Free preview mode

Enjoy the free questions and consider upgrading to gain full access!

CGEITFree trialFree trial

By isaca
Aug, 2025

Verified

25Q per page

Question 51

A steering committee has been advised by the IT project management office that individual business units are building systems components that could be leveraged by other business units. Instead, identical components are being duplicated across the enterprise. Which of the following committee directives would be the BEST way to reduce the likelihood of this duplication?

  • A: Implement stage gate reviews to assess systems.
  • B: Establish an enterprise architecture.
  • C: Perform an assessment of change management processes.
  • D: Review IT system release management practices.

Question 52

To support the enterprise's digital transformation, the CIO has been asked to include an Internet of Things (IoT) component in the IT strategy. Which of the following should be the FIRST consideration?

  • A: Ensuring IoT usage in the industry has been analyzed
  • B: Ensuring IoT can be used in current revenue streams
  • C: Ensuring solution providers and their IoT use cases have been researched
  • D: Ensuring initial approvals are limited to small IoT projects to gain experience

Question 53

An enterprise decides to accept the IT risk of a subsidiary located in another country even though it exceeds the enterprise's risk appetite. Which of the following would be the BEST justification for this decision?

  • A: Local market common practices
  • B: Risk framework alignment
  • C: Technical gaps among subsidiaries
  • D: Compliance with local regulations

Question 54

A retail enterprise wants to leverage emerging technologies to create a new sales channel for its customers. However, IT has little experience with these technologies and is unsure if the proposed schedule can be met. Which of the following will BEST help to determine IT's ability to meet this need?

  • A: Conducting a resource gap assessment
  • B: Defining business benefits realization metrics
  • C: Reviewing the resource management policy
  • D: Developing a target state enterprise architecture

Question 55

Which of the following should be the MOST important consideration when designing an implementation plan for IT governance?

  • A: Roles and responsibilities
  • B: Risk tolerance levels
  • C: Organization culture
  • D: Principle and policies

Question 56

Once the strategic vision has been established, which of the following would be the BEST activity for supporting the implementation of performance measures?

  • A: Document policy requirements.
  • B: Document strengths, weaknesses, opportunities, and threats.
  • C: Identify key performance indicators (KPIs).
  • D: Monitor service level performance.

Question 57

Which of the following is MOST critical for the successful implementation of an IT process?

  • A: Objectives and metrics
  • B: IT process assessment
  • C: Process framework
  • D: Service delivery process model

Question 58

An enterprise has made a decision to move some business applications to the public cloud despite being very new to the cloud environment. What is MOST important for the CIO to do to help ensure the success of this initiative?

  • A: Review the vendor management framework.
  • B: Request a right-to-audit clause in the provider contract.
  • C: Require a vulnerability and threat assessment.
  • D: Ensure the cloud provider complies with international standards.

Question 59

Which of the following is the PRIMARY role of an enterprise architecture?

  • A: Improves transparency and compliance
  • B: Provides a visual perspective of information systems
  • C: Improves interoperability and scalability
  • D: Ensures continuous innovation

Question 60

When conducting a risk assessment in support of a new regulatory requirement, the IT risk committee should FIRST consider the:

  • A: cost burden to achieve compliance.
  • B: disruption to normal business operations.
  • C: readiness of IT systems to address the risk.
  • D: risk profile of the enterprise.

Question 61

An enterprise is planning to migrate its IT infrastructure to a cloud-based solution but does not have experience with this technology. Which of the following should be done FIRST to reduce the risk of IT service disruptions when using this new technology?

  • A: Evaluate the sourcing options.
  • B: Reflect the change in the enterprise architecture (EA).
  • C: Implement key performance indicators (KPIs).
  • D: Engage an experienced IT consultant to perform the migration.

Question 62

Which of the following BEST reflects mature risk management in an enterprise?

  • A: A regularly updated risk register
  • B: Responsive risk awareness culture
  • C: Ongoing risk assessment
  • D: Ongoing investment in risk mitigation

Question 63

An IT strategy committee wants to evaluate how well the IT department supports the business strategy. Which of the following is the BEST method for making this determination?

  • A: Capability maturity assessment
  • B: IT balanced scorecard reporting
  • C: IT controls assurance program
  • D: Customer survey analysis

Question 64

The board of directors of an enterprise has questioned whether the business is focused on optimizing value. The IT strategy committee's BEST action to address the board's concern is to:

  • A: initiate reporting and review of key IT performance metrics.
  • B: form a technology council to monitor the efficiency of project implementation.
  • C: conduct a portfolio review to assess the benefits realization of IT investments.
  • D: conduct a benchmark to assess IT value relative to competitors.

Question 65

From a governance perspective, which of the following is MOST important to enhance in an enterprise undergoing rapid development of a cloud technology?

  • A: Change management processes to capture organizational and project changes.
  • B: Data restructuring plan to ensure the architecture supports future changes.
  • C: IT project dashboard reporting to capture new risk, threats, and scenarios.
  • D: Configuration management processes to ensure availability goals are maintained.

Question 66

A regulatory audit of an IT department has identified discrepancies between processes described in the procedures and what is actually done by system administrators. The discrepancies were caused by recent IT application changes. Which of the following would be the BEST way to prevent the recurrence of similar findings in the future?

  • A: Include the update of documentation within the change management framework.
  • B: Assign the responsibility for periodic revisions and changes to process owners.
  • C: Require each IT employee to confirm compliance with IT procedures on an annual basis.
  • D: Establish high-level procedures to minimize process changes.

Question 67

Which of the following is the MOST important input for designing a development program to help IT employees improve their ability to respond to business needs?

  • A: Skills competency assessment
  • B: Cost-benefit analysis
  • C: Annual performance evaluations
  • D: Capability maturity model

Question 68

The accountability for a business continuity program for business-critical systems is BEST assigned to the:

  • A: director of internal audit,
  • B: enterprise risk manager.
  • C: chief information officer.
  • D: chief executive officer.

Question 69

Which of the following should occur FIRST in the IT investment process?

  • A: Analyze the risks and benefits of the investment for each IT project.
  • B: Assess each project's impact on the enterprise's investment plan.
  • C: Select IT projects that will best support the enterprise's mission.
  • D: Analyze IT investments based on past data.

Question 70

To ensure IT risk is managed in a consistent manner, it is MOST important for IT governance to establish a:

  • A: risk management reporting tool to ensure compliance.
  • B: balanced scorecard that includes IT risks.
  • C: risk management committee to identify IT-related risks.
  • D: risk management framework.

Question 71

A CIO is planning to implement an enterprise resource planning (ERP) system at the request of the business. Of the following, who is accountable for providing sponsorship for the IT-enabled change across the enterprise?

  • A: CIO
  • B: CEO
  • C: IT strategy committee
  • D: Human resource director

Question 72

Which of the following would a CIO use to present the overall view of IT performance to the board of directors?

  • A: Maturity model
  • B: Balanced scorecard
  • C: Key performance indicators (KPIs)
  • D: Key risk indicators (KRIS)

Question 73

An enterprise wants to implement an IT governance framework to ensure enterprise expectations of IT are met. Which of the following would be the MOST beneficial outcome of implementing the framework?

  • A: Optimization of IT performance
  • B: Development of IT policies
  • C: Creation of an IT balanced scorecard
  • D: Establishment of key IT risk indicators

That’s the end of your free questions

You’ve reached the preview limit for CGEIT

Consider upgrading to gain full access!

Page 3 of 15 • Questions 51-75 of 363

Free preview mode

Enjoy the free questions and consider upgrading to gain full access!