecting a vendor to provide services associated with a critical application which of the following is the MOST important consideration with respect to business continuity planning (BCP)?
The PRIMARY reason a CIO and IT senior management should stay aware of the business environment is to:
The CEO of an organization is concerned that there are inconsistencies in the way information assets are classified across the enterprise. Which of the following is be the BEST way for the CIO to address these concerns?
Which of the following is the PRIMARY purpose of an effective set of key risk indicators (KRIs)?
Which of the following BEST demonstrates the effectiveness of enterprise IT governance?
An enterprise is concerned with the potential for data leakage as a result of increased use of social media in the workplace, and wishes to establish a social media strategy. Which of the following should be the MOST important consideration in developing this strategy?
An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?
Which of the following should a new CIO do FIRST to ensure information assets are effectively governed?
An IT strategy committee wants to ensure stakeholders understand who owns each strategic objective. To enable this understanding, which of the following should be communicated to stakeholders?
An enterprise's decision to move to a virtualized architecture will have the GREATEST impact on: