Certified in the Governance of Enterprise IT Exam Questions and Answers
Which of the following is a CIO's BEST approach to ensure IT executes against an approved strategy?
Which of the following would BEST help to prevent an IT system from becoming obsolete before its planned return on investment (ROI)?
An enterprise's board of directors is developing a strategy change. Although the strategy is not finalized, the board recognizes the need for IT to be responsive. Which of the following is the FIRST step to prepare for this change?
An enterprise's IT department has failed to deliver required solutions on time due to insufficient resource allocation, resulting in a longer time to market. Which of the following is the BEST way for the chief information officer (CIO) to address this situation?
Which of the following situations provides the BEST justification for considering the adoption of a qualitative risk assessment method?
Which of the following will BEST enable an enterprise to convey IT governance direction and objectives?
Which of the following should be done FIRST when developing an IT strategy to support a new AI business strategy?
Which of the following is the BEST way for a CIO to ensure that the work of IT employees is aligned with approved IT directives?
An enterprise’s IT department has been operating independently without regard to business concerns, leading to misalignment between business and IT. The BEST way to establish alignment would be to require:
An enterprise will be adopting wearable technology to improve business performance. Which of the following is the BEST way for the CIO to validate IT’s preparedness for this initiative?
Which of the following is the BEST way for a CIO to ensure that IT-related training is taken seriously by the IT management team and direct employees?
Forensic analysis revealed an attempted breach of a personnel database containing sensitive data. A subsequent investigation found that no one within the enterprise was aware of the breach attempt, even though logs recorded the unauthorized access actions. To prevent a similar situation in the future, what is MOST important for IT governance to require?
Which of the following provides an enterprise with the BEST understanding of the value proposition for employing a new cloud service?
An organization requires updates to their IT infrastructure to meet business needs. Which of the following will provide the MOST useful information when planning for the necessary IT investments?
An enterprise has launched a digitization effort requiring a single view of customer information across all product lines. Which of the following should be done FIRST to enable this initiative?
Which of the following BEST enables informed IT investment decisions?
An enterprise is required to implement several regulatory requirements. Which of the following functions is BEST suited to determine compliance priorities?
Which of the following BEST supports an IT strategy committee’s objective to align employee competencies with planned initiatives?
An IT governance committee is defining a risk management policy for a portfolio of IT-enabled investments. Which of the following should be the PRIMARY consideration when developing the policy?
New legislation requires an enterprise to report cybersecurity incidents to a government agency within a defined timeline. Which of the following should be the FIRST course of action?
An enterprise plans to migrate its applications and data to an external cloud environment. Which of the following should be the ClO's PRIMARY focus before the migration?
When an enterprise plans to deploy mobile device technologies, it is MOST important for leadership to ensure that:
When identifying improvements focused on the information asset life cycle, which of the following is CRITICAL for enabling data interoperability?
A regulator has expressed concerns about the timeliness of information reported from an enterprise. Which of the following should be done FIRST to address this issue?
Which of the following should be done FIRST when preparing to migrate patient records to a cloud service provider?
Which of the following should be the MOST important consideration when establishing key performance indicators (KPIs) for IT initiatives?
When an enterprise outsources to a third-party data center, who is accountable for the governance of data retention controls for the data that has been transferred?
Which of the following is MOST helpful in determining whether an enterprise’s quality assurance (QA) program is meeting business requirements?
An enterprise is planning to upgrade its current enterprise resource planning (ERP) system to remain competitive within the industry. Which of the following would be MOST helpful to facilitate a successful implementation?
An enterprise has an overarching enterprise architecture (EA) document. The CIO is concerned that EA is not leveraged in recent IT-enabled investments. Which of the following would BEST help to address these concerns and enforce the leveraging of EA?
Which of the following is the BEST approach to ensure global regulatory compliance when implementing a new business process?
Which of the following is the BEST critical success factor (CSF) to use when changing an IT value management program in an enterprise?
Which of the following should be the CIO’s GREATEST consideration when making changes to the IT strategy?
An IT governance committee realizes there are antiquated technologies in use throughout the enterprise. Which of the following is the BEST group to evaluate the recommendations to address these shortcomings?
Which of the following BEST enables an enterprise to minimize the risks of intellectual property theft and loss of sensitive information when acquiring Internet of Things (IoT) hardware and software components?
The GREATEST benefit associated with a decision to implement performance metrics for key IT assets is the ability to:
A CIO observes that many information assets are hosted on legacy technology that can no longer be patched or updated. The systems are not currently in use, but business units are reluctant to decommission assets due to information retention requirements. Which of the following is the BEST strategic response to this situation?
When conducting a risk assessment in support of a new regulatory
requirement, the IT risk committee should FIRST consider the:
Of the following, who is responsible for the achievement of IT strategic objectives?
Which of the following is MOST important for the successful establishment of an ethics program?
Which of the following BEST enables an enterprise to determine an appropriate retention policy for its information assets?
When selecting a cloud provider, which of the following provides the MOST comprehensive information regarding the current status and effectiveness of the provider's controls?
Which of the following is MOST important to have in place to ensure a business continuity plan (BCP) can be executed?
A newly appointed CIO is concerned that IT is too reactive and wants to ensure IT adds value to the enterprise by proactively anticipating business needs. Which of the following will BEST contribute to meeting this objective?
Despite an adequate training budget, IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?
What should be the FIRST action of a new CIO when considering an IT governance framework for an enterprise?
A series of cyber events impacting internet-facing business services has been successfully contained. To minimize future business risk exposure, which of the following should the board require of the IT team?
Which of the following is the GREATEST consideration when evaluating whether to comply with the new carbon footprint regulations impacted by blockchain technology?
Which of the following BEST facilitates the adoption of an IT governance program in an enterprise?
Despite an adequate training budget. IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?
An organization has decided to integrate IT risk with the enterprise risk management (ERM) framework. The FIRST step to enable this integration is to establish:
Which of the following BEST helps to ensure that IT standards will be consistently applied across the enterprise?
Which of the following is the BEST way for a CIO to provide progress updates on a newly implemented IT strategic plan to the board of directors?
Present an IT summary dashboard.
Present IT critical success factors (CSFs).
Report results Of key risk indicators (KRIs).
An enterprise has decided to use third-party software for a business process which is hosted and supported by the same third party. The BEST way to provide quality of service oversight would be to establish a process:
The board of an enterprise has decided to implement an emerging technology, and employees are extremely concerned about the unknown future of the company. What should be the CIO’s PRIMARY responsibility in addressing these concerns?
Which of the following provides the STRONGEST indication that IT governance is well established within an organizational culture?
Senior management is concerned about the unauthorized use of third-party data that is stored within the enterprise's data repositories. Which of the following is the BEST way to address this concern?
Which of the following is the PRIMARY outcome of using a comprehensive architecture framework?
A newly established IT steering committee is concerned whether a system is meeting availability objectives. Which of the following will provide the BEST information to make an assessment?
What is the BEST way for IT to achieve compliance with regulatory requirements?
Which of the following would BEST help assess the effectiveness of a newly established IT governance framework?
Which of the following BEST enables an enterprise to determine whether a current program for IT infrastructure migration to the cloud is continuing to provide benefits?
An enterprise wants to establish key risk indicators (KRIs) in an effort to better manage IT risk. Which of the following should be identified FIRST?
To define the risk management strategy, which of the following MUST be set by the board of directors?
Which of the following is the PRIMARY responsibility of a data steward at an enterprise with mature data management programs?
From a governance perspective, which of the following functions MUST approve the agreed-upon criteria for a new technology-enabled service before submitting the final high-level design to project stakeholders?
Which of the following has the GREATEST impact on the design of an IT governance framework?
The BEST way for a CIO to justify maintaining and supporting social media platforms is by demonstrating:
Which of the following is the BEST approach to assist an enterprise in planning for iT-enabled investments?
Which of the following BEST supports the implementation of an effective data classification policy?
Which of the following is the BEST way to implement effective IT risk management?
Following a re-prioritization of business objectives by management, which of the following should be performed FIRST to allocate resources to IT processes?
The PRIMARY reason a CIO and IT senior management should stay aware of the business environment is to:
In which of the following situations is it MOST appropriate to use a quantitative risk assessment?
An enterprise is approaching the escalation date of a major IT risk. The IT steering committee wants to ascertain who is responsible for the risk response. Where should the committee find this information?
Communicating which of the following to staff BEST demonstrates senior management's commitment to IT governance?
Which of the following would be the BEST way for an IT steering committee to monitor the adoption of a new enterprise IT strategy?
An enterprise-wide strategic plan has been approved by the board of directors. Which of the following would BEST support the planning of IT investments required for the enterprise?
An IT strategy committee wants to ensure stakeholders understand who owns each strategic objective. To enable this understanding, which of the following should be communicated to stakeholders?
What should be an IT steering committee's FIRST course of action when an enterprise is considering establishing a virtual reality store to sell its products?
A financial services company has implemented the use of a cloud-based centralized customer relationship management (CRM) system. The company has decided to go multi-national. Which of the following should be the enterprise risk management (ERM) committee's PRIMARY consideration?
Which of the following is the MOST appropriate mechanism for measuring overall IT organizational performance?
Which of the following has PRIMARY responsibility to define the requirements for IT service levels for the enterprise?
A root-cause analysis indicates a major service disruption due to a lack of competency of newly hired IT system administrators. Who should be accountable for resolving the situation?
Which of the following would be the MOST effective way to ensure IT capabilities are appropriately aligned with business requirements for specific business processes?
An enterprise has lost an unencrypted backup tape of archived customer data. A data breach report is not mandatory in the relevant jurisdiction. From an ethical standpoint, what should the enterprise do NEXT?
The CIO of a global technology company is considering introducing a bring your own device (BYOD) program. What should the CIO do FIRST?
As part of the implementation of IT governance, the board of an enterprise should establish an IT strategy committee to:
Which of the following is the MOST important input for designing a development program to help IT employees improve their ability to respond to business needs?
To evaluate IT resource management, it is MOST important to define:
Which of the following should be established FIRST so that data owners can consistently assess the level of data protection needed across the enterprise?
Which of the following is the PRIMARY consideration when developing an information asset management program?
When updating an IT governance framework to support an outsourcing strategy, which of the following is MOST important?
An enterprise has finalized a major acquisition and a new business strategy in line with stakeholder needs has been introduced to help ensure continuous alignment of IT with the new business strategy the CiO should FIRST
Which of the following provides the BEST evidence of an IT risk-aware culture across an enterprise?
Individual business units within an enterprise have been designing their own IT solutions without consulting the IT department. From a governance perspective, what is the GREATEST issue associated with this situation?
To ensure that information can be traced to the originating event and accountable parties, an enterprise should FIRST:
An enterprise is planning a transformation initiative by leveraging emerging technology that will have a significant impact on existing products and services Which of the following is the BEST way for IT to prepare for this change?
Following the rollout of an enterprise IT software solution that hosts sensitive data it was discovered that the application's role-based access control was not functioning as specified Which of the following is the BEST way to prevent reoccurrence in the future?
Which of the following is MOST important to review during IT strategy development?
An internal audit revealed a widespread perception that the enterprise's IT governance reporting lacks transparency Which of the following should the CIO do FIRST?
Which of the following is the MOST important reason to include internal audit as a stakeholder when establishing clear roles for the governance of IT?
A health tech enterprise wants to ensure that its in-house developed mobile app for users complies with data privacy regulations. Which of the following should be identified FIRST when creating an inventory of information systems and data related to the mobile app?
The PRIMARY objective of promoting business ethics within the IT enterprise should be to ensure:
An enterprise's global IT program management office (PMO) has recently discovered that several IT projects are being run within a specific region without knowledge of the PMO. The projects are on time, on budget, and will deliver the proposed benefits to the specific region. Which of the following should be the PRIMARY concern of the PMO?
An enterprise has entered into a new market which brings additional regulatory compliance requirements. What should be done FIRST to address these requirements?
Which of the following is the BEST way to maximize the value of an enterprise’s information asset base?
To develop appropriate measures to improve organizational performance, the measures MUST be:
An independent consultant has been hired to conduct an ad hoc audit of an enterprise’s information security office with results reported to the IT governance committee and the board Which of the following is MOST important to provide to the consultant before the audit begins?
Which of the following BEST indicates that a change management process has been implemented successfully?
An IT risk committee is trying to mitigate the risk associated with a newly implemented bring your own device (BYOD) policy and supporting mobile device management (MDM) tools. Which of the following would be the BEST way to ensure employees understand how to protect sensitive corporate data on their mobile devices?
Which of the following has the GREATEST influence on data quality assurance?
Which of the following is the BEST indication that information security requirements are taken into consideration when developing IT processes?
Which of the following is MOST important for an IT strategy committee to ensure before initiating the development of an IT strategic plan?
When developing an IT training plan, which of the following is the BEST way to ensure that resource skills requirements are identified?
An enterprise is adopting a new governance framework. Of the following, the MOST effective method to help ensure that key activities are performed by appropriate resources is through the use of:
Which of the following is the BEST indication that enterprise value is being derived from IT?
What should be done FIRST when feedback indicates recently implemented software products are not meeting business unit expectations?
Which of the following roles should approve major IT purchases to help prevent conflicts of interest?
To enable IT to deliver adequate services and maintain availability of a web-facing infrastructure, an IT governance committee should FIRST establish:
To minimize the potential mishandling of customer personal information in a system located in a country with strict privacy regulations which of the following is the BEST action to take?
An enterprise's board of directors has determined that IT is not sufficiently supporting its corporate objectives, and has established a committee to address this problem. Which of the following should be the committees FIRST action?
Business management is seeking assurance from the CIO that controls are in place to help minimize the risk of critical IT systems being unavailable during month-end financial processing. What is the BEST way to address this concern?
Which of the following should be identified FIRST when determining appropriate IT key risk indicators (KRIs)?
The PRIMARY reason for implementing an IT governance program in an enterprise is to
When assessing the impact of a new regulatory requirement, which of the following should be the FIRST course of action?
Which of the following would be MOST helpful to an enterprise that wants to standardize how sensitive corporate data is handled?
Which of the following is MOST important to consider when planning to implement a cloud-based application for sharing documents with internal and external parties?
Which of the following should be the PRIMARY goal of implementing service level agreements (SLAs) with an outsourcing vendor?
An enterprise has identified potential environmental disasters that could occur in the area where its data center is located. Which of the following should be done NEXT?
The MAIN responsibility of the board of directors regarding the management of enterprise risk is to:
The FIRST step in aligning resource management to the enterprise's IT strategic plan would be to
The risk committee is overwhelmed by the number of false positives included in risk reports. What action would BEST address this situation?
Which of the following is a responsibility of an IT strategy committee?
A new chief information officer (CIO) of an enterprise recommends implementing portfolio management after realizing there is no process in place for evaluating investments prior to selection. What should be the PRIMARY strategic goal driving this decision?
Which of the following is the GREATEST benefit of using a quantitative risk assessment method?
The CIO in a large enterprise is seeking assurance that significant IT risk is being proactively monitored and does not exceed agreed risk tolerance levels. The BEST way to provide this ongoing assurance is to require the development of:
The CIO of an enterprise learns the payroll server of a competitor has been the victim of ransomware. To help plan for the possibility of ransomed corporate data, what should be the ClO's FIRST course of action?
An enterprise has had the same IT governance framework in place for several years. Currently, large and small capital projects go through the same architectural governance reviews. Despite repeated requests to streamline the review process for small capital projects, business units have received no response from IT. The business units have recently escalated this issue to the newly appointed GO. Which of the following should be done FIRST to begin addressing business needs?
To benefit from economies of scale, a CIO is deciding whether to outsource some IT services. Which of the following would be the MOST important consideration during the decision-making process?
An enterprise decides to accept the IT risk of a subsidiary located in another country even though it exceeds the enterprise's risk appetite. Which of the following would be the BEST justification for this decision?
Acceptance of an enterprise's newly implemented IT governance initiatives has been resisted by a functional group requesting more autonomy over technology choices. Which of the following is MOST important to accommodate this need for autonomy?
An enterprise's service center is experiencing long delays in fulfilling! T service requests and very low customer satisfaction. The BEST way to determine if staff competency is the root cause of these performance problems is to compare required staff competencies with:
Prior to setting IT objectives, an enterprise MUST have established its:
An enterprise can BEST assess the benefits of a new IT project through its life cycle by:
A marketing enterprise is considering procuring customer information to more accurately target customer communications and increase sales. The data has a very high cost to the enterprise. Which of the following would provide the MOST comprehensive view into the potential value to the organization?
An enterprise has made the strategic decision to reduce operating costs for the next year and is taking advantage of cost reductions offered by an external cloud service provider. Which of the following should be the IT steering committee's PRIMARY concern?
Which of the following is the GREATEST impact to an enterprise that has ineffective information architecture?
An enterprise's internal audit group has scheduled a control review of a payroll system project but has been told to wait until the system is implemented. Which of the following is the GREATEST risk associated with the delay?
It has been discovered that multiple business units across an enterprise are using duplicate IT applications and services to fulfill their individual needs. Which of the following would be MOST helpful to address this concern?
Senior management wants to expand offshoring to include IT services as other types of business offshoring have already resulted in significant financial benefits for the enterprise. The CIO is currently midway through a successful five-year strategy that relies heavily on internal IT resources. What should the CIO do NEXT?
An enterprise considering implementing IT governance should FIRST develop the scope of the IT governance program and:
Which of the following BEST reflects the ethical values adopted by an IT organization?
An enterprise's board of directors can BEST manage enterprise risk by:
Which of the following is the BEST way to demonstrate that IT strategy supports a new enterprise strategy?
Which of the following is the MOST effective approach to ensure senior management sponsorship of IT risk management?
A CIO believes that a recent mission-critical IT decision by the board of directors is not in the best financial interest of all stakeholders. Which of the following is the MOST ethical course of action?
An IT governance committee wants to ensure there is a clear description of the "data owner" in the enterprise data policy. Which of the following would BEST define the owner of data stored in an external cloud?
An enterprise's information security function is making changes to its data retention and backup policies. Which of the following presents the GREATEST risk?
IT has launched new portfolio management policies and processes to improve the alignment of IT projects with enterprise goals. The latest audit report indicates that no improvement has been made due to confusion in the decision-making process. Which of the following is the BEST course of action for the CIO?
Which of the following should be the MAIN governance focus when implementing a newly approved bring your own device (BYOD) policy?
Which of the following MOST effectively prevents an IT system from becoming technologically obsolete before its planned return on investment (ROi)?
Senior management is reviewing the results of a recent security incident with significant business impact. Which of the following findings should be of GREATEST concern?
While monitoring an enterprise's IT projects portfolio, it is discovered that a project is 75% complete, but all budgeted resources have been expended. Which of the following is the MOST important task to perform?
Which of the following BEST lowers costs and improves scalability from an IT enterprise architecture (EA) perspective?
A newly established IT steering committee is concerned about whether a system is meeting availability objectives. Which of the following will provide the BEST information to make an assessment?
The MOST important aspect of an IT governance framework to ensure that IT supports repeatable business processes is:
Which of the following is the MOST effective means for IT management to report to executive management regarding the value of IT?
Which of the following would be of MOST concern regarding the effectiveness of risk management processes?
Which of the following MUST be established before implementing an information architecture that restricts access to data based on sensitivity?
From a governance perspective, the PRIMARY goal of an IT risk optimization process should be to ensure:
Of the following, who should approve the criteria for information quality within an enterprise?
Which of the following is the MOST effective way to manage risks within the enterprise?
When evaluating benefits realization of IT process performance, the analysis MUST be based on;
A large retail chain realizes that while there has not been any loss of data, IT security has not been a priority and should become a key goal for the enterprise. What should be the FIRST high-level initiative for a newly created IT strategy committee in order to support this business goal?
The PRIMARY reason for an enterprise to adopt an IT governance framework is to:
Which of the following should be the MAIN reason for an enterprise to implement an IT risk management framework?
Which of the following BEST reflects mature risk management in an enterprise?
Which of the following is MOST important to effectively initiate IT-enabled change?
Which of the following components of a policy BEST enables the governance of enterprise IT?
Which of the following would BEST enable business innovation through IT?
An audit report has revealed that data scientists are analyzing sensitive "big data" files using an offsite cloud because corporate servers do not have the necessary processing capabilities. A review of policies indicates this practice is not prohibited. Which of the following should be the FIRST strategic action to address the report?
Which of the following is the MOST important consideration for data classification to be successfully implemented?
A healthcare enterprise that is subject to strict compliance requirements has decided to outsource several key IT services to third-party providers. Which of the following would be the BEST way to assess compliance and avoid reputational damage?
The board of a start-up company has directed the CIO to develop a technology resource acquisition and management policy. Which of the following should be the MOST important consideration during the development of this policy?
Which of the following aspects of the transition from X-rays to digital images would be BEST addressed by implementing information security policy and procedures?
The MOST successful IT performance metrics are those that:
The CIO of a financial services company is tasked with ensuring IT processes are in compliance with recently instituted regulatory changes. The FIRST course of action should be to:
A new and expanding enterprise has recently received a report indicating 90% of its data has been collected in just the last six months, triggering data breach and privacy concerns. What should be the IT steering committee's FIRST course of action to ensure new data is managed effectively?
Which of the following groups should approve the implementation of new technology?
An IT audit report indicates that a lack of IT employee risk awareness is creating serious security issues in application design and configuration. Which of the following would be the BEST key risk indicator (KRI) to show progress in IT employee behavior?
A global financial institution has decided to integrate data from branch locations into a common database to address regulatory reporting requirements. Analysis of data flows and the full data life cycle should be conducted at which level?
A global enterprise is experiencing an economic downturn and is rapidly losing market share. IT senior management is reassessing the core activities of the business, including IT, and the associated resource implications. Management has decided to focus on its local market and to close international operations. A critical issue from a resource management perspective is to retain the most capable staff. This is BEST achieved by:
The BEST way to manage continuous improvement of governance-related processes is to:
The use of new technology in an enterprise will require specific expertise and updated system development processes. There is concern that IT is not properly sourced. Which of the following should be the FIRST course of action?
An enterprise learns that a new privacy regulation was recently published to protect customers in the event of a breach involving personally identifiable information (Pll). The IT risk management team's FIRST course of action should be to:
Which of the following is an ADVANTAGE of using strategy mapping?
The PRIMARY benefit of integrating IT resource planning into enterprise strategic planning is that it enables the enterprise to:
An IT strategy committee wants to ensure that a risk program is successfully implemented throughout the enterprise. Which of the following would BEST support this goal?
A chief technology officer (CTO) wants to ensure IT governance practices adequately address risk management specific to mobile applications. To create the appropriate risk policies for IT, it is MOST important for the CTO to:
Which of the following responsibilities should be retained within an enterprise when outsourcing a project management office (PMO) function?
Which of the following would BEST help to improve an enterprise's ability to manage large IT investment projects?
Results of an enterprise's customer survey indicate customers prefer using mobile applications. However, this same survey shows the enterprise's mobile applications are considered inferior compared to legacy browser-based applications. Which of the following should be the FIRST step in creating an effective long-term mobile application strategy?
Establishing a uniform definition for likelihood and impact through risk management standards PRIMARILY addresses which of the following concerns?