Which THREE items should be included in a benefit realization plan?
Defined metrics are required to quantify achievement.
Why this answer
A benefits plan needs accountability, measurable metrics, and timing/frequency of review.
214 questions total · 3pages · All types, answers revealed
Page 3 of 3
Which THREE items should be included in a benefit realization plan?
Defined metrics are required to quantify achievement.
Why this answer
A benefits plan needs accountability, measurable metrics, and timing/frequency of review.
An IT audit reveals that risk mitigation activities are being performed, but they are not being tracked. What is the governance risk?
Without documentation, governance compliance cannot be proven.
Why this answer
Lack of tracking prevents verification and accountability.
An organization is updating its IT governance policies. Which element must be included to ensure policy enforcement?
Clear accountability is the foundation of policy enforcement.
Why this answer
Policies must define roles, responsibilities, and clear consequences or procedures for compliance to be enforceable.
An organization is migrating to a hybrid cloud environment. Which IT resource allocation strategy best aligns with CGEIT principles for optimizing cloud expenditure?
This provides accountability and visibility into resource consumption per business unit.
Why this answer
FinOps principles emphasize visibility, accountability, and optimization of cloud spend through chargeback models.
A dashboard shows that an IT project has achieved 90% of its technical deliverables, but only 20% of its anticipated benefits. What is the most appropriate management action?
You must investigate why the system isn't delivering value despite technical completion.
Why this answer
A gap between delivery and benefit usually implies a problem with adoption, business change, or strategy execution.
A project is expected to deliver cost savings through automation. Which metric is the best indicator of this benefit?
This directly quantifies the efficiency gain (the benefit).
Why this answer
The reduction in labor hours or headcount cost is a direct measure of automation benefits.
If an IT investment's benefits are being realized faster than planned, what is the governance board's role?
Identifying best practices from accelerated projects enhances future portfolio performance.
Why this answer
Accelerated benefit realization may offer opportunities to reinvest or adjust the portfolio strategy.
Which TWO of the following steps are critical when performing a benefits-based business case review?
Variance analysis is essential for any review.
Why this answer
Reviewing requires checking against the plan and assessing the continued relevance of the business case.
In the context of the COBIT 2019 framework, what does 'Governance' mean?
This is the core definition of governance within the COBIT framework.
Why this answer
Governance ensures that stakeholder needs, conditions, and options are evaluated to determine balanced, agreed-upon enterprise objectives.
When implementing a resource governance policy, which action is most critical to success?
Without leadership support and buy-in, policies are rarely followed.
Why this answer
Ensuring that the policy is supported by executive leadership and clearly communicated across the organization is essential for adoption.
Which THREE of the following are essential components of a risk reporting framework?
Provides the 'so what' for the reader.
Why this answer
Effective reports must be timely, relevant, and actionable for decision-makers.
An organization is struggling with high IT operational costs. Which governance practice is most likely to reduce these costs?
Standardization simplifies management, reduces complexity, and lowers support costs.
Why this answer
Standardization reduces complexity, technical debt, and support costs, leading to lower total cost of ownership (TCO).
A conflict arises between the IT department's desire for innovation and the business unit's desire for operational stability. What is the role of governance?
Governance is the mechanism to resolve such conflicts by aligning with the overall strategy.
Why this answer
Governance provides the framework (via the IT steering committee) to balance these competing priorities based on the organization's risk appetite and strategic goals.
A firm identifies that its IT governance framework is too burdensome for its agile, small-team structure. What is the most appropriate governance action?
Adjusting the governance system to fit the organizational context is a key principle of COBIT 2019.
Why this answer
COBIT 2019 suggests 'design factors' like enterprise size and agile development methodology to tailor the framework to be efficient and non-burdensome.
An organization is transitioning from a traditional project-based IT budget to a Value Stream-aligned funding model. Which mechanism is most effective for ensuring that IT investments remain tethered to realized enterprise value?
Value Stream KPIs provide the direct link between IT investment activities and the delivery of business value in a lean-agile funding model.
Why this answer
Establishing a value stream mapping process allows for the continuous monitoring of flow efficiency and value delivery, ensuring that funding is allocated to outcomes rather than just project outputs.
What is the primary benefit of categorizing IT investments into a portfolio?
Portfolio balance ensures resources support overall strategy.
Why this answer
Portfolio management allows the organization to balance risk, return, and strategic alignment across all investments.
Which role is typically responsible for the final acceptance of IT risks at the enterprise level?
Risk ownership and acceptance reside at the executive/board level.
Why this answer
Senior management/Board accountability is required for enterprise risk.
Which action should the governance body take if a major IT risk is identified that exceeds the enterprise's risk appetite?
Transparency and formal treatment plans are required for risks exceeding appetite.
Why this answer
When risk exceeds appetite, the board or governance committee must formally accept, mitigate, or transfer the risk.
A newly appointed CIO is establishing an IT governance framework. Which approach best ensures that IT governance activities are integrated into existing business decision-making processes?
Embedding roles ensures that governance is part of daily business operations.
Why this answer
Integrating IT governance into existing business processes ensures sustainability and adoption, rather than creating a siloed IT governance structure.
When establishing a Benefits Management Plan, which stakeholder group is primarily responsible for the ultimate realization of the benefits identified in the business case?
Business process owners are responsible for integrating the new IT capabilities into daily operations to achieve the defined business outcomes.
Why this answer
While IT delivers the capability, the business owners or operational managers are the ones who must change their processes and behaviors to realize the projected benefits.
What is the relationship between 'IT Risk' and 'Enterprise Risk'?
IT risks, when realized, impact the overall enterprise risk profile.
Why this answer
IT risk is a subset of enterprise risk.
Which of the following is an example of an 'indirect' benefit?
Intangible benefits like morale are indirect but valuable.
Why this answer
Indirect benefits are intangible or non-monetary improvements, such as improved brand reputation or employee morale.
Which THREE factors should the board of directors consider when establishing IT governance oversight mechanisms?
The board is ultimately responsible for enterprise compliance.
Why this answer
Board oversight must focus on risk appetite, strategic alignment, and compliance.
A project is technically sound, but the business units are resisting the change. What is the most likely cause?
Successful benefits realization requires winning over the people who must use the system.
Why this answer
Resistance to change often stems from a lack of involvement in the benefits design process.
Why should benefit realization planning start at the inception of an IT investment?
Defining metrics early provides a target for the project to aim at.
Why this answer
Early planning ensures that the project is designed with the end-state business objectives in mind.
A large enterprise is transitioning to a hybrid cloud environment. How should the governance policy be updated to maintain effective oversight?
Effective cloud governance requires recognizing the shared responsibility model in policy.
Why this answer
Governance policies must evolve to cover new risk models, such as shared responsibility in cloud environments, ensuring oversight remains intact.
The IT steering committee is evaluating a high-cost digital transformation project. What should the committee prioritize to ensure strategic alignment?
Steering committees must focus on how investments deliver business value.
Why this answer
The primary role of the steering committee is to ensure the project supports the enterprise's strategic objectives.
Which stakeholder is ultimately accountable for the governance of IT in an enterprise?
The Board holds ultimate accountability for the enterprise's governance.
Why this answer
The Board of Directors and senior executive management are ultimately accountable for the enterprise and its governance, including IT.
What is the primary objective of 'IT resource management' as part of IT governance?
Resource optimization is the core of this governance domain.
Why this answer
The objective is to optimize the investment in and use of IT resources (people, hardware, software, information).
Which TWO of the following are primary objectives of IT risk governance?
Core governance goal.
Why this answer
Governance focuses on ensuring risk management aligns with strategy and business value.
When assessing the feasibility of a project, why is it necessary to evaluate the 'risk of benefit realization'?
Evaluating realization risk prevents investing in projects with low ROI probability.
Why this answer
If the risk of not achieving the benefit is too high, the project might not be a sound investment regardless of its cost.
Which document is essential for formalizing the relationship and expectations between IT and the business units?
SLAs are the standard governance tool for defining service delivery expectations.
Why this answer
The Service Level Agreement (SLA) is the formal document that sets the requirements, responsibilities, and performance expectations for IT services.
Which THREE items are necessary to calculate the 'Total Cost of Ownership' (TCO) for a new IT project?
Labor is a significant implementation cost.
Why this answer
TCO encompasses all costs, including acquisition, implementation, and ongoing operational support.
An IT project is nearing completion. Which activity best signifies that the 'Value Delivery' phase is beginning?
Value is realized when the business begins to operate differently.
Why this answer
Value delivery occurs when the solution is operationalized and the business starts changing to realize the benefits.
What is the primary benefit of asset management within IT resource governance?
Asset management is the foundation for knowing what exists, what is used, and what is compliant.
Why this answer
Effective asset management provides the visibility required to optimize utilization and ensure compliance.
A project delivers a new system, but the benefits are not realized due to an outdated manual process that was not updated. Where did the benefits management plan fail?
Technology alone does not deliver value without process change.
Why this answer
The plan failed to address the business process changes required to make the technology effective.
An organization is merging with another company. How should the governance structures be reconciled?
This is the standard approach to integrating governance after a merger.
Why this answer
The governance team must perform a gap analysis of both frameworks and synthesize them to support the new, combined organizational strategy.
Which TWO stakeholders are essential for successful IT governance?
The executing authority.
Why this answer
The Board of Directors and the Executive Management are the essential top-level stakeholders for governance.
The board of directors is concerned about the impact of recent cybersecurity threats on the company's reputation. Which TWO of the following actions should the Governance committee prioritize to address these concerns?
Ensures the board's strategic concerns (reputation) are translated into risk tolerance.
Why this answer
Aligning risk reporting with board interests and ensuring management accountability are key responsibilities of the governance committee.
When planning for the retirement of legacy systems, which factor is most critical for resource optimization?
Without this, retirement can cause unforeseen failures and inefficient resource allocation.
Why this answer
Understanding the dependencies of the legacy system is crucial to avoiding operational disruption and ensuring resources are not wasted maintaining unnecessary components.
Which TWO of the following are considered key elements of a robust Benefits Realization Plan (BRP)?
Accountability is a core component of a valid BRP.
Why this answer
A BRP must identify the specific benefits and define the metrics/accountability for achieving those benefits to be effective.
When a risk event occurs, what is the first step in the incident response process from a governance perspective?
Containment is the immediate priority to minimize loss.
Why this answer
The first step is to contain the issue and notify the appropriate parties.
What is the primary purpose of an IT governance framework?
This encompasses the core intent of IT governance frameworks.
Why this answer
The purpose is to ensure that IT goals align with business goals and that risks are managed while resources are used responsibly.
Which THREE metrics are commonly used to measure the success of an IT investment?
Customer impact is a key qualitative success metric.
Why this answer
Success is measured by financial returns, operational efficiency, and strategic outcomes.
A multinational corporation is struggling with IT strategic alignment. The board wants to ensure IT investments directly correlate to business value. Which metric should the governance committee prioritize?
This is the most direct measure of strategic alignment as it tracks the link between IT output and business outcomes.
Why this answer
Strategic alignment is best measured by the ratio of IT project benefits realized compared to the planned business value, linking IT spend to financial outcomes.
Which document outlines the authority and responsibilities of the IT governance committee?
The charter is the foundational document for any governance committee.
Why this answer
The committee charter is the formal document that defines the purpose, authority, and responsibilities of a governance body.
Which THREE of the following represent effective ways to integrate IT risk into the organizational culture?
Education builds awareness.
Why this answer
Culture change requires leadership, training, and incentive alignment.
What is the most effective way to ensure that IT risk management is integrated with enterprise risk management (ERM)?
A common language and threshold structure ensures risks are comparable across the enterprise.
Why this answer
Common language and metrics are required for cross-departmental risk alignment.
An organization has decentralized its IT operations, leading to fragmented governance. Which action will best restore governance oversight while retaining operational agility?
Federated governance balances centralized oversight with local operational flexibility.
Why this answer
Federated governance models allow for central policy setting and oversight while allowing local operational autonomy.
Which THREE of the following are elements of a strong IT resource governance policy?
Metrics are necessary to monitor and improve performance.
Why this answer
Clear definitions of roles, standard processes for allocation, and defined metrics for success are essential for a governance policy.
Which THREE of the following are essential elements of an IT risk governance policy?
Ensures that significant risks are known and managed.
Why this answer
Risk governance policies must define the risk appetite, the responsibilities for managing risk, and the reporting process for risk exposure.
Which of the following is the primary purpose of a Key Risk Indicator (KRI)?
KRIs are designed to detect trends that lead to risk realization.
Why this answer
KRIs are early warning signs that risk exposure is changing.
A firm is experiencing 'IT resource starvation' in key strategic projects due to excessive operational support requirements. What is the appropriate governance response?
This is the correct approach to ensure resources are directed toward business-critical goals.
Why this answer
Rebalancing resources from 'run' (operations) to 'grow/transform' (strategic) is necessary to achieve strategic objectives.
An IT project is failing to deliver promised business value. What is the most likely governance failure?
If IT is not aligned with business value, it will fail to deliver results.
Why this answer
Value delivery is directly linked to effective risk and performance management.
Why should IT projects include a 'disbenefit' analysis in their business case?
Full disclosure of both pros and cons is necessary for governance.
Why this answer
Ignoring disbenefits makes the business case look artificially positive and leads to poor decision-making.
Which TWO are common IT governance structures?
Standard governance body.
Why this answer
The IT steering committee and the architecture board are classic governance structures.
A firm is experiencing 'governance drift' where IT initiatives are no longer aligned with corporate strategy. Which action should the governance committee take first?
Updating the design factors is the COBIT-prescribed way to adjust a governance system to shifting business strategy.
Why this answer
The first step in addressing governance drift is to re-evaluate the strategic goals and determine if the governance framework needs re-designing to accommodate changes.
Which THREE types of risks should IT governance oversee?
Risks to daily service.
Why this answer
Operational, strategic, and compliance risks are the primary categories of risk within IT governance.
A large multinational corporation is transitioning to COBIT 2019. The governance board needs to prioritize governance objectives. Which action should the IT governance lead take first?
Design factors are the primary mechanism for tailoring the governance system.
Why this answer
The first step in COBIT 2019 is to perform a design factors analysis to tailor the governance system to the enterprise's unique context.
An organization realizes its IT strategy is not yielding the expected business benefits. What is the most effective approach to remediate this?
Alignment review ensures IT is focusing on the right things to generate value.
Why this answer
The strategy itself must be reviewed and re-aligned with business goals, possibly leading to a shift in the portfolio.
The board of directors requests a summary of the current IT risk posture. Which documentation should the practitioner use as the primary source?
The register is the official repository for high-level enterprise risks.
Why this answer
The enterprise risk register provides the consolidated view required by the board.
An enterprise is adopting a 'Benefits-led' approach to IT governance. Which artifact is the most critical for documenting the causal link between IT-enabled outcomes and organizational strategy?
The BDM is the standard tool for showing the logical, causal links between project outputs, outcomes, and enterprise benefits.
Why this answer
A Benefits Dependency Map (or Benefit Map) explicitly links the IT investment to intermediate capabilities and final business outcomes, proving the causal chain.
If a project is completed but the expected benefits are not realized, what is the best initial step for a CGEIT professional?
The network helps visualize where the chain broke, such as lack of training or process change.
Why this answer
The professional must investigate the cause, which usually lies in the gap between technical delivery and operational adoption.
A company is struggling with shadow IT. Which governance strategy is most effective?
Addressing the root cause and providing better alternatives is the governance-led approach.
Why this answer
Shadow IT is usually a symptom of a slow or restrictive IT process. The governance approach is to improve IT service agility while providing secure, compliant alternatives.
Page 3 of 3
Practice CGEIT by domain
Target a specific domain to shore up weak areas.
See all domains with question counts →