CGEIT · domain
Risk Optimization
Practise ISACA Certified in the Governance of Enterprise IT (CGEIT) (CGEIT) Risk Optimization practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.
Focused practice
Practice Risk Optimization questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Risk Optimization
Risk Optimization questions test whether you can apply the concept in context, not just recognise a definition.
How the topic appears in realistic exam-style scenarios.
Which detail in the question changes the correct answer.
How to eliminate plausible but wrong options.
How to connect the question back to the wider exam objective.
Watch out for
Common Risk Optimization exam traps
- ▸Answering from memory before reading the full scenario.
- ▸Missing a constraint such as cost, availability, security, scope or command context.
- ▸Choosing a broad answer when the question asks for the most specific fix.
- ▸Ignoring why the wrong options are tempting.
Question index
All Risk Optimization questions (46)
Click any question to see the full explanation, or start a practice session above.
Which TWO of the following factors should influence the frequency of risk reporting to the board?
Hard2During an IT governance board meeting, the CGEIT practitioner notices that the current risk profile deviates significantly from the approved risk appetite. What is the most appropriate next step?
Medium3A company is conducting a risk analysis. Which of the following is an example of an 'inherent risk'?
Easy4Why is it important to define risk appetite before developing a risk response plan?
Medium5You are evaluating the maturity of your organization's risk reporting to the board. Which THREE of the following elements are essential for high-maturity reporting?
Hard6A firm has decided to pursue a high-risk innovation strategy. How should the enterprise risk appetite statement be adjusted to support this goal?
Hard7When assessing the impact of a risk, what is the best perspective to take?
Easy8During a merger, the IT risk governance team identifies incompatible security standards. What is the correct approach?
Hard9A company is performing a risk assessment of a new software vendor. Which factor is most relevant for the governance of third-party risk?
Easy10An IT project is identified as having a high inherent risk that exceeds the board-approved appetite. The project is critical for competitive advantage. Which approach is most appropriate?
Hard11An enterprise is aligning its IT risk appetite with corporate strategic objectives. Which action should the CGEIT-certified practitioner prioritize first?
Easy12Which metric is most useful for reporting the effectiveness of IT risk management to the board?
Medium13Which THREE of the following are key inputs for defining the IT risk appetite?
Medium14An organization's risk appetite has been set as 'low' for data breaches. A new project introduces a moderate risk of a breach. What is the most appropriate governance action?
Hard15Your organization is undergoing a major digital transformation. To ensure risk is optimized throughout the lifecycle, what is the most critical governance activity during the planning phase?
Hard16An organization is transitioning to a cloud-based infrastructure. Which governance mechanism is most effective for ensuring that the cloud service provider's risk management practices remain aligned with the enterprise's risk appetite?
Hard17Which THREE of the following are common risk response strategies?
Medium18An organization experiences a high frequency of minor IT incidents. What is the most effective governance action to ensure this does not result in a significant enterprise risk?
Hard19You are auditing the integration of IT risk management. Which finding indicates a failure in the governance of enterprise risk?
Medium20A company is establishing an IT Risk Committee. Which group should have the most significant representation?
Medium21Which TWO of the following describe the role of the 'Risk Owner'?
Easy22Which of the following is a key component of an effective IT risk management policy?
Medium23An enterprise is facing a high-impact risk that cannot be fully mitigated. The board decides to transfer this risk. Which of the following is the best implementation of risk transfer?
Hard24When balancing risk and value in IT investment, what is the primary consideration for the CGEIT practitioner?
Easy25Which TWO of the following are key elements of a Business Impact Analysis (BIA)?
Medium26Which TWO of the following are examples of 'Avoidance' as a risk response?
Hard27When reporting IT risk to the board, which of the following provides the most value?
Easy28A company is using a risk maturity model to improve its IT risk management. What is the main benefit?
Medium29To effectively integrate risk management into enterprise governance, which THREE activities should be conducted?
Easy30An organization is integrating IT risk management into its enterprise governance framework. Which approach best ensures that IT risk is treated as a component of enterprise risk?
Easy31An enterprise is adopting an agile development methodology. How should the CGEIT-certified practitioner modify the risk governance process?
Hard32Which TWO of the following are examples of risk mitigation?
Easy33An enterprise is evaluating the trade-off between the cost of risk mitigation and the potential business benefit. Which framework or approach should the practitioner use?
Medium34An enterprise is adopting a 'Risk-Based Approach' to IT governance. How should this impact the IT budget allocation?
Hard35An IT audit reveals that risk mitigation activities are being performed, but they are not being tracked. What is the governance risk?
Hard36Which THREE of the following are essential components of a risk reporting framework?
Medium37Which role is typically responsible for the final acceptance of IT risks at the enterprise level?
Easy38What is the relationship between 'IT Risk' and 'Enterprise Risk'?
Easy39Which TWO of the following are primary objectives of IT risk governance?
Easy40The board of directors is concerned about the impact of recent cybersecurity threats on the company's reputation. Which TWO of the following actions should the Governance committee prioritize to address these concerns?
Medium41When a risk event occurs, what is the first step in the incident response process from a governance perspective?
Easy42Which THREE of the following represent effective ways to integrate IT risk into the organizational culture?
Hard43What is the most effective way to ensure that IT risk management is integrated with enterprise risk management (ERM)?
Medium44Which of the following is the primary purpose of a Key Risk Indicator (KRI)?
Easy45An IT project is failing to deliver promised business value. What is the most likely governance failure?
Hard46The board of directors requests a summary of the current IT risk posture. Which documentation should the practitioner use as the primary source?
MediumOther domains
All CGEIT exam domains
Frequently asked questions
- What does the Risk Optimization domain cover on the CGEIT exam?
- Risk Optimization questions test whether you can apply the concept in context, not just recognise a definition.
- How many questions are in this domain?
- This page lists all 46 Risk Optimization questions in the CGEIT question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Risk Optimization questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.