Courseiva

CCNA It Governance Mgmt Questions

34 of 109 questions · Page 2/2 · It Governance Mgmt topic · Answers revealed

76
MCQhard

An organization uses the policy shown. Which of the following is an omission in the policy?

A.No definition of authorized users
B.No mention of backup frequency
C.No specification of data disposal methods after retention periods
D.Missing encryption requirement for log data
AnswerC

The policy defines retention but not deletion or archiving.

Why this answer

The policy does not specify data disposal methods after the retention period, which is a critical omission for data lifecycle management. Option A is incorrect because authorized users are likely defined elsewhere in the policy. Option B is incorrect because backup frequency is mentioned.

Option D is incorrect because encryption may not be required for all log data based on the policy context.

77
Multi-Selectmedium

An organization is adopting COBIT 2019. Which TWO of the following are components of the governance system?

Select 2 answers
A.Processes
B.IT hardware inventory
C.Information flows
D.Organizational structures
E.Employee satisfaction surveys
AnswersA, D

Processes are a core component in COBIT.

Why this answer

The correct answers are A (Processes) and D (Organizational structures). COBIT 2019 defines governance system components that include processes and organizational structures, among others. Processes describe the organized sets of practices, while organizational structures define roles and responsibilities.

Option B (IT hardware inventory) is a resource or asset, not a component of the governance system. Option C (Information flows) is related to the Information component but is not a standalone component; information itself is a component, but flows are part of processes. Option E (Employee satisfaction surveys) is an HR activity, not a governance component.

78
MCQhard

A multinational corporation is adopting a hybrid cloud strategy. The IT governance board must decide on a framework to ensure alignment with business objectives and regulatory compliance. Which framework is MOST appropriate?

A.ITIL 4 Service Value System
B.COBIT 2019
C.ISO/IEC 27001 Information Security Management
D.PMBOK Guide
AnswerB

COBIT 2019 is a comprehensive framework for IT governance and management.

Why this answer

COBIT 2019 is the most appropriate framework because it is specifically designed for IT governance, providing a comprehensive set of controls and processes to align IT with business objectives and ensure regulatory compliance. In a hybrid cloud strategy, COBIT 2019's focus on governance objectives, stakeholder needs, and risk management directly addresses the board's need for oversight across on-premises and cloud environments, unlike frameworks that target service management, security, or project management.

Exam trap

The trap here is that candidates often confuse ITIL (service management) with governance, assuming that best practices for service delivery inherently cover board-level alignment and compliance, but ITIL lacks the governance objectives and stakeholder-driven goal cascade that COBIT provides for hybrid cloud strategies.

How to eliminate wrong answers

Option A is wrong because ITIL 4 Service Value System focuses on IT service management (ITSM) best practices, such as incident and change management, but lacks the governance and compliance alignment mechanisms required for board-level decision-making in a hybrid cloud strategy. Option C is wrong because ISO/IEC 27001 is an information security management standard that addresses security controls and risk management, but it does not provide a holistic governance framework for aligning IT with business objectives and regulatory compliance across the entire enterprise. Option D is wrong because PMBOK Guide is a project management framework that covers project lifecycle and processes, but it is not designed for ongoing IT governance or ensuring sustained alignment with business goals and compliance in a hybrid cloud environment.

79
Multi-Selectmedium

Which TWO of the following are primary objectives of IT governance as defined by COBIT 5?

Select 2 answers
A.Resource optimization
B.Cost reduction
C.Incident response
D.Value delivery
E.Data encryption
AnswersA, D

Resource optimization is a key governance objective.

Why this answer

Options A and D are correct because COBIT 5 defines primary IT governance objectives as stakeholder value delivery and resource optimization. Option B (cost reduction) is a management objective, not governance. Option C (incident response) is an operational activity.

Option E (data encryption) is a security control.

80
Multi-Selecteasy

Which TWO of the following are key components of an IT governance framework?

Select 2 answers
A.IT strategy committee
B.IT asset inventory
C.IT risk management
D.IT project portfolio management
E.IT help desk ticketing system
AnswersA, C

Governance requires a steering or strategy committee.

Why this answer

Options A and C are correct. An IT governance framework includes structures like an IT strategy committee (A) and processes like IT risk management (C). B (IT asset inventory) is an operational practice, D (IT project portfolio management) is a management practice, and E (IT help desk ticketing system) is operational.

None of these are core governance components.

81
MCQhard

During an IT audit, the auditor discovers that the IT department has not conducted a business impact analysis (BIA) for three years. The organization's disaster recovery plan (DRP) is based on the previous BIA. The IT manager argues that the DRP is still valid because no major changes have occurred. What should the auditor recommend?

A.Recommend that a new BIA be conducted to validate and update the DRP.
B.Accept the IT manager's rationale and close the finding.
C.Recommend terminating the current DRP until the BIA is completed.
D.Recommend accepting the risk and documenting the decision.
AnswerA

A current BIA is essential to identify changes in business processes and threats, ensuring the DRP is aligned.

Why this answer

A business impact analysis (BIA) is the foundation of a valid disaster recovery plan (DRP). Without a current BIA, the DRP may not reflect the organization's current critical processes, recovery time objectives (RTOs), or recovery point objectives (RPOs). Even if no major changes are perceived, subtle shifts in dependencies, resource availability, or regulatory requirements can render the DRP ineffective.

Therefore, the auditor should recommend conducting a new BIA to validate and update the DRP.

Exam trap

The trap here is that candidates may assume the IT manager's claim of 'no major changes' is sufficient, but the CISA exam emphasizes that a BIA must be periodically reviewed (typically annually) regardless of perceived stability, because hidden dependencies or gradual changes can still affect recovery requirements.

How to eliminate wrong answers

Option B is wrong because accepting the IT manager's rationale without evidence ignores the risk that the DRP may be outdated; the auditor's role is to verify, not assume, that no changes have impacted recovery requirements. Option C is wrong because terminating the current DRP would leave the organization without any recovery plan until the BIA is completed, increasing operational risk unnecessarily. Option D is wrong because accepting the risk and documenting the decision without further action is premature; the auditor should first recommend a BIA to determine the actual risk level before deciding to accept it.

82
Multi-Selectmedium

An organization is implementing IT governance based on COBIT. Which THREE of the following are enablers? (Select exactly three.)

Select 3 answers
A.Application software
B.Organizational structures
C.Culture, ethics, and behavior
D.Network infrastructure
E.Processes
AnswersB, C, E

Structures are enablers for decision-making.

Why this answer

COBIT defines enablers as factors that influence the effectiveness of governance. Processes, organizational structures, and culture/ethics/behavior are key enablers. Network infrastructure and application software are resources, not enablers in the COBIT framework.

83
Multi-Selectmedium

An organization is implementing an IT governance framework to align IT with business objectives. Which TWO of the following are primary responsibilities of the IT steering committee?

Select 2 answers
A.Performing daily IT operations
B.Defining IT security policies
C.Approving IT project budgets and priorities
D.Conducting technical vulnerability assessments
E.Ensuring IT investments deliver value
AnswersC, E

The IT steering committee provides oversight and approval for major IT investments and priorities.

Why this answer

Options C and E are correct. The IT steering committee is responsible for approving IT project budgets and priorities (C) and ensuring IT investments deliver value (E). Performing daily IT operations (A) is an operational management task.

Defining IT security policies (B) is typically the responsibility of the security function. Conducting technical vulnerability assessments (D) is a technical operational activity.

84
MCQmedium

Based on the exhibit, which metric would be LEAST relevant to the 'Customer' perspective?

A.Number of New Features Delivered
B.System Uptime Percentage
C.Satisfaction Survey Score
D.Complaint Resolution Time
AnswerB

Correct. Uptime is more aligned with internal process perspective.

Why this answer

(System Uptime Percentage) is the least relevant to the Customer perspective because system uptime is an operational metric that primarily supports the Internal Process perspective (e.g., reliability and availability). In contrast, the other options directly measure customer satisfaction and engagement: Number of New Features (customer-driven innovation), Satisfaction Survey Score (direct feedback), and Complaint Resolution Time (service responsiveness). While uptime may indirectly affect customer satisfaction, it is not a direct measure of the customer perspective as defined by balanced scorecard frameworks.

85
MCQmedium

A large financial institution has a well-defined IT governance framework with a clear organizational structure, policies, and processes. However, the internal audit department has identified that several IT projects are over budget and behind schedule. The project managers blame unclear requirements and scope creep. The IT governance committee meets monthly but reviews projects only at a high level. The auditor's best recommendation to improve project governance is to:

A.Increase the frequency of security reviews for all projects
B.Change the IT steering committee's meeting frequency to weekly with detailed reviews
C.Establish a project management office (PMO) to oversee project governance and reporting
D.Require all projects to use a specific project management software tool
AnswerC

Establishing a project management office (PMO) provides standardized project governance, oversight, and controls to prevent scope creep and improve delivery performance.

Why this answer

Establishing a project management office (PMO) provides standardized project management practices, oversight, and controls to prevent scope creep and improve delivery. Option A is tactical and focuses on security, not project delivery. Option B changes meeting frequency but does not establish a dedicated project governance function.

Option D mandates a tool but does not address underlying governance processes.

86
MCQhard

During a risk assessment, an IS auditor identifies that the IT department has not performed a business impact analysis (BIA) for critical systems. Which of the following is the MOST significant risk?

A.Non-compliance with software licensing
B.Increased likelihood of security breaches
C.Inability to calculate total cost of ownership
D.Uncertainty regarding recovery time objectives for critical systems
AnswerD

BIA defines RTOs; without it, recovery priorities are unclear.

Why this answer

Without a BIA, recovery time objectives (RTOs) are uncertain, leading to potential unacceptable downtime. Option A is a consequence but not the primary risk. Option B is incorrect because BIA is for recovery, not cost.

Option C is less direct.

87
MCQhard

A financial institution is required by regulators to demonstrate that IT controls are effective. Which of the following provides the BEST evidence?

A.IT balanced scorecard
B.Internal audit reports
C.IT risk register
D.Service organization control (SOC) reports
AnswerD

SOC reports provide independent assurance on controls.

Why this answer

Service organization control (SOC) reports are independent audits of control effectiveness, highly regarded by regulators. Internal audit reports are valuable but may lack independence; risk register and balanced scorecard are not direct evidence of control effectiveness.

88
MCQeasy

An IT department uses a balanced scorecard to measure performance. Which metric would BEST reflect the 'customer perspective'?

A.Training hours per employee
B.System uptime percentage
C.User satisfaction survey results
D.Project completion rate
AnswerC

Correct. Directly measures customer perception.

Why this answer

The customer perspective focuses on user satisfaction and service responsiveness. Option A is incorrect as training hours relate to learning and growth perspective. Option B is incorrect as system uptime is an internal process metric.

Option D is incorrect as project completion rate is an internal efficiency metric.

89
MCQmedium

An IT manager is reviewing the service level agreements (SLAs) for a cloud-based email service. The SLA guarantees 99.9% uptime per month. The service experienced an outage of 45 minutes in a 30-day month. Did the service meet the SLA?

A.Yes, because 45 minutes is within 0.1% of the total time.
B.Yes, because the SLA is calculated per day, not per month.
C.No, because any downtime exceeding 30 minutes is a violation.
D.No, because the allowed downtime for 99.9% uptime is approximately 43 minutes.
AnswerD

The SLA allows 43.2 minutes; 45 minutes is over the limit.

Why this answer

The SLA guarantees 99.9% uptime per month. For a 30-day month (43,200 minutes), 99.9% uptime allows only 0.1% downtime, which is 43.2 minutes. The actual outage of 45 minutes exceeds this threshold, so the SLA was not met.

Option D correctly identifies the allowed downtime as approximately 43 minutes.

Exam trap

The trap here is that candidates may incorrectly round 43.2 minutes to 43 minutes and then assume 45 minutes is close enough, or they may mistakenly think 0.1% of a month is 30 minutes, leading them to choose option C.

How to eliminate wrong answers

Option A is wrong because 45 minutes is not within 0.1% of the total time; 0.1% of 43,200 minutes is 43.2 minutes, so 45 minutes exceeds the allowed downtime. Option B is wrong because the SLA explicitly states 'per month,' not per day, and calculating per day would allow even less downtime (e.g., 0.1% of 1,440 minutes = 1.44 minutes per day). Option C is wrong because the SLA does not specify a 30-minute threshold; the allowed downtime is derived from the 99.9% uptime calculation, not an arbitrary 30-minute limit.

90
MCQmedium

An IT audit revealed that the organization's IT steering committee has not met in the past six months. Which of the following is the MOST likely consequence of this situation?

A.Higher IT staff turnover.
B.Increased number of security incidents.
C.Inconsistent IT policies across departments.
D.Delayed decision-making on IT investments.
AnswerD

The committee's primary role is to make strategic decisions.

Why this answer

The IT steering committee is responsible for approving and prioritizing IT investments; without meetings, decisions on investments are delayed. Option A is less direct, as turnover is influenced by many factors. Option B is incorrect because security incidents are typically addressed by operational security teams.

Option C is incorrect because IT policies are usually set by separate governance processes, not solely by the steering committee.

91
Multi-Selecteasy

Which TWO of the following are benefits of establishing an IT steering committee?

Select 2 answers
A.Improved operational efficiency of IT systems
B.Enhanced prioritization of IT investments
C.Better alignment between IT and business strategy
D.Reduction of management overhead
E.Direct control over technical IT decisions
AnswersB, C

Prioritization is a core benefit.

Why this answer

Options B and C are correct because an IT steering committee provides strategic alignment and prioritization of IT initiatives, ensuring they align with business goals. Option A is not a benefit; operational efficiency is a management responsibility, not a committee function. Option D is incorrect; establishing a steering committee may add governance overhead rather than reduce management overhead.

Option E is not a primary benefit; technical decisions are typically delegated to IT management.

92
MCQmedium

An organization is planning to outsource its data center operations. Which of the following governance practices should be implemented to ensure proper oversight?

A.Conduct annual financial audits of the outsourcer.
B.Require the outsourcer to obtain ISO 27001 certification.
C.Establish a service level agreement (SLA) with key performance indicators (KPIs).
D.Allow the outsourcer to manage all security controls independently.
AnswerC

SLA with KPIs enables ongoing performance monitoring.

Why this answer

Establishing a service level agreement (SLA) with key performance indicators (KPIs) provides measurable performance targets and accountability, ensuring proper oversight of outsourced data center operations. Option A (annual financial audits) addresses financial compliance but not operational oversight. Option B (ISO 27001 certification) is a certification, not an ongoing governance practice.

Option D (allowing the outsourcer to manage all security controls independently) abdicates the organization's responsibility for oversight.

93
Multi-Selecthard

Which THREE of the following are commonly recognized benefits of implementing a formal IT service management (ITSM) framework such as ITIL?

Select 3 answers
A.Better alignment between IT services and business needs
B.Guaranteed zero downtime for critical services
C.Elimination of the need for external IT audits
D.Improved service quality and availability
E.Increased efficiency and cost savings through standardized processes
AnswersA, D, E

ITSM incorporates business requirements into service design and delivery.

Why this answer

A formal ITSM framework like ITIL explicitly focuses on aligning IT service delivery with business objectives through defined processes like service strategy and service design. This alignment ensures that IT investments and operations directly support business outcomes, such as improving customer satisfaction or enabling new revenue streams, rather than operating in a silo.

Exam trap

The trap here is that candidates may confuse the risk-reduction benefits of ITSM (like improved availability) with an absolute guarantee, or assume that a framework replaces independent verification, when in reality ITSM improves processes but does not eliminate the need for external audits or guarantee perfect uptime.

94
MCQeasy

An IT manager is developing a governance policy for change management. Which element is MOST important to include?

A.Project management methodology
B.Detailed technical procedures
C.List of all applications
D.Roles and responsibilities
AnswerD

Roles and responsibilities is correct because clearly defined roles and responsibilities ensure accountability in the change process.

Why this answer

Clearly defined roles and responsibilities ensure accountability in the change process. Option A is incorrect because project management methodology is separate from governance policy. Option B is incorrect as detailed technical procedures are part of implementation, not governance.

Option C is incorrect because a list of all applications is operational, not a governance element.

95
Multi-Selecthard

Which THREE of the following are components of a typical IT governance framework?

Select 3 answers
A.Network troubleshooting procedures
B.Strategic alignment of IT with business
C.Risk management and compliance
D.Performance measurement and reporting
E.Vendor contract management
AnswersB, C, D

Core governance component.

Why this answer

Strategic alignment of IT with business is a core component of an IT governance framework because it ensures that IT initiatives directly support and enable the organization's business objectives and strategies. This alignment is achieved through mechanisms like balanced scorecards and IT steering committees, which prioritize IT investments based on business value. Without this component, IT may operate in a silo, leading to wasted resources and missed opportunities.

Exam trap

The trap here is that candidates often confuse operational IT activities (like troubleshooting or contract management) with the strategic, oversight-oriented components of governance, leading them to select options that describe 'doing IT' rather than 'governing IT'.

96
MCQmedium

A company's IT governance policy requires that all critical systems have a documented business continuity plan (BCP). During an audit, an IT auditor finds that the BCP for a critical financial system has not been updated in three years. Which of the following is the BEST recommendation?

A.Archive the outdated BCP and develop a new one from scratch.
B.Update the BCP to reflect current processes and conduct a test.
C.Accept the risk because the system has been stable.
D.Implement a new system with built-in redundancy.
AnswerB

Updating and testing ensures the plan is viable and aligns with governance requirements.

Why this answer

IT governance policies require that BCPs remain current to reflect actual operational processes. An outdated BCP (three years stale) may contain obsolete recovery procedures, contact information, or dependencies, rendering it ineffective during a real incident. Updating the BCP and then testing it validates that the documented steps align with the current system architecture and can be executed successfully, which is a core requirement of the BCP lifecycle per ISACA guidelines.

Exam trap

The trap here is that candidates may assume a stable system means the BCP remains valid, but CISA tests the principle that BCPs must be living documents reviewed and tested at regular intervals (typically annually) regardless of system stability.

How to eliminate wrong answers

Option A is wrong because archiving and rewriting from scratch is unnecessarily disruptive and time-consuming; the existing BCP likely contains valuable baseline information that should be reviewed and updated rather than discarded. Option C is wrong because accepting risk based on system stability ignores the fact that processes, personnel, and dependencies change over time; a stable system does not guarantee that the BCP's recovery steps, contact lists, or resource allocations are still valid. Option D is wrong because implementing a new system with built-in redundancy is a disproportionate and costly response to an outdated BCP; it does not address the immediate compliance gap and may introduce new risks without proper BCP documentation.

97
MCQmedium

According to COBIT 2019, which design factor is MOST critical for tailoring a governance system?

A.Regulatory environment
B.Technology complexity
C.Organizational size
D.Enterprise strategy
AnswerD

Correct. Strategy sets the direction for governance design.

Why this answer

Enterprise strategy determines the governance objectives and risk appetite, making it the most critical design factor. Options A, B, and C are all important but secondary; they influence the system but are driven by strategy.

98
MCQeasy

An organization's IT strategy must be aligned with business strategy. Which of the following is the PRIMARY benefit of this alignment?

A.Faster adoption of new technologies
B.Enhanced security posture
C.Reduced IT operational costs
D.Increased value of IT investments to business objectives
AnswerD

Alignment ensures IT delivers value that supports business strategy.

Why this answer

When IT strategy is aligned with business strategy, every IT investment is directly tied to achieving specific business objectives, such as increasing revenue, improving customer experience, or enabling new business models. This alignment ensures that resources are allocated to projects that deliver measurable business value, rather than being spent on technology for its own sake. The primary benefit is therefore the increased value of IT investments to business objectives, as misalignment often leads to wasted expenditure on systems that do not support core business goals.

Exam trap

The trap here is that candidates often confuse operational benefits (like cost reduction or faster tech adoption) with the strategic primary benefit, failing to recognize that alignment is fundamentally about ensuring IT investments deliver value to the business, not about efficiency or security alone.

How to eliminate wrong answers

Option A is wrong because faster adoption of new technologies is a potential operational benefit, but it is not the primary benefit of alignment; rapid adoption without business context can actually lead to misalignment and wasted resources. Option B is wrong because enhanced security posture is a critical outcome of good IT governance, but it is a secondary benefit that results from aligning security controls with business risk appetite, not the primary reason for aligning IT and business strategy. Option C is wrong because reduced IT operational costs can be a byproduct of alignment (e.g., eliminating redundant systems), but cost reduction is not the primary goal; the primary goal is ensuring IT spending directly supports business value creation, which may sometimes require increased investment.

99
MCQhard

An organization is implementing a new ERP system. The project sponsor requests a change that will significantly increase project scope without additional budget. Which of the following is the BEST action for the project manager?

A.Accept the change and adjust the project timeline accordingly.
B.Initiate the formal change control process and escalate to the steering committee.
C.Implement the change and inform the steering committee later.
D.Reject the change because it is outside the original scope.
AnswerB

Proper change control ensures governance and stakeholder involvement.

Why this answer

The project manager must follow the formal change control process to evaluate the impact of a scope change that lacks additional budget. Escalating to the steering committee is appropriate because they have the authority to approve or reject changes that affect project constraints, ensuring alignment with organizational governance and IT strategy.

Exam trap

The trap here is that candidates may choose to reject the change outright (Option D) thinking it protects the baseline, but the CISA exam emphasizes following the formal change control process and escalating to the appropriate governance body rather than making unilateral decisions.

How to eliminate wrong answers

Option A is wrong because accepting the change without budget or formal approval violates project governance and may lead to resource overallocation and timeline failure. Option C is wrong because implementing the change before informing the steering committee bypasses the required change control process and risks unauthorized scope creep. Option D is wrong because outright rejection without following the change control process denies the steering committee the opportunity to assess the change's strategic value or reallocate priorities.

100
MCQhard

An organization's data classification policy defines 'Confidential' data as requiring encryption at rest. An IS auditor discovers that a database containing customer personal information is not encrypted. What is the auditor's BEST course of action?

A.Encrypt the database immediately
B.Report the finding to the data owner and IT management
C.Recommend a compensating control
D.Verify the classification of the data
AnswerB

Reporting ensures accountability for remediation.

Why this answer

The IS auditor's primary responsibility is to report findings to the appropriate stakeholders—the data owner and IT management—so they can take corrective action. Option A is incorrect because implementing controls is management's responsibility, not the auditor's. Option C is premature; compensating controls should be recommended after reporting and discussing the risk.

Option D is unnecessary since the data classification policy already defines 'Confidential' data requiring encryption, and the auditor has identified a violation of that policy.

101
MCQeasy

During an IT audit, the auditor discovers that the IT strategy is not formally documented. Which of the following is the MOST significant risk associated with this finding?

A.Difficulty in recruiting qualified IT staff.
B.Inability to measure the performance of IT systems.
C.Lack of alignment between IT investments and business goals.
D.Increased operational costs due to unplanned IT initiatives.
AnswerC

Undocumented strategy leads to misalignment, the most significant risk.

Why this answer

Without a formally documented IT strategy, IT investments may not be aligned with business goals, leading to misalignment and wasted resources. This is the most significant risk as it directly impacts the organization's ability to achieve its objectives. Option A is possible but less direct.

Option B is a consequence but not the most significant. Option D is a potential outcome but not as critical as misalignment with business goals.

102
Multi-Selectmedium

Which TWO of the following are key responsibilities of an IT steering committee?

Select 2 answers
A.Monitoring IT performance and value delivery
B.Managing day-to-day IT operations
C.Writing and testing application code
D.Prioritizing IT projects and allocating resources
E.Conducting IT audit engagements
AnswersA, D

Steering committee oversees performance.

Why this answer

The IT steering committee is a senior-level governance body responsible for aligning IT strategy with business objectives. Monitoring IT performance and value delivery (A) is a key responsibility because the committee must ensure that IT investments generate the expected business benefits and that service levels meet agreed targets. Prioritizing IT projects and allocating resources (D) is also a core duty, as the committee decides which initiatives receive funding and staffing based on strategic importance and risk, rather than operational urgency.

Exam trap

The trap here is confusing governance responsibilities (steering committee) with management or execution tasks (operations, coding, auditing), leading candidates to select options that sound plausible but belong to lower-level roles.

103
Multi-Selecthard

Which THREE of the following are indicators of mature IT governance?

Select 3 answers
A.The IT department has high staff retention.
B.IT risks are formally assessed and managed.
C.IT projects are completed on time and within budget.
D.IT decisions are aligned with business strategy.
E.The board receives regular IT performance reports.
AnswersB, D, E

Formal assessment and management of IT risks indicates mature IT governance by demonstrating a structured, proactive approach to safeguarding organisational assets. This systematic process moves beyond ad-hoc reactions, encompassing continuous identification, evaluation, mitigation, and monitoring of potential threats. Such formalisation signifies an organisation's commitment to repeatable, controlled mechanisms for achieving strategic objectives, a definitive characteristic of governance maturity.

Why this answer

Options B, D, and E are correct. Mature IT governance is indicated by formal risk assessment and management (B), alignment of IT decisions with business strategy (D), and regular board reporting on IT performance (E). Option A (high staff retention) is an HR metric, not a governance indicator.

Option C (on-time and within-budget projects) is a project management measure, not a governance maturity indicator.

104
MCQmedium

An IT department is struggling with project delays and budget overruns. Which governance practice would be MOST effective?

A.Establishing a project management office (PMO)
B.Outsourcing projects
C.Increasing IT staff
D.Adopting agile methodology
AnswerA

PMO provides governance, standards, and oversight.

Why this answer

Establishing a Project Management Office (PMO) provides standardized project management practices, oversight, and governance, addressing delays and overruns. Agile methodology alone may not provide governance; increasing staff or outsourcing may not solve underlying issues.

105
Drag & Dropmedium

Arrange the steps to perform a risk assessment in the correct order.

Drag steps to the numbered slots on the right, or tap a step then tap a slot.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Risk assessment begins with asset identification, then threat/vulnerability identification, followed by risk analysis, prioritization, and documentation of treatment.

106
MCQeasy

An organization is developing its IT strategy to align with the overall business strategy. The business strategy emphasizes rapid market expansion through digital products. Which of the following IT strategies would BEST support this business goal?

A.Standardize all IT systems to reduce complexity.
B.Adopt agile development methods and scalable cloud infrastructure.
C.Outsource all IT operations to a low-cost provider.
D.Minimize IT investment to preserve capital for business growth.
AnswerB

Agile and cloud enable rapid, scalable deployment of digital products.

Why this answer

Rapid market expansion through digital products requires agility, speed, and scalability. Agile development methods enable iterative, fast delivery of features, while cloud infrastructure provides elastic resources to scale quickly. Option A is wrong because excessive standardization can hinder innovation and slow down time-to-market.

Option C is wrong because outsourcing to a low-cost provider may prioritize cost over speed and quality, which is not suitable for rapid expansion. Option D is wrong because minimizing IT investment would deprive the organization of the necessary resources to develop and scale digital products.

107
MCQmedium

A company is considering restructuring its IT department from a centralized to a decentralized model to give business units more autonomy. What is a PRIMARY governance risk associated with this move?

A.Difficulty in managing vendor contracts due to decentralization.
B.Reduced innovation due to lack of central coordination.
C.Increased risk of project cost overruns.
D.Inconsistent IT policies and security controls across business units.
AnswerD

Inconsistent IT policies and security controls directly impact governance by undermining standardization and control.

Why this answer

The primary governance risk when moving from a centralized to a decentralized IT model is the potential for inconsistent IT policies and security controls across business units (Option D). Decentralization gives business units autonomy, which can lead to differences in how IT policies are interpreted and applied, increasing the risk of security gaps and non-compliance. Option A (difficulty in managing vendor contracts) is a valid operational concern but not a primary governance risk.

Option B (reduced innovation) is unlikely, as decentralization often fosters innovation. Option C (increased cost overruns) can occur but is typically a financial risk rather than a governance risk.

108
MCQmedium

An organization has experienced several security incidents due to unauthorized changes to production systems. Which governance mechanism should be strengthened?

A.IT asset management
B.Configuration management database
C.Incident response plan
D.Change management process
AnswerD

This controls the approval and implementation of changes.

Why this answer

A change management process ensures that all changes are authorized, tested, and approved, directly addressing unauthorized changes. Asset management, CMDB, and incident response are supportive but not the primary control.

109
MCQeasy

An IT steering committee is reviewing a proposal for a new customer relationship management (CRM) system. Which of the following BEST demonstrates that the proposal aligns with the organization's strategic goals?

A.The business case includes a clear link to the organization's five-year strategic plan.
B.The project manager has extensive experience with CRM implementations.
C.The proposed system includes advanced analytics capabilities.
D.The vendor offers discounted licensing for the first year.
AnswerA

Direct reference to the strategic plan demonstrates alignment.

Why this answer

A clear link to the organization's five-year strategic plan demonstrates that the proposal aligns with strategic goals. Option B is about the project manager's experience, which does not indicate strategic alignment. Option C describes a feature that may be beneficial but is not inherently tied to strategic goals.

Option D is a cost-saving tactic, not evidence of strategic alignment.

← PreviousPage 2 of 2 · 109 questions total

Ready to test yourself?

Try a timed practice session using only It Governance Mgmt questions.