Courseiva

ISACA Certified in the Governance of Enterprise IT (CGEIT) (CGEIT) (CGEIT) — Questions 151214

214 questions total · 3pages · All types, answers revealed

Page 2

Page 3 of 3

151
Multi-Selectmedium

Which THREE items should be included in a benefit realization plan?

Select 3 answers
A.The list of technical software vulnerabilities.
B.The specific metrics to measure the benefit.
C.The target date for the realization of the benefit.
D.The server hardware specifications.
E.The name of the benefit owner.
AnswersB, C, E

Defined metrics are required to quantify achievement.

Why this answer

A benefits plan needs accountability, measurable metrics, and timing/frequency of review.

152
MCQhard

An IT audit reveals that risk mitigation activities are being performed, but they are not being tracked. What is the governance risk?

A.The hardware will become obsolete faster.
B.There is no evidence to demonstrate that risks are being effectively managed.
C.The IT department will be overstaffed.
D.The budget will be spent on unnecessary tools.
AnswerB

Without documentation, governance compliance cannot be proven.

Why this answer

Lack of tracking prevents verification and accountability.

153
MCQmedium

An organization is updating its IT governance policies. Which element must be included to ensure policy enforcement?

A.A copy of the IT department's budget spreadsheet
B.Defined roles, responsibilities, and accountability mechanisms
C.A detailed technical configuration guide for all servers
D.A list of all software vendor names used by the company
AnswerB

Clear accountability is the foundation of policy enforcement.

Why this answer

Policies must define roles, responsibilities, and clear consequences or procedures for compliance to be enforceable.

154
MCQmedium

An organization is migrating to a hybrid cloud environment. Which IT resource allocation strategy best aligns with CGEIT principles for optimizing cloud expenditure?

A.Transition all workloads to on-demand instances to ensure maximum agility
B.Standardize on a single cloud service provider to simplify vendor management
C.Automate infrastructure provisioning through Infrastructure as Code (IaC) without budget gates
D.Implement a centralized tag-based chargeback and showback model
AnswerD

This provides accountability and visibility into resource consumption per business unit.

Why this answer

FinOps principles emphasize visibility, accountability, and optimization of cloud spend through chargeback models.

155
MCQmedium

A dashboard shows that an IT project has achieved 90% of its technical deliverables, but only 20% of its anticipated benefits. What is the most appropriate management action?

A.Reduce the budget for the remainder of the project.
B.Review the benefits realization plan to assess organizational change progress.
C.Accelerate the technical project completion to reach 100%.
D.Lower the benefit targets to match the current progress.
AnswerB

You must investigate why the system isn't delivering value despite technical completion.

Why this answer

A gap between delivery and benefit usually implies a problem with adoption, business change, or strategy execution.

156
MCQmedium

A project is expected to deliver cost savings through automation. Which metric is the best indicator of this benefit?

A.The number of users trained on the new system.
B.The number of systems upgraded.
C.The total budget spent on software licenses.
D.The reduction in manual labor hours per transaction.
AnswerD

This directly quantifies the efficiency gain (the benefit).

Why this answer

The reduction in labor hours or headcount cost is a direct measure of automation benefits.

157
MCQhard

If an IT investment's benefits are being realized faster than planned, what is the governance board's role?

A.Analyze the cause of the acceleration to see if it can be replicated in other projects.
B.Terminate the project immediately to save remaining funds.
C.Double the budget to see if benefits can be increased even further.
D.Ignore the acceleration and continue with the original plan.
AnswerA

Identifying best practices from accelerated projects enhances future portfolio performance.

Why this answer

Accelerated benefit realization may offer opportunities to reinvest or adjust the portfolio strategy.

158
Multi-Selecthard

Which TWO of the following steps are critical when performing a benefits-based business case review?

Select 2 answers
A.Updating the project team's contact list.
B.Comparing current project performance against the business case.
C.Checking if the project complies with the latest IT security standards.
D.Validating that the business environment and strategic priorities have not changed significantly.
E.Reviewing the technical code repository.
AnswersB, D

Variance analysis is essential for any review.

Why this answer

Reviewing requires checking against the plan and assessing the continued relevance of the business case.

159
MCQmedium

In the context of the COBIT 2019 framework, what does 'Governance' mean?

A.Execution of technical tasks.
B.Evaluation, direction, and monitoring of enterprise activities.
C.Managing the budget of the IT department.
D.Developing software applications.
AnswerB

This is the core definition of governance within the COBIT framework.

Why this answer

Governance ensures that stakeholder needs, conditions, and options are evaluated to determine balanced, agreed-upon enterprise objectives.

160
MCQhard

When implementing a resource governance policy, which action is most critical to success?

A.Hiring a dedicated resource governance manager
B.Automating all policy enforcement mechanisms
C.Creating a 500-page policy document covering every scenario
D.Securing executive sponsorship and driving organizational buy-in
AnswerD

Without leadership support and buy-in, policies are rarely followed.

Why this answer

Ensuring that the policy is supported by executive leadership and clearly communicated across the organization is essential for adoption.

161
Multi-Selectmedium

Which THREE of the following are essential components of a risk reporting framework?

Select 3 answers
A.Actionable insights and trends.
B.Clear identification of the target audience.
C.A comprehensive list of every single IT asset.
D.Definition of risk appetite thresholds.
E.The source code of the reporting software.
AnswersA, B, D

Provides the 'so what' for the reader.

Why this answer

Effective reports must be timely, relevant, and actionable for decision-makers.

162
MCQmedium

An organization is struggling with high IT operational costs. Which governance practice is most likely to reduce these costs?

A.Increasing the frequency of vendor contract renegotiations
B.Outsourcing all IT infrastructure management
C.Standardizing hardware and software platforms across the enterprise
D.Eliminating the IT governance committee
AnswerC

Standardization simplifies management, reduces complexity, and lowers support costs.

Why this answer

Standardization reduces complexity, technical debt, and support costs, leading to lower total cost of ownership (TCO).

163
MCQhard

A conflict arises between the IT department's desire for innovation and the business unit's desire for operational stability. What is the role of governance?

A.The IT department should always win for innovation.
B.The governance framework should facilitate a balance based on strategic priorities.
C.The business unit should always win for stability.
D.The board should ignore the conflict.
AnswerB

Governance is the mechanism to resolve such conflicts by aligning with the overall strategy.

Why this answer

Governance provides the framework (via the IT steering committee) to balance these competing priorities based on the organization's risk appetite and strategic goals.

164
MCQhard

A firm identifies that its IT governance framework is too burdensome for its agile, small-team structure. What is the most appropriate governance action?

A.Standardize all processes across the company.
B.Tailor the governance system by adjusting design factors.
C.Ignore the framework until the company grows.
D.Appoint more auditors to monitor compliance.
AnswerB

Adjusting the governance system to fit the organizational context is a key principle of COBIT 2019.

Why this answer

COBIT 2019 suggests 'design factors' like enterprise size and agile development methodology to tailor the framework to be efficient and non-burdensome.

165
MCQmedium

An organization is transitioning from a traditional project-based IT budget to a Value Stream-aligned funding model. Which mechanism is most effective for ensuring that IT investments remain tethered to realized enterprise value?

A.Integrating Value Stream Key Performance Indicators (KPIs) into the portfolio governance cycle.
B.Automating the project portfolio management (PPM) approval workflow.
C.Implementing a formal Chargeback accounting system.
D.Moving to a strict Capital Expenditure (CAPEX) prioritization process.
AnswerA

Value Stream KPIs provide the direct link between IT investment activities and the delivery of business value in a lean-agile funding model.

Why this answer

Establishing a value stream mapping process allows for the continuous monitoring of flow efficiency and value delivery, ensuring that funding is allocated to outcomes rather than just project outputs.

166
MCQeasy

What is the primary benefit of categorizing IT investments into a portfolio?

A.To ensure every project is completed at the same time.
B.To balance the investment mix between innovation, growth, and maintenance.
C.To force all projects to use the same software vendor.
D.To reduce the cost of IT staff salaries.
AnswerB

Portfolio balance ensures resources support overall strategy.

Why this answer

Portfolio management allows the organization to balance risk, return, and strategic alignment across all investments.

167
MCQeasy

Which role is typically responsible for the final acceptance of IT risks at the enterprise level?

A.The Network Engineer.
B.The external auditor.
C.The IT Security Manager.
D.The Chief Information Officer (CIO) or the Board.
AnswerD

Risk ownership and acceptance reside at the executive/board level.

Why this answer

Senior management/Board accountability is required for enterprise risk.

168
MCQmedium

Which action should the governance body take if a major IT risk is identified that exceeds the enterprise's risk appetite?

A.Formally communicate the risk to the board and propose a risk treatment plan
B.Wait for the risk to manifest before taking action
C.Re-evaluate the definition of risk appetite to match the current state
D.Request the IT department to simply delete the system causing the risk
E.Ignore the risk if it helps achieve a short-term profit target
AnswerA

Transparency and formal treatment plans are required for risks exceeding appetite.

Why this answer

When risk exceeds appetite, the board or governance committee must formally accept, mitigate, or transfer the risk.

169
MCQmedium

A newly appointed CIO is establishing an IT governance framework. Which approach best ensures that IT governance activities are integrated into existing business decision-making processes?

A.Embedding IT governance roles and responsibilities into existing business management functions
B.Requiring all IT decisions to be signed off by the board of directors
C.Implementing an IT-only governance framework based strictly on COBIT 2019
D.Creating a separate IT governance committee with independent reporting lines
AnswerA

Embedding roles ensures that governance is part of daily business operations.

Why this answer

Integrating IT governance into existing business processes ensures sustainability and adoption, rather than creating a siloed IT governance structure.

170
MCQeasy

When establishing a Benefits Management Plan, which stakeholder group is primarily responsible for the ultimate realization of the benefits identified in the business case?

A.The Project Management Office (PMO) Manager.
B.The Business Process Owners.
C.The Chief Information Officer (CIO).
D.The Enterprise Architect.
AnswerB

Business process owners are responsible for integrating the new IT capabilities into daily operations to achieve the defined business outcomes.

Why this answer

While IT delivers the capability, the business owners or operational managers are the ones who must change their processes and behaviors to realize the projected benefits.

171
MCQeasy

What is the relationship between 'IT Risk' and 'Enterprise Risk'?

A.They are exactly the same thing.
B.Enterprise risk is a subset of IT risk.
C.IT risk is entirely separate from enterprise risk.
D.IT risk is a subset of enterprise risk and must be managed together.
AnswerD

IT risks, when realized, impact the overall enterprise risk profile.

Why this answer

IT risk is a subset of enterprise risk.

172
MCQhard

Which of the following is an example of an 'indirect' benefit?

A.Improved employee morale and productivity due to better UI.
B.Increased revenue from new digital sales channels.
C.Decrease in server hardware acquisition costs.
D.Reduction in annual software maintenance costs.
AnswerA

Intangible benefits like morale are indirect but valuable.

Why this answer

Indirect benefits are intangible or non-monetary improvements, such as improved brand reputation or employee morale.

173
Multi-Selecthard

Which THREE factors should the board of directors consider when establishing IT governance oversight mechanisms?

Select 3 answers
A.Regulatory and compliance requirements.
B.Alignment of IT initiatives with business strategy.
C.Enterprise risk appetite.
D.Daily network uptime statistics.
E.Detailed software configuration standards.
AnswersA, B, C

The board is ultimately responsible for enterprise compliance.

Why this answer

Board oversight must focus on risk appetite, strategic alignment, and compliance.

174
MCQhard

A project is technically sound, but the business units are resisting the change. What is the most likely cause?

A.The benefits realization plan did not include change management or stakeholder engagement.
B.The technical documentation is missing.
C.The budget was too high.
D.The project was finished too quickly.
AnswerA

Successful benefits realization requires winning over the people who must use the system.

Why this answer

Resistance to change often stems from a lack of involvement in the benefits design process.

175
MCQeasy

Why should benefit realization planning start at the inception of an IT investment?

A.To secure the budget before the project is approved.
B.To identify technical risks in the software architecture.
C.To ensure that the project team is selected correctly.
D.To ensure that the desired business outcomes are clearly defined and measurable.
AnswerD

Defining metrics early provides a target for the project to aim at.

Why this answer

Early planning ensures that the project is designed with the end-state business objectives in mind.

176
MCQmedium

A large enterprise is transitioning to a hybrid cloud environment. How should the governance policy be updated to maintain effective oversight?

A.Develop policies addressing shared responsibility and cloud governance controls.
B.Centralize all IT infrastructure back to on-premises.
C.Shift all responsibility for security to the cloud provider.
D.Eliminate the need for internal IT policies.
AnswerA

Effective cloud governance requires recognizing the shared responsibility model in policy.

Why this answer

Governance policies must evolve to cover new risk models, such as shared responsibility in cloud environments, ensuring oversight remains intact.

177
MCQmedium

The IT steering committee is evaluating a high-cost digital transformation project. What should the committee prioritize to ensure strategic alignment?

A.The potential for technical debt reduction.
B.The specific vendor selection process used for the software purchase.
C.The business value proposition and contribution to organizational goals.
D.Detailed technical architectural specifications.
AnswerC

Steering committees must focus on how investments deliver business value.

Why this answer

The primary role of the steering committee is to ensure the project supports the enterprise's strategic objectives.

178
MCQeasy

Which stakeholder is ultimately accountable for the governance of IT in an enterprise?

A.The IT Steering Committee
B.The Internal Audit department
C.The Chief Information Officer (CIO)
D.The Board of Directors
AnswerD

The Board holds ultimate accountability for the enterprise's governance.

Why this answer

The Board of Directors and senior executive management are ultimately accountable for the enterprise and its governance, including IT.

179
MCQeasy

What is the primary objective of 'IT resource management' as part of IT governance?

A.To ensure IT staff are working 40 hours per week
B.To eliminate the need for IT staff through automation
C.To buy the cheapest available technology
D.To optimize the allocation and use of IT resources to support the business
AnswerD

Resource optimization is the core of this governance domain.

Why this answer

The objective is to optimize the investment in and use of IT resources (people, hardware, software, information).

180
Multi-Selecteasy

Which TWO of the following are primary objectives of IT risk governance?

Select 2 answers
A.Fixing broken computer keyboards.
B.Ensuring risk management processes deliver value.
C.Increasing the IT budget by 20% annually.
D.Ensuring that IT risks are aligned with business strategy.
E.Writing code for the software developers.
AnswersB, D

Core governance goal.

Why this answer

Governance focuses on ensuring risk management aligns with strategy and business value.

181
MCQhard

When assessing the feasibility of a project, why is it necessary to evaluate the 'risk of benefit realization'?

A.To ensure the project follows the vendor's best practices.
B.To ensure the technical project has no bugs.
C.To reduce the number of stakeholders involved.
D.To determine if the expected value can realistically be achieved under current conditions.
AnswerD

Evaluating realization risk prevents investing in projects with low ROI probability.

Why this answer

If the risk of not achieving the benefit is too high, the project might not be a sound investment regardless of its cost.

182
MCQeasy

Which document is essential for formalizing the relationship and expectations between IT and the business units?

A.Governance Policy Statement.
B.Project Charter.
C.IT Strategic Plan.
D.Service Level Agreement (SLA).
AnswerD

SLAs are the standard governance tool for defining service delivery expectations.

Why this answer

The Service Level Agreement (SLA) is the formal document that sets the requirements, responsibilities, and performance expectations for IT services.

183
Multi-Selecthard

Which THREE items are necessary to calculate the 'Total Cost of Ownership' (TCO) for a new IT project?

Select 3 answers
A.The number of users who will be trained.
B.Project staff salaries during the development phase.
C.Hardware and software acquisition costs.
D.The predicted revenue increase.
E.Ongoing annual maintenance and support costs.
AnswersB, C, E

Labor is a significant implementation cost.

Why this answer

TCO encompasses all costs, including acquisition, implementation, and ongoing operational support.

184
MCQhard

An IT project is nearing completion. Which activity best signifies that the 'Value Delivery' phase is beginning?

A.The project management office closes the project file.
B.The vendor invoice is paid in full.
C.The business operations teams begin using the system to execute new processes.
D.The final code is checked into the repository.
AnswerC

Value is realized when the business begins to operate differently.

Why this answer

Value delivery occurs when the solution is operationalized and the business starts changing to realize the benefits.

185
MCQeasy

What is the primary benefit of asset management within IT resource governance?

A.Reducing the need for IT staff
B.Ensuring all hardware is painted the same color
C.Automating the password reset process
D.Providing visibility into the IT inventory for optimization and compliance
AnswerD

Asset management is the foundation for knowing what exists, what is used, and what is compliant.

Why this answer

Effective asset management provides the visibility required to optimize utilization and ensure compliance.

186
MCQhard

A project delivers a new system, but the benefits are not realized due to an outdated manual process that was not updated. Where did the benefits management plan fail?

A.In the software coding standards.
B.In the technical design phase.
C.In the business change management and process alignment components.
D.In the project budget management.
AnswerC

Technology alone does not deliver value without process change.

Why this answer

The plan failed to address the business process changes required to make the technology effective.

187
MCQhard

An organization is merging with another company. How should the governance structures be reconciled?

A.Adopt the framework of the company with more employees.
B.Keep both frameworks as they are.
C.Abandon both frameworks and start from scratch.
D.Conduct a gap analysis and develop a unified governance framework.
AnswerD

This is the standard approach to integrating governance after a merger.

Why this answer

The governance team must perform a gap analysis of both frameworks and synthesize them to support the new, combined organizational strategy.

188
Multi-Selectmedium

Which TWO stakeholders are essential for successful IT governance?

Select 2 answers
A.Local IT repair technicians
B.Delivery drivers
C.Executive Management
D.Board of Directors
E.External janitorial staff
AnswersC, D

The executing authority.

Why this answer

The Board of Directors and the Executive Management are the essential top-level stakeholders for governance.

189
Multi-Selectmedium

The board of directors is concerned about the impact of recent cybersecurity threats on the company's reputation. Which TWO of the following actions should the Governance committee prioritize to address these concerns?

Select 2 answers
A.Directing the CISO to provide a summary of all blocked network packets.
B.Reviewing the alignment of the current risk appetite with the brand resilience strategy.
C.Requiring the IT department to upgrade all legacy hardware immediately.
D.Changing the password rotation policy for all employees.
E.Requesting a report on the effectiveness of current incident response and crisis communication plans.
AnswersB, E

Ensures the board's strategic concerns (reputation) are translated into risk tolerance.

Why this answer

Aligning risk reporting with board interests and ensuring management accountability are key responsibilities of the governance committee.

190
MCQhard

When planning for the retirement of legacy systems, which factor is most critical for resource optimization?

A.Detailed mapping of interdependencies and data flows with current systems
B.The initial cost of implementing the system
C.The amount of documentation available for the system
D.The age of the hardware
AnswerA

Without this, retirement can cause unforeseen failures and inefficient resource allocation.

Why this answer

Understanding the dependencies of the legacy system is crucial to avoiding operational disruption and ensuring resources are not wasted maintaining unnecessary components.

191
Multi-Selecteasy

Which TWO of the following are considered key elements of a robust Benefits Realization Plan (BRP)?

Select 2 answers
A.Detailed software vendor licensing terms.
B.Project team contact list.
C.Technical architectural diagrams.
D.Clear identification of benefits and their owners.
E.Defined metrics and baseline performance measurements.
AnswersD, E

Accountability is a core component of a valid BRP.

Why this answer

A BRP must identify the specific benefits and define the metrics/accountability for achieving those benefits to be effective.

192
MCQeasy

When a risk event occurs, what is the first step in the incident response process from a governance perspective?

A.Draft a press release.
B.Contain the threat to prevent further business impact.
C.Identify the person responsible for the incident.
D.Perform a root cause analysis.
AnswerB

Containment is the immediate priority to minimize loss.

Why this answer

The first step is to contain the issue and notify the appropriate parties.

193
MCQeasy

What is the primary purpose of an IT governance framework?

A.To automate IT operations.
B.To ensure 100% system uptime.
C.To provide a structured approach for achieving IT value and managing risk.
D.To minimize IT costs at all times.
AnswerC

This encompasses the core intent of IT governance frameworks.

Why this answer

The purpose is to ensure that IT goals align with business goals and that risks are managed while resources are used responsibly.

194
Multi-Selecthard

Which THREE metrics are commonly used to measure the success of an IT investment?

Select 3 answers
A.Total cost of software development.
B.Customer satisfaction or Net Promoter Score (NPS).
C.Return on Investment (ROI).
D.Net Present Value (NPV).
E.The number of hours the development team worked.
AnswersB, C, D

Customer impact is a key qualitative success metric.

Why this answer

Success is measured by financial returns, operational efficiency, and strategic outcomes.

195
MCQhard

A multinational corporation is struggling with IT strategic alignment. The board wants to ensure IT investments directly correlate to business value. Which metric should the governance committee prioritize?

A.Percentage of IT initiatives that directly contribute to documented business strategy goals.
B.Total cost of ownership (TCO) of IT assets.
C.System uptime and availability percentages.
D.IT project delivery on time and within budget.
AnswerA

This is the most direct measure of strategic alignment as it tracks the link between IT output and business outcomes.

Why this answer

Strategic alignment is best measured by the ratio of IT project benefits realized compared to the planned business value, linking IT spend to financial outcomes.

196
MCQeasy

Which document outlines the authority and responsibilities of the IT governance committee?

A.The committee charter.
B.The annual financial report.
C.The IT project plan.
D.The employee handbook.
AnswerA

The charter is the foundational document for any governance committee.

Why this answer

The committee charter is the formal document that defines the purpose, authority, and responsibilities of a governance body.

197
Multi-Selecthard

Which THREE of the following represent effective ways to integrate IT risk into the organizational culture?

Select 3 answers
A.Regular risk management training for all staff.
B.Changing the corporate logo.
C.Linking performance bonuses to risk management outcomes.
D.Executive sponsorship of risk management initiatives.
E.Reducing the number of IT staff.
AnswersA, C, D

Education builds awareness.

Why this answer

Culture change requires leadership, training, and incentive alignment.

198
MCQmedium

What is the most effective way to ensure that IT risk management is integrated with enterprise risk management (ERM)?

A.Moving the IT risk management function under the responsibility of the Chief Financial Officer.
B.Requiring IT to report risks directly to the Chief Risk Officer on a weekly basis.
C.Mandating that IT uses the same risk assessment software as the finance department.
D.Aligning the IT risk taxonomy and reporting thresholds with the corporate ERM framework.
AnswerD

A common language and threshold structure ensures risks are comparable across the enterprise.

Why this answer

Common language and metrics are required for cross-departmental risk alignment.

199
MCQhard

An organization has decentralized its IT operations, leading to fragmented governance. Which action will best restore governance oversight while retaining operational agility?

A.Mandate that all business units use the same IT software stack
B.Standardize all IT purchasing processes across the enterprise
C.Implement a federated governance structure with central policy oversight
D.Centralize all IT functions and reporting lines under the CIO
AnswerC

Federated governance balances centralized oversight with local operational flexibility.

Why this answer

Federated governance models allow for central policy setting and oversight while allowing local operational autonomy.

200
Multi-Selecthard

Which THREE of the following are elements of a strong IT resource governance policy?

Select 3 answers
A.A list of all individual employee salaries
B.A list of all vendor passwords
C.Defined KPIs and metrics to measure the effectiveness of resource usage
D.Standardized processes for requesting, approving, and allocating resources
E.Clearly defined roles, responsibilities, and decision-making authorities
AnswersC, D, E

Metrics are necessary to monitor and improve performance.

Why this answer

Clear definitions of roles, standard processes for allocation, and defined metrics for success are essential for a governance policy.

201
Multi-Selecthard

Which THREE of the following are essential elements of an IT risk governance policy?

Select 3 answers
A.Procedures for reporting and escalating risks
B.The physical location of all backup tapes
C.Defined enterprise risk appetite and tolerance levels
D.A list of all software vendors currently in use
E.Clear roles and responsibilities for risk ownership
AnswersA, C, E

Ensures that significant risks are known and managed.

Why this answer

Risk governance policies must define the risk appetite, the responsibilities for managing risk, and the reporting process for risk exposure.

202
MCQeasy

Which of the following is the primary purpose of a Key Risk Indicator (KRI)?

A.To serve as an early warning signal of potential risk events.
B.To ensure that all employees have completed security awareness training.
C.To provide a detailed log of all security threats blocked by the firewall.
D.To measure the success of past risk mitigation strategies.
AnswerA

KRIs are designed to detect trends that lead to risk realization.

Why this answer

KRIs are early warning signs that risk exposure is changing.

203
MCQmedium

A firm is experiencing 'IT resource starvation' in key strategic projects due to excessive operational support requirements. What is the appropriate governance response?

A.Conduct a portfolio review to rebalance resource allocation from 'keep-the-lights-on' activities to strategic initiatives
B.Force strategic projects to operate with lower performance requirements
C.Require all IT staff to work overtime to complete projects
D.Increase the overall IT budget to hire more staff
AnswerA

This is the correct approach to ensure resources are directed toward business-critical goals.

Why this answer

Rebalancing resources from 'run' (operations) to 'grow/transform' (strategic) is necessary to achieve strategic objectives.

204
MCQhard

An IT project is failing to deliver promised business value. What is the most likely governance failure?

A.The IT team was not using the latest programming language.
B.Inadequate alignment between IT risk management and business value objectives.
C.The IT budget was slightly over the projected amount.
D.The project manager lacked a certification.
AnswerB

If IT is not aligned with business value, it will fail to deliver results.

Why this answer

Value delivery is directly linked to effective risk and performance management.

205
MCQmedium

Why should IT projects include a 'disbenefit' analysis in their business case?

A.To increase the project budget.
B.To reduce the amount of documentation required.
C.To provide a transparent and realistic view of the project's impact.
D.To satisfy the software vendor's requirements.
AnswerC

Full disclosure of both pros and cons is necessary for governance.

Why this answer

Ignoring disbenefits makes the business case look artificially positive and leads to poor decision-making.

206
Multi-Selecteasy

Which TWO are common IT governance structures?

Select 2 answers
A.Architecture Review Board
B.Coffee and Donut Club
C.Software testing team
D.Help desk support
E.IT Steering Committee
AnswersA, E

Standard governance body.

Why this answer

The IT steering committee and the architecture board are classic governance structures.

207
MCQhard

A firm is experiencing 'governance drift' where IT initiatives are no longer aligned with corporate strategy. Which action should the governance committee take first?

A.Perform a review of business strategy and IT design factors.
B.Replace the existing CIO.
C.Conduct an audit of all current IT projects.
D.Increase the IT budget to support more initiatives.
AnswerA

Updating the design factors is the COBIT-prescribed way to adjust a governance system to shifting business strategy.

Why this answer

The first step in addressing governance drift is to re-evaluate the strategic goals and determine if the governance framework needs re-designing to accommodate changes.

208
Multi-Selecthard

Which THREE types of risks should IT governance oversee?

Select 3 answers
A.Operational risks
B.Risk of office plant death
C.Risk of printer paper jam
D.Compliance risks
E.Strategic risks
AnswersA, D, E

Risks to daily service.

Why this answer

Operational, strategic, and compliance risks are the primary categories of risk within IT governance.

209
MCQmedium

A large multinational corporation is transitioning to COBIT 2019. The governance board needs to prioritize governance objectives. Which action should the IT governance lead take first?

A.Conduct a design factors assessment.
B.Implement the IT Balanced Scorecard.
C.Adopt all 40 governance objectives immediately.
D.Draft new board-level IT policies.
AnswerA

Design factors are the primary mechanism for tailoring the governance system.

Why this answer

The first step in COBIT 2019 is to perform a design factors analysis to tailor the governance system to the enterprise's unique context.

210
MCQhard

An organization realizes its IT strategy is not yielding the expected business benefits. What is the most effective approach to remediate this?

A.Increase the frequency of software deployments.
B.Cancel all current IT projects.
C.Perform a strategic alignment review to identify gaps between IT capabilities and business needs.
D.Immediately hire more IT staff.
AnswerC

Alignment review ensures IT is focusing on the right things to generate value.

Why this answer

The strategy itself must be reviewed and re-aligned with business goals, possibly leading to a shift in the portfolio.

211
MCQmedium

The board of directors requests a summary of the current IT risk posture. Which documentation should the practitioner use as the primary source?

A.The latest enterprise risk register.
B.The system administrator's patch management reports.
C.The IT department's operational incident logs.
D.The annual budget allocation for IT security.
AnswerA

The register is the official repository for high-level enterprise risks.

Why this answer

The enterprise risk register provides the consolidated view required by the board.

212
MCQhard

An enterprise is adopting a 'Benefits-led' approach to IT governance. Which artifact is the most critical for documenting the causal link between IT-enabled outcomes and organizational strategy?

A.The Project Charter.
B.The Balanced Scorecard (BSC).
C.The IT Strategy document.
D.The Benefits Dependency Map (BDM).
AnswerD

The BDM is the standard tool for showing the logical, causal links between project outputs, outcomes, and enterprise benefits.

Why this answer

A Benefits Dependency Map (or Benefit Map) explicitly links the IT investment to intermediate capabilities and final business outcomes, proving the causal chain.

213
MCQhard

If a project is completed but the expected benefits are not realized, what is the best initial step for a CGEIT professional?

A.Ignore the missing benefits as long as the system works.
B.Analyze the 'Benefit Dependency Network' to identify where the link between output and outcome failed.
C.Start a new, more expensive project.
D.Blame the technical team for poor coding.
AnswerB

The network helps visualize where the chain broke, such as lack of training or process change.

Why this answer

The professional must investigate the cause, which usually lies in the gap between technical delivery and operational adoption.

214
MCQhard

A company is struggling with shadow IT. Which governance strategy is most effective?

A.Identify the cause of shadow IT and provide sanctioned, secure alternatives.
B.Block all unauthorized websites and applications.
C.Increase the budget for the IT department.
D.Fire any employee caught using non-sanctioned tools.
AnswerA

Addressing the root cause and providing better alternatives is the governance-led approach.

Why this answer

Shadow IT is usually a symptom of a slow or restrictive IT process. The governance approach is to improve IT service agility while providing secure, compliant alternatives.

Page 2

Page 3 of 3

All pages