Courseiva

ISACA Certified in the Governance of Enterprise IT (CGEIT) (CGEIT) (CGEIT) — Questions 76150

214 questions total · 3pages · All types, answers revealed

Page 1

Page 2 of 3

Page 3
76
MCQmedium

During a strategic alignment review, the governance committee identifies that IT investments are not delivering expected value. What is the most effective first step for the committee?

A.Cancel all current IT projects and restart with new priorities
B.Outsource the IT portfolio management function to a third-party consultant
C.Conduct a portfolio review to map current IT investments to strategic business objectives
D.Reduce the IT budget by 20% to increase efficiency metrics
AnswerC

Mapping investments to business objectives identifies misalignment and value leakage.

Why this answer

The committee must first assess the transparency and accuracy of the IT investment portfolio against business goals.

77
MCQeasy

In the context of IT governance, what is the primary responsibility of the board of directors?

A.Providing strategic direction and monitoring governance performance.
B.Managing the procurement of software and hardware.
C.Developing IT policies and procedures.
D.Day-to-day management of IT operations.
AnswerA

The board sets the tone and provides oversight of the governance framework.

Why this answer

The board's primary role is oversight, ensuring that IT governance is established and that risks are managed in alignment with enterprise appetite.

78
MCQhard

A firm's IT audit identifies a lack of accountability for data governance. Which governance mechanism should be implemented?

A.Outsource all data storage.
B.Install more data encryption tools.
C.Centralize all data in one database.
D.Appoint data owners and establish a data governance committee.
AnswerD

Defining clear roles and oversight is the foundation of data governance accountability.

Why this answer

Assigning data ownership and establishing a data governance council are the standard mechanisms to ensure accountability.

79
MCQmedium

In the context of benefits realization, what is a 'leading indicator'?

A.The final revenue growth reported at year-end.
B.The number of users who attended training sessions.
C.The total cost of the project.
D.The adoption rate of a new system during the pilot phase.
AnswerD

Early adoption is a predictor of future process efficiency gains.

Why this answer

A leading indicator is a metric that predicts a future outcome, often used before the full benefit is realized.

80
MCQmedium

Why is it important to define the 'baseline' before starting an IT project?

A.To provide a clear point of comparison for measuring the impact of the new system.
B.To select the software vendor.
C.To determine the final cost of the project.
D.To ensure the team knows what to build.
AnswerA

Without a starting point, you cannot quantify the change.

Why this answer

The baseline represents the status quo, allowing you to measure the actual improvement (benefit) after the project.

81
MCQmedium

An organization is struggling with 'Shadow IT' negatively impacting their consolidated benefits realization report. Which governance approach best mitigates this risk while maintaining IT agility?

A.Restricting network access to cloud-based SaaS providers.
B.Developing a standard service catalog and internal IT brokerage model.
C.Consolidating all IT budgets into a single central cost center.
D.Implementing a strict ban on non-approved software acquisition.
AnswerB

A brokerage model allows business units to consume IT services governed under the enterprise framework, ensuring benefits can be tracked.

Why this answer

Establishing an 'Internal IT Marketplace' or a standard service catalog provides business units with the agility they seek while ensuring that their spending is captured within the governance framework.

82
MCQhard

An IT manager is conducting workforce planning for an upcoming digital transformation. Which approach is most effective for identifying skill gaps?

A.Conducting a gap analysis comparing current IT staff competencies against future state requirements
B.Surveying staff on their preferred technologies for professional development
C.Reviewing employee performance appraisals from the previous two years
D.Increasing the budget for external recruitment to bring in new talent
AnswerA

This aligns the workforce with the specific needs of the transformation.

Why this answer

Competency mapping against strategic IT goals is the standard practice for identifying future needs.

83
Multi-Selecthard

Which TWO of the following are critical success factors for implementing a new IT governance program?

Select 2 answers
A.Active support and commitment from senior leadership
B.Replacing all existing IT management staff
C.Focusing exclusively on technical automation tools
D.Ignoring existing business processes to start fresh
E.Integration of governance into the organizational culture
AnswersA, E

Without leadership, governance lacks the authority to be effective.

Why this answer

Leadership support and cultural integration are essential for the success of any governance program.

84
MCQhard

A company's IT governance structure is being challenged because IT costs are inconsistent. What is the most appropriate governance step to take?

A.Arbitrarily cap all IT spending.
B.Increase the IT department's headcount.
C.Switch to a cloud-only model.
D.Review and align IT investment prioritization with business outcomes.
AnswerD

Alignment ensures that funds are spent on the initiatives that drive the most value.

Why this answer

The steering committee should review the IT investment portfolio and budget allocation to ensure consistency with strategic business priorities.

85
MCQhard

An organization experiences a high frequency of minor IT incidents. What is the most effective governance action to ensure this does not result in a significant enterprise risk?

A.Updating the incident management policy to mandate shorter SLA targets.
B.Increasing the budget for incident response staff.
C.Requiring all incidents to be reported directly to the board of directors.
D.Implementing a root cause analysis (RCA) program to identify systemic patterns across recurring incidents.
AnswerD

RCA identifies the underlying governance and control weaknesses that allow minor risks to persist.

Why this answer

Aggregating risk is essential. Multiple minor incidents can indicate a systemic control weakness that, if unaddressed, leads to a major catastrophe.

86
MCQmedium

You are auditing the integration of IT risk management. Which finding indicates a failure in the governance of enterprise risk?

A.The IT risk register is reviewed quarterly by the IT steering committee.
B.The CISO reports to the CIO instead of the CEO.
C.IT risk assessments are performed independently of business impact analysis (BIA).
D.The risk management policy was updated 18 months ago.
AnswerC

Risk assessment must be contextually relevant to business processes; decoupling them prevents effective prioritization.

Why this answer

If risk management activities are not linked to the strategic business objectives, the organization lacks effective governance over IT risk.

87
Multi-Selecteasy

Which TWO metrics are used to measure strategic alignment?

Select 2 answers
A.Number of server reboots
B.Average salary of IT staff
C.Percentage of projects aligned with business strategy
D.Number of printers repaired
E.Business value realized from IT investments
AnswersC, E

Direct measure of alignment.

Why this answer

Portfolio alignment and value delivery metrics are key indicators of strategic alignment.

88
Multi-Selectmedium

Which TWO of the following are essential components of an effective IT governance framework?

Select 2 answers
A.Organizational structures
B.Processes for decision-making and accountability
C.A list of all IT hardware serial numbers
D.The daily IT operational budget
E.Detailed programming language standards
AnswersA, B

Structures define who makes decisions.

Why this answer

A governance framework must include both organizational structures and clear processes for decision-making.

89
MCQeasy

What is the primary indicator that IT strategic alignment is successful?

A.IT cost as a percentage of revenue is minimized.
B.The IT department is fully staffed.
C.IT projects are completed on time.
D.Business goals are met through the effective use of IT.
AnswerD

This demonstrates that IT is driving business value.

Why this answer

Successful alignment is visible when IT investments and operations directly support the achievement of the enterprise's strategic goals.

90
Multi-Selectmedium

Which THREE of the following are primary domains of IT governance according to standard frameworks?

Select 3 answers
A.Risk management
B.Value delivery
C.Hardware procurement automation
D.Strategic alignment
E.Helpdesk ticket resolution speed
AnswersA, B, D

A core domain of IT governance.

Why this answer

IT governance covers strategic alignment, value delivery, risk management, resource management, and performance measurement.

91
MCQmedium

A company is establishing an IT Risk Committee. Which group should have the most significant representation?

A.The local IT vendors.
B.The human resources department.
C.Key business process owners and senior IT leadership.
D.The junior IT support staff.
AnswerC

Business owners understand the impact, IT provides the technical expertise.

Why this answer

Governance requires representation from the business, not just IT.

92
Multi-Selectmedium

Which THREE of the following should be considered when assessing the resource requirements for a new IT project?

Select 3 answers
A.The preferred lunch break times of the project manager
B.The personal hobbies of the project team members
C.Necessary computing and storage infrastructure capacity
D.Required technical skills and available expertise
E.Ongoing operational and maintenance resource needs post-implementation
AnswersC, D, E

Infrastructure requirements must be planned to ensure performance.

Why this answer

Human expertise, infrastructure capacity, and long-term maintenance costs are all critical factors in assessing project resource needs.

93
MCQeasy

An organization is establishing a benefits realization framework. What is the primary purpose of defining key performance indicators (KPIs) at the start of an IT investment?

A.To ensure software development complies with vendor licensing requirements.
B.To provide a baseline for measuring the achievement of expected business outcomes.
C.To automate the generation of project status reports for stakeholders.
D.To allocate budget for ongoing maintenance and support costs.
AnswerB

KPIs are quantitative measures used to track the progress toward strategic business goals.

Why this answer

Defining KPIs early allows for the establishment of baseline performance data, which is essential to measure the delta created by the investment.

94
Multi-Selecteasy

Which TWO of the following describe the role of the 'Risk Owner'?

Select 2 answers
A.Writing all the company's marketing emails.
B.Responsible for monitoring the effectiveness of controls.
C.Approving the company's annual tax filing.
D.Accountable for managing the identified risk.
E.Fixing all hardware issues in the company.
AnswersB, D

Core responsibility.

Why this answer

Risk owners are accountable for the management and monitoring of specific risks.

95
MCQmedium

How should IT governance ensure that IT-related risks are identified and managed?

A.By eliminating IT risk entirely.
B.By outsourcing all IT operations to a third party.
C.By incorporating risk management into the enterprise's IT governance policy.
D.By performing all risk assessments at the board level.
AnswerC

Policies define the risk management expectations that management must execute.

Why this answer

Governance frameworks integrate risk management by setting policies and requiring management to establish risk assessment processes.

96
MCQmedium

Which of the following is a key component of an effective IT risk management policy?

A.Roles and responsibilities for risk ownership.
B.The specific model of routers used in the network.
C.The salary structure for IT staff.
D.A detailed list of all system passwords.
AnswerA

Governance requires clear accountability for managing risks.

Why this answer

A policy must define roles, responsibilities, and the framework for action.

97
MCQeasy

In the context of benefits realization, what does the term 'disbenefit' mean?

A.A cost that was not included in the original budget.
B.A negative consequence of the IT investment.
C.A benefit that was planned but not achieved.
D.The depreciation of hardware assets over time.
AnswerB

Disbenefits must be identified and managed as part of the total project impact.

Why this answer

A disbenefit is an adverse or negative impact resulting from the implementation of a project.

98
MCQmedium

A business case includes a 'Sensitivity Analysis'. What is the purpose of this analysis in benefits realization?

A.To determine how changes in key assumptions affect the projected return on investment.
B.To test the security of the application against breaches.
C.To identify which stakeholders are sensitive to change.
D.To measure the speed of the software.
AnswerA

It helps managers understand the robustness of the business case.

Why this answer

Sensitivity analysis tests how changes in variables (like cost or usage) impact the overall project ROI.

99
MCQhard

An enterprise is facing a high-impact risk that cannot be fully mitigated. The board decides to transfer this risk. Which of the following is the best implementation of risk transfer?

A.Moving all data to a public cloud provider.
B.Purchasing comprehensive cyber-insurance to cover potential financial losses.
C.Outsourcing the entire IT department to a third-party managed service provider.
D.Signing an indemnity clause in a software license agreement.
AnswerB

Insurance is a classic transfer mechanism for financial liability.

Why this answer

Risk transfer is about moving financial liability, not operational responsibility.

100
MCQeasy

Which document should provide the framework for how IT resources are prioritized and allocated?

A.Annual IT Operating Budget
B.Disaster Recovery Plan
C.Service Level Agreement (SLA)
D.IT Strategic Plan
AnswerD

The IT strategic plan defines the priorities for resource allocation based on business goals.

Why this answer

The IT Strategic Plan aligns IT initiatives and resource allocation with business objectives.

101
MCQhard

An organization adopts a multi-cloud strategy. Which governance challenge is most significant regarding resource optimization?

A.The slower speed of provisioning resources
B.The lack of consistent visibility, policy enforcement, and cost management across platforms
C.The difficulty of finding cloud architects
D.The increased cost of data egress fees between clouds
AnswerB

Multi-cloud environments inherently fragment management, making unified governance difficult.

Why this answer

Managing fragmented resources across multiple providers complicates cost tracking, security policy enforcement, and skill management.

102
MCQeasy

When balancing risk and value in IT investment, what is the primary consideration for the CGEIT practitioner?

A.Prioritizing compliance over all other business requirements.
B.Total elimination of IT risk.
C.Maximizing the return on investment (ROI) regardless of risk exposure.
D.Optimizing the realization of benefits while maintaining risk exposure within the enterprise appetite.
AnswerD

This is the core definition of balancing risk and value in IT governance.

Why this answer

Governance is about the trade-offs. Delivering value requires taking risks; the objective is to optimize, not eliminate, risk.

103
Multi-Selectmedium

Which TWO of the following are key elements of a Business Impact Analysis (BIA)?

Select 2 answers
A.The color scheme of the company website.
B.The specific model of server hardware.
C.Identification of critical business processes.
D.The annual salary of the IT staff.
E.Determining the maximum tolerable downtime.
AnswersC, E

Foundational BIA step.

Why this answer

BIA identifies critical processes and the impact of their disruption.

104
MCQmedium

A large organization is attempting to reduce technical debt. Which resource management approach is most effective?

A.Outsourcing the maintenance of legacy systems
B.Pausing all new development until all legacy systems are replaced
C.Waiting for a major system failure to justify remediation budget
D.Allocating a set percentage of capacity to technical debt remediation in every sprint/cycle
AnswerD

This balances new features with debt reduction, ensuring progress without stopping development.

Why this answer

Allocating a fixed percentage of resources to technical debt reduction in every development cycle ensures continuous progress.

105
MCQmedium

Which stakeholder should provide the final approval for the IT governance policy?

A.The IT Steering Committee.
B.The Board of Directors.
C.The Chief Technology Officer (CTO).
D.The Chief Information Security Officer (CISO).
AnswerB

Final oversight and accountability for the governance framework belong to the board.

Why this answer

The board of directors (or equivalent) has ultimate accountability for the organization's governance, including IT governance.

106
MCQeasy

What is the primary objective of a 'Benefits Management Plan'?

A.To list the server hardware requirements.
B.To secure the budget from the finance team.
C.To document the project schedule.
D.To define the responsibilities, metrics, and timeline for achieving expected benefits.
AnswerD

The plan provides the roadmap for value realization.

Why this answer

The plan outlines how the benefits will be measured, tracked, and realized throughout the project lifecycle.

107
Multi-Selecthard

Which TWO of the following are examples of 'Avoidance' as a risk response?

Select 2 answers
A.Buying insurance for a data center.
B.Deciding not to enter a new market with high regulatory risk.
C.Creating a backup of the database.
D.Installing an antivirus program.
E.Canceling a project with excessive security risks.
AnswersB, E

This eliminates the risk by not engaging.

Why this answer

Avoidance is exiting an activity that carries risk.

108
MCQmedium

A company is planning a digital transformation. What governance action is necessary to ensure the transformation supports business strategy?

A.Outsource the entire transformation to an external systems integrator
B.Establish a governance structure that includes business unit leaders in transformation decision-making
C.Focus primarily on reducing IT costs to fund the project
D.Select the latest cloud-based ERP software before defining business requirements
AnswerB

Inclusive decision-making ensures the project meets business needs.

Why this answer

Linking the digital transformation initiative to clear, measurable business objectives is essential for governance.

109
MCQeasy

When reporting IT risk to the board, which of the following provides the most value?

A.A list of all open vulnerabilities categorized by severity.
B.A heat map showing the impact of top risks on business value drivers.
C.The total number of security incidents reported in the last quarter.
D.A detailed technical audit report of the firewall configurations.
AnswerB

Boards prioritize risks based on their potential impact on strategic goals.

Why this answer

Boards need context, trends, and business impact rather than technical metrics.

110
Multi-Selecthard

Which THREE items are required for an effective IT investment governance process?

Select 3 answers
A.Project prioritization process
B.Employee birthday party planning
C.Office chair selection
D.Formal business case review
E.Post-implementation value tracking
AnswersA, D, E

Step in investment governance.

Why this answer

Business case approval, project prioritization, and ROI measurement are the core steps in investment governance.

111
Multi-Selectmedium

Which TWO of the following are effective strategies for optimizing workforce resources?

Select 2 answers
A.Reducing the frequency of staff performance reviews
B.Using a flexible resource model for non-core, variable IT activities
C.Requiring all staff to work in the office five days a week
D.Increasing the number of layers in the management hierarchy
E.Implementing a cross-training program to increase staff versatility
AnswersB, E

This allows for scaling resources without the overhead of permanent staff.

Why this answer

Cross-training and flexible resource pools (like contractors for non-core work) are effective strategies for workforce optimization.

112
Multi-Selecthard

Which TWO of the following are key indicators that an organization's IT resource allocation is ineffective?

Select 2 answers
A.Low turnover rate among IT staff
B.Use of automated project management software
C.High adoption of standard, approved hardware platforms
D.Frequent misalignment between IT projects and business strategic objectives
E.High percentage of IT budget spent on 'keep-the-lights-on' maintenance
AnswersD, E

This is a direct indicator that resources are not being allocated to the right initiatives.

Why this answer

Ineffective allocation leads to missed business goals and a high volume of 'keep-the-lights-on' work, leaving little room for innovation.

113
MCQmedium

A company is using a risk maturity model to improve its IT risk management. What is the main benefit?

A.To automatically reduce the cost of IT security.
B.To establish a baseline and track improvements over time.
C.To force all departments to use the same IT tools.
D.To determine exactly how many employees are needed in the risk department.
AnswerB

Maturity models provide a standardized way to measure growth.

Why this answer

Maturity models identify gaps to allow for targeted improvements.

114
MCQmedium

An enterprise is facing significant shadow IT growth. What is the best governance action to optimize resources?

A.Audit all business units and penalize those using shadow IT
B.Restrict all unauthorized cloud service access via the firewall
C.Implement a cloud access security broker (CASB) to provide secure, governed alternatives
D.Mandate that all IT needs be submitted via the central IT ticketing system
AnswerC

CASBs allow for the secure use of cloud services by providing visibility and control.

Why this answer

Rather than banning shadow IT, governance should provide approved, user-friendly alternatives to regain control and efficiency.

115
MCQeasy

What is the primary role of the IT governance framework in an enterprise?

A.To align IT strategy with business strategy and deliver value
B.To serve as a technical manual for system administration
C.To automate all IT monitoring and reporting
D.To replace the need for IT management
AnswerA

The core purpose of governance is to ensure IT value delivery and alignment.

Why this answer

The framework provides the structure, processes, and mechanisms to ensure IT meets business goals and manages risk.

116
MCQeasy

What is the primary difference between a Project Manager and a Benefits Owner?

A.There is no difference between these two roles.
B.The project manager is responsible for the technical output; the benefits owner is responsible for the business outcome.
C.The project manager is responsible for the company's financial results.
D.The benefits owner manages the daily development tasks.
AnswerB

This is the core distinction between project delivery and benefits realization.

Why this answer

The project manager delivers the project; the benefits owner realizes the value after delivery.

117
Multi-Selectmedium

Which THREE of the following represent effective ways to monitor IT governance compliance?

Select 3 answers
A.Reviewing IT governance performance dashboards
B.Monitoring the speed of the office Wi-Fi
C.Conducting regular internal audits of governance controls
D.Ensuring regular reports on policy compliance are provided to the board
E.Asking staff to informally report any issues
AnswersA, C, D

Dashboards provide continuous visibility into governance metrics.

Why this answer

Compliance monitoring relies on audit, formal performance metrics, and regular reporting.

118
MCQhard

An organization's governance committee decides to stop funding a legacy IT system that is still critical for a specific department. What should be done?

A.Conduct an impact analysis and develop a migration strategy.
B.Decommission it immediately to save money.
C.Force the department to find their own funding.
D.Ignore the committee's decision and keep paying.
AnswerA

Governance requires evaluating the impact and planning for continuity.

Why this answer

The committee must perform a formal impact assessment and create a transition plan that ensures business continuity before decommissioning.

119
MCQhard

During a portfolio review, it is discovered that a program's benefits are being realized, but the project costs have exceeded the contingency fund by 20%. What is the best immediate action for the benefits owner?

A.Conduct a re-evaluation of the business case to determine if the expected ROI is still valid.
B.Immediately terminate the project to prevent further cost overruns.
C.Ignore the cost overrun as long as the project delivery schedule remains on track.
D.Request an additional budget from the steering committee without analysis.
AnswerA

A revised business case ensures that the investment remains value-justified under new cost constraints.

Why this answer

The benefits owner must determine if the increased costs impact the overall net value (ROI) to decide whether to continue the investment.

120
Multi-Selecteasy

To effectively integrate risk management into enterprise governance, which THREE activities should be conducted?

Select 3 answers
A.Defining the enterprise risk appetite in quantitative or qualitative terms.
B.Establishing clear accountability for risk ownership at the executive level.
C.Standardizing the IT configuration management database (CMDB) structure.
D.Integrating risk reporting into the existing enterprise performance management process.
E.Outsourcing the primary data center to a tier-one cloud provider.
AnswersA, B, D

The appetite sets the boundary for all decision-making.

Why this answer

Governance of IT risk requires strategic alignment, clear communication, and defined accountability structures.

121
MCQeasy

A company is shifting from a project-based to a value-based management model. Which of the following best describes an 'outcome' versus an 'output'?

A.An output is a strategic goal; an outcome is a project milestone.
B.An output is the increased sales revenue; an outcome is the new CRM software.
C.An output and an outcome are essentially the same and can be used interchangeably.
D.An output is the automated reporting tool; an outcome is the reduction in manual data entry time.
AnswerD

The tool is the deliverable; the time savings is the benefit derived from that deliverable.

Why this answer

An output is what is delivered (the product), whereas an outcome is the resulting state or benefit to the organization.

122
MCQeasy

An organization is integrating IT risk management into its enterprise governance framework. Which approach best ensures that IT risk is treated as a component of enterprise risk?

A.Implementing a standalone IT risk registry managed only by the CISO.
B.Establishing a common risk taxonomy shared between the IT risk and Enterprise Risk Management (ERM) functions.
C.Focusing exclusively on technical vulnerabilities in the IT asset inventory.
D.Delegating all IT risk assessments to the IT infrastructure team.
AnswerB

A common taxonomy allows for aggregation and comparison of IT risks with other enterprise risks.

Why this answer

Integrating IT risk into the enterprise risk framework ensures visibility for the board and alignment with business objectives, rather than treating it as a siloed technical concern.

123
MCQeasy

Which of the following is an example of a financial benefit?

A.Enhanced brand reputation.
B.Improved employee morale.
C.Increased customer satisfaction scores.
D.Reduced annual operating expenses due to process automation.
AnswerD

Direct cost reduction is a clear financial benefit.

Why this answer

Financial benefits are those that directly impact the organization's bottom line.

124
MCQmedium

An organization is considering a 'cloud-first' policy. What should be the primary governance focus when allocating resources?

A.Establishing a cloud center of excellence (CCoE) to govern adoption and best practices
B.Selecting the cloud vendor with the lowest price
C.Training all IT staff on a single cloud platform
D.Mandating the migration of all legacy systems regardless of suitability
AnswerA

A CCoE ensures consistent governance, security, and cost optimization across cloud adoption.

Why this answer

A cloud-first strategy requires robust governance over cloud spend, security, and integration to prevent runaway costs and fragmented infrastructure.

125
Multi-Selecteasy

Which TWO documents are essential for establishing governance oversight?

Select 2 answers
A.Governance policy
B.Server maintenance schedule
C.Vendor contact list
D.IT ticket log
E.Committee charter
AnswersA, E

Sets the rules and expectations.

Why this answer

The governance policy and the committee charter are the foundational documents for oversight.

126
MCQhard

An enterprise is adopting an agile development methodology. How should the CGEIT-certified practitioner modify the risk governance process?

A.Require a formal risk assessment for every sprint cycle.
B.Remove risk governance requirements until the project reaches the production phase.
C.Replace the risk register with a daily stand-up meeting for risk tracking.
D.Implement automated security scanning within the CI/CD pipeline.
AnswerD

Integrating governance controls directly into the toolchain is the best practice for agile environments.

Why this answer

Governance must adapt to the velocity of agile without sacrificing oversight.

127
MCQmedium

When benefits are reported as 'percentage of goal achieved', what is a potential risk?

A.Percentages are too difficult for stakeholders to understand.
B.Percentages cannot be calculated for IT projects.
C.Percentages are always accurate.
D.Percentages may hide the underlying absolute values and total costs.
AnswerD

A high percentage of a small goal may look better than a low percentage of a massive goal.

Why this answer

Percentages can mask the absolute scale of the benefit or the cost incurred to achieve it.

128
MCQeasy

Which role is generally responsible for implementing the governance policies defined by the board?

A.Internal Audit.
B.The Board of Directors.
C.Executive Management.
D.The IT support team.
AnswerC

Executive management translates governance directives into operational reality.

Why this answer

Management, led by the executive suite, is responsible for executing the strategies and policies set by the board.

129
MCQhard

A company is integrating a new AI technology. How should the governance structure oversee this risk?

A.Mandate that no new AI technology is used.
B.Allow the IT team to proceed without oversight.
C.Update governance policies and risk thresholds for new technology.
D.Focus solely on the cost of the technology.
AnswerC

Proactive policy and risk assessment update is the correct governance approach for new tech.

Why this answer

Emerging technology requires the IT steering committee to review the risk appetite and update governance policies to manage new types of ethical and operational risks.

130
Multi-Selectmedium

Which TWO factors are essential for a successful benefits realization culture?

Select 2 answers
A.A focus on learning from both successes and failures.
B.Requiring all employees to learn programming.
C.Clear accountability for benefit achievement.
D.Frequent updates to the technical architecture.
E.Reducing the number of board meetings.
AnswersA, C

A 'no-blame' learning culture allows for honest benefit tracking.

Why this answer

A culture of benefits realization requires accountability and a focus on measurement rather than blame.

131
Multi-Selecthard

Which TWO of the following are key inputs for defining the IT governance strategy?

Select 2 answers
A.The number of employees in the IT department
B.The IT department's current server capacity
C.The enterprise's risk appetite
D.The enterprise's overall business strategy
E.The vendor names of all installed software
AnswersC, D

Risk appetite determines the required level of control and oversight.

Why this answer

IT governance must be derived from the enterprise's strategic goals and its appetite for risk.

132
MCQeasy

What is the primary purpose of an IT value framework?

A.To minimize the IT budget.
B.To align IT investments with enterprise strategic goals.
C.To manage the technical infrastructure components.
D.To automate the software development life cycle.
AnswerB

Alignment ensures the right projects are chosen to deliver business value.

Why this answer

An IT value framework ensures that IT investments provide the intended value to the business.

133
MCQhard

Which document is the primary source for defining the success criteria of an IT project?

A.The vendor contract.
B.The technical design document.
C.The business case.
D.The project charter.
AnswerC

The business case establishes the return on investment and the benefits to be realized.

Why this answer

The business case provides the justification and the defined expected benefits for the project.

134
MCQhard

A firm identifies a significant variance between projected ROI and actual realized benefits for a major digital transformation initiative. Which action should the CGEIT practitioner prioritize to address the root cause of the benefit shortfall?

A.Implement a new project management software tool for better reporting.
B.Update the project charter to reflect lower performance expectations.
C.Re-evaluate the Benefits Realization Plan (BRP) against realized operational performance data.
D.Conduct a post-implementation audit of IT infrastructure performance.
AnswerC

The BRP is the authoritative document linking investment to business outcomes; checking it against reality is the primary step in diagnosing realization gaps.

Why this answer

Benefits realization management requires an iterative review of the Benefits Realization Plan against actual operational data to identify whether the assumptions made during business case development are still valid.

135
Multi-Selectmedium

Which TWO roles are typically involved in the IT Steering Committee?

Select 2 answers
A.Chief Information Officer (CIO)
B.Chief Financial Officer (CFO)
C.Security Support Staff
D.External Custodial Services
E.Junior Software Developer
AnswersA, B

IT leadership is required to represent IT capabilities.

Why this answer

Both executive business leadership and senior IT leadership must participate for the committee to be effective.

136
MCQmedium

When a project is integrated into an enterprise portfolio, what is the governance board's main responsibility regarding benefits?

A.To conduct daily meetings with the development team.
B.To monitor the realization of benefits and authorize corrective action if necessary.
C.To write the detailed technical specification for the project.
D.To manage the daily vendor relationship.
AnswerB

Governance involves oversight of benefits realization against the business case.

Why this answer

The governance board ensures that the investment remains aligned with enterprise strategy and that the benefits are being realized as planned.

137
Multi-Selecteasy

Which TWO of the following are examples of risk mitigation?

Select 2 answers
A.Avoiding the use of cloud computing entirely.
B.Implementing regular system backups.
C.Installing a firewall.
D.Purchasing cyber-insurance.
E.Accepting the risk of a minor system outage.
AnswersB, C

This reduces the impact of data loss.

Why this answer

Mitigation involves taking action to reduce the likelihood or impact of a risk.

138
Multi-Selectmedium

Which TWO mechanisms are used by governance to monitor performance?

Select 2 answers
A.Hardware inventory scan
B.Daily stand-up meetings
C.Independent internal audit
D.Periodic performance reporting
E.Office security badge logs
AnswersC, D

Provides objective assurance.

Why this answer

Reporting and internal auditing are key mechanisms for governance monitoring.

139
MCQhard

A corporation is shifting from a centralized to a decentralized IT structure. How does this affect governance?

A.Governance must define common standards while allowing local decision-making flexibility.
B.The board should take over all local IT decisions.
C.The governance framework is no longer required.
D.Decentralization makes IT governance impossible.
AnswerA

This is the 'center of excellence' model required for decentralized IT governance.

Why this answer

Decentralization shifts control, requiring a governance framework that emphasizes shared standards and monitoring across multiple business units.

140
Multi-Selectmedium

Which TWO of the following are governance-related challenges when allocating resources for emerging technologies?

Select 2 answers
A.The technology is too cheap to purchase
B.The technology is widely available in the market
C.Lack of defined governance frameworks for the new technology
D.Significant skill gaps within the current IT workforce
E.It is always compatible with existing infrastructure
AnswersC, D

New technologies often precede the creation of policies and governance models.

Why this answer

Emerging technologies often lack established governance models and possess significant skill gaps, making them difficult to manage.

141
MCQmedium

In the context of IT portfolio management, what does 'value optimization' mean?

A.Balancing investments to achieve the best possible outcomes for the organization given resource constraints.
B.Always choosing the cheapest project.
C.Automating the IT support ticket system.
D.Minimizing the number of IT projects.
AnswerA

Optimization is about making the best tradeoffs for maximum impact.

Why this answer

Value optimization is the practice of continuously adjusting the portfolio to maximize the overall business value generated by IT investments.

142
Multi-Selecteasy

Which TWO of the following are primary pillars of IT Governance?

Select 2 answers
A.Strategic alignment
B.Hardware procurement cost
C.Network speed optimization
D.Value delivery
E.Software development speed
AnswersA, D

Ensuring IT supports the business is a core pillar.

Why this answer

Strategic alignment and value delivery are foundational pillars of IT governance.

143
MCQhard

In the context of workforce planning, what is the impact of shifting to Agile development practices on resource governance?

A.Necessity to shift from project-based resource allocation to stable, product-based team funding
B.Greater reliance on long-term, detailed resource planning cycles
C.Increased need for centralized resource pool management
D.Reduced requirement for developer cross-training
AnswerA

Agile models rely on stable teams rather than temporary project-based resourcing.

Why this answer

Agile requires dedicated, cross-functional teams, which necessitates a shift from project-based to product-based resource allocation.

144
MCQmedium

An enterprise is evaluating the trade-off between the cost of risk mitigation and the potential business benefit. Which framework or approach should the practitioner use?

A.Total Cost of Ownership (TCO) analysis.
B.Key Risk Indicator (KRI) dashboarding.
C.Business Impact Analysis (BIA).
D.Return on Security Investment (ROSI).
AnswerD

ROSI calculates the value of risk mitigation relative to the cost of controls.

Why this answer

Cost-benefit analysis in risk management is fundamental to risk optimization.

145
MCQeasy

Why must benefits be linked to strategic enterprise goals?

A.To ensure that IT projects contribute to the organization's mission and competitive advantage.
B.To make the project documentation look professional.
C.To keep the IT department busy.
D.To satisfy the project manager's requirements.
AnswerA

Strategic alignment is the fundamental justification for any investment.

Why this answer

Linking benefits to strategy ensures that IT investment contributes to the overall success and direction of the business.

146
MCQmedium

A project manager is calculating the Return on Investment (ROI) for an IT infrastructure upgrade. Which factor must be included in the 'Investment Cost' component of the ROI calculation?

A.The depreciation schedule of existing legacy assets.
B.The training costs for staff to operate the new infrastructure.
C.The projected increase in annual sales revenue.
D.The market value of competitor technology.
AnswerB

Implementation costs, such as training, are critical components of the total investment cost.

Why this answer

Total Cost of Ownership (TCO) includes not just acquisition, but implementation and operational overheads.

147
MCQeasy

When should an IT governance framework be reviewed?

A.Never, once it is implemented.
B.Only when an audit fails.
C.Every day.
D.At regular intervals and upon significant enterprise changes.
AnswerD

Proactive and trigger-based reviews ensure the framework stays relevant.

Why this answer

Frameworks should be reviewed periodically or when significant changes occur in business strategy or the internal/external environment.

148
MCQmedium

When implementing a benefits management plan, what is the primary role of the 'Benefits Owner'?

A.To manage the technical development life cycle of the software.
B.To authorize the release of funds from the enterprise budget.
C.To ensure that the business operational changes required to achieve the benefits are implemented.
D.To audit the project documentation for compliance with PMBOK standards.
AnswerC

Benefits owners are responsible for the business side of change management.

Why this answer

The benefits owner is accountable for ensuring that the business changes necessary to realize the value actually take place.

149
MCQeasy

What is the most effective way to communicate benefit realization status to stakeholders?

A.Hold a meeting only when the project fails.
B.Wait until the project is finished to report anything.
C.Send a 50-page technical document every month.
D.Use a visual dashboard that maps metrics to business objectives.
AnswerD

Dashboards facilitate quick, data-driven decisions.

Why this answer

Dashboards provide visual, easy-to-understand status updates relevant to stakeholders.

150
MCQhard

An enterprise is adopting a 'Risk-Based Approach' to IT governance. How should this impact the IT budget allocation?

A.Budget is focused entirely on upgrading legacy systems.
B.Budget is minimized to save costs across the board.
C.Budget is prioritized for areas with the highest risk exposure.
D.Budget is distributed equally across all IT departments.
AnswerC

Risk-based allocation ensures funds mitigate the most significant threats.

Why this answer

Resources should be prioritized where the most significant risks exist.

Page 1

Page 2 of 3

Page 3

All pages