DPI · domain
Guiding Principles And GRC
Practise ITIL 4 Strategist: Direct, Plan and Improve (DPI) (DPI) Guiding Principles And GRC practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Guiding Principles And GRC questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Guiding Principles And GRC
Guiding Principles And GRC questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Guiding Principles And GRC exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Guiding Principles And GRC questions (48)
Click any question to see the full explanation, or start a practice session above.
An IT team wants to improve their risk management maturity but does not know where their current vulnerabilities lie. What should be their very first step according to ITIL 4 guiding principles?
Easy2An organization is establishing an enterprise GRC dashboard in PowerBI. The risk team wants to track 150 different Key Risk Indicators (KRIs). Executive leadership complains that the dashboard is overwhelming and useless for decision-making. Which guiding principle should be applied to redesign the dashboard?
Hard3A company's risk management department operates independently of the enterprise architecture team. As a result, new software purchased by architecture frequently fails security risk reviews. Which guiding principle should be used to rectify this disconnect?
Medium4An organization is beginning a compliance maturity assessment. The lead auditor insists on interviewing frontline service desk agents to understand how security policies are applied daily. Which guiding principle does this practice reflect?
Easy5A company is updating its disaster recovery (DR) plan. The compliance team mandates a 4-hour Recovery Time Objective (RTO) for all systems, including non-critical marketing blogs. The IT architect objects, pointing out the prohibitive cost. Which ITIL 4 principle should guide the resolution of this conflict?
Medium6An organization's internal audit department identifies that cloud resource provisioning lacks appropriate approval gates. The cloud team wants to use AWS Control Tower and Service Catalog to enforce governance without slowing down developers. Which guiding principle is best demonstrated by building guardrails into automated provisioning templates?
Medium7An enterprise risk management committee wants to overhaul its risk assessment methodology. Which THREE of the following approaches integrate ITIL 4 guiding principles into modern enterprise risk management? (Choose three.)
Hard8An IT team is designing a new compliance dashboard in ServiceNow. Before building custom widgets, they review the platform's out-of-the-box reporting templates. Which guiding principle does this represent?
Easy9A company is implementing ISO/IEC 27001 information security controls. Instead of trying to certify all 114 controls across 50 business units simultaneously, the CISO selects 10 critical controls for the core payment platform first. Which guiding principles are primarily being utilized?
Medium10An enterprise risk management framework mandates that third-party cloud providers undergo annual SOC 2 Type II audits. A strategic AI startup vendor only possesses a SOC 2 Type I report. How should the enterprise apply ITIL 4 guiding principles to evaluate this risk without blocking innovation?
Hard11An IT governance committee is designing a risk management training program for software engineers. Which THREE practices align with ITIL 4 guiding principles? (Choose three.)
Medium12Which TWO of the following behaviors best exemplify 'Collaborate and promote visibility' within an IT governance context? (Choose two.)
Easy13An organization is integrating ESG (Environmental, Social, and Governance) criteria into its IT sourcing strategy. Leadership wants to ensure that supplier selection doesn't just check boxes, but genuinely contributes to sustainability outcomes. Which combination of guiding principles should drive this GRC initiative?
Hard14When auditing a legacy application, an IT governance team discovers that no documentation exists. Instead of demanding a massive documentation project, the team applies 'Start where you are'. What should they do?
Easy15Which TWO of the following actions best demonstrate the principle 'Focus on value' in an IT governance framework? (Choose two.)
Easy16An enterprise GRC committee discovers that shadow IT (unapproved SaaS tools) is rampant because the official procurement and compliance review process takes 90 days. To fix this, the committee establishes a 'fast-track' pre-vetted catalog of SaaS tools. How does this solution align with ITIL 4 principles?
Hard17A global financial institution is restructuring its compliance framework to support agile software delivery. Which THREE of the following strategies align with ITIL 4 guiding principles and modern GRC practices? (Choose three.)
Hard18A global bank is deploying a new AI-driven credit scoring system. The model's decision-making logic is a black box, creating potential regulatory compliance issues under fair lending laws. How should the enterprise apply ITIL guiding principles to address this GRC challenge?
Hard19An IT director wants to use the 'Progress iteratively with feedback' principle when implementing a new ISO 37001 Anti-Bribery management system. What is the most appropriate first action?
Easy20An organization is evaluating its vendor risk management process using the 'Optimize and automate' guiding principle. Manual spreadsheet tracking of third-party compliance certificates has led to missed renewals. Which tool configuration best applies this principle?
Medium21An IT governance board is evaluating how to apply 'Optimize and automate' to its vendor risk assessment process. Which THREE of the following initiatives represent correct applications of this principle? (Choose three.)
Medium22An organization is launching a new DevOps pipeline and wants to ensure that all team members feel psychological safety and ownership while complying with corporate audit standards. Which guiding principle should the release manager emphasize first to balance innovation with structure?
Easy23A multinational corporation is consolidating its regional GRC tools into a single global instance of ServiceNow GRC. The project team attempts to migrate all 5,000 legacy control procedures simultaneously on a single weekend, resulting in massive data corruption and audit failures. Which guiding principle was violated?
Medium24An enterprise is deploying a Zero Trust Architecture (ZTA). Rather than restricting access based solely on corporate network perimeter, ZTA verifies every user and device continuously. How does this architectural shift embody 'Think and work holistically' in the context of GRC?
Hard25Which TWO of the following indicators suggest an organization is failing to apply 'Think and work holistically'? (Choose two.)
Easy26An IT team is attempting to map out all enterprise risks at once, causing paralysis by analysis. Which ITIL 4 guiding principle should be used to get the risk assessment project moving again?
Easy27An internal auditor discovers that IT staff are storing passwords in an unencrypted Excel sheet. Instead of issuing a harsh reprimand, the security manager runs a workshop to explain password manager tools. Which principle is best exhibited by educating rather than just punishing?
Easy28A financial institution uses Archer GRC for regulatory compliance tracking. The compliance team operates in a strict silo from the software development teams using Jira. Which guiding principle is most directly being violated by this organizational structure?
Medium29A software development organization is integrating static application security testing (SAST) into GitHub Actions. Developers complain that false positives block builds daily, leading them to disable the security checks. How should the security team apply ITIL 4 principles to correct this?
Medium30A CISO is evaluating why security compliance failures continue to occur despite extensive policies. According to ITIL 4 guiding principles and GRC best practices, which THREE underlying root causes should the CISO investigate? (Choose three.)
Hard31An IT service manager is reviewing the incident management process to ensure GDPR compliance during data breach reporting. The manager cuts out three redundant management approval steps that added no legal value. Which guiding principle is being applied?
Easy32Which TWO of the following scenarios demonstrate a failure to apply 'Progress iteratively with feedback'? (Choose two.)
Easy33An internal audit reveals that privileged access management (PAM) policies are frequently bypassed by systems administrators during critical outages. The security team wants to enforce rigid automated lockdowns. How should the 'Collaborate and promote visibility' and 'Think and work holistically' principles be combined to address this?
Hard34A compliance team is designing a new data privacy training module. Before creating new content, they review existing HR onboarding slides. Which guiding principle does this action represent?
Easy35During a high-severity incident review in Jira Service Management, the incident commander realizes that strict adherence to an outdated change management compliance policy prevented a rapid hotfix. How should the 'Think and work holistically' principle be applied to resolve this GRC conflict?
Hard36An enterprise GRC committee is reviewing its risk management strategy. Which TWO practices effectively integrate ITIL 4 guiding principles into risk governance? (Choose two.)
Medium37Which TWO of the following actions best demonstrate the ITIL 4 guiding principle 'Start where you are'? (Choose two.)
Easy38A federal agency must comply with FedRAMP high security standards while adopting cloud-native microservices. The traditional security review process takes 12 months. To apply ITIL 4 principles, the architecture board introduces Policy-as-Code using OPA (Open Policy Agent) integrated into GitLab CI pipelines. Which combination of guiding principles is best demonstrated here?
Hard39A Chief Information Security Officer (CISO) is establishing a risk appetite statement. Business unit leaders are pushing back, claiming the security policies violate 'Focus on value' by slowing down revenue-generating features. How can the CISO reconcile value creation with risk protection using ITIL 4 concepts?
Hard40An IT manager is holding a workshop to map out why security compliance approvals are taking three weeks. The manager invites representatives from legal, security, development, and operations. Which guiding principle is primarily being applied?
Easy41An enterprise risk management (ERM) framework requires annual risk assessments across 500 IT services. The process takes 6 months, rendering the output obsolete by completion. Which ITIL 4 principle-driven strategy resolves this GRC flaw?
Hard42When conducting a risk assessment for a new cloud migration project, the project manager lists all potential failure points without prioritizing them, leading to decision fatigue. Which guiding principle should be applied to prioritize the risks?
Easy43A company's internal audit department issues 200 findings per year, but IT can only remediate 20 due to resource constraints. The audit findings pile up year over year, creating massive regulatory exposure. How should IT and audit apply 'Focus on value' and 'Keep it simple and practical' to resolve this?
Medium44A multinational enterprise is updating its GRC framework in ServiceNow GRC to incorporate ITIL 4 guiding principles. The risk manager notices that compliance policies often delay agile software deployments. Which approach best applies the 'Keep it simple and practical' principle to this bottleneck?
Medium45A financial services firm is deploying robotic process automation (RPA) bots to handle customer loan applications. Compliance requires that every bot decision be fully auditable. The development team wants to deploy bots immediately without logging logic. Which governance conflict does this represent regarding ITIL principles?
Medium46An IT organization is migrating its GRC platform from an on-premises tool to ServiceNow GRC. Which THREE ITIL 4 guiding principle considerations are critical for a successful migration? (Choose three.)
Medium47A healthcare provider is configuring access controls in Epic EHR to comply with HIPAA regulations. Clinicians complain that multi-factor authentication (MFA) prompts every 15 minutes disrupt patient care. How should the governance board apply ITIL 4 principles to balance security compliance with clinical value?
Medium48When applying 'Keep it simple and practical' to enterprise compliance and risk frameworks, which THREE practices should an organization adopt? (Choose three.)
MediumOther domains
All DPI exam domains
Frequently asked questions
- What does the Guiding Principles And GRC domain cover on the DPI exam?
- Guiding Principles And GRC questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 48 Guiding Principles And GRC questions in the DPI question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Guiding Principles And GRC questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.