Which metric is the most effective indicator of IT governance success?
Governance is successful when IT investments yield the expected business value.
Why this answer
Value realization is the ultimate test of IT governance effectiveness.
214 questions total · 3pages · All types, answers revealed
Page 1 of 3
Page 2Which metric is the most effective indicator of IT governance success?
Governance is successful when IT investments yield the expected business value.
Why this answer
Value realization is the ultimate test of IT governance effectiveness.
Which TWO of the following factors should influence the frequency of risk reporting to the board?
High risk/high change requires more frequent reporting.
Why this answer
Frequency should be driven by risk volatility and business impact.
Which factor most significantly influences the design of an IT governance system?
Strategy defines the direction that IT governance must support.
Why this answer
Enterprise strategy is the primary driver for IT governance, as the framework must support the business objectives.
A newly appointed CIO is integrating COBIT 2019 into the existing governance framework. Which action best ensures that the governance system is dynamic?
COBIT 2019 requires tailoring the governance system through design factors to remain relevant.
Why this answer
COBIT 2019 focuses on the design factor of a dynamic system, emphasizing the need for regular updates to governance components based on changes in enterprise strategy.
Which type of IT resource is most likely to become a bottleneck during a rapid increase in business demand?
Computing resources are often the first to experience constraints during sudden demand spikes.
Why this answer
Computing resources (CPU, memory, storage) often hit physical or configured limits quickly when demand spikes.
An organization adopts a new IT governance policy. Which mechanism best ensures that employees understand and follow the policy?
Awareness through communication and training is key to policy enforcement.
Why this answer
Policy adherence is best fostered through communication, training, and integration into performance expectations.
Which of the following best defines IT Governance?
This is the standard definition of governance, focusing on direction and control.
Why this answer
IT governance ensures that IT aligns with business goals, delivers value, manages risk, and optimizes resources.
Which THREE factors should be considered when tailoring a COBIT 2019 governance system?
Design factor regarding implementation approach.
Why this answer
Size, threat landscape, and adoption strategy are key design factors in COBIT 2019.
Which of the following is the best way to ensure the business is prepared for a new IT solution?
Business readiness depends on the people and processes, not just technology.
Why this answer
Change management activities, such as training and process redesign, are essential for business readiness.
Which TWO elements should be included in a business case report to the executive team?
Executives must understand the risks before approving.
Why this answer
Executives need to see the value (ROI) and the risks associated with the investment.
Which THREE factors should be considered when assessing the 'Value' of an IT investment in a portfolio?
Financial ROI is a core component of portfolio value.
Why this answer
Value is derived from strategic fit, financial return, and the risk of not proceeding.
During an IT governance board meeting, the CGEIT practitioner notices that the current risk profile deviates significantly from the approved risk appetite. What is the most appropriate next step?
Transparency and proposing corrective governance actions are core responsibilities.
Why this answer
Governance requires transparency and corrective action when thresholds are exceeded.
Which THREE factors should be evaluated when prioritizing IT investments within a portfolio for maximum benefit realization?
Alignment ensures the investment supports the organization's goals.
Why this answer
Portfolio prioritization considers strategic alignment, the financial return, and the risk profile (including deliverability) of the investments.
When evaluating IT resource governance, which indicator best measures the effectiveness of resource allocation?
This measures if resources are being allocated to the most valuable initiatives.
Why this answer
Return on IT Investment (ROITI) or realized business value relative to resource expenditure is a key indicator.
Which of the following is an example of an 'IT governance structure'?
This is a governance structure.
Why this answer
An IT steering committee is a formal body specifically created to handle governance tasks like prioritization and alignment.
A global company needs to compare IT investment performance across different business units using different currencies and operational models. Which metric is most suitable for normalization?
Normalizing TCO against output (e.g., revenue per IT dollar) provides a comparable efficiency metric across different environments.
Why this answer
Total Cost of Ownership (TCO) normalization allows for a comparison of cost-to-benefit ratios that are not skewed by regional accounting differences or currency fluctuations.
Which THREE of the following are key steps in the lifecycle of IT infrastructure resource management?
This is the initial phase of the lifecycle.
Why this answer
Planning, monitoring/optimizing, and decommissioning are the core phases of the IT infrastructure lifecycle.
Which role is primarily accountable for ensuring the 'Business Case' for a new IT investment is accurate and justifiable?
The sponsor owns the investment and is responsible for its value proposition.
Why this answer
The business sponsor, typically a senior business leader, owns the case and is accountable for its success.
A company is conducting a risk analysis. Which of the following is an example of an 'inherent risk'?
Inherent risk is the raw exposure of a threat.
Why this answer
Inherent risk is the risk level before any controls are applied.
An enterprise is transitioning to a hybrid cloud environment. Which governance mechanism is most critical to ensure compliance with data sovereignty regulations?
Classification dictates where data can reside, which is essential for sovereignty compliance.
Why this answer
Defining data classification and governance policies is the prerequisite for managing data residency in a hybrid cloud.
Which THREE of the following are common challenges when implementing IT governance?
Governance is often introduced to fix this, but the lack of it is a major implementation challenge.
Why this answer
Resistance to change, lack of leadership support, and lack of alignment are common failures.
Which activity is essential for effective IT resource governance?
Monitoring is critical to ensure resources are used as intended and aligned with goals.
Why this answer
Monitoring resource usage against planned budgets and performance targets is the core of resource governance.
Which THREE activities are required when managing the 'Benefits Lifecycle'?
Post-implementation tracking is the final phase of the lifecycle.
Why this answer
The lifecycle includes planning, execution/monitoring, and post-project review.
During a portfolio review, a project is identified as having a positive Net Present Value (NPV) but a low 'Strategic Fit' score. What is the most appropriate governance action?
A disconnect between NPV and strategic fit suggests the strategy or the business case evaluation criteria need refinement.
Why this answer
If a project has high financial value but low strategic fit, it should be scrutinized to see if it distracts from the core mission, potentially requiring a re-evaluation of the investment's place in the strategic portfolio.
What is the primary role of the Chief Information Officer (CIO) in governance?
The CIO links the governance (board) and management (IT) levels.
Why this answer
The CIO is the bridge, responsible for translating the board's governance direction into IT management execution.
Why is it important to define risk appetite before developing a risk response plan?
Risk response plans are triggered when risks exceed the appetite.
Why this answer
Appetite acts as the boundary for decision-making.
Which of the following describes the 'Benefit Dependency Network' (BDN)?
BDNs connect the dots between IT output and business strategy.
Why this answer
The BDN maps the relationships between IT deliverables, business changes, and final strategic outcomes.
Which governance mechanism is best for ensuring that IT resource allocation remains aligned with changing business priorities?
Portfolio review allows for reallocation based on updated business value and risk.
Why this answer
Regular review of the IT portfolio ensures that resources are continuously redirected to the highest-value projects.
A newly appointed CIO is establishing an IT governance framework. Which approach best ensures that IT governance is integrated into the enterprise's existing management structure?
Mapping activities to existing processes ensures seamless integration and accountability.
Why this answer
Integrating governance into existing management structures is a core tenet of COBIT to ensure IT is not siloed.
You are evaluating the maturity of your organization's risk reporting to the board. Which THREE of the following elements are essential for high-maturity reporting?
Contextualizes risk within the business strategy.
Why this answer
High-maturity reporting is strategic, contextual, and forward-looking, rather than purely historical or technical.
What is the primary objective of infrastructure resource management in a governance context?
This is the fundamental goal of IT resource governance.
Why this answer
Infrastructure management aims to balance cost, performance, and capacity to support business objectives.
An organization is failing to achieve the expected ROI on IT investments. Which governance mechanism is most likely missing?
Value realization is a core responsibility of the IT Steering Committee.
Why this answer
The IT Steering Committee is responsible for reviewing and approving business cases, ensuring projects are prioritized based on value and ROI.
Who is ultimately responsible for the governance of enterprise IT?
The board has the final accountability for governance of the enterprise.
Why this answer
The board of directors (or equivalent governing body) bears the ultimate responsibility for ensuring the enterprise is governed effectively.
Which TWO of the following are common challenges in tracking benefits?
Delayed benefits make it hard to maintain stakeholder interest and accurate tracking.
Why this answer
Benefits are often difficult to isolate from other business factors and may be delayed.
Which THREE of the following are common IT resource management challenges?
This is a fundamental and perennial challenge in IT management.
Why this answer
Budget constraints, balancing operations with innovation, and managing legacy systems are classic challenges in IT resource management.
A firm has decided to pursue a high-risk innovation strategy. How should the enterprise risk appetite statement be adjusted to support this goal?
This allows for calculated risks while putting boundaries around the duration and impact of those risks.
Why this answer
Governance bodies must define risk tolerance thresholds that allow for strategic agility while ensuring that excessive risk does not threaten core enterprise continuity.
Which THREE principles are central to COBIT 2019 governance?
Core COBIT principle.
Why this answer
Meeting stakeholder needs, holistic approach, and dynamic governance are core COBIT 2019 principles.
What is the primary purpose of a Post-Implementation Review (PIR) in the context of benefits realization?
PIRs close the loop on benefits planning and provide feedback for future investments.
Why this answer
The PIR confirms whether the benefits identified in the business case were actually achieved after the project is complete.
A company is experiencing friction between IT and business units regarding project priorities. What governance structure should be strengthened to resolve this?
The committee balances business and IT interests to establish project priorities.
Why this answer
An IT steering committee is specifically designed to facilitate communication and priority alignment between IT and business leadership.
When balancing internal versus external IT resource sourcing, which factor best dictates the decision?
Strategic alignment with core competencies is the primary determinant for sourcing decisions.
Why this answer
Core competencies define what should remain internal to maintain competitive advantage, while non-core activities are candidates for external sourcing.
When assessing the impact of a risk, what is the best perspective to take?
Governance is concerned with the impact on enterprise value.
Why this answer
Impact is defined by the loss of business value, not technical downtime.
A project team is using a 'Benefits-Based' approach. What would they do differently than a 'Project-Based' team?
Focus remains on the value, not just the scope.
Why this answer
A benefits-based approach continuously checks if the work being done is still providing value, even if the plan changes.
To optimize IT infrastructure resources, an organization adopts a software-defined infrastructure (SDI) approach. What is a key governance risk that must be addressed?
The abstraction layer in SDI can make policy enforcement more complex if not properly governed.
Why this answer
SDI shifts control to software, making configuration management and policy enforcement critical.
Which TWO activities are necessary to ensure that IT benefits are sustainably realized post-implementation?
Continuous tracking ensures that the realized benefits remain stable or grow.
Why this answer
Sustainability requires that the business processes are permanently modified and that ongoing performance is measured to prevent regression.
During a merger, the IT risk governance team identifies incompatible security standards. What is the correct approach?
Harmonization ensures consistency and effective risk management.
Why this answer
A unified standard must be established to manage risk consistently.
Which THREE of the following are key aspects of workforce planning in IT?
Retaining skilled staff is crucial for long-term capability.
Why this answer
Identifying needs, developing talent, and retaining staff are the core pillars of effective workforce planning.
The enterprise is reviewing its IT governance structure. Which THREE of the following are primary responsibilities of the Board of Directors regarding IT governance?
Ensuring IT investments support business objectives is a board duty.
Why this answer
The Board is responsible for strategic alignment, value delivery, and risk management oversight.
An organization wants to improve its IT governance maturity. What is the most important first step?
You must understand where you are before you can plan where you are going.
Why this answer
Assessing the current state (maturity) of the governance system is the essential first step before setting goals for improvement.
Which of the following best describes 'strategic alignment' in IT governance?
This directly defines strategic alignment.
Why this answer
Strategic alignment is the process of ensuring that IT objectives and activities directly support the enterprise's mission and goals.
An IT investment shows a positive ROI, but the business units are not using the new system as intended. What is the most likely cause?
Benefits realization depends on the system being used in business operations.
Why this answer
Poor adoption indicates a failure in change management or a lack of alignment between the system and business processes.
A governance review reveals that IT decision-making is too slow to support rapid market changes. What should be done?
Delegation of authority balances speed with controlled oversight.
Why this answer
The governance model should be reviewed to streamline decision-making without sacrificing oversight, often through delegation of authority.
What is the primary role of an IT Steering Committee?
This is the core function of an IT Steering Committee.
Why this answer
The steering committee aligns IT with business strategy and oversees major investments and project priorities.
A company is performing a risk assessment of a new software vendor. Which factor is most relevant for the governance of third-party risk?
Data exposure risk is the primary driver of third-party governance requirements.
Why this answer
Third-party risk management is rooted in understanding the criticality of the service provided.
Which TWO are common challenges in IT governance implementation?
People often resist change in oversight.
Why this answer
Lack of executive support and cultural resistance are the most common barriers to effective governance.
Which TWO of the following are key responsibilities of an IT steering committee?
This ensures projects deliver the intended business value.
Why this answer
The steering committee is responsible for aligning IT priorities with business needs and monitoring performance against those goals.
An IT project is identified as having a high inherent risk that exceeds the board-approved appetite. The project is critical for competitive advantage. Which approach is most appropriate?
This follows the governance process of accountability and board-level oversight for high-risk strategic decisions.
Why this answer
Governance allows for risk acceptance at the appropriate level if the business value is high.
An organization is evaluating its governance structure against the COBIT 2019 framework. Where should the authority for IT governance decisions reside?
The IT Steering Committee acts as a formal bridge between the board/executive management and IT operations for decision-making.
Why this answer
COBIT 2019 emphasizes that governance accountability rests with the board, but authority is often delegated to a designated governance committee.
What is the benefit of a standardized IT governance framework?
These are the fundamental benefits of adopting a framework like COBIT.
Why this answer
Standardization provides a common language, consistent processes, and clear accountability across the enterprise.
Which of the following is an example of an IT governance 'outcome'?
Alignment is a direct result/outcome of successful governance.
Why this answer
An outcome is the result of effective governance, such as the achievement of business objectives through IT-enabled value.
Which TWO items are considered 'Governance enablers' in COBIT?
Enabler of governance.
Why this answer
Processes and organizational structures are defined as key enablers within the COBIT framework.
An enterprise is aligning its IT risk appetite with corporate strategic objectives. Which action should the CGEIT-certified practitioner prioritize first?
Establishing risk capacity and appetite relative to strategic goals is the fundamental first step in risk optimization.
Why this answer
Aligning risk appetite requires a clear understanding of the enterprise's strategic goals and its capacity to absorb loss.
Which metric is most useful for reporting the effectiveness of IT risk management to the board?
This directly answers whether the organization is staying within appetite.
Why this answer
The board needs to see the trend of risk exposure over time.
Which practice best ensures that IT workforce planning aligns with the enterprise's long-term business strategy?
This ensures that IT capabilities are planned in lockstep with business goals.
Why this answer
Aligning IT workforce plans with business strategy ensures the right talent is available for upcoming initiatives.
Which key element should a balanced scorecard (BSC) for IT governance include?
This is the classic Kaplan/Norton BSC structure adapted for IT governance.
Why this answer
A balanced scorecard for IT should measure performance across financial, customer, internal process, and learning/growth perspectives.
Which TWO of the following are primary components of IT resource management?
Hardware, software, and cloud assets are central to IT resource management.
Why this answer
IT resource management fundamentally involves both the human (workforce) and the technical (infrastructure) assets of the organization.
Which document is primary evidence that the board of directors is fulfilling its oversight responsibility for IT governance?
Board minutes are the formal record of governance oversight decisions.
Why this answer
The IT strategy, when reviewed and approved by the board, demonstrates active oversight.
Which THREE of the following are key inputs for defining the IT risk appetite?
Appetite must serve the strategy.
Why this answer
Appetite is defined by strategic goals, resource capacity, and stakeholder expectations.
When establishing an IT governance committee, what is a key requirement for its effectiveness?
Cross-functional representation is essential for aligning IT governance with enterprise goals.
Why this answer
A committee must have representation from both business and IT to ensure that decisions are aligned with business priorities and that IT has a voice.
Which THREE components are critical for an IT governance system to be effective?
Governance operates through documented processes.
Why this answer
Processes, organizational structures, and information flows are core components of a governance system.
An organization's risk appetite has been set as 'low' for data breaches. A new project introduces a moderate risk of a breach. What is the most appropriate governance action?
Risk optimization involves applying controls to align residual risk with appetite.
Why this answer
If a project exceeds appetite, controls must be enhanced or the project must be modified.
Your organization is undergoing a major digital transformation. To ensure risk is optimized throughout the lifecycle, what is the most critical governance activity during the planning phase?
This ensures that risk is considered alongside cost and benefit before any commitment is made.
Why this answer
Embedding risk criteria into the project selection and prioritization process ensures that the organization only commits resources to projects that align with the board's risk appetite.
An organization is transitioning to a cloud-based infrastructure. Which governance mechanism is most effective for ensuring that the cloud service provider's risk management practices remain aligned with the enterprise's risk appetite?
This ensures the provider is contractually bound to maintain visibility into the risk profile.
Why this answer
Continuous monitoring and contractual requirements are key for third-party risk governance.
Which TWO activities are part of the post-implementation benefits review?
This is the primary goal of the review.
Why this answer
The review compares actuals to plans and documents lessons for future improvement.
Which TWO items are commonly included in an IT Governance Policy?
Defines what the policy applies to.
Why this answer
Policies define the scope of the framework and the roles/responsibilities of the stakeholders.
Which THREE of the following are common risk response strategies?
Valid strategy.
Why this answer
Standard risk strategies are Accept, Avoid, Transfer, and Mitigate.
Page 1 of 3
Page 2Practice CGEIT by domain
Target a specific domain to shore up weak areas.
See all domains with question counts →