Courseiva

CGEIT · domain

Risk Optimization

Practise ISACA Certified in the Governance of Enterprise IT (CGEIT) (CGEIT) Risk Optimization practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

46 questions15 easy15 medium16 hard

Focused practice

Practice Risk Optimization questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Risk Optimization

Risk Optimization questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common Risk Optimization exam traps

  • Answering from memory before reading the full scenario.
  • Missing a constraint such as cost, availability, security, scope or command context.
  • Choosing a broad answer when the question asks for the most specific fix.
  • Ignoring why the wrong options are tempting.

Question index

All Risk Optimization questions (46)

Click any question to see the full explanation, or start a practice session above.

1

Which TWO of the following factors should influence the frequency of risk reporting to the board?

Hard
2

During an IT governance board meeting, the CGEIT practitioner notices that the current risk profile deviates significantly from the approved risk appetite. What is the most appropriate next step?

Medium
3

A company is conducting a risk analysis. Which of the following is an example of an 'inherent risk'?

Easy
4

Why is it important to define risk appetite before developing a risk response plan?

Medium
5

You are evaluating the maturity of your organization's risk reporting to the board. Which THREE of the following elements are essential for high-maturity reporting?

Hard
6

A firm has decided to pursue a high-risk innovation strategy. How should the enterprise risk appetite statement be adjusted to support this goal?

Hard
7

When assessing the impact of a risk, what is the best perspective to take?

Easy
8

During a merger, the IT risk governance team identifies incompatible security standards. What is the correct approach?

Hard
9

A company is performing a risk assessment of a new software vendor. Which factor is most relevant for the governance of third-party risk?

Easy
10

An IT project is identified as having a high inherent risk that exceeds the board-approved appetite. The project is critical for competitive advantage. Which approach is most appropriate?

Hard
11

An enterprise is aligning its IT risk appetite with corporate strategic objectives. Which action should the CGEIT-certified practitioner prioritize first?

Easy
12

Which metric is most useful for reporting the effectiveness of IT risk management to the board?

Medium
13

Which THREE of the following are key inputs for defining the IT risk appetite?

Medium
14

An organization's risk appetite has been set as 'low' for data breaches. A new project introduces a moderate risk of a breach. What is the most appropriate governance action?

Hard
15

Your organization is undergoing a major digital transformation. To ensure risk is optimized throughout the lifecycle, what is the most critical governance activity during the planning phase?

Hard
16

An organization is transitioning to a cloud-based infrastructure. Which governance mechanism is most effective for ensuring that the cloud service provider's risk management practices remain aligned with the enterprise's risk appetite?

Hard
17

Which THREE of the following are common risk response strategies?

Medium
18

An organization experiences a high frequency of minor IT incidents. What is the most effective governance action to ensure this does not result in a significant enterprise risk?

Hard
19

You are auditing the integration of IT risk management. Which finding indicates a failure in the governance of enterprise risk?

Medium
20

A company is establishing an IT Risk Committee. Which group should have the most significant representation?

Medium
21

Which TWO of the following describe the role of the 'Risk Owner'?

Easy
22

Which of the following is a key component of an effective IT risk management policy?

Medium
23

An enterprise is facing a high-impact risk that cannot be fully mitigated. The board decides to transfer this risk. Which of the following is the best implementation of risk transfer?

Hard
24

When balancing risk and value in IT investment, what is the primary consideration for the CGEIT practitioner?

Easy
25

Which TWO of the following are key elements of a Business Impact Analysis (BIA)?

Medium
26

Which TWO of the following are examples of 'Avoidance' as a risk response?

Hard
27

When reporting IT risk to the board, which of the following provides the most value?

Easy
28

A company is using a risk maturity model to improve its IT risk management. What is the main benefit?

Medium
29

To effectively integrate risk management into enterprise governance, which THREE activities should be conducted?

Easy
30

An organization is integrating IT risk management into its enterprise governance framework. Which approach best ensures that IT risk is treated as a component of enterprise risk?

Easy
31

An enterprise is adopting an agile development methodology. How should the CGEIT-certified practitioner modify the risk governance process?

Hard
32

Which TWO of the following are examples of risk mitigation?

Easy
33

An enterprise is evaluating the trade-off between the cost of risk mitigation and the potential business benefit. Which framework or approach should the practitioner use?

Medium
34

An enterprise is adopting a 'Risk-Based Approach' to IT governance. How should this impact the IT budget allocation?

Hard
35

An IT audit reveals that risk mitigation activities are being performed, but they are not being tracked. What is the governance risk?

Hard
36

Which THREE of the following are essential components of a risk reporting framework?

Medium
37

Which role is typically responsible for the final acceptance of IT risks at the enterprise level?

Easy
38

What is the relationship between 'IT Risk' and 'Enterprise Risk'?

Easy
39

Which TWO of the following are primary objectives of IT risk governance?

Easy
40

The board of directors is concerned about the impact of recent cybersecurity threats on the company's reputation. Which TWO of the following actions should the Governance committee prioritize to address these concerns?

Medium
41

When a risk event occurs, what is the first step in the incident response process from a governance perspective?

Easy
42

Which THREE of the following represent effective ways to integrate IT risk into the organizational culture?

Hard
43

What is the most effective way to ensure that IT risk management is integrated with enterprise risk management (ERM)?

Medium
44

Which of the following is the primary purpose of a Key Risk Indicator (KRI)?

Easy
45

An IT project is failing to deliver promised business value. What is the most likely governance failure?

Hard
46

The board of directors requests a summary of the current IT risk posture. Which documentation should the practitioner use as the primary source?

Medium

Frequently asked questions

What does the Risk Optimization domain cover on the CGEIT exam?
Risk Optimization questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 46 Risk Optimization questions in the CGEIT question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Risk Optimization questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
ISACA Certified in the Governance of Enterprise IT (CGEIT) (CGEIT) Risk Optimization Practice Questions