Courseiva

ISACA Certified in the Governance of Enterprise IT (CGEIT) (CGEIT) (CGEIT) — Questions 175

214 questions total · 3pages · All types, answers revealed

Page 1 of 3

Page 2
1
MCQhard

Which metric is the most effective indicator of IT governance success?

A.Degree of alignment between IT investments and business value realized
B.Total cost of IT hardware and software maintenance
C.Number of IT projects completed on time
D.Number of IT security patches applied per month
AnswerA

Governance is successful when IT investments yield the expected business value.

Why this answer

Value realization is the ultimate test of IT governance effectiveness.

2
Multi-Selecthard

Which TWO of the following factors should influence the frequency of risk reporting to the board?

Select 2 answers
A.The size of the IT office building.
B.The current risk posture and volatility of the environment.
C.The number of years the board members have served.
D.The color of the risk report cover page.
E.The significance of the risks to business objectives.
AnswersB, E

High risk/high change requires more frequent reporting.

Why this answer

Frequency should be driven by risk volatility and business impact.

3
MCQeasy

Which factor most significantly influences the design of an IT governance system?

A.The specific software vendors used.
B.The current IT hardware lifecycle.
C.The organization's strategy and business goals.
D.The number of employees in the IT department.
AnswerC

Strategy defines the direction that IT governance must support.

Why this answer

Enterprise strategy is the primary driver for IT governance, as the framework must support the business objectives.

4
MCQmedium

A newly appointed CIO is integrating COBIT 2019 into the existing governance framework. Which action best ensures that the governance system is dynamic?

A.Focusing solely on the 'Ensure Governance Framework Setting and Maintenance' objective.
B.Implementing all 40 governance and management objectives immediately.
C.Adopting the framework exactly as published in the COBIT core publication.
D.Customizing the governance system based on the enterprise's unique design factors.
AnswerD

COBIT 2019 requires tailoring the governance system through design factors to remain relevant.

Why this answer

COBIT 2019 focuses on the design factor of a dynamic system, emphasizing the need for regular updates to governance components based on changes in enterprise strategy.

5
MCQeasy

Which type of IT resource is most likely to become a bottleneck during a rapid increase in business demand?

A.Policies and procedures
B.Organizational culture
C.Computing infrastructure
D.Strategic documentation
AnswerC

Computing resources are often the first to experience constraints during sudden demand spikes.

Why this answer

Computing resources (CPU, memory, storage) often hit physical or configured limits quickly when demand spikes.

6
MCQmedium

An organization adopts a new IT governance policy. Which mechanism best ensures that employees understand and follow the policy?

A.Including the policy in the organization's long-term strategic plan
B.Threatening immediate termination for any policy deviation
C.Establishing a formal communication and training plan regarding the policy
D.Encrypting the policy document on the corporate intranet
AnswerC

Awareness through communication and training is key to policy enforcement.

Why this answer

Policy adherence is best fostered through communication, training, and integration into performance expectations.

7
MCQeasy

Which of the following best defines IT Governance?

A.Purchasing new software for the company.
B.Managing daily IT support tickets.
C.Updating antivirus software across the network.
D.A structure of relationships and processes to direct and control the enterprise.
AnswerD

This is the standard definition of governance, focusing on direction and control.

Why this answer

IT governance ensures that IT aligns with business goals, delivers value, manages risk, and optimizes resources.

8
Multi-Selecthard

Which THREE factors should be considered when tailoring a COBIT 2019 governance system?

Select 3 answers
A.Adoption strategy
B.Enterprise size
C.Office paint color
D.Employee cafeteria menu
E.Threat landscape
AnswersA, B, E

Design factor regarding implementation approach.

Why this answer

Size, threat landscape, and adoption strategy are key design factors in COBIT 2019.

9
MCQeasy

Which of the following is the best way to ensure the business is prepared for a new IT solution?

A.Increase the marketing budget for the product.
B.Update the technical server hardware.
C.Develop a comprehensive change management and training plan.
D.Finalize the security policy document.
AnswerC

Business readiness depends on the people and processes, not just technology.

Why this answer

Change management activities, such as training and process redesign, are essential for business readiness.

10
Multi-Selectmedium

Which TWO elements should be included in a business case report to the executive team?

Select 2 answers
A.The list of names of all developers.
B.The daily project status meeting minutes.
C.The server hardware configuration details.
D.The key risks and potential mitigations.
E.The project's ROI analysis.
AnswersD, E

Executives must understand the risks before approving.

Why this answer

Executives need to see the value (ROI) and the risks associated with the investment.

11
Multi-Selecthard

Which THREE factors should be considered when assessing the 'Value' of an IT investment in a portfolio?

Select 3 answers
A.Financial benefits such as cost reduction or revenue growth.
B.The number of vendors involved in the project.
C.The total volume of code written.
D.Strategic alignment with enterprise objectives.
E.The risk of business disruption if the project is not implemented.
AnswersA, D, E

Financial ROI is a core component of portfolio value.

Why this answer

Value is derived from strategic fit, financial return, and the risk of not proceeding.

12
MCQmedium

During an IT governance board meeting, the CGEIT practitioner notices that the current risk profile deviates significantly from the approved risk appetite. What is the most appropriate next step?

A.Update the enterprise risk management policy to include the new risks.
B.Instruct the IT department to stop all new projects until the risk is lowered.
C.Formally report the variance to the board and propose a remediation plan.
D.Adjust the risk appetite levels to match the current risk profile.
AnswerC

Transparency and proposing corrective governance actions are core responsibilities.

Why this answer

Governance requires transparency and corrective action when thresholds are exceeded.

13
Multi-Selectmedium

Which THREE factors should be evaluated when prioritizing IT investments within a portfolio for maximum benefit realization?

Select 3 answers
A.Strategic alignment with enterprise objectives.
B.Project team experience with specific programming languages.
C.The age of the current hardware infrastructure.
D.Risk of non-delivery or failure to achieve benefits.
E.Estimated financial ROI or NPV.
AnswersA, D, E

Alignment ensures the investment supports the organization's goals.

Why this answer

Portfolio prioritization considers strategic alignment, the financial return, and the risk profile (including deliverability) of the investments.

14
MCQmedium

When evaluating IT resource governance, which indicator best measures the effectiveness of resource allocation?

A.Total IT spend as a percentage of revenue
B.Average server uptime percentage
C.Degree of alignment between IT projects and strategic business objectives
D.Number of IT staff certifications earned per year
AnswerC

This measures if resources are being allocated to the most valuable initiatives.

Why this answer

Return on IT Investment (ROITI) or realized business value relative to resource expenditure is a key indicator.

15
MCQmedium

Which of the following is an example of an 'IT governance structure'?

A.A daily backup job schedule
B.A database management system (DBMS) upgrade project
C.An IT steering committee
D.A list of helpdesk tickets for the week
AnswerC

This is a governance structure.

Why this answer

An IT steering committee is a formal body specifically created to handle governance tasks like prioritization and alignment.

16
MCQmedium

A global company needs to compare IT investment performance across different business units using different currencies and operational models. Which metric is most suitable for normalization?

A.Number of active projects per business unit.
B.IT spend as a percentage of total head count.
C.Local currency ROI calculations.
D.Normalized TCO relative to business unit output.
AnswerD

Normalizing TCO against output (e.g., revenue per IT dollar) provides a comparable efficiency metric across different environments.

Why this answer

Total Cost of Ownership (TCO) normalization allows for a comparison of cost-to-benefit ratios that are not skewed by regional accounting differences or currency fluctuations.

17
Multi-Selecthard

Which THREE of the following are key steps in the lifecycle of IT infrastructure resource management?

Select 3 answers
A.Planning and acquisition
B.Decommissioning and disposal
C.Employee vacation scheduling
D.Monitoring and optimization of usage
E.Social media content creation
AnswersA, B, D

This is the initial phase of the lifecycle.

Why this answer

Planning, monitoring/optimizing, and decommissioning are the core phases of the IT infrastructure lifecycle.

18
MCQmedium

Which role is primarily accountable for ensuring the 'Business Case' for a new IT investment is accurate and justifiable?

A.The Lead Developer.
B.The IT Security Officer.
C.The Business Sponsor.
D.The Project Manager.
AnswerC

The sponsor owns the investment and is responsible for its value proposition.

Why this answer

The business sponsor, typically a senior business leader, owns the case and is accountable for its success.

19
MCQeasy

A company is conducting a risk analysis. Which of the following is an example of an 'inherent risk'?

A.The risk that exists in the absence of any controls.
B.The risk remaining after all security patches are installed.
C.The risk that is accepted by the board of directors.
D.The risk that has been mitigated by insurance.
AnswerA

Inherent risk is the raw exposure of a threat.

Why this answer

Inherent risk is the risk level before any controls are applied.

20
MCQhard

An enterprise is transitioning to a hybrid cloud environment. Which governance mechanism is most critical to ensure compliance with data sovereignty regulations?

A.Automated provisioning of infrastructure using Infrastructure as Code (IaC)
B.Establishing a service level agreement (SLA) with the cloud provider
C.Increasing the frequency of penetration testing on cloud endpoints
D.Implementing a robust data classification policy and control framework
AnswerD

Classification dictates where data can reside, which is essential for sovereignty compliance.

Why this answer

Defining data classification and governance policies is the prerequisite for managing data residency in a hybrid cloud.

21
Multi-Selecthard

Which THREE of the following are common challenges when implementing IT governance?

Select 3 answers
A.Lack of strategic alignment between IT and business
B.The high cost of office furniture
C.Resistance to change within the organization
D.Insufficient executive and board support
E.The inability to find enough IT technicians
AnswersA, C, D

Governance is often introduced to fix this, but the lack of it is a major implementation challenge.

Why this answer

Resistance to change, lack of leadership support, and lack of alignment are common failures.

22
MCQeasy

Which activity is essential for effective IT resource governance?

A.Writing code for new applications
B.Updating user passwords
C.Monitoring and reporting on resource utilization
D.Purchasing new server hardware
AnswerC

Monitoring is critical to ensure resources are used as intended and aligned with goals.

Why this answer

Monitoring resource usage against planned budgets and performance targets is the core of resource governance.

23
Multi-Selecthard

Which THREE activities are required when managing the 'Benefits Lifecycle'?

Select 3 answers
A.Reducing the number of project stakeholders.
B.Tracking the realization of benefits after implementation.
C.Ensuring project deliverables align with business requirements.
D.Updating the project's source code documentation.
E.Identifying and quantifying potential benefits.
AnswersB, C, E

Post-implementation tracking is the final phase of the lifecycle.

Why this answer

The lifecycle includes planning, execution/monitoring, and post-project review.

24
MCQhard

During a portfolio review, a project is identified as having a positive Net Present Value (NPV) but a low 'Strategic Fit' score. What is the most appropriate governance action?

A.Immediately cancel the project to preserve strategic alignment.
B.Transfer ownership of the project to the operations department for maintenance.
C.Conduct a re-assessment of the strategic goals to determine if the project's value proposition has been overlooked.
D.Prioritize the project to maximize immediate cash flow.
AnswerC

A disconnect between NPV and strategic fit suggests the strategy or the business case evaluation criteria need refinement.

Why this answer

If a project has high financial value but low strategic fit, it should be scrutinized to see if it distracts from the core mission, potentially requiring a re-evaluation of the investment's place in the strategic portfolio.

25
MCQmedium

What is the primary role of the Chief Information Officer (CIO) in governance?

A.Setting the overall corporate strategy.
B.Ensuring IT management acts in accordance with the board's governance directives.
C.Performing all internal IT audits.
D.Solely focused on hiring technical staff.
AnswerB

The CIO links the governance (board) and management (IT) levels.

Why this answer

The CIO is the bridge, responsible for translating the board's governance direction into IT management execution.

26
MCQmedium

Why is it important to define risk appetite before developing a risk response plan?

A.To provide a threshold for determining which risks require action.
B.To simplify the budget process for IT.
C.To automatically approve all low-impact risks.
D.Because the government requires it by law.
AnswerA

Risk response plans are triggered when risks exceed the appetite.

Why this answer

Appetite acts as the boundary for decision-making.

27
MCQmedium

Which of the following describes the 'Benefit Dependency Network' (BDN)?

A.A network diagram of project team communication channels.
B.A list of all server interdependencies.
C.A visualization of how investments and changes lead to business benefits.
D.A schedule of hardware maintenance updates.
AnswerC

BDNs connect the dots between IT output and business strategy.

Why this answer

The BDN maps the relationships between IT deliverables, business changes, and final strategic outcomes.

28
MCQmedium

Which governance mechanism is best for ensuring that IT resource allocation remains aligned with changing business priorities?

A.Review of individual employee performance metrics
B.Periodic review of the IT investment portfolio
C.Annual budgeting process
D.Monthly meeting with the IT help desk
AnswerB

Portfolio review allows for reallocation based on updated business value and risk.

Why this answer

Regular review of the IT portfolio ensures that resources are continuously redirected to the highest-value projects.

29
MCQeasy

A newly appointed CIO is establishing an IT governance framework. Which approach best ensures that IT governance is integrated into the enterprise's existing management structure?

A.Require all IT departments to report directly to the Chief Risk Officer.
B.Map IT governance activities to existing business decision-making processes and accountabilities.
C.Adopt a proprietary framework developed by a third-party IT consulting firm.
D.Implement a parallel IT governance board independent of the executive committee.
AnswerB

Mapping activities to existing processes ensures seamless integration and accountability.

Why this answer

Integrating governance into existing management structures is a core tenet of COBIT to ensure IT is not siloed.

30
Multi-Selecthard

You are evaluating the maturity of your organization's risk reporting to the board. Which THREE of the following elements are essential for high-maturity reporting?

Select 3 answers
A.Presentation of risk trends in relation to strategic business milestones.
B.Clear identification of residual risk compared to defined risk appetite thresholds.
C.Detailed technical architectural diagrams of all security tools.
D.Reporting on the status of all low-impact vulnerability scans.
E.Documentation of emerging risks that could impact the enterprise's long-term viability.
AnswersA, B, E

Contextualizes risk within the business strategy.

Why this answer

High-maturity reporting is strategic, contextual, and forward-looking, rather than purely historical or technical.

31
MCQeasy

What is the primary objective of infrastructure resource management in a governance context?

A.Ensuring IT resources support business goals efficiently and effectively
B.Maximizing the utilization of all available hardware
C.Minimizing the total number of IT personnel required
D.Upgrading all infrastructure to the latest available versions annually
AnswerA

This is the fundamental goal of IT resource governance.

Why this answer

Infrastructure management aims to balance cost, performance, and capacity to support business objectives.

32
MCQhard

An organization is failing to achieve the expected ROI on IT investments. Which governance mechanism is most likely missing?

A.An IT Steering Committee focused on value realization.
B.Regular penetration testing.
C.A robust incident management process.
D.Standardized server configurations.
AnswerA

Value realization is a core responsibility of the IT Steering Committee.

Why this answer

The IT Steering Committee is responsible for reviewing and approving business cases, ensuring projects are prioritized based on value and ROI.

33
MCQeasy

Who is ultimately responsible for the governance of enterprise IT?

A.The IT Manager.
B.The CEO.
C.The Board of Directors.
D.The IT Auditor.
AnswerC

The board has the final accountability for governance of the enterprise.

Why this answer

The board of directors (or equivalent governing body) bears the ultimate responsibility for ensuring the enterprise is governed effectively.

34
Multi-Selectmedium

Which TWO of the following are common challenges in tracking benefits?

Select 2 answers
A.The long time lag between project implementation and benefit realization.
B.The high cost of cloud hosting services.
C.The difficulty in isolating IT benefits from other business activities.
D.The requirement to have a steering committee.
E.The lack of software tools to track project milestones.
AnswersA, C

Delayed benefits make it hard to maintain stakeholder interest and accurate tracking.

Why this answer

Benefits are often difficult to isolate from other business factors and may be delayed.

35
Multi-Selecteasy

Which THREE of the following are common IT resource management challenges?

Select 3 answers
A.Balancing operational support with innovation and growth
B.Budget limitations and fiscal pressures
C.Deciding on the color scheme of the IT website
D.Choosing the best office chair for staff
E.Managing and retiring legacy systems
AnswersA, B, E

This is a fundamental and perennial challenge in IT management.

Why this answer

Budget constraints, balancing operations with innovation, and managing legacy systems are classic challenges in IT resource management.

36
MCQhard

A firm has decided to pursue a high-risk innovation strategy. How should the enterprise risk appetite statement be adjusted to support this goal?

A.Mandate that all innovation projects pass a legacy audit before approval.
B.Outsource the management of all new innovation projects to a third party.
C.Establish a higher risk appetite for experimental initiatives with clear sunset clauses.
D.Lower the threshold for all IT risk controls to ensure maximum security.
AnswerC

This allows for calculated risks while putting boundaries around the duration and impact of those risks.

Why this answer

Governance bodies must define risk tolerance thresholds that allow for strategic agility while ensuring that excessive risk does not threaten core enterprise continuity.

37
Multi-Selecthard

Which THREE principles are central to COBIT 2019 governance?

Select 3 answers
A.Maximizing individual developer freedom
B.Dynamic governance system
C.Outsourcing everything
D.Meeting stakeholder needs
E.Holistic approach
AnswersB, D, E

Core COBIT principle.

Why this answer

Meeting stakeholder needs, holistic approach, and dynamic governance are core COBIT 2019 principles.

38
MCQeasy

What is the primary purpose of a Post-Implementation Review (PIR) in the context of benefits realization?

A.To verify if the expected benefits have been achieved and identify lessons learned.
B.To ensure the system meets all security standards.
C.To finalize the payment for external contractors.
D.To evaluate the performance of the project manager.
AnswerA

PIRs close the loop on benefits planning and provide feedback for future investments.

Why this answer

The PIR confirms whether the benefits identified in the business case were actually achieved after the project is complete.

39
MCQmedium

A company is experiencing friction between IT and business units regarding project priorities. What governance structure should be strengthened to resolve this?

A.The IT Change Advisory Board (CAB)
B.The IT Steering Committee
C.The Security Operations Center (SOC)
D.The IT Infrastructure Architecture board
AnswerB

The committee balances business and IT interests to establish project priorities.

Why this answer

An IT steering committee is specifically designed to facilitate communication and priority alignment between IT and business leadership.

40
MCQhard

When balancing internal versus external IT resource sourcing, which factor best dictates the decision?

A.The current market salary for IT professionals
B.Whether the activity provides a core competitive advantage to the organization
C.The historical preference of the IT department
D.The availability of local outsourcing vendors
AnswerB

Strategic alignment with core competencies is the primary determinant for sourcing decisions.

Why this answer

Core competencies define what should remain internal to maintain competitive advantage, while non-core activities are candidates for external sourcing.

41
MCQeasy

When assessing the impact of a risk, what is the best perspective to take?

A.The cost of the hardware that needs to be replaced.
B.The effect on business objectives and value delivery.
C.The percentage of the IT budget consumed by the incident.
D.The number of hours required to restore the system.
AnswerB

Governance is concerned with the impact on enterprise value.

Why this answer

Impact is defined by the loss of business value, not technical downtime.

42
MCQhard

A project team is using a 'Benefits-Based' approach. What would they do differently than a 'Project-Based' team?

A.Re-evaluate project features and deliverables against the expected benefits throughout the project lifecycle.
B.Spend more time on technical documentation.
C.Ignore the business outcomes until the end of the project.
D.Focus more on meeting the project milestones on time.
AnswerA

Focus remains on the value, not just the scope.

Why this answer

A benefits-based approach continuously checks if the work being done is still providing value, even if the plan changes.

43
MCQhard

To optimize IT infrastructure resources, an organization adopts a software-defined infrastructure (SDI) approach. What is a key governance risk that must be addressed?

A.Inability to scale infrastructure resources rapidly
B.Complexity in maintaining consistent security and compliance policies across virtualized environments
C.Increased dependency on proprietary hardware vendors
D.Decreased flexibility in managing application workloads
AnswerB

The abstraction layer in SDI can make policy enforcement more complex if not properly governed.

Why this answer

SDI shifts control to software, making configuration management and policy enforcement critical.

44
Multi-Selecthard

Which TWO activities are necessary to ensure that IT benefits are sustainably realized post-implementation?

Select 2 answers
A.Conducting ongoing post-implementation reviews of benefit metrics.
B.Archiving all project documents to a secure repository.
C.Transitioning support responsibility to the maintenance team immediately.
D.Embedding new operational processes into business-as-usual (BAU).
E.Increasing the IT budget for the project team to add new features.
AnswersA, D

Continuous tracking ensures that the realized benefits remain stable or grow.

Why this answer

Sustainability requires that the business processes are permanently modified and that ongoing performance is measured to prevent regression.

45
MCQhard

During a merger, the IT risk governance team identifies incompatible security standards. What is the correct approach?

A.Develop a harmonized set of standards that addresses the risks of the combined entity.
B.Allow each department to continue using their own standards.
C.Hire an external firm to manage the integration.
D.Force the smaller company to immediately adopt the larger company's standards.
AnswerA

Harmonization ensures consistency and effective risk management.

Why this answer

A unified standard must be established to manage risk consistently.

46
Multi-Selecteasy

Which THREE of the following are key aspects of workforce planning in IT?

Select 3 answers
A.Implementing retention strategies for key talent
B.Developing training and professional development programs
C.Selecting the IT department's holiday party venue
D.Identifying current and future competency requirements
E.Mandatory office attendance policies
AnswersA, B, D

Retaining skilled staff is crucial for long-term capability.

Why this answer

Identifying needs, developing talent, and retaining staff are the core pillars of effective workforce planning.

47
Multi-Selecthard

The enterprise is reviewing its IT governance structure. Which THREE of the following are primary responsibilities of the Board of Directors regarding IT governance?

Select 3 answers
A.Defining the technical configuration of server clusters.
B.Directing the strategic alignment of IT with business goals.
C.Overseeing the enterprise risk management framework.
D.Managing the daily IT helpdesk ticket queue.
E.Ensuring value delivery from IT investments.
AnswersB, C, E

Ensuring IT investments support business objectives is a board duty.

Why this answer

The Board is responsible for strategic alignment, value delivery, and risk management oversight.

48
MCQmedium

An organization wants to improve its IT governance maturity. What is the most important first step?

A.Buying an expensive IT governance tool.
B.Assessing the current state of governance maturity.
C.Implementing all COBIT objectives at once.
D.Changing the IT leadership team.
AnswerB

You must understand where you are before you can plan where you are going.

Why this answer

Assessing the current state (maturity) of the governance system is the essential first step before setting goals for improvement.

49
MCQeasy

Which of the following best describes 'strategic alignment' in IT governance?

A.Requiring IT staff to wear uniforms
B.Purchasing the most advanced technology available
C.Ensuring the data center is located in a seismically safe area
D.Ensuring IT plans and business plans are synchronized
AnswerD

This directly defines strategic alignment.

Why this answer

Strategic alignment is the process of ensuring that IT objectives and activities directly support the enterprise's mission and goals.

50
MCQhard

An IT investment shows a positive ROI, but the business units are not using the new system as intended. What is the most likely cause?

A.The benefits realization plan did not adequately address business change and adoption.
B.The steering committee met too frequently.
C.The project lacked sufficient technical documentation.
D.The project was delivered under budget.
AnswerA

Benefits realization depends on the system being used in business operations.

Why this answer

Poor adoption indicates a failure in change management or a lack of alignment between the system and business processes.

51
MCQhard

A governance review reveals that IT decision-making is too slow to support rapid market changes. What should be done?

A.Require the board of directors to approve every IT change
B.Delegate specific decision-making authorities to lower levels based on defined thresholds
C.Remove all governance oversight requirements to speed up decisions
D.Stop all development until the governance process is redesigned
AnswerB

Delegation of authority balances speed with controlled oversight.

Why this answer

The governance model should be reviewed to streamline decision-making without sacrificing oversight, often through delegation of authority.

52
MCQmedium

What is the primary role of an IT Steering Committee?

A.Managing the IT staff performance reviews.
B.Reviewing IT strategy and project portfolio alignment with business goals.
C.Scheduling system maintenance windows.
D.Designing the network architecture.
AnswerB

This is the core function of an IT Steering Committee.

Why this answer

The steering committee aligns IT with business strategy and oversees major investments and project priorities.

53
MCQeasy

A company is performing a risk assessment of a new software vendor. Which factor is most relevant for the governance of third-party risk?

A.The nature of the data accessed or processed by the vendor.
B.The location of the software vendor's headquarters.
C.The number of employees working for the software vendor.
D.The brand reputation of the software vendor.
AnswerA

Data exposure risk is the primary driver of third-party governance requirements.

Why this answer

Third-party risk management is rooted in understanding the criticality of the service provided.

54
Multi-Selectmedium

Which TWO are common challenges in IT governance implementation?

Select 2 answers
A.Cultural resistance
B.Insufficient desk space
C.Slow elevator speed
D.Unreliable office internet
E.Lack of executive support
AnswersA, E

People often resist change in oversight.

Why this answer

Lack of executive support and cultural resistance are the most common barriers to effective governance.

55
Multi-Selectmedium

Which TWO of the following are key responsibilities of an IT steering committee?

Select 2 answers
A.Reviewing IT project status and business value delivery
B.Installing server software patches
C.Performing daily system performance monitoring
D.Managing the helpdesk ticket queue
E.Approving the enterprise-wide IT strategy and investment portfolio
AnswersA, E

This ensures projects deliver the intended business value.

Why this answer

The steering committee is responsible for aligning IT priorities with business needs and monitoring performance against those goals.

56
MCQhard

An IT project is identified as having a high inherent risk that exceeds the board-approved appetite. The project is critical for competitive advantage. Which approach is most appropriate?

A.Present a business case to the board for formal risk acceptance with compensatory controls.
B.Implement excessive controls regardless of project cost.
C.Direct the IT team to lower the risk by reducing project scope.
D.Cancel the project immediately to maintain compliance.
AnswerA

This follows the governance process of accountability and board-level oversight for high-risk strategic decisions.

Why this answer

Governance allows for risk acceptance at the appropriate level if the business value is high.

57
MCQmedium

An organization is evaluating its governance structure against the COBIT 2019 framework. Where should the authority for IT governance decisions reside?

A.The IT Steering Committee.
B.The IT Security Manager.
C.The Chief Information Officer (CIO).
D.The external auditors.
AnswerA

The IT Steering Committee acts as a formal bridge between the board/executive management and IT operations for decision-making.

Why this answer

COBIT 2019 emphasizes that governance accountability rests with the board, but authority is often delegated to a designated governance committee.

58
MCQeasy

What is the benefit of a standardized IT governance framework?

A.It automatically reduces IT costs by 50%.
B.It provides a clear structure, common language, and consistent practices.
C.It eliminates the need for any oversight.
D.It replaces the need for IT management.
AnswerB

These are the fundamental benefits of adopting a framework like COBIT.

Why this answer

Standardization provides a common language, consistent processes, and clear accountability across the enterprise.

59
MCQmedium

Which of the following is an example of an IT governance 'outcome'?

A.Completion of a training course.
B.The purchasing of a new software license.
C.A new server installation.
D.Increased alignment of IT services with business objectives.
AnswerD

Alignment is a direct result/outcome of successful governance.

Why this answer

An outcome is the result of effective governance, such as the achievement of business objectives through IT-enabled value.

60
Multi-Selectmedium

Which TWO items are considered 'Governance enablers' in COBIT?

Select 2 answers
A.Personal employee cars
B.Office air conditioning
C.Breakroom snacks
D.Organizational structures
E.Processes
AnswersD, E

Enabler of governance.

Why this answer

Processes and organizational structures are defined as key enablers within the COBIT framework.

61
MCQeasy

An enterprise is aligning its IT risk appetite with corporate strategic objectives. Which action should the CGEIT-certified practitioner prioritize first?

A.Draft the IT risk register for department heads.
B.Define the enterprise risk capacity based on strategic objectives.
C.Conduct a technical vulnerability scan of all production servers.
D.Implement an automated GRC risk dashboard.
AnswerB

Establishing risk capacity and appetite relative to strategic goals is the fundamental first step in risk optimization.

Why this answer

Aligning risk appetite requires a clear understanding of the enterprise's strategic goals and its capacity to absorb loss.

62
MCQmedium

Which metric is most useful for reporting the effectiveness of IT risk management to the board?

A.The number of help desk tickets closed.
B.The number of emails blocked by the spam filter.
C.The trend of residual risk levels compared to risk appetite.
D.The total volume of data stored on the servers.
AnswerC

This directly answers whether the organization is staying within appetite.

Why this answer

The board needs to see the trend of risk exposure over time.

63
MCQmedium

Which practice best ensures that IT workforce planning aligns with the enterprise's long-term business strategy?

A.Focusing exclusively on reducing IT headcount
B.Integrating IT human capital planning with the enterprise strategic planning process
C.Hiring only the most certified candidates
D.Relying on contractors for all new initiatives
AnswerB

This ensures that IT capabilities are planned in lockstep with business goals.

Why this answer

Aligning IT workforce plans with business strategy ensures the right talent is available for upcoming initiatives.

64
MCQmedium

Which key element should a balanced scorecard (BSC) for IT governance include?

A.Only financial metrics.
B.Only technical uptime metrics.
C.Financial, customer, internal process, and learning and growth perspectives.
D.Only employee satisfaction metrics.
AnswerC

This is the classic Kaplan/Norton BSC structure adapted for IT governance.

Why this answer

A balanced scorecard for IT should measure performance across financial, customer, internal process, and learning/growth perspectives.

65
Multi-Selecteasy

Which TWO of the following are primary components of IT resource management?

Select 2 answers
A.Office facility maintenance
B.Infrastructure resource management
C.Customer relationship marketing
D.Workforce planning
E.Public relations strategy
AnswersB, D

Hardware, software, and cloud assets are central to IT resource management.

Why this answer

IT resource management fundamentally involves both the human (workforce) and the technical (infrastructure) assets of the organization.

66
MCQeasy

Which document is primary evidence that the board of directors is fulfilling its oversight responsibility for IT governance?

A.An IT incident report detailing recent system downtime
B.A technical architecture document describing the enterprise network
C.The minutes of board meetings documenting IT strategy review and approval
D.A list of software licenses purchased by the IT department
AnswerC

Board minutes are the formal record of governance oversight decisions.

Why this answer

The IT strategy, when reviewed and approved by the board, demonstrates active oversight.

67
Multi-Selectmedium

Which THREE of the following are key inputs for defining the IT risk appetite?

Select 3 answers
A.The enterprise's strategic objectives.
B.The current technical debt of the IT systems.
C.The specific brand of coffee in the breakroom.
D.The number of printers in the office.
E.Stakeholder risk tolerance levels.
AnswersA, B, E

Appetite must serve the strategy.

Why this answer

Appetite is defined by strategic goals, resource capacity, and stakeholder expectations.

68
MCQmedium

When establishing an IT governance committee, what is a key requirement for its effectiveness?

A.It must be composed only of technical experts.
B.It must include representation from both business and IT.
C.It must be chaired by the CIO.
D.It must meet at least once a week.
AnswerB

Cross-functional representation is essential for aligning IT governance with enterprise goals.

Why this answer

A committee must have representation from both business and IT to ensure that decisions are aligned with business priorities and that IT has a voice.

69
Multi-Selecthard

Which THREE components are critical for an IT governance system to be effective?

Select 3 answers
A.Defined processes
B.Unlimited breakroom coffee
C.The latest gaming console
D.Organizational structures
E.Information flows
AnswersA, D, E

Governance operates through documented processes.

Why this answer

Processes, organizational structures, and information flows are core components of a governance system.

70
MCQhard

An organization's risk appetite has been set as 'low' for data breaches. A new project introduces a moderate risk of a breach. What is the most appropriate governance action?

A.Implement additional security controls to bring the residual risk within the 'low' appetite.
B.Accept the risk because the project is strategically important.
C.Lower the 'low' appetite threshold to 'moderate'.
D.Document the risk in the risk register and ignore it for now.
AnswerA

Risk optimization involves applying controls to align residual risk with appetite.

Why this answer

If a project exceeds appetite, controls must be enhanced or the project must be modified.

71
MCQhard

Your organization is undergoing a major digital transformation. To ensure risk is optimized throughout the lifecycle, what is the most critical governance activity during the planning phase?

A.Ensuring the technical architecture is fully documented.
B.Setting up an automated monitoring tool for the new cloud environment.
C.Hiring a third-party consultant to conduct a penetration test on the future system.
D.Defining explicit risk-based criteria for project prioritization in the business case.
AnswerD

This ensures that risk is considered alongside cost and benefit before any commitment is made.

Why this answer

Embedding risk criteria into the project selection and prioritization process ensures that the organization only commits resources to projects that align with the board's risk appetite.

72
MCQhard

An organization is transitioning to a cloud-based infrastructure. Which governance mechanism is most effective for ensuring that the cloud service provider's risk management practices remain aligned with the enterprise's risk appetite?

A.Performing an annual penetration test on the provider's infrastructure.
B.Mandating a SOC 2 Type II report review on an annual basis.
C.Embedding ongoing risk assessment requirements into the service provider contract.
D.Establishing clear service level agreements (SLAs) with penalty clauses for downtime.
AnswerC

This ensures the provider is contractually bound to maintain visibility into the risk profile.

Why this answer

Continuous monitoring and contractual requirements are key for third-party risk governance.

73
Multi-Selectmedium

Which TWO activities are part of the post-implementation benefits review?

Select 2 answers
A.Changing the project manager's job description.
B.Re-installing the software.
C.Evaluating actual benefits against the business case.
D.Identifying lessons learned to improve future benefits planning.
E.Deleting the project documentation.
AnswersC, D

This is the primary goal of the review.

Why this answer

The review compares actuals to plans and documents lessons for future improvement.

74
Multi-Selecteasy

Which TWO items are commonly included in an IT Governance Policy?

Select 2 answers
A.Scope of governance
B.Network IP addresses
C.Server rack layout
D.Roles and responsibilities
E.Daily task list
AnswersA, D

Defines what the policy applies to.

Why this answer

Policies define the scope of the framework and the roles/responsibilities of the stakeholders.

75
Multi-Selectmedium

Which THREE of the following are common risk response strategies?

Select 3 answers
A.Ignore.
B.Avoid.
C.Transfer.
D.Delete.
E.Accept.
AnswersB, C, E

Valid strategy.

Why this answer

Standard risk strategies are Accept, Avoid, Transfer, and Mitigate.

Page 1 of 3

Page 2

All pages