Courseiva

CCNA Governance OF Enterprise IT Questions

75 of 80 questions · Page 1/2 · Governance OF Enterprise IT · Answers revealed

1
MCQhard

Which metric is the most effective indicator of IT governance success?

A.Degree of alignment between IT investments and business value realized
B.Total cost of IT hardware and software maintenance
C.Number of IT projects completed on time
D.Number of IT security patches applied per month
AnswerA

Governance is successful when IT investments yield the expected business value.

Why this answer

Value realization is the ultimate test of IT governance effectiveness.

2
MCQeasy

Which factor most significantly influences the design of an IT governance system?

A.The specific software vendors used.
B.The current IT hardware lifecycle.
C.The organization's strategy and business goals.
D.The number of employees in the IT department.
AnswerC

Strategy defines the direction that IT governance must support.

Why this answer

Enterprise strategy is the primary driver for IT governance, as the framework must support the business objectives.

3
MCQmedium

A newly appointed CIO is integrating COBIT 2019 into the existing governance framework. Which action best ensures that the governance system is dynamic?

A.Focusing solely on the 'Ensure Governance Framework Setting and Maintenance' objective.
B.Implementing all 40 governance and management objectives immediately.
C.Adopting the framework exactly as published in the COBIT core publication.
D.Customizing the governance system based on the enterprise's unique design factors.
AnswerD

COBIT 2019 requires tailoring the governance system through design factors to remain relevant.

Why this answer

COBIT 2019 focuses on the design factor of a dynamic system, emphasizing the need for regular updates to governance components based on changes in enterprise strategy.

4
MCQmedium

An organization adopts a new IT governance policy. Which mechanism best ensures that employees understand and follow the policy?

A.Including the policy in the organization's long-term strategic plan
B.Threatening immediate termination for any policy deviation
C.Establishing a formal communication and training plan regarding the policy
D.Encrypting the policy document on the corporate intranet
AnswerC

Awareness through communication and training is key to policy enforcement.

Why this answer

Policy adherence is best fostered through communication, training, and integration into performance expectations.

5
MCQeasy

Which of the following best defines IT Governance?

A.Purchasing new software for the company.
B.Managing daily IT support tickets.
C.Updating antivirus software across the network.
D.A structure of relationships and processes to direct and control the enterprise.
AnswerD

This is the standard definition of governance, focusing on direction and control.

Why this answer

IT governance ensures that IT aligns with business goals, delivers value, manages risk, and optimizes resources.

6
Multi-Selecthard

Which THREE factors should be considered when tailoring a COBIT 2019 governance system?

Select 3 answers
A.Adoption strategy
B.Enterprise size
C.Office paint color
D.Employee cafeteria menu
E.Threat landscape
AnswersA, B, E

Design factor regarding implementation approach.

Why this answer

Size, threat landscape, and adoption strategy are key design factors in COBIT 2019.

7
MCQmedium

Which of the following is an example of an 'IT governance structure'?

A.A daily backup job schedule
B.A database management system (DBMS) upgrade project
C.An IT steering committee
D.A list of helpdesk tickets for the week
AnswerC

This is a governance structure.

Why this answer

An IT steering committee is a formal body specifically created to handle governance tasks like prioritization and alignment.

8
MCQhard

An enterprise is transitioning to a hybrid cloud environment. Which governance mechanism is most critical to ensure compliance with data sovereignty regulations?

A.Automated provisioning of infrastructure using Infrastructure as Code (IaC)
B.Establishing a service level agreement (SLA) with the cloud provider
C.Increasing the frequency of penetration testing on cloud endpoints
D.Implementing a robust data classification policy and control framework
AnswerD

Classification dictates where data can reside, which is essential for sovereignty compliance.

Why this answer

Defining data classification and governance policies is the prerequisite for managing data residency in a hybrid cloud.

9
Multi-Selecthard

Which THREE of the following are common challenges when implementing IT governance?

Select 3 answers
A.Lack of strategic alignment between IT and business
B.The high cost of office furniture
C.Resistance to change within the organization
D.Insufficient executive and board support
E.The inability to find enough IT technicians
AnswersA, C, D

Governance is often introduced to fix this, but the lack of it is a major implementation challenge.

Why this answer

Resistance to change, lack of leadership support, and lack of alignment are common failures.

10
MCQmedium

What is the primary role of the Chief Information Officer (CIO) in governance?

A.Setting the overall corporate strategy.
B.Ensuring IT management acts in accordance with the board's governance directives.
C.Performing all internal IT audits.
D.Solely focused on hiring technical staff.
AnswerB

The CIO links the governance (board) and management (IT) levels.

Why this answer

The CIO is the bridge, responsible for translating the board's governance direction into IT management execution.

11
MCQeasy

A newly appointed CIO is establishing an IT governance framework. Which approach best ensures that IT governance is integrated into the enterprise's existing management structure?

A.Require all IT departments to report directly to the Chief Risk Officer.
B.Map IT governance activities to existing business decision-making processes and accountabilities.
C.Adopt a proprietary framework developed by a third-party IT consulting firm.
D.Implement a parallel IT governance board independent of the executive committee.
AnswerB

Mapping activities to existing processes ensures seamless integration and accountability.

Why this answer

Integrating governance into existing management structures is a core tenet of COBIT to ensure IT is not siloed.

12
MCQhard

An organization is failing to achieve the expected ROI on IT investments. Which governance mechanism is most likely missing?

A.An IT Steering Committee focused on value realization.
B.Regular penetration testing.
C.A robust incident management process.
D.Standardized server configurations.
AnswerA

Value realization is a core responsibility of the IT Steering Committee.

Why this answer

The IT Steering Committee is responsible for reviewing and approving business cases, ensuring projects are prioritized based on value and ROI.

13
MCQeasy

Who is ultimately responsible for the governance of enterprise IT?

A.The IT Manager.
B.The CEO.
C.The Board of Directors.
D.The IT Auditor.
AnswerC

The board has the final accountability for governance of the enterprise.

Why this answer

The board of directors (or equivalent governing body) bears the ultimate responsibility for ensuring the enterprise is governed effectively.

14
Multi-Selecthard

Which THREE principles are central to COBIT 2019 governance?

Select 3 answers
A.Maximizing individual developer freedom
B.Dynamic governance system
C.Outsourcing everything
D.Meeting stakeholder needs
E.Holistic approach
AnswersB, D, E

Core COBIT principle.

Why this answer

Meeting stakeholder needs, holistic approach, and dynamic governance are core COBIT 2019 principles.

15
MCQmedium

A company is experiencing friction between IT and business units regarding project priorities. What governance structure should be strengthened to resolve this?

A.The IT Change Advisory Board (CAB)
B.The IT Steering Committee
C.The Security Operations Center (SOC)
D.The IT Infrastructure Architecture board
AnswerB

The committee balances business and IT interests to establish project priorities.

Why this answer

An IT steering committee is specifically designed to facilitate communication and priority alignment between IT and business leadership.

16
Multi-Selecthard

The enterprise is reviewing its IT governance structure. Which THREE of the following are primary responsibilities of the Board of Directors regarding IT governance?

Select 3 answers
A.Defining the technical configuration of server clusters.
B.Directing the strategic alignment of IT with business goals.
C.Overseeing the enterprise risk management framework.
D.Managing the daily IT helpdesk ticket queue.
E.Ensuring value delivery from IT investments.
AnswersB, C, E

Ensuring IT investments support business objectives is a board duty.

Why this answer

The Board is responsible for strategic alignment, value delivery, and risk management oversight.

17
MCQmedium

An organization wants to improve its IT governance maturity. What is the most important first step?

A.Buying an expensive IT governance tool.
B.Assessing the current state of governance maturity.
C.Implementing all COBIT objectives at once.
D.Changing the IT leadership team.
AnswerB

You must understand where you are before you can plan where you are going.

Why this answer

Assessing the current state (maturity) of the governance system is the essential first step before setting goals for improvement.

18
MCQeasy

Which of the following best describes 'strategic alignment' in IT governance?

A.Requiring IT staff to wear uniforms
B.Purchasing the most advanced technology available
C.Ensuring the data center is located in a seismically safe area
D.Ensuring IT plans and business plans are synchronized
AnswerD

This directly defines strategic alignment.

Why this answer

Strategic alignment is the process of ensuring that IT objectives and activities directly support the enterprise's mission and goals.

19
MCQhard

A governance review reveals that IT decision-making is too slow to support rapid market changes. What should be done?

A.Require the board of directors to approve every IT change
B.Delegate specific decision-making authorities to lower levels based on defined thresholds
C.Remove all governance oversight requirements to speed up decisions
D.Stop all development until the governance process is redesigned
AnswerB

Delegation of authority balances speed with controlled oversight.

Why this answer

The governance model should be reviewed to streamline decision-making without sacrificing oversight, often through delegation of authority.

20
MCQmedium

What is the primary role of an IT Steering Committee?

A.Managing the IT staff performance reviews.
B.Reviewing IT strategy and project portfolio alignment with business goals.
C.Scheduling system maintenance windows.
D.Designing the network architecture.
AnswerB

This is the core function of an IT Steering Committee.

Why this answer

The steering committee aligns IT with business strategy and oversees major investments and project priorities.

21
Multi-Selectmedium

Which TWO are common challenges in IT governance implementation?

Select 2 answers
A.Cultural resistance
B.Insufficient desk space
C.Slow elevator speed
D.Unreliable office internet
E.Lack of executive support
AnswersA, E

People often resist change in oversight.

Why this answer

Lack of executive support and cultural resistance are the most common barriers to effective governance.

22
Multi-Selectmedium

Which TWO of the following are key responsibilities of an IT steering committee?

Select 2 answers
A.Reviewing IT project status and business value delivery
B.Installing server software patches
C.Performing daily system performance monitoring
D.Managing the helpdesk ticket queue
E.Approving the enterprise-wide IT strategy and investment portfolio
AnswersA, E

This ensures projects deliver the intended business value.

Why this answer

The steering committee is responsible for aligning IT priorities with business needs and monitoring performance against those goals.

23
MCQmedium

An organization is evaluating its governance structure against the COBIT 2019 framework. Where should the authority for IT governance decisions reside?

A.The IT Steering Committee.
B.The IT Security Manager.
C.The Chief Information Officer (CIO).
D.The external auditors.
AnswerA

The IT Steering Committee acts as a formal bridge between the board/executive management and IT operations for decision-making.

Why this answer

COBIT 2019 emphasizes that governance accountability rests with the board, but authority is often delegated to a designated governance committee.

24
MCQeasy

What is the benefit of a standardized IT governance framework?

A.It automatically reduces IT costs by 50%.
B.It provides a clear structure, common language, and consistent practices.
C.It eliminates the need for any oversight.
D.It replaces the need for IT management.
AnswerB

These are the fundamental benefits of adopting a framework like COBIT.

Why this answer

Standardization provides a common language, consistent processes, and clear accountability across the enterprise.

25
MCQmedium

Which of the following is an example of an IT governance 'outcome'?

A.Completion of a training course.
B.The purchasing of a new software license.
C.A new server installation.
D.Increased alignment of IT services with business objectives.
AnswerD

Alignment is a direct result/outcome of successful governance.

Why this answer

An outcome is the result of effective governance, such as the achievement of business objectives through IT-enabled value.

26
Multi-Selectmedium

Which TWO items are considered 'Governance enablers' in COBIT?

Select 2 answers
A.Personal employee cars
B.Office air conditioning
C.Breakroom snacks
D.Organizational structures
E.Processes
AnswersD, E

Enabler of governance.

Why this answer

Processes and organizational structures are defined as key enablers within the COBIT framework.

27
MCQmedium

Which key element should a balanced scorecard (BSC) for IT governance include?

A.Only financial metrics.
B.Only technical uptime metrics.
C.Financial, customer, internal process, and learning and growth perspectives.
D.Only employee satisfaction metrics.
AnswerC

This is the classic Kaplan/Norton BSC structure adapted for IT governance.

Why this answer

A balanced scorecard for IT should measure performance across financial, customer, internal process, and learning/growth perspectives.

28
MCQeasy

Which document is primary evidence that the board of directors is fulfilling its oversight responsibility for IT governance?

A.An IT incident report detailing recent system downtime
B.A technical architecture document describing the enterprise network
C.The minutes of board meetings documenting IT strategy review and approval
D.A list of software licenses purchased by the IT department
AnswerC

Board minutes are the formal record of governance oversight decisions.

Why this answer

The IT strategy, when reviewed and approved by the board, demonstrates active oversight.

29
MCQmedium

When establishing an IT governance committee, what is a key requirement for its effectiveness?

A.It must be composed only of technical experts.
B.It must include representation from both business and IT.
C.It must be chaired by the CIO.
D.It must meet at least once a week.
AnswerB

Cross-functional representation is essential for aligning IT governance with enterprise goals.

Why this answer

A committee must have representation from both business and IT to ensure that decisions are aligned with business priorities and that IT has a voice.

30
Multi-Selecthard

Which THREE components are critical for an IT governance system to be effective?

Select 3 answers
A.Defined processes
B.Unlimited breakroom coffee
C.The latest gaming console
D.Organizational structures
E.Information flows
AnswersA, D, E

Governance operates through documented processes.

Why this answer

Processes, organizational structures, and information flows are core components of a governance system.

31
Multi-Selecteasy

Which TWO items are commonly included in an IT Governance Policy?

Select 2 answers
A.Scope of governance
B.Network IP addresses
C.Server rack layout
D.Roles and responsibilities
E.Daily task list
AnswersA, D

Defines what the policy applies to.

Why this answer

Policies define the scope of the framework and the roles/responsibilities of the stakeholders.

32
MCQmedium

During a strategic alignment review, the governance committee identifies that IT investments are not delivering expected value. What is the most effective first step for the committee?

A.Cancel all current IT projects and restart with new priorities
B.Outsource the IT portfolio management function to a third-party consultant
C.Conduct a portfolio review to map current IT investments to strategic business objectives
D.Reduce the IT budget by 20% to increase efficiency metrics
AnswerC

Mapping investments to business objectives identifies misalignment and value leakage.

Why this answer

The committee must first assess the transparency and accuracy of the IT investment portfolio against business goals.

33
MCQeasy

In the context of IT governance, what is the primary responsibility of the board of directors?

A.Providing strategic direction and monitoring governance performance.
B.Managing the procurement of software and hardware.
C.Developing IT policies and procedures.
D.Day-to-day management of IT operations.
AnswerA

The board sets the tone and provides oversight of the governance framework.

Why this answer

The board's primary role is oversight, ensuring that IT governance is established and that risks are managed in alignment with enterprise appetite.

34
MCQhard

A firm's IT audit identifies a lack of accountability for data governance. Which governance mechanism should be implemented?

A.Outsource all data storage.
B.Install more data encryption tools.
C.Centralize all data in one database.
D.Appoint data owners and establish a data governance committee.
AnswerD

Defining clear roles and oversight is the foundation of data governance accountability.

Why this answer

Assigning data ownership and establishing a data governance council are the standard mechanisms to ensure accountability.

35
Multi-Selecthard

Which TWO of the following are critical success factors for implementing a new IT governance program?

Select 2 answers
A.Active support and commitment from senior leadership
B.Replacing all existing IT management staff
C.Focusing exclusively on technical automation tools
D.Ignoring existing business processes to start fresh
E.Integration of governance into the organizational culture
AnswersA, E

Without leadership, governance lacks the authority to be effective.

Why this answer

Leadership support and cultural integration are essential for the success of any governance program.

36
MCQhard

A company's IT governance structure is being challenged because IT costs are inconsistent. What is the most appropriate governance step to take?

A.Arbitrarily cap all IT spending.
B.Increase the IT department's headcount.
C.Switch to a cloud-only model.
D.Review and align IT investment prioritization with business outcomes.
AnswerD

Alignment ensures that funds are spent on the initiatives that drive the most value.

Why this answer

The steering committee should review the IT investment portfolio and budget allocation to ensure consistency with strategic business priorities.

37
Multi-Selecteasy

Which TWO metrics are used to measure strategic alignment?

Select 2 answers
A.Number of server reboots
B.Average salary of IT staff
C.Percentage of projects aligned with business strategy
D.Number of printers repaired
E.Business value realized from IT investments
AnswersC, E

Direct measure of alignment.

Why this answer

Portfolio alignment and value delivery metrics are key indicators of strategic alignment.

38
Multi-Selectmedium

Which TWO of the following are essential components of an effective IT governance framework?

Select 2 answers
A.Organizational structures
B.Processes for decision-making and accountability
C.A list of all IT hardware serial numbers
D.The daily IT operational budget
E.Detailed programming language standards
AnswersA, B

Structures define who makes decisions.

Why this answer

A governance framework must include both organizational structures and clear processes for decision-making.

39
MCQeasy

What is the primary indicator that IT strategic alignment is successful?

A.IT cost as a percentage of revenue is minimized.
B.The IT department is fully staffed.
C.IT projects are completed on time.
D.Business goals are met through the effective use of IT.
AnswerD

This demonstrates that IT is driving business value.

Why this answer

Successful alignment is visible when IT investments and operations directly support the achievement of the enterprise's strategic goals.

40
Multi-Selectmedium

Which THREE of the following are primary domains of IT governance according to standard frameworks?

Select 3 answers
A.Risk management
B.Value delivery
C.Hardware procurement automation
D.Strategic alignment
E.Helpdesk ticket resolution speed
AnswersA, B, D

A core domain of IT governance.

Why this answer

IT governance covers strategic alignment, value delivery, risk management, resource management, and performance measurement.

41
MCQmedium

How should IT governance ensure that IT-related risks are identified and managed?

A.By eliminating IT risk entirely.
B.By outsourcing all IT operations to a third party.
C.By incorporating risk management into the enterprise's IT governance policy.
D.By performing all risk assessments at the board level.
AnswerC

Policies define the risk management expectations that management must execute.

Why this answer

Governance frameworks integrate risk management by setting policies and requiring management to establish risk assessment processes.

42
MCQmedium

Which stakeholder should provide the final approval for the IT governance policy?

A.The IT Steering Committee.
B.The Board of Directors.
C.The Chief Technology Officer (CTO).
D.The Chief Information Security Officer (CISO).
AnswerB

Final oversight and accountability for the governance framework belong to the board.

Why this answer

The board of directors (or equivalent) has ultimate accountability for the organization's governance, including IT governance.

43
MCQmedium

A company is planning a digital transformation. What governance action is necessary to ensure the transformation supports business strategy?

A.Outsource the entire transformation to an external systems integrator
B.Establish a governance structure that includes business unit leaders in transformation decision-making
C.Focus primarily on reducing IT costs to fund the project
D.Select the latest cloud-based ERP software before defining business requirements
AnswerB

Inclusive decision-making ensures the project meets business needs.

Why this answer

Linking the digital transformation initiative to clear, measurable business objectives is essential for governance.

44
Multi-Selecthard

Which THREE items are required for an effective IT investment governance process?

Select 3 answers
A.Project prioritization process
B.Employee birthday party planning
C.Office chair selection
D.Formal business case review
E.Post-implementation value tracking
AnswersA, D, E

Step in investment governance.

Why this answer

Business case approval, project prioritization, and ROI measurement are the core steps in investment governance.

45
MCQeasy

What is the primary role of the IT governance framework in an enterprise?

A.To align IT strategy with business strategy and deliver value
B.To serve as a technical manual for system administration
C.To automate all IT monitoring and reporting
D.To replace the need for IT management
AnswerA

The core purpose of governance is to ensure IT value delivery and alignment.

Why this answer

The framework provides the structure, processes, and mechanisms to ensure IT meets business goals and manages risk.

46
Multi-Selectmedium

Which THREE of the following represent effective ways to monitor IT governance compliance?

Select 3 answers
A.Reviewing IT governance performance dashboards
B.Monitoring the speed of the office Wi-Fi
C.Conducting regular internal audits of governance controls
D.Ensuring regular reports on policy compliance are provided to the board
E.Asking staff to informally report any issues
AnswersA, C, D

Dashboards provide continuous visibility into governance metrics.

Why this answer

Compliance monitoring relies on audit, formal performance metrics, and regular reporting.

47
MCQhard

An organization's governance committee decides to stop funding a legacy IT system that is still critical for a specific department. What should be done?

A.Conduct an impact analysis and develop a migration strategy.
B.Decommission it immediately to save money.
C.Force the department to find their own funding.
D.Ignore the committee's decision and keep paying.
AnswerA

Governance requires evaluating the impact and planning for continuity.

Why this answer

The committee must perform a formal impact assessment and create a transition plan that ensures business continuity before decommissioning.

48
Multi-Selecteasy

Which TWO documents are essential for establishing governance oversight?

Select 2 answers
A.Governance policy
B.Server maintenance schedule
C.Vendor contact list
D.IT ticket log
E.Committee charter
AnswersA, E

Sets the rules and expectations.

Why this answer

The governance policy and the committee charter are the foundational documents for oversight.

49
MCQeasy

Which role is generally responsible for implementing the governance policies defined by the board?

A.Internal Audit.
B.The Board of Directors.
C.Executive Management.
D.The IT support team.
AnswerC

Executive management translates governance directives into operational reality.

Why this answer

Management, led by the executive suite, is responsible for executing the strategies and policies set by the board.

50
MCQhard

A company is integrating a new AI technology. How should the governance structure oversee this risk?

A.Mandate that no new AI technology is used.
B.Allow the IT team to proceed without oversight.
C.Update governance policies and risk thresholds for new technology.
D.Focus solely on the cost of the technology.
AnswerC

Proactive policy and risk assessment update is the correct governance approach for new tech.

Why this answer

Emerging technology requires the IT steering committee to review the risk appetite and update governance policies to manage new types of ethical and operational risks.

51
Multi-Selecthard

Which TWO of the following are key inputs for defining the IT governance strategy?

Select 2 answers
A.The number of employees in the IT department
B.The IT department's current server capacity
C.The enterprise's risk appetite
D.The enterprise's overall business strategy
E.The vendor names of all installed software
AnswersC, D

Risk appetite determines the required level of control and oversight.

Why this answer

IT governance must be derived from the enterprise's strategic goals and its appetite for risk.

52
Multi-Selectmedium

Which TWO roles are typically involved in the IT Steering Committee?

Select 2 answers
A.Chief Information Officer (CIO)
B.Chief Financial Officer (CFO)
C.Security Support Staff
D.External Custodial Services
E.Junior Software Developer
AnswersA, B

IT leadership is required to represent IT capabilities.

Why this answer

Both executive business leadership and senior IT leadership must participate for the committee to be effective.

53
Multi-Selectmedium

Which TWO mechanisms are used by governance to monitor performance?

Select 2 answers
A.Hardware inventory scan
B.Daily stand-up meetings
C.Independent internal audit
D.Periodic performance reporting
E.Office security badge logs
AnswersC, D

Provides objective assurance.

Why this answer

Reporting and internal auditing are key mechanisms for governance monitoring.

54
MCQhard

A corporation is shifting from a centralized to a decentralized IT structure. How does this affect governance?

A.Governance must define common standards while allowing local decision-making flexibility.
B.The board should take over all local IT decisions.
C.The governance framework is no longer required.
D.Decentralization makes IT governance impossible.
AnswerA

This is the 'center of excellence' model required for decentralized IT governance.

Why this answer

Decentralization shifts control, requiring a governance framework that emphasizes shared standards and monitoring across multiple business units.

55
Multi-Selecteasy

Which TWO of the following are primary pillars of IT Governance?

Select 2 answers
A.Strategic alignment
B.Hardware procurement cost
C.Network speed optimization
D.Value delivery
E.Software development speed
AnswersA, D

Ensuring IT supports the business is a core pillar.

Why this answer

Strategic alignment and value delivery are foundational pillars of IT governance.

56
MCQeasy

When should an IT governance framework be reviewed?

A.Never, once it is implemented.
B.Only when an audit fails.
C.Every day.
D.At regular intervals and upon significant enterprise changes.
AnswerD

Proactive and trigger-based reviews ensure the framework stays relevant.

Why this answer

Frameworks should be reviewed periodically or when significant changes occur in business strategy or the internal/external environment.

57
MCQmedium

An organization is updating its IT governance policies. Which element must be included to ensure policy enforcement?

A.A copy of the IT department's budget spreadsheet
B.Defined roles, responsibilities, and accountability mechanisms
C.A detailed technical configuration guide for all servers
D.A list of all software vendor names used by the company
AnswerB

Clear accountability is the foundation of policy enforcement.

Why this answer

Policies must define roles, responsibilities, and clear consequences or procedures for compliance to be enforceable.

58
MCQmedium

In the context of the COBIT 2019 framework, what does 'Governance' mean?

A.Execution of technical tasks.
B.Evaluation, direction, and monitoring of enterprise activities.
C.Managing the budget of the IT department.
D.Developing software applications.
AnswerB

This is the core definition of governance within the COBIT framework.

Why this answer

Governance ensures that stakeholder needs, conditions, and options are evaluated to determine balanced, agreed-upon enterprise objectives.

59
MCQhard

A conflict arises between the IT department's desire for innovation and the business unit's desire for operational stability. What is the role of governance?

A.The IT department should always win for innovation.
B.The governance framework should facilitate a balance based on strategic priorities.
C.The business unit should always win for stability.
D.The board should ignore the conflict.
AnswerB

Governance is the mechanism to resolve such conflicts by aligning with the overall strategy.

Why this answer

Governance provides the framework (via the IT steering committee) to balance these competing priorities based on the organization's risk appetite and strategic goals.

60
MCQhard

A firm identifies that its IT governance framework is too burdensome for its agile, small-team structure. What is the most appropriate governance action?

A.Standardize all processes across the company.
B.Tailor the governance system by adjusting design factors.
C.Ignore the framework until the company grows.
D.Appoint more auditors to monitor compliance.
AnswerB

Adjusting the governance system to fit the organizational context is a key principle of COBIT 2019.

Why this answer

COBIT 2019 suggests 'design factors' like enterprise size and agile development methodology to tailor the framework to be efficient and non-burdensome.

61
MCQmedium

Which action should the governance body take if a major IT risk is identified that exceeds the enterprise's risk appetite?

A.Formally communicate the risk to the board and propose a risk treatment plan
B.Wait for the risk to manifest before taking action
C.Re-evaluate the definition of risk appetite to match the current state
D.Request the IT department to simply delete the system causing the risk
E.Ignore the risk if it helps achieve a short-term profit target
AnswerA

Transparency and formal treatment plans are required for risks exceeding appetite.

Why this answer

When risk exceeds appetite, the board or governance committee must formally accept, mitigate, or transfer the risk.

62
MCQmedium

A newly appointed CIO is establishing an IT governance framework. Which approach best ensures that IT governance activities are integrated into existing business decision-making processes?

A.Embedding IT governance roles and responsibilities into existing business management functions
B.Requiring all IT decisions to be signed off by the board of directors
C.Implementing an IT-only governance framework based strictly on COBIT 2019
D.Creating a separate IT governance committee with independent reporting lines
AnswerA

Embedding roles ensures that governance is part of daily business operations.

Why this answer

Integrating IT governance into existing business processes ensures sustainability and adoption, rather than creating a siloed IT governance structure.

63
Multi-Selecthard

Which THREE factors should the board of directors consider when establishing IT governance oversight mechanisms?

Select 3 answers
A.Regulatory and compliance requirements.
B.Alignment of IT initiatives with business strategy.
C.Enterprise risk appetite.
D.Daily network uptime statistics.
E.Detailed software configuration standards.
AnswersA, B, C

The board is ultimately responsible for enterprise compliance.

Why this answer

Board oversight must focus on risk appetite, strategic alignment, and compliance.

64
MCQmedium

A large enterprise is transitioning to a hybrid cloud environment. How should the governance policy be updated to maintain effective oversight?

A.Develop policies addressing shared responsibility and cloud governance controls.
B.Centralize all IT infrastructure back to on-premises.
C.Shift all responsibility for security to the cloud provider.
D.Eliminate the need for internal IT policies.
AnswerA

Effective cloud governance requires recognizing the shared responsibility model in policy.

Why this answer

Governance policies must evolve to cover new risk models, such as shared responsibility in cloud environments, ensuring oversight remains intact.

65
MCQmedium

The IT steering committee is evaluating a high-cost digital transformation project. What should the committee prioritize to ensure strategic alignment?

A.The potential for technical debt reduction.
B.The specific vendor selection process used for the software purchase.
C.The business value proposition and contribution to organizational goals.
D.Detailed technical architectural specifications.
AnswerC

Steering committees must focus on how investments deliver business value.

Why this answer

The primary role of the steering committee is to ensure the project supports the enterprise's strategic objectives.

66
MCQeasy

Which stakeholder is ultimately accountable for the governance of IT in an enterprise?

A.The IT Steering Committee
B.The Internal Audit department
C.The Chief Information Officer (CIO)
D.The Board of Directors
AnswerD

The Board holds ultimate accountability for the enterprise's governance.

Why this answer

The Board of Directors and senior executive management are ultimately accountable for the enterprise and its governance, including IT.

67
MCQeasy

What is the primary objective of 'IT resource management' as part of IT governance?

A.To ensure IT staff are working 40 hours per week
B.To eliminate the need for IT staff through automation
C.To buy the cheapest available technology
D.To optimize the allocation and use of IT resources to support the business
AnswerD

Resource optimization is the core of this governance domain.

Why this answer

The objective is to optimize the investment in and use of IT resources (people, hardware, software, information).

68
MCQeasy

Which document is essential for formalizing the relationship and expectations between IT and the business units?

A.Governance Policy Statement.
B.Project Charter.
C.IT Strategic Plan.
D.Service Level Agreement (SLA).
AnswerD

SLAs are the standard governance tool for defining service delivery expectations.

Why this answer

The Service Level Agreement (SLA) is the formal document that sets the requirements, responsibilities, and performance expectations for IT services.

69
MCQhard

An organization is merging with another company. How should the governance structures be reconciled?

A.Adopt the framework of the company with more employees.
B.Keep both frameworks as they are.
C.Abandon both frameworks and start from scratch.
D.Conduct a gap analysis and develop a unified governance framework.
AnswerD

This is the standard approach to integrating governance after a merger.

Why this answer

The governance team must perform a gap analysis of both frameworks and synthesize them to support the new, combined organizational strategy.

70
Multi-Selectmedium

Which TWO stakeholders are essential for successful IT governance?

Select 2 answers
A.Local IT repair technicians
B.Delivery drivers
C.Executive Management
D.Board of Directors
E.External janitorial staff
AnswersC, D

The executing authority.

Why this answer

The Board of Directors and the Executive Management are the essential top-level stakeholders for governance.

71
MCQeasy

What is the primary purpose of an IT governance framework?

A.To automate IT operations.
B.To ensure 100% system uptime.
C.To provide a structured approach for achieving IT value and managing risk.
D.To minimize IT costs at all times.
AnswerC

This encompasses the core intent of IT governance frameworks.

Why this answer

The purpose is to ensure that IT goals align with business goals and that risks are managed while resources are used responsibly.

72
MCQhard

A multinational corporation is struggling with IT strategic alignment. The board wants to ensure IT investments directly correlate to business value. Which metric should the governance committee prioritize?

A.Percentage of IT initiatives that directly contribute to documented business strategy goals.
B.Total cost of ownership (TCO) of IT assets.
C.System uptime and availability percentages.
D.IT project delivery on time and within budget.
AnswerA

This is the most direct measure of strategic alignment as it tracks the link between IT output and business outcomes.

Why this answer

Strategic alignment is best measured by the ratio of IT project benefits realized compared to the planned business value, linking IT spend to financial outcomes.

73
MCQeasy

Which document outlines the authority and responsibilities of the IT governance committee?

A.The committee charter.
B.The annual financial report.
C.The IT project plan.
D.The employee handbook.
AnswerA

The charter is the foundational document for any governance committee.

Why this answer

The committee charter is the formal document that defines the purpose, authority, and responsibilities of a governance body.

74
MCQhard

An organization has decentralized its IT operations, leading to fragmented governance. Which action will best restore governance oversight while retaining operational agility?

A.Mandate that all business units use the same IT software stack
B.Standardize all IT purchasing processes across the enterprise
C.Implement a federated governance structure with central policy oversight
D.Centralize all IT functions and reporting lines under the CIO
AnswerC

Federated governance balances centralized oversight with local operational flexibility.

Why this answer

Federated governance models allow for central policy setting and oversight while allowing local operational autonomy.

75
Multi-Selecthard

Which THREE of the following are essential elements of an IT risk governance policy?

Select 3 answers
A.Procedures for reporting and escalating risks
B.The physical location of all backup tapes
C.Defined enterprise risk appetite and tolerance levels
D.A list of all software vendors currently in use
E.Clear roles and responsibilities for risk ownership
AnswersA, C, E

Ensures that significant risks are known and managed.

Why this answer

Risk governance policies must define the risk appetite, the responsibilities for managing risk, and the reporting process for risk exposure.

Page 1 of 2 · 80 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Governance OF Enterprise IT questions.