Courseiva

CCNA Guiding Principles And GRC Questions

48 questions · Guiding Principles And GRC · All types, answers revealed

1
MCQeasy

An IT team wants to improve their risk management maturity but does not know where their current vulnerabilities lie. What should be their very first step according to ITIL 4 guiding principles?

A.Assess current risk practices and vulnerabilities using direct observation and existing documentation.
B.Implement an expensive AI-powered risk scoring platform.
C.Outsource all risk management to an external Big Four auditing firm.
D.Rewrite all corporate risk policies from scratch.
AnswerA

Starting where you are requires investigating the actual current state before planning improvements.

Why this answer

Not knowing where vulnerabilities lie means assessing the current state using 'Start where you are'.

2
MCQhard

An organization is establishing an enterprise GRC dashboard in PowerBI. The risk team wants to track 150 different Key Risk Indicators (KRIs). Executive leadership complains that the dashboard is overwhelming and useless for decision-making. Which guiding principle should be applied to redesign the dashboard?

A.Automate email alerts to send all 150 KRIs to executives every hour.
B.Apply 'Focus on value' and 'Keep it simple and practical' to streamline the dashboard down to the critical few KRIs that directly impact strategic business objectives.
C.Add 50 more operational metrics to ensure absolute coverage of every IT asset.
D.Acknowledge the dashboard failure and abandon risk metric reporting entirely.
AnswerB

Streamlining to critical metrics aligns with value and practicality, making data actionable for executives.

Why this answer

Too many metrics cause cognitive overload. Filtering down to the few vital metrics aligns with 'Focus on value' and 'Keep it simple and practical'.

3
MCQmedium

A company's risk management department operates independently of the enterprise architecture team. As a result, new software purchased by architecture frequently fails security risk reviews. Which guiding principle should be used to rectify this disconnect?

A.Focus on value
B.Optimize and automate
C.Keep it simple and practical
D.Collaborate and promote visibility
AnswerD

Bringing risk management and enterprise architecture together through shared visibility prevents failed reviews.

Why this answer

Disconnected departments need to work together and see each other's pipelines. 'Collaborate and promote visibility' addresses this organizational silo.

4
MCQeasy

An organization is beginning a compliance maturity assessment. The lead auditor insists on interviewing frontline service desk agents to understand how security policies are applied daily. Which guiding principle does this practice reflect?

A.Think and work holistically
B.Focus on value
C.Optimize and automate
D.Start where you are
AnswerD

Investigating actual current practices on the front line establishes an accurate baseline.

Why this answer

Interviewing frontline staff to understand actual daily practice reflects 'Start where you are'.

5
MCQmedium

A company is updating its disaster recovery (DR) plan. The compliance team mandates a 4-hour Recovery Time Objective (RTO) for all systems, including non-critical marketing blogs. The IT architect objects, pointing out the prohibitive cost. Which ITIL 4 principle should guide the resolution of this conflict?

A.Start where you are
B.Keep it simple and practical
C.Optimize and automate
D.Focus on value
AnswerD

Evaluating whether a 4-hour RTO for a marketing blog delivers ROI ensures investments align with true business value.

Why this answer

Applying tiered DR based on business criticality embodies 'Focus on value' and 'Think and work holistically'.

6
MCQmedium

An organization's internal audit department identifies that cloud resource provisioning lacks appropriate approval gates. The cloud team wants to use AWS Control Tower and Service Catalog to enforce governance without slowing down developers. Which guiding principle is best demonstrated by building guardrails into automated provisioning templates?

A.Optimize and automate
B.Start where you are
C.Collaborate and promote visibility
D.Focus on value
AnswerA

Using AWS Control Tower and Service Catalog automates compliance guardrails directly into the provisioning workflow.

Why this answer

Embedding governance into automated provisioning templates aligns with 'Optimize and automate' and 'Keep it simple and practical'.

7
Multi-Selecthard

An enterprise risk management committee wants to overhaul its risk assessment methodology. Which THREE of the following approaches integrate ITIL 4 guiding principles into modern enterprise risk management? (Choose three.)

Select 3 answers
A.Leveraging API-driven telemetry from cloud security posture management (CSPM) tools to automate risk scoring ('Optimize and automate').
B.Integrating operational, financial, cybersecurity, and regulatory risks into a holistic, enterprise-wide risk model ('Think and work holistically').
C.Requiring all risk assessments to be performed manually on physical paper forms to prevent digital tampering.
D.Collaborating closely with product owners, developers, and compliance officers to co-create risk mitigation plans ('Collaborate and promote visibility').
E.Operating risk management entirely independently of business strategy to maintain uncompromised objectivity.
AnswersA, B, D

Automating risk scoring via CSPM APIs applies optimization and automation.

Why this answer

Options A, B, and E represent holistic integration, automation, and value-driven risk management.

8
MCQeasy

An IT team is designing a new compliance dashboard in ServiceNow. Before building custom widgets, they review the platform's out-of-the-box reporting templates. Which guiding principle does this represent?

A.Focus on value
B.Start where you are
C.Think and work holistically
D.Optimize and automate
AnswerB

Checking existing out-of-the-box templates before creating custom widgets investigates what is already available in the current state.

Why this answer

Reviewing out-of-the-box features before building custom solutions represents 'Start where you are' and 'Keep it simple and practical'.

9
MCQmedium

A company is implementing ISO/IEC 27001 information security controls. Instead of trying to certify all 114 controls across 50 business units simultaneously, the CISO selects 10 critical controls for the core payment platform first. Which guiding principles are primarily being utilized?

A.Start where you are AND Collaborate and promote visibility
B.Progress iteratively with feedback AND Focus on value
C.Optimize and automate AND Keep it simple and practical
D.Think and work holistically AND Start where you are
AnswerB

Focusing on the payment platform delivers critical value first, and tackling 10 controls at a time is iterative.

Why this answer

Selecting a subset of controls for a core platform is 'Progress iteratively with feedback' combined with 'Focus on value' (starting with payment platform value).

10
MCQhard

An enterprise risk management framework mandates that third-party cloud providers undergo annual SOC 2 Type II audits. A strategic AI startup vendor only possesses a SOC 2 Type I report. How should the enterprise apply ITIL 4 guiding principles to evaluate this risk without blocking innovation?

A.Rewrite the startup's security architecture yourself to achieve SOC 2 Type II compliance.
B.Apply risk-based evaluation ('Focus on value') and establish an iterative vendor development plan ('Progress iteratively with feedback') accepting Type I temporarily with a binding contract for Type II within 6 months.
C.Waive all SOC 2 audit requirements permanently for AI vendors.
D.Instantly terminate negotiations with the AI startup to maintain strict compliance adherence.
AnswerB

This balances risk governance with innovation and value creation through iterative milestones.

Why this answer

A rigid binary rejection (Type I vs Type II) ignores value and adaptability. Applying 'Progress iteratively with feedback' and 'Focus on value' allows the enterprise to accept a Type I temporarily while requiring an accelerated path to Type II.

11
Multi-Selectmedium

An IT governance committee is designing a risk management training program for software engineers. Which THREE practices align with ITIL 4 guiding principles? (Choose three.)

Select 3 answers
A.Forcing engineers to memorize a 500-page regulatory compliance statute word-for-word before writing any code.
B.Focusing the training on how risk management enables secure, continuous software delivery ('Focus on value').
C.Making the training mandatory only for executives while completely excluding engineers from security awareness.
D.Designing short, practical, scenario-based training modules embedded directly into the developer onboarding workflow ('Keep it simple and practical').
E.Co-creating the training content with both security experts and software engineers ('Collaborate and promote visibility').
AnswersB, D, E

Connecting training to secure delivery highlights business value.

Why this answer

Options A, C, and D reflect collaboration, practical design, and value-driven education.

12
Multi-Selecteasy

Which TWO of the following behaviors best exemplify 'Collaborate and promote visibility' within an IT governance context? (Choose two.)

Select 2 answers
A.Restricting access to risk registers to senior executive leadership only.
B.Mandating that all communication between departments must occur via formal, multi-week written ticket queues.
C.Displaying real-time security incident and compliance status dashboards on screens visible to all IT and business teams.
D.Writing compliance policies in secret within the legal department and releasing them without notice.
E.Involving development, operations, security, and legal teams in joint risk identification workshops.
AnswersC, E

Displaying real-time dashboards actively promotes visibility across teams.

Why this answer

Options B and D directly promote transparency and cross-functional collaboration.

13
MCQhard

An organization is integrating ESG (Environmental, Social, and Governance) criteria into its IT sourcing strategy. Leadership wants to ensure that supplier selection doesn't just check boxes, but genuinely contributes to sustainability outcomes. Which combination of guiding principles should drive this GRC initiative?

A.Start where you are AND Progress iteratively with feedback
B.Focus on value AND Think and work holistically
C.Keep it simple and practical AND Optimize and automate
D.Collaborate and promote visibility AND Keep it simple and practical
AnswerB

Focus on value ensures the ESG criteria matter to stakeholders, and holistic thinking ensures supply chain impacts are viewed end-to-end.

Why this answer

Focus on value ensures the ESG criteria align with true stakeholder outcomes, while Think and work holistically ensures supply chain and environmental impacts are considered end-to-end.

14
MCQeasy

When auditing a legacy application, an IT governance team discovers that no documentation exists. Instead of demanding a massive documentation project, the team applies 'Start where you are'. What should they do?

A.Scrap the application immediately and rewrite it from scratch.
B.Inspect the running application code and configuration directly to establish an accurate baseline of its current state.
C.Assume the application is fully compliant based on its age and sign off on the audit.
D.Hire an external consultant to write a 200-page historical report.
AnswerB

Inspecting the actual current state rather than relying on guesswork embodies 'Start where you are'.

Why this answer

'Start where you are' means investigating the current state directly through observation and testing rather than assuming or starting from scratch with unverified data.

15
Multi-Selecteasy

Which TWO of the following actions best demonstrate the principle 'Focus on value' in an IT governance framework? (Choose two.)

Select 2 answers
A.Eliminating all risk management activities to maximize short-term financial returns at any cost.
B.Measuring the success of a GRC program by the reduction of actual business risk and improved stakeholder trust.
C.Spending 90% of the IT budget on administrative paperwork rather than system security.
D.Prioritizing security investments that protect critical customer data and maintain core revenue-generating value streams.
E.Implementing compliance controls solely because an auditor asked for them, regardless of whether they protect business assets.
AnswersB, D

Measuring risk reduction and stakeholder trust ties GRC directly to value outcomes.

Why this answer

Options B and D ensure that governance investments directly protect and enhance stakeholder value.

16
MCQhard

An enterprise GRC committee discovers that shadow IT (unapproved SaaS tools) is rampant because the official procurement and compliance review process takes 90 days. To fix this, the committee establishes a 'fast-track' pre-vetted catalog of SaaS tools. How does this solution align with ITIL 4 principles?

A.It applies 'Optimize and automate' by deploying spyware on employee laptops to detect unapproved software.
B.It applies 'Start where you are' by punishing employees who used shadow IT in the past.
C.It eliminates all governance to allow employees to buy whatever software they want.
D.It applies 'Keep it simple and practical' by removing bureaucratic friction while maintaining compliance guardrails through pre-vetting.
AnswerD

Pre-vetted catalogs simplify the user experience and reduce cycle time while preserving governance.

Why this answer

The 90-day review was impractical. Creating a pre-vetted catalog applies 'Keep it simple and practical' and addresses user needs ('Focus on value') while maintaining governance.

17
Multi-Selecthard

A global financial institution is restructuring its compliance framework to support agile software delivery. Which THREE of the following strategies align with ITIL 4 guiding principles and modern GRC practices? (Choose three.)

Select 3 answers
A.Requiring a physical paper sign-off from the board of directors for every single code commit.
B.Integrating risk and compliance professionals directly into agile scrum teams as active participants.
C.Designing lightweight, risk-based compliance gates that scale according to the business criticality of the application.
D.Eliminating all regulatory oversight and delegating compliance sign-offs entirely to junior developers.
E.Replacing annual monolithic compliance audits with continuous, automated compliance monitoring.
AnswersB, C, E

Embedding compliance staff in scrum teams directly applies 'Collaborate and promote visibility'.

Why this answer

Options A, C, and D embody practical, value-focused, and automated GRC strategies in agile environments.

18
MCQhard

A global bank is deploying a new AI-driven credit scoring system. The model's decision-making logic is a black box, creating potential regulatory compliance issues under fair lending laws. How should the enterprise apply ITIL guiding principles to address this GRC challenge?

A.Integrate Explainable AI (XAI) techniques, legal compliance reviews, and cross-functional validation into the model deployment lifecycle.
B.Deploy the black-box model immediately and address regulatory complaints only if auditors notice.
C.Outsource the credit scoring process entirely to an unregulated fintech startup.
D.Abandon all machine learning initiatives and return exclusively to manual paper-based scoring.
AnswerA

This ensures transparency (visibility), legal compliance, and cross-functional collaboration across the value stream.

Why this answer

Explainable AI requires visibility, stakeholder collaboration, and holistic evaluation of regulatory impact. 'Collaborate and promote visibility' combined with risk governance is critical.

19
MCQeasy

An IT director wants to use the 'Progress iteratively with feedback' principle when implementing a new ISO 37001 Anti-Bribery management system. What is the most appropriate first action?

A.Roll out the anti-bribery policy to all global offices simultaneously on day one.
B.Wait for external auditors to mandate specific policy sections before making any changes.
C.Draft a 500-page governance handbook before engaging any stakeholders.
D.Implement the policy in a single department first, gather feedback, and refine before expanding.
AnswerD

Piloting in a single department embodies iterative progress and early feedback collection.

Why this answer

Progressing iteratively involves breaking large initiatives down into manageable pieces and gathering feedback early.

20
MCQmedium

An organization is evaluating its vendor risk management process using the 'Optimize and automate' guiding principle. Manual spreadsheet tracking of third-party compliance certificates has led to missed renewals. Which tool configuration best applies this principle?

A.Switch from Excel spreadsheets to a shared Microsoft Word document.
B.Hire two additional compliance analysts to manually check spreadsheets daily.
C.Implement an automated vendor risk portal with automated alerting for certificate expirations and integrated scoring.
D.Eliminate vendor risk reviews to speed up procurement.
AnswerC

This optimizes the workflow and automates repetitive, error-prone tasks.

Why this answer

Automating vendor risk assessments using a dedicated GRC platform like RSA Archer or ServiceNow Vendor Risk Management eliminates manual tracking errors.

21
Multi-Selectmedium

An IT governance board is evaluating how to apply 'Optimize and automate' to its vendor risk assessment process. Which THREE of the following initiatives represent correct applications of this principle? (Choose three.)

Select 3 answers
A.Configuring automated email reminders and escalation workflows for overdue vendor security certificates.
B.Using API integrations between Jira and ServiceNow to automatically sync compliance remediation tasks.
C.Implementing automated vendor risk scoring based on continuous threat intelligence feeds.
D.Firing all risk analysts and letting vendors grade their own security compliance without verification.
E.Replacing all computers with manual typewriters to eliminate software vulnerabilities.
AnswersA, B, C

Automated reminders and escalations streamline repetitive tracking tasks.

Why this answer

Options A, C, and E represent automation and optimization of vendor risk workflows.

22
MCQeasy

An organization is launching a new DevOps pipeline and wants to ensure that all team members feel psychological safety and ownership while complying with corporate audit standards. Which guiding principle should the release manager emphasize first to balance innovation with structure?

A.Collaborate and promote visibility
B.Think and work holistically
C.Optimize and automate
D.Focus on value
AnswerA

Collaboration breaks down silos between developers, operations, and compliance auditors, fostering transparency and psychological safety.

Why this answer

Start where you are helps teams evaluate their current state honestly. However, 'Progress iteratively with feedback' combined with 'Collaborate and promote visibility' establishes the immediate safe space needed for DevOps adoption while respecting compliance. Wait, the best fit for balancing innovation and structure while starting clean is 'Focus on value' aligned with 'Keep it simple and practical'.

Actually, 'Collaborate and promote visibility' breaks down silos between development and audit teams.

23
MCQmedium

A multinational corporation is consolidating its regional GRC tools into a single global instance of ServiceNow GRC. The project team attempts to migrate all 5,000 legacy control procedures simultaneously on a single weekend, resulting in massive data corruption and audit failures. Which guiding principle was violated?

A.Focus on value
B.Keep it simple and practical
C.Progress iteratively with feedback
D.Collaborate and promote visibility
AnswerC

Failing to phase the migration and test in smaller batches violates iterative progression.

Why this answer

Attempting a massive simultaneous migration of 5,000 controls without staging violates 'Progress iteratively with feedback'.

24
MCQhard

An enterprise is deploying a Zero Trust Architecture (ZTA). Rather than restricting access based solely on corporate network perimeter, ZTA verifies every user and device continuously. How does this architectural shift embody 'Think and work holistically' in the context of GRC?

A.It delegates all security perimeter decisions entirely to end users.
B.It assumes internal network traffic is inherently trustworthy and secure.
C.It focuses exclusively on physical data center security.
D.It integrates identity, device telemetry, network context, and data classification into an end-to-end continuous risk evaluation model.
AnswerD

Zero Trust evaluates all variables across the entire ecosystem, embodying holistic risk management.

Why this answer

Zero Trust looks at identity, device posture, location, and data sensitivity across the entire ecosystem rather than trusting a single perimeter, reflecting holistic thinking and comprehensive risk management.

25
Multi-Selecteasy

Which TWO of the following indicators suggest an organization is failing to apply 'Think and work holistically'? (Choose two.)

Select 2 answers
A.Incident management post-mortems involve all stakeholder groups to determine root causes.
B.Cloud migration strategies take into account cost, security, operational readiness, and business value simultaneously.
C.The security team creates impenetrable firewalls without consulting the usability needs of customer-facing application teams.
D.Compliance audits consistently surprise IT teams because compliance officers never review operational workflows before issuing findings.
E.The organization maintains regular communication channels between legal, HR, and IT departments.
AnswersC, D

Creating security policies in isolation without considering user impact violates holistic thinking.

Why this answer

Options A and C indicate siloed thinking and lack of holistic visibility across the organization.

26
MCQeasy

An IT team is attempting to map out all enterprise risks at once, causing paralysis by analysis. Which ITIL 4 guiding principle should be used to get the risk assessment project moving again?

A.Keep it simple and practical
B.Collaborate and promote visibility
C.Optimize and automate
D.Think and work holistically
AnswerA

Simplifying the approach and focusing on the most critical risks breaks analysis paralysis.

Why this answer

When analysis paralysis occurs, 'Keep it simple and practical' or 'Progress iteratively with feedback' helps break tasks down.

27
MCQeasy

An internal auditor discovers that IT staff are storing passwords in an unencrypted Excel sheet. Instead of issuing a harsh reprimand, the security manager runs a workshop to explain password manager tools. Which principle is best exhibited by educating rather than just punishing?

A.Start where you are
B.Optimize and automate
C.Collaborate and promote visibility
D.Focus on value
AnswerC

Running an educational workshop instead of issuing punitive reprimands fosters collaboration and transparent understanding of security risks.

Why this answer

Educating and working together rather than operating in a punitive vacuum reflects 'Collaborate and promote visibility' and 'Keep it simple and practical'.

28
MCQmedium

A financial institution uses Archer GRC for regulatory compliance tracking. The compliance team operates in a strict silo from the software development teams using Jira. Which guiding principle is most directly being violated by this organizational structure?

A.Start where you are
B.Collaborate and promote visibility
C.Focus on value
D.Keep it simple and practical
AnswerB

Operating in strict silos directly violates the principle of collaboration and visibility.

Why this answer

Silos prevent holistic thinking and collaboration. 'Collaborate and promote visibility' is designed to break down functional silos.

29
MCQmedium

A software development organization is integrating static application security testing (SAST) into GitHub Actions. Developers complain that false positives block builds daily, leading them to disable the security checks. How should the security team apply ITIL 4 principles to correct this?

A.Mandate immediate termination for developers who disable security checks.
B.Disable SAST checks permanently to keep builds fast.
C.Move SAST checks to a manual review that occurs once a year.
D.Iteratively tune SAST rule sets in collaboration with developers to minimize false positives while maintaining vulnerability detection.
AnswerD

Collaborative iterative tuning resolves the false positive friction while keeping security effective.

Why this answer

False positives causing bypasses mean the rules are impractical or poorly tuned. Tuning rules iteratively with developer feedback applies 'Progress iteratively with feedback' and 'Keep it simple and practical'.

30
Multi-Selecthard

A CISO is evaluating why security compliance failures continue to occur despite extensive policies. According to ITIL 4 guiding principles and GRC best practices, which THREE underlying root causes should the CISO investigate? (Choose three.)

Select 3 answers
A.The organization may have automated too many security controls, leaving zero room for human error.
B.Security and compliance teams operate in strict silos, failing to collaborate with business operations ('Collaborate and promote visibility').
C.Policies may be overly bureaucratic and impractical, causing employees to create workarounds and shadow IT ('Keep it simple and practical').
D.Risk management policies may be disconnected from customer and business value streams, making them appear as arbitrary roadblocks ('Focus on value').
E.The CISO may have started their assessment by looking at the current state too thoroughly.
AnswersB, C, D

Siloed security teams create rules disconnected from operational realities.

Why this answer

Options A, C, and E address common systemic root causes: silos, impractical processes, and lack of value alignment.

31
MCQeasy

An IT service manager is reviewing the incident management process to ensure GDPR compliance during data breach reporting. The manager cuts out three redundant management approval steps that added no legal value. Which guiding principle is being applied?

A.Optimize and automate
B.Keep it simple and practical
C.Start where you are
D.Think and work holistically
AnswerB

Removing redundant approval steps simplifies the workflow and eliminates unnecessary bureaucracy.

Why this answer

Removing redundant steps that add no value embodies 'Keep it simple and practical' and 'Focus on value'.

32
Multi-Selecteasy

Which TWO of the following scenarios demonstrate a failure to apply 'Progress iteratively with feedback'? (Choose two.)

Select 2 answers
A.A project manager breaks down a large ISO certification project into monthly milestones with stakeholder reviews.
B.A bank attempts to migrate all 100 legacy core banking systems to a new cloud GRC platform in a single weekend.
C.A development team releases minor compliance updates to production every week and adjusts rules based on user feedback.
D.An enterprise spends 24 months writing a massive 800-page cybersecurity policy before testing any controls in practice.
E.An IT director conducts regular monthly retrospectives with the compliance team to refine approval workflows.
AnswersB, D

A big-bang migration of 100 core systems in a weekend ignores iterative staging and risk management.

Why this answer

Options A and C represent monolithic 'big bang' approaches that ignore iterative feedback.

33
MCQhard

An internal audit reveals that privileged access management (PAM) policies are frequently bypassed by systems administrators during critical outages. The security team wants to enforce rigid automated lockdowns. How should the 'Collaborate and promote visibility' and 'Think and work holistically' principles be combined to address this?

A.Engage system administrators and auditors together to design transparent, auditable 'break-glass' emergency access workflows.
B.Outsource all outage troubleshooting to external vendors who are subject to PAM controls.
C.Suspend all PAM controls permanently so administrators can never be blocked during an outage.
D.Implement immediate automated termination for any admin who bypasses PAM, regardless of outage severity.
AnswerA

This combines collaboration (admins + auditors) and holistic thinking (balancing security with outage recovery needs).

Why this answer

Rigid lockdowns cause bypasses. Holistic thinking and collaboration require understanding *why* admins bypass controls during outages and co-creating break-glass procedures that maintain visibility without causing outages.

34
MCQeasy

A compliance team is designing a new data privacy training module. Before creating new content, they review existing HR onboarding slides. Which guiding principle does this action represent?

A.Start where you are
B.Focus on value
C.Optimize and automate
D.Think and work holistically
AnswerA

Reviewing existing assets before creating new ones prevents redundant work.

Why this answer

Reviewing existing material before building something new is the essence of 'Start where you are'.

35
MCQhard

During a high-severity incident review in Jira Service Management, the incident commander realizes that strict adherence to an outdated change management compliance policy prevented a rapid hotfix. How should the 'Think and work holistically' principle be applied to resolve this GRC conflict?

A.Bypass the change advisory board (CAB) entirely for all future incidents without updating the formal risk policy.
B.Escalate the compliance officer's authority to veto any emergency changes to protect system stability.
C.Redesign the end-to-end value stream by integrating risk evaluation criteria directly into automated emergency change models.
D.Outsource incident response to a third party to avoid internal policy conflicts.
AnswerC

This addresses the whole system, aligning speed, incident management, and compliance governance.

Why this answer

Holistic thinking requires looking at the end-to-end value stream rather than isolated department silos (IT vs Compliance). Modifying the policy to include expedited emergency change paths links speed with governance.

36
Multi-Selectmedium

An enterprise GRC committee is reviewing its risk management strategy. Which TWO practices effectively integrate ITIL 4 guiding principles into risk governance? (Choose two.)

Select 2 answers
A.Treating risk management as an isolated, bureaucratic legal function completely separate from IT operations.
B.Hiding audit findings from development teams to prevent panic and maintain morale.
C.Mandating a 12-month manual approval process for all minor software patches to ensure zero risk.
D.Aligning risk appetites directly with the organization's key value streams and customer outcomes.
E.Embedding automated compliance checks and risk assessments directly into CI/CD deployment pipelines.
AnswersD, E

Aligning risk with value streams connects governance directly to business value ('Focus on value').

Why this answer

Options B and E represent integrating risk governance with practical, value-driven, and holistic ITIL principles.

37
Multi-Selecteasy

Which TWO of the following actions best demonstrate the ITIL 4 guiding principle 'Start where you are'? (Choose two.)

Select 2 answers
A.Mapping out the complete end-to-end customer journey across multiple departments.
B.Conducting a baseline audit of existing legacy software before planning migration activities.
C.Establishing weekly cross-functional standup meetings between security and development teams.
D.Automating software deployment pipelines using GitHub Actions.
E.Reviewing existing out-of-the-box compliance templates in ServiceNow before building custom forms.
AnswersB, E

Auditing existing legacy software establishes an accurate current baseline before planning.

Why this answer

'Start where you are' involves investigating the current state directly and reusing existing working practices. Options A and D directly reflect this.

38
MCQhard

A federal agency must comply with FedRAMP high security standards while adopting cloud-native microservices. The traditional security review process takes 12 months. To apply ITIL 4 principles, the architecture board introduces Policy-as-Code using OPA (Open Policy Agent) integrated into GitLab CI pipelines. Which combination of guiding principles is best demonstrated here?

A.Progress iteratively with feedback AND Start where you are
B.Collaborate and promote visibility AND Focus on value
C.Optimize and automate AND Keep it simple and practical
D.Start where you are AND Think and work holistically
AnswerC

Policy-as-Code automates compliance checks (optimize and automate) and streamlines the review process (keep it simple and practical).

Why this answer

Writing compliance rules as code and automating them in the pipeline embodies 'Optimize and automate' while keeping the review practical and fast ('Keep it simple and practical').

39
MCQhard

A Chief Information Security Officer (CISO) is establishing a risk appetite statement. Business unit leaders are pushing back, claiming the security policies violate 'Focus on value' by slowing down revenue-generating features. How can the CISO reconcile value creation with risk protection using ITIL 4 concepts?

A.Delegate risk appetite definitions entirely to software developers.
B.Transfer all risk to cyber insurance carriers and remove internal security controls.
C.Align risk thresholds directly with the organization's specific value streams, treating risk management as an enabler of secure value co-creation.
D.Enforce strict compliance controls uniformly regardless of business impact to guarantee zero security breaches.
AnswerC

This connects risk appetite directly to value creation, satisfying both business speed and governance.

Why this answer

Value and risk are inextricably linked. Protection enables sustainable value creation. The CISO must frame risk management as an enabler of value rather than a blocker.

40
MCQeasy

An IT manager is holding a workshop to map out why security compliance approvals are taking three weeks. The manager invites representatives from legal, security, development, and operations. Which guiding principle is primarily being applied?

A.Optimize and automate
B.Keep it simple and practical
C.Focus on value
D.Collaborate and promote visibility
AnswerD

Involving cross-functional stakeholders in mapping a workflow fosters collaboration and transparency.

Why this answer

Inviting multiple stakeholder groups to a workshop to map a process directly applies 'Collaborate and promote visibility'.

41
MCQhard

An enterprise risk management (ERM) framework requires annual risk assessments across 500 IT services. The process takes 6 months, rendering the output obsolete by completion. Which ITIL 4 principle-driven strategy resolves this GRC flaw?

A.Conduct risk assessments only when a severe regulatory fine is issued.
B.Hire 10 more risk analysts to complete the annual spreadsheets in 3 weeks.
C.Replace annual monolithic risk reviews with continuous, automated risk monitoring integrated into CI/CD pipelines.
D.Abolish the ERM framework and rely entirely on intuition during major incidents.
AnswerC

Continuous automated monitoring embodies optimization and ensures risk data remains current.

Why this answer

A 6-month monolithic risk cycle is inefficient. Shifting to continuous, iterative risk assessments aligns with 'Progress iteratively with feedback' and 'Optimize and automate'.

42
MCQeasy

When conducting a risk assessment for a new cloud migration project, the project manager lists all potential failure points without prioritizing them, leading to decision fatigue. Which guiding principle should be applied to prioritize the risks?

A.Focus on value
B.Optimize and automate
C.Start where you are
D.Collaborate and promote visibility
AnswerA

Focusing on value helps identify which risks threaten critical business outcomes the most, allowing for effective prioritization.

Why this answer

Prioritizing what matters most aligns with 'Focus on value' and 'Keep it simple and practical'.

43
MCQmedium

A company's internal audit department issues 200 findings per year, but IT can only remediate 20 due to resource constraints. The audit findings pile up year over year, creating massive regulatory exposure. How should IT and audit apply 'Focus on value' and 'Keep it simple and practical' to resolve this?

A.Ignore all future audit reports and operate without internal controls.
B.Jointly prioritize findings based on actual business risk and critical value stream impact, tackling remediation in manageable batches.
C.Hire 50 temporary auditors to write more findings.
D.Outsource audit remediation to an unvetted offshore contractor.
AnswerB

Focusing on high-value, high-risk items makes remediation practical and impactful.

Why this answer

Trying to fix 200 findings fails. Collaborating to prioritize the top risks that threaten critical business value resolves the backlog.

44
MCQmedium

A multinational enterprise is updating its GRC framework in ServiceNow GRC to incorporate ITIL 4 guiding principles. The risk manager notices that compliance policies often delay agile software deployments. Which approach best applies the 'Keep it simple and practical' principle to this bottleneck?

A.Delegate all risk management decisions entirely to the software development leads.
B.Conduct a 3-month comprehensive audit of all historical agile deployments before releasing new code.
C.Design lightweight, automated compliance checks embedded directly within the CI/CD pipeline.
D.Remove all compliance gates for agile teams to maximize deployment speed.
AnswerC

This streamlines the process, removing bureaucracy while maintaining necessary compliance controls.

Why this answer

'Keep it simple and practical' dictates that unnecessary bureaucracy should be stripped away. Designing minimal viable compliance controls integrated directly into the Jira/ServiceNow workflow achieves this.

45
MCQmedium

A financial services firm is deploying robotic process automation (RPA) bots to handle customer loan applications. Compliance requires that every bot decision be fully auditable. The development team wants to deploy bots immediately without logging logic. Which governance conflict does this represent regarding ITIL principles?

A.A conflict between 'Optimize and automate' and governance requirements for transparency and auditability.
B.A conflict between 'Think and work holistically' and HR hiring policies.
C.A conflict between 'Keep it simple and practical' and physical security.
D.A conflict between 'Focus on value' and 'Start where you are'.
AnswerA

Automation speed (Optimize and automate) directly conflicts with audit transparency requirements unless logging is built into the bots.

Why this answer

Deploying bots without logging ignores risk governance and transparency ('Collaborate and promote visibility').

46
Multi-Selectmedium

An IT organization is migrating its GRC platform from an on-premises tool to ServiceNow GRC. Which THREE ITIL 4 guiding principle considerations are critical for a successful migration? (Choose three.)

Select 3 answers
A.Migrating all 10,000 custom scripts and legacy workflows in a single high-risk weekend deployment.
B.Taking the opportunity to clean up and simplify outdated, bureaucratic control procedures during the migration ('Keep it simple and practical').
C.Phasing the migration module by module (e.g., Policy compliance first, then Risk, then Vendor Risk) ('Progress iteratively with feedback').
D.Assessing existing controls and data structures in the legacy tool before planning the migration ('Start where you are').
E.Ensuring that only the lead architect knows the migration plan to prevent unnecessary discussion.
AnswersB, C, D

Cleaning up outdated procedures during migration aligns with keeping things simple and practical.

Why this answer

Options A, C, and D cover baseline assessment, iterative migration, and workflow simplification.

47
MCQmedium

A healthcare provider is configuring access controls in Epic EHR to comply with HIPAA regulations. Clinicians complain that multi-factor authentication (MFA) prompts every 15 minutes disrupt patient care. How should the governance board apply ITIL 4 principles to balance security compliance with clinical value?

A.Remove MFA entirely for all clinical staff to maximize speed of care.
B.Transfer patient care tasks to administrative staff to handle logins.
C.Apply 'Keep it simple and practical' and 'Focus on value' to adjust session timeout rules and implement context-aware authentication (e.g., badge-tap proximity access).
D.Increase MFA frequency to every 5 minutes to ensure maximum compliance rigor.
AnswerC

This maintains security compliance while removing friction for clinicians, aligning with value and practicality.

Why this answer

Balancing security with clinical workflow requires focusing on value and keeping things practical/usable, ensuring compliance doesn't destroy clinical efficiency.

48
Multi-Selectmedium

When applying 'Keep it simple and practical' to enterprise compliance and risk frameworks, which THREE practices should an organization adopt? (Choose three.)

Select 3 answers
A.Eliminating redundant approval steps that do not add measurable risk mitigation or business value.
B.Requiring manual spreadsheet logging for every single low-risk server ping.
C.Focusing on the absolute vital few controls that manage the greatest threats rather than trying to control everything equally.
D.Designing clear, straightforward policies that frontline staff can easily understand and execute.
E.Drafting 1,000-page governance manuals for every minor IT service desk procedure.
AnswersA, C, D

Removing redundant approvals simplifies workflows and removes waste.

Why this answer

Options A, B, and E represent streamlining, removing waste, and focusing on essential practices.

Ready to test yourself?

Try a timed practice session using only Guiding Principles And GRC questions.