Which TWO of the following factors should influence the frequency of risk reporting to the board?
High risk/high change requires more frequent reporting.
Why this answer
Frequency should be driven by risk volatility and business impact.
46 questions · Risk Optimization · All types, answers revealed
Which TWO of the following factors should influence the frequency of risk reporting to the board?
High risk/high change requires more frequent reporting.
Why this answer
Frequency should be driven by risk volatility and business impact.
During an IT governance board meeting, the CGEIT practitioner notices that the current risk profile deviates significantly from the approved risk appetite. What is the most appropriate next step?
Transparency and proposing corrective governance actions are core responsibilities.
Why this answer
Governance requires transparency and corrective action when thresholds are exceeded.
A company is conducting a risk analysis. Which of the following is an example of an 'inherent risk'?
Inherent risk is the raw exposure of a threat.
Why this answer
Inherent risk is the risk level before any controls are applied.
Why is it important to define risk appetite before developing a risk response plan?
Risk response plans are triggered when risks exceed the appetite.
Why this answer
Appetite acts as the boundary for decision-making.
You are evaluating the maturity of your organization's risk reporting to the board. Which THREE of the following elements are essential for high-maturity reporting?
Contextualizes risk within the business strategy.
Why this answer
High-maturity reporting is strategic, contextual, and forward-looking, rather than purely historical or technical.
A firm has decided to pursue a high-risk innovation strategy. How should the enterprise risk appetite statement be adjusted to support this goal?
This allows for calculated risks while putting boundaries around the duration and impact of those risks.
Why this answer
Governance bodies must define risk tolerance thresholds that allow for strategic agility while ensuring that excessive risk does not threaten core enterprise continuity.
When assessing the impact of a risk, what is the best perspective to take?
Governance is concerned with the impact on enterprise value.
Why this answer
Impact is defined by the loss of business value, not technical downtime.
During a merger, the IT risk governance team identifies incompatible security standards. What is the correct approach?
Harmonization ensures consistency and effective risk management.
Why this answer
A unified standard must be established to manage risk consistently.
A company is performing a risk assessment of a new software vendor. Which factor is most relevant for the governance of third-party risk?
Data exposure risk is the primary driver of third-party governance requirements.
Why this answer
Third-party risk management is rooted in understanding the criticality of the service provided.
An IT project is identified as having a high inherent risk that exceeds the board-approved appetite. The project is critical for competitive advantage. Which approach is most appropriate?
This follows the governance process of accountability and board-level oversight for high-risk strategic decisions.
Why this answer
Governance allows for risk acceptance at the appropriate level if the business value is high.
An enterprise is aligning its IT risk appetite with corporate strategic objectives. Which action should the CGEIT-certified practitioner prioritize first?
Establishing risk capacity and appetite relative to strategic goals is the fundamental first step in risk optimization.
Why this answer
Aligning risk appetite requires a clear understanding of the enterprise's strategic goals and its capacity to absorb loss.
Which metric is most useful for reporting the effectiveness of IT risk management to the board?
This directly answers whether the organization is staying within appetite.
Why this answer
The board needs to see the trend of risk exposure over time.
Which THREE of the following are key inputs for defining the IT risk appetite?
Appetite must serve the strategy.
Why this answer
Appetite is defined by strategic goals, resource capacity, and stakeholder expectations.
An organization's risk appetite has been set as 'low' for data breaches. A new project introduces a moderate risk of a breach. What is the most appropriate governance action?
Risk optimization involves applying controls to align residual risk with appetite.
Why this answer
If a project exceeds appetite, controls must be enhanced or the project must be modified.
Your organization is undergoing a major digital transformation. To ensure risk is optimized throughout the lifecycle, what is the most critical governance activity during the planning phase?
This ensures that risk is considered alongside cost and benefit before any commitment is made.
Why this answer
Embedding risk criteria into the project selection and prioritization process ensures that the organization only commits resources to projects that align with the board's risk appetite.
An organization is transitioning to a cloud-based infrastructure. Which governance mechanism is most effective for ensuring that the cloud service provider's risk management practices remain aligned with the enterprise's risk appetite?
This ensures the provider is contractually bound to maintain visibility into the risk profile.
Why this answer
Continuous monitoring and contractual requirements are key for third-party risk governance.
Which THREE of the following are common risk response strategies?
Valid strategy.
Why this answer
Standard risk strategies are Accept, Avoid, Transfer, and Mitigate.
An organization experiences a high frequency of minor IT incidents. What is the most effective governance action to ensure this does not result in a significant enterprise risk?
RCA identifies the underlying governance and control weaknesses that allow minor risks to persist.
Why this answer
Aggregating risk is essential. Multiple minor incidents can indicate a systemic control weakness that, if unaddressed, leads to a major catastrophe.
You are auditing the integration of IT risk management. Which finding indicates a failure in the governance of enterprise risk?
Risk assessment must be contextually relevant to business processes; decoupling them prevents effective prioritization.
Why this answer
If risk management activities are not linked to the strategic business objectives, the organization lacks effective governance over IT risk.
A company is establishing an IT Risk Committee. Which group should have the most significant representation?
Business owners understand the impact, IT provides the technical expertise.
Why this answer
Governance requires representation from the business, not just IT.
Which TWO of the following describe the role of the 'Risk Owner'?
Core responsibility.
Why this answer
Risk owners are accountable for the management and monitoring of specific risks.
Which of the following is a key component of an effective IT risk management policy?
Governance requires clear accountability for managing risks.
Why this answer
A policy must define roles, responsibilities, and the framework for action.
An enterprise is facing a high-impact risk that cannot be fully mitigated. The board decides to transfer this risk. Which of the following is the best implementation of risk transfer?
Insurance is a classic transfer mechanism for financial liability.
Why this answer
Risk transfer is about moving financial liability, not operational responsibility.
When balancing risk and value in IT investment, what is the primary consideration for the CGEIT practitioner?
This is the core definition of balancing risk and value in IT governance.
Why this answer
Governance is about the trade-offs. Delivering value requires taking risks; the objective is to optimize, not eliminate, risk.
Which TWO of the following are key elements of a Business Impact Analysis (BIA)?
Foundational BIA step.
Why this answer
BIA identifies critical processes and the impact of their disruption.
Which TWO of the following are examples of 'Avoidance' as a risk response?
This eliminates the risk by not engaging.
Why this answer
Avoidance is exiting an activity that carries risk.
When reporting IT risk to the board, which of the following provides the most value?
Boards prioritize risks based on their potential impact on strategic goals.
Why this answer
Boards need context, trends, and business impact rather than technical metrics.
A company is using a risk maturity model to improve its IT risk management. What is the main benefit?
Maturity models provide a standardized way to measure growth.
Why this answer
Maturity models identify gaps to allow for targeted improvements.
To effectively integrate risk management into enterprise governance, which THREE activities should be conducted?
The appetite sets the boundary for all decision-making.
Why this answer
Governance of IT risk requires strategic alignment, clear communication, and defined accountability structures.
An organization is integrating IT risk management into its enterprise governance framework. Which approach best ensures that IT risk is treated as a component of enterprise risk?
A common taxonomy allows for aggregation and comparison of IT risks with other enterprise risks.
Why this answer
Integrating IT risk into the enterprise risk framework ensures visibility for the board and alignment with business objectives, rather than treating it as a siloed technical concern.
An enterprise is adopting an agile development methodology. How should the CGEIT-certified practitioner modify the risk governance process?
Integrating governance controls directly into the toolchain is the best practice for agile environments.
Why this answer
Governance must adapt to the velocity of agile without sacrificing oversight.
Which TWO of the following are examples of risk mitigation?
This reduces the impact of data loss.
Why this answer
Mitigation involves taking action to reduce the likelihood or impact of a risk.
An enterprise is evaluating the trade-off between the cost of risk mitigation and the potential business benefit. Which framework or approach should the practitioner use?
ROSI calculates the value of risk mitigation relative to the cost of controls.
Why this answer
Cost-benefit analysis in risk management is fundamental to risk optimization.
An enterprise is adopting a 'Risk-Based Approach' to IT governance. How should this impact the IT budget allocation?
Risk-based allocation ensures funds mitigate the most significant threats.
Why this answer
Resources should be prioritized where the most significant risks exist.
An IT audit reveals that risk mitigation activities are being performed, but they are not being tracked. What is the governance risk?
Without documentation, governance compliance cannot be proven.
Why this answer
Lack of tracking prevents verification and accountability.
Which THREE of the following are essential components of a risk reporting framework?
Provides the 'so what' for the reader.
Why this answer
Effective reports must be timely, relevant, and actionable for decision-makers.
Which role is typically responsible for the final acceptance of IT risks at the enterprise level?
Risk ownership and acceptance reside at the executive/board level.
Why this answer
Senior management/Board accountability is required for enterprise risk.
What is the relationship between 'IT Risk' and 'Enterprise Risk'?
IT risks, when realized, impact the overall enterprise risk profile.
Why this answer
IT risk is a subset of enterprise risk.
Which TWO of the following are primary objectives of IT risk governance?
Core governance goal.
Why this answer
Governance focuses on ensuring risk management aligns with strategy and business value.
The board of directors is concerned about the impact of recent cybersecurity threats on the company's reputation. Which TWO of the following actions should the Governance committee prioritize to address these concerns?
Ensures the board's strategic concerns (reputation) are translated into risk tolerance.
Why this answer
Aligning risk reporting with board interests and ensuring management accountability are key responsibilities of the governance committee.
When a risk event occurs, what is the first step in the incident response process from a governance perspective?
Containment is the immediate priority to minimize loss.
Why this answer
The first step is to contain the issue and notify the appropriate parties.
Which THREE of the following represent effective ways to integrate IT risk into the organizational culture?
Education builds awareness.
Why this answer
Culture change requires leadership, training, and incentive alignment.
What is the most effective way to ensure that IT risk management is integrated with enterprise risk management (ERM)?
A common language and threshold structure ensures risks are comparable across the enterprise.
Why this answer
Common language and metrics are required for cross-departmental risk alignment.
Which of the following is the primary purpose of a Key Risk Indicator (KRI)?
KRIs are designed to detect trends that lead to risk realization.
Why this answer
KRIs are early warning signs that risk exposure is changing.
An IT project is failing to deliver promised business value. What is the most likely governance failure?
If IT is not aligned with business value, it will fail to deliver results.
Why this answer
Value delivery is directly linked to effective risk and performance management.
The board of directors requests a summary of the current IT risk posture. Which documentation should the practitioner use as the primary source?
The register is the official repository for high-level enterprise risks.
Why this answer
The enterprise risk register provides the consolidated view required by the board.
Ready to test yourself?
Try a timed practice session using only Risk Optimization questions.