Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

Isaca CGEIT - Certified in the Governance of Enterprise IT Exam

Page: 1 / 14
Total 682 questions

Which of the following is the BEST indicator of effective IT governance?

A.

Regulatory authorities have given a favorable report on IT controls.

B.

Executive management is involved in important IT decisions and activities.

C.

The chief information security officer (CISO) reports to a board member.

D.

IT management is proactive in reporting IT project status to executive management.

Which of the following should be done FIRST when preparing to migrate patient records to a cloud service provider?

A.

Review the current data governance policy.

B.

Update the enterprise architecture (EA).

C.

Revise the risk management framework.

D.

Define the service level agreement (SLA).

Which of the following is MOST important to have in place to ensure a business continuity plan (BCP) can be executed?

A.

Defined roles.

B.

Replicated systems.

C.

A risk register.

D.

Budget allocation.

Which of the following should be the CIO’s GREATEST consideration when making changes to the IT strategy?

A.

Have key stakeholders been consulted?

B.

Has the impact to the enterprise architecture (EA) been assessed?

C.

Have IT risk metrics been adjusted?

D.

Has the investment portfolio been revised?

Which of the following BEST enables an enterprise to determine whether a current program for IT infrastructure migration to the cloud is continuing to provide benefits?

A.

Key performance indicators (KPls)

B.

Total cost of ownership (TCO)

C.

Key risk indicators (KRIS)

D.

Net present value (NPV)

An IT team is having difficulty meeting new demands placed on the department as a result of a major and radical shift in enterprise business strategy. Which of the following is the ClO's BEST course of action to address this situation?

A.

Utilize third parties for non-value-added processes.

B.

Align the business strategy with the IT strategy.

C.

Review the current IT strategy.

D.

Review the IT risk appetite.

Which of the following is the GREATEST driver of ethical decision making in an IT enterprise?

A.

Corporate culture

B.

Process and control environment

C.

Code of conduct

D.

Training and awareness programs

Which of the following is the PRIMARY objective of a data protection impact assessment?

A.

To identify and analyze how data privacy might be affected by business processes.

B.

To evaluate the quality and integrity of personal data stored in an enterprise.

C.

To estimate the value created by personal data as it progresses through its life cycle.

D.

To ensure key business processes and related data interfaces are documented.

Which of the following is the BEST way for a CIO to ensure that the work of IT employees is aligned with approved IT directives?

A.

Mandate technical training related to the IT objectives.

B.

Have business leaders present their departments' objectives.

C.

Include relevant IT goals in individual performance objectives.

D.

Request a progress review of IT objectives by internal audit.

Which of the following BEST supports an IT strategy committee’s objective to align employee competencies with planned initiatives?

A.

Set management goals to hire cooperative work experience students.

B.

Specify minimum training hours required for continuing professional education.

C.

Require balanced scorecard concepts training of all employees.

D.

Add achievement of competencies to employee performance goals.

A CIO engages a consulting firm to conduct a benchmark analysis of the organization’s IT governance framework against industry best practices. Several recommendations to improve the maturity of the framework are identified. Which of the following should be the CIO’s NEXT course of action?

A.

Evaluate the feasibility of the recommendations.

B.

Obtain approval from the IT steering committee to implement the recommendations.

C.

Develop a plan to integrate the recommendations.

D.

Appoint a project manager to implement the recommendations.

An enterprise’s IT director is concerned that the chair of the IT steering committee is stealing confidential company information. Which of the following is the IT director’s BEST course of action?

A.

File a report with the local law enforcement agency.

B.

Report the concern to the ethics hotline.

C.

Discuss the concern with the chair directly.

D.

Conduct an investigation to substantiate the chair’s activities.

An enterprise is planning to upgrade its current enterprise resource planning (ERP) system to remain competitive within the industry. Which of the following would be MOST helpful to facilitate a successful implementation?

A.

Documenting the current ERP processes and procedures

B.

Reviewing the ERP post-implementation report

C.

Establishing a change and transition planning process

D.

Conducting a comprehensive requirements review

Which of the following is the BEST way to minimize the potential mishandling of customer personal information in a system that is located in a country with strict privacy regulations?

A.

Revise IT policies, standards, and procedures

B.

Implement a SIEM solution

C.

Consult the legal and compliance department

D.

Establish new IT key risk indicators (KRIs)

Which of the following roles is accountable for the confidentiality, integrity, and availability of information within an enterprise?

A.

Data owner

B.

Lead legal counsel

C.

Risk manager

D.

Data custodian