Certified in the Governance of Enterprise IT Exam Questions and Answers
Which of the following has the GREATEST influence on data quality assurance?
Which of the following is MOST critical to support IT governance cultural changes within an organization?
To minimize the potential mishandling of customer personal information in a system located in a country with strict privacy regulations which of the following is the BEST action to take?
When preparing a new IT strategic plan for board approval, the MOST important consideration is to ensure the plan identifies:
The IT department has determined that problems with a business report are due to quality issues within a set of data to whom should IT refer the matter for resolution?
Which of the following should IT governance mandate before any transition of data from a legacy system to a new technology platform?
The CIO of a financial and insurance company is considering the projects and portfolio for the coming year Which of the following projects is a non-discretionary project?
The responsibility for the development of a business continuity plan (BCP) is BEST assigned to the:
An enterprise's chief information officer (CIO) has been receiving complaints from business executives regarding the amount their units are being charged for IT services. To maintain a good relationship with business peers, the CIO wants to be responsive to these complaints. To address this issue, the FIRST step should be to:
Which of the following BEST supports an enterprise's ability to comply with privacy laws and regulations?
A root-cause analysis indicates a major service disruption due to a lack of competency of newly hired IT system administrators. Who should be accountable for resolving the situation?
An IT steering committee is concerned that enterprise technologies have grown stagnant and are outdated. Which of the following is the BEST strategy to invest in modern technology?
The use of an enterprise architecture (EA) framework BEST supports IT governance by providing:
An enterprise is planning to outsource data processing for personally identifiable information (Pll). When is the MOST appropriate time to define the requirements for security and privacy of information?
Which of the following is the BEST indication that information security requirements are taken into consideration when developing IT processes?
An enterprise is determining the objectives for an IT training improvement initiative from a governance prosected. it would be MOST important to ensure that:
Which of the following is the GREATEST benefit of using a quantitative risk assessment method?
Business management is seeking assurance from the CIO that controls are in place to help minimize the risk of critical IT systems being unavailable during month-end financial processing. What is the BEST way to address this concern?
When establishing a risk management process which of the following should be the FIRST step?
Enterprise leadership is concerned with the potential for discrimination against certain demographic groups resulting from the use of machine learning models What should be done FIRST to address this concern?
A new chief information officer (CIO) of an enterprise recommends implementing portfolio management after realizing there is no process in place for evaluating investments prior to selection. What should be the PRIMARY strategic goal driving this decision?
The PRIMARY reason for implementing an IT governance program in an enterprise is to
Which of the following should senior management do FIRST when developing and managing digital applications for a new enterprise?
Which of the following is (he GREATEST benefit of using the life cycle approach to govern information assets?
The BEST time to identity metrics to measure the performance of an IT-enabled investment is during:
IT senior management is concerned that IT service levels consistently fall below those outlined in the service level agreement (SLA). Which of the following would BEST enable the CIO to build a corrective action plan?
An internal audit revealed a widespread perception that the enterprise's IT governance reporting lacks transparency Which of the following should the CIO do FIRST?
Which of the following is MOST important to include in IT governance reporting to the board of directors?
What should be an IT steering committee's FIRST course of action when an enterprise is considering establishing a virtual reality store to sell its products?
An enterprise is adopting a new governance framework. Of the following, the MOST effective method to help ensure that key activities are performed by appropriate resources is through the use of:
The CIO of a global technology company is considering introducing a bring your own device (BYOD) program. What should the CIO do FIRST?
Following a re-prioritization of business objectives by management, which of the following should be performed FIRST to allocate resources to IT processes?
Which of the following is the MOST important benefit of effective IT governance reporting?
When considering an IT change that would enable a potential new line of business, the FIRST strategic step for IT governance would be to ensure agreement among the stakeholders regarding:
Which of the following is a PRIMARY responsibility of the CIO when an enterprise plans to replace its enterprise resource applications?
A financial services company has implemented the use of a cloud-based centralized customer relationship management (CRM) system. The company has decided to go multi-national. Which of the following should be the enterprise risk management (ERM) committee's PRIMARY consideration?
Which of the following is the BEST outcome measure to determine the effectiveness of IT nsk management processes?
An independent consultant has been hired to conduct an ad hoc audit of an enterprise’s information security office with results reported to the IT governance committee and the board Which of the following is MOST important to provide to the consultant before the audit begins?
An assessment reveals that enterprise risk management (ERM) practices are being applied inconsistently by IT staff. Which of the following would be the MOST effective corrective action?
Which of the following is the MOST important input for designing a development program to help IT employees improve their ability to respond to business needs?
A multinational enterprise is planning to migrate to cloud-based systems. Which of the following should be of MOST concern to the risk management committee?
An enterprise's executive team has recently released a new IT strategy and related objectives. Which of the following would be the MOST effective way for the CIO to ensure IT personnel are supporting the new strategy's objectives?
Which of the following should be the MOST important consideration when designing an implementation plan for IT governance?
Which of the following should be the FIRST step in updating an IT strategic plan?
Which of the following should be management's GREATEST consideration when trying to optimize the use of benefits from IT?
Which of the following would be MOST useful for prioritizing IT improvement initiatives to achieve desired business outcomes?
Which of the following should be done FIRST when designing an IT balanced scorecard?
Which of the following is the BEST way to ensure all enterprise employees understand the corporate code of business conduct?
An IT strategy committee has reviewed an audit report indicating sales employees are using personal smartphones to conduct corporate business. Although the committee appreciates the business benefits, it is also concerned with the security risk. To deliver the business benefit, what should be the committee's FIRST recommendation?
Which of the following should be identified FIRST when determining appropriate IT key risk indicators (KRIs)?
An enterprise has decided to execute a risk self-assessment to identify improvement opportunities for current IT services. Which of the following is MOST important to address in the assessment?
Which of the following should be the FIRST action taken by a newly formed IT governance committee to ensure reports are compliant with regulations and identify key IT risks?
A newly hired CIO has been told the enterprise has an established IT governance process, but finds it is not being followed. To address this problem, the CIO should FIRST
An enterprise's global IT program management office (PMO) has recently discovered that several IT projects are being run within a specific region without knowledge of the PMO. The projects are on time, on budget, and will deliver the proposed benefits to the specific region. Which of the following should be the PRIMARY concern of the PMO?
The CIO of an international enterprise is considering the use of an offshore cloud service provider to store customer data. Which of the following should be the MOST important consideration when making this decision?
What is the BEST criterion for prioritizing IT risk remediation when resource requirements are equal?
A large bank has completed several acquisitions in the last few years that have resulted in redundant IT applications. To align with the strategic initiative of providing integrated services to customers, the IT steering committee has decided to share data and integrate applications. Which of the following would be MOST important to review in this situation?
Which of the following IT governance actions would be the BEST way to minimize the likelihood of IT failures jeopardizing the corporate value of an IT-dependent organization?
Which of the following should be the PRIMARY basis for establishing categories within an information classification scheme?
IT senior management has just received a survey report indicating that more than one third of the organization's key IT staff plan to retire within the next 12 months. Which of the following is the MOST important governance action to prepare for this possibility?
The PRIMARY objective of promoting business ethics within the IT enterprise should be to ensure:
Which of the following would a CIO use to present the overall view of IT performance to the board of directors?
An organization is evaluating vendors to provide mobile device management (MDM) services. Which of the following is a KEY governance consideration for the IT steering committee?
Which of the following is MOST important to the successful implementation of enterprise architecture (EA)?
An IT value delivery framework PRIMARILY helps an enterprise
Which of the following provides the BEST evidence of effective IT governance?
When developing an IT training plan, which of the following is the BEST way to ensure that resource skills requirements are identified?
A business has outsourced IT operations to several third-party providers, but service level agreements (SLAs) are not clearly defined in all cases. Which of the following is the GREATEST risk to the business?
Which of the following BEST facilitates the standardization of IT vendor selection?
Which of the following should be the PRIMARY consideration when implementing an emerging technology with unclear regulatory and compliance requirements?
Which of the following is the PRIMARY outcome of using a comprehensive architecture framework?
Which of the following is the MOST efficient approach for using risk scenarios to evaluate a new business opportunity?
Which of the following is MOST important for the successful establishment of an ethics program?
An audit department recently uncovered a series of security breaches. It was determined that network intrusion detection logs were recording the suspicious activity, but IT staff were not reviewing logs due to competing business demands. To address this situation, the IT steering committee’s FIRST priority should be:
Which of the following is the PRIMARY responsibility of a data steward at an enterprise with mature data management programs?
Which of the following is the BEST way for a CIO to provide progress updates on a newly implemented IT strategic plan to the board of directors?
Present an IT summary dashboard.
Present IT critical success factors (CSFs).
Report results Of key risk indicators (KRIs).
What is the BEST way for IT to achieve compliance with regulatory requirements?
A CIO engages a consulting firm to conduct a benchmark analysis of the organization’s IT governance framework against industry best practices. Several recommendations to improve the maturity of the framework are identified. Which of the following should be the CIO's NEXT course of action?
An enterprise has an overarching enterprise architecture (EA) document. The CIO is concerned that EA is not leveraged in recent IT-enabled investments. Which of the following would BEST help to address these concerns and enforce the leveraging of EA?
Which of the following is MOST important to consider when monitoring the performance of IT resources?
Which of the following is MOST important to consider when monitoring the performance of IT resources?
Which of the following provides an enterprise with the BEST understanding of the value proposition for employing a new cloud service?
A healthcare enterprise is procuring Internet of Things (IoT) devices to be used across its facilities. Which of the following is MOST important to establish before vendors are engaged to provide the devices?
An enterprise is planning to upgrade its current enterprise resource planning (ERP) system to remain competitive within the industry. Which of the following would be MOST helpful to facilitate a successful implementation?
Which of the following is the MOST important course of action when initiating a procurement process for a Zero Trust solution?
When an enterprise is evaluating potential IT service vendors, which of the following BEST enables a clear understanding of the vendor's capabilities that will be critical to the enterprise's strategy?
Due diligence process
A CIO engages a consulting firm to conduct a benchmark analysis of the organization’s IT governance framework against industry best practices. Several recommendations to improve the maturity of the framework are identified. Which of the following should be the CIO’s NEXT course of action?
Due to budget cuts, IT has been forced to limit service offerings in the portfolio. There has been significant resistance from business leaders to this decision. Which of the following is the BEST way for the CIO to find a solution that is aligned with business objectives?
An enterprise has launched a digitization effort requiring a single view of customer information across all product lines. Which of the following should be done FIRST to enable this initiative?
Which strategic planning approach would be MOST appropriate for a large enterprise to follow when revamping its IT services?
Which of the following is the MOST efficient way for an IT transformation project manager to communicate the project progress with stakeholders?
Establish governance forums within project management.
The BEST way for a CIO to justify maintaining and supporting social media platforms is by demonstrating:
An enterprise plans to migrate its applications and data to an external cloud environment. Which of the following should be the ClO's PRIMARY focus before the migration?
An enterprise learns that some of its business divisions have been approaching technology vendors for cloud services, resulting in duplicate support contracts and underutilization of IT services. Which of the following should be done FIRST to address this issue?
A board of directors is concerned with the total cost of IT. Which of the following is MOST important for the CIO to include in an explanation to the board?
Which of the following should be the MOST important consideration when establishing key performance indicators (KPIs) for IT initiatives?
A CIO realizes a significant change is required in the way IT responds to key external customers and needs to gain support from the enterprise to address this situation. What should be done FIRST?
An enterprise's IT department has failed to deliver required solutions on time due to insufficient resource allocation, resulting in a longer time to market. Which of the following is the BEST way for the chief information officer (CIO) to address this situation?
To measure the value of IT-enabled investments, an enterprise needs to identify its drivers as defined by its:
Which of the following is the GREATEST advantage of earned value management when used for evaluating benefits from the implementation of blockchain projects for IT contracts management?
An enterprise is implementing its first mobile sales channel. Final approval for accepting the associated IT risk should be obtained from which of the following?
Risk manager
Business sponsor
An internal auditor conducts an assessment of a two-year-old IT risk management program. Which of the following findings should be of MOST concern to the CIO?
IT governance within an enterprise is attempting to drive a cultural shift to enhance compliance with IT security policies. The BEST way to support this objective is to ensure that enterprise IT policies are:
Which of the following is MOST important to have in place to ensure a business continuity plan (BCP) can be executed?
A CIO was notified that a new employee was observed wearing a headset with an optical lens at the organization's data center. The individual was entering voice commands into the device. When approached, the employee explained the device is a new personal technology serving as a hands-free version of a smart phone. The CIO is concerned with potential security vulnerabilities of allowing such devices, and whether they should be banned from the facility. What should be the NEXT course of action in response to the ClO's concern?
Of the following, who is responsible for the achievement of IT strategic objectives?
A regulator has expressed concerns about the timeliness of information reported from an enterprise. Which of the following should be done FIRST to address this issue?
To help ensure the IT portfolio provides maximum value to an organization, IT projects are BEST prioritized based on:
cost-benefit analysis results.
alignment with business strategy.
An enterprise wants to implement metrics to monitor the performance of its IT portfolio. Whose input is MOST important to consider when establishing these metrics?
Which of the following characteristics would BEST indicate that an IT process is a good candidate for outsourcing?
A global organization has noticed a significant decrease in the return on IT investments in a particular region. To enhance project governance in this region, the CEO should FIRST:
Which of the following is MOST important to effectively incorporate innovation and emerging technologies into an enterprise’s IT strategy?
Which of the following BEST supports an IT strategy committee’s objective to align employee competencies with planned initiatives?
In a large enterprise, which of the following is the BEST approach to enable effective communication to senior management regarding the project status for a strategic enterprise resource management system implementation?
Which of the following is the PRIMARY objective of a data protection impact assessment?
Which of the following is MOST likely to have a negative impact on
accountability for information risk ownership?
Which of the following is the PRIMARY reason to monitor data classification efforts?
Which of the following is the GREATEST expected strategic organizational benefit from the standardization of technical platforms?
An enterprise's current business continuity plan (BCP) fails to consider many common crisis events. What would be MOST helpful to address this situation?
After experiencing poor recovery times following a catastrophic event, an enterprise is seeking to improve its disaster recovery capabilities. Which of the following would BEST enable the enterprise to accomplish this objective?
A CIO is planning to interview enterprise stakeholders to assess whether the IT strategic plan is continuing to support enterprise business objectives. The CIO would be MOST effective by starting the interview process with:
Which of the following is the BEST way to minimize the potential mishandling of customer personal information in a system that is located in a country with strict privacy regulations?
Which of the following is MOST relevant to report to the board of directors regarding the execution of IT strategy?
Which of the following is the FIRST step when developing an IT risk management framework?
Which of the following is the MOST effective approach to ensure senior management sponsorship of IT risk management?
An enterprise has decided to adopt cloud services. Which of the following should be established FIRST?
An enterprise has established a goal of leveraging AI as a source of strategic advantage. Which of the following should be done FIRST when developing the related IT strategy?
Which of the following is the PRIMARY objective of quantum computing architecture when addressing complex problems in a short amount of time using specialized algorithms?
Which of the following is a CIO's BEST approach to ensure IT executes against an approved strategy?
Which of the following is MOST important to have in place to ensure a business continuity plan (BCP) can be executed?
An enterprise that provides standardized outsourced IT services has signed a new contract with a demanding major client. Which of the following is the BEST approach for managing the associated risks within the enterprise's risk tolerance?
A publicly traded enterprise wants to demonstrate that its board of directors is providing adequate strategic oversight of IT. Which of the following BEST supports this objective?
Which of the following BEST enables an enterprise to determine whether a current program for IT infrastructure migration to the cloud is continuing to provide benefits?
An ongoing project is on track according to project plan. However, a recent regulation change will have a major impact to the project. The project sponsor's NEXT step should be to:
Which of the following is the MOST important characteristic of a well-defined information architecture?
Which of the following should be the PRIMARY outcome of IT governance?
A new regulation requires enterprises to disclose when significant cyber incidents occur. Which of the following is MOST important for the enterprise to determine?
What should be the FIRST action of a new CIO when considering an IT governance framework for an enterprise?
Which of the following should be the MOST important consideration when defining an information architecture?
A financial institution with a highly regarded reputation for protecting customer interests has recently deployed a mobile payments program. Which of the following key risk indicators (KRIs) would be of MOST interest to the CIO?
To benefit from economies of scale, a CIO is deciding whether to outsource some IT services. Which of the following would be the MOST important consideration during the decision-making process?
Which of the following MUST be established before implementing an information architecture that restricts access to data based on sensitivity?
When developing effective metrics for the measurement of solution delivery, it is MOST important to:
Which of the following BEST lowers costs and improves scalability from an IT enterprise architecture (EA) perspective?
An enterprise embarked on an aggressive strategy requiring the implementation of several large IT projects impacting multiple business processes across all departments. Initially employees were supportive of the strategy, but there is growing fatigue and frustration with the ongoing newcapabilities which must be learned. Which of the following would be the BEST action performed by senior management?
Which of the following provides the BEST assurance on the effectiveness of IT service management processes?
An enterprise's internal audit group has scheduled a control review of a payroll system project but has been told to wait until the system is implemented. Which of the following is the GREATEST risk associated with the delay?
A business case indicates an enterprise would reduce costs by implementing a bring your own device (BYOD) program allowing employees to use personal devices for email. Which of the following should be the FIRST governance action?
An enterprise has decided to utilize a cloud vendor for the first time to provide email as a service, eliminating in-house email capabilities. Which of the following IT strategic actions should be triggered by this decision?
The BEST way to manage an outsourced vendor relationship is by:
A review of the effectiveness of IT governance within an enterprise has revealed that several innovation improvement initiatives are failing. An analysis shows a lack of stakeholder buy-in to the improvements. Implementing which of the following would have prevented this problem?
A healthcare enterprise that is subject to strict compliance requirements has decided to outsource several key IT services to third-party providers. Which of the following would be the BEST way to assess compliance and avoid reputational damage?
An enterprise has established a new department to oversee the life cycle of activities that support data management objectives. Which of the following should be done NEXT?
Which of the following roles has PRIMARY accountability for the security related to data assets?
Which of the following should be the MAIN governance focus when implementing a newly approved bring your own device (BYOD) policy?
IT has launched new portfolio management policies and processes to improve the alignment of IT projects with enterprise goals. The latest audit report indicates that no improvement has been made due to confusion in the decision-making process. Which of the following is the BEST course of action for the CIO?
An IT director has become aware that a certain subset of data collected lawfully can be used to generate additional revenue. However, this particular use of the data is outside the original intention. What is the PRIMARY reason this situation should be escalated to the IT steering committee?
A retail enterprise has cost reduction as its top priority. From a governance perspective, which of the following should be the MOST important consideration when evaluating different IT investment options?
Which of the following would BEST enable business innovation through IT?
A global financial enterprise has been experiencing a substantial number of information security incidents that have directly affected its business reputation. Which of the following should be the IT governance board's FIRST course of action?
An IT director is negotiating a contract with a vendor for application management services. There is concern by other departments that the outsourced services may not be delivered successfully. Which of the following is the BEST way for the IT director to address this concern?
Of the following, who should approve the criteria for information quality within an enterprise?
An enterprise's CIO requires all IT processes within the enterprise to be clearly defined. Which of the following would be the MOST immediate outcome?
An analysis of an organization s security breach is complete. The results indicate that the quality of the code used for updates to its primary customer-facing software has been declining and security flaws were introduced. The FIRST IT governance action to correct this problem should be to review:
An enterprise has a large backlog of IT projects. The current strategy is to execute projects as they are submitted, but executive management does not believe this method is optimal. Which of the following is the MOST important action to address this concern?
A global financial institution has decided to integrate data from branch locations into a common database to address regulatory reporting requirements. Analysis of data flows and the full data life cycle should be conducted at which level?
An executive sponsor of a partially completed IT project has learned that the financial assumptions supporting the project have changed. Which of the following governance actions should be taken FIRST?
What is the PRIMARY objective for performing an IT due diligence review prior to the acquisition of a competitor?
A large retail chain realizes that while there has not been any loss of data, IT security has not been a priority and should become a key goal for the enterprise. What should be the FIRST high-level initiative for a newly created IT strategy committee in order to support this business goal?
A board of directors wants to ensure the enterprise is responsive to changes in its environment that would directly impact critical business processes. Which of the following will BEST facilitate meeting this objective?
When determining the optimal IT service levels to support business, which of the following is MOST important?
Which of the following is PRIMARILY achieved through performance measurement?
Which of the following is the PRIMARY ongoing responsibility of the IT governance function related to risk?
An enterprise has a zero-tolerance policy regarding security. This policy is causing a large number of email attachments to be blocked and is a disruption to enterprise. Which of the following should be the FIRST governance step to address this email issue?
Which of the following is the GREATEST impact to an enterprise that has ineffective information architecture?
Which of the following is the MOST important driver of IT governance?
When implementing an IT governance framework, which of the following would BEST ensure acceptance of the framework?
The PRIMARY reason for an enterprise to adopt an IT governance framework is to:
Establishing a uniform definition for likelihood and impact through risk management standards PRIMARILY addresses which of the following concerns?
Which of the following is an ADVANTAGE of using strategy mapping?
Which of the following is the PRIMARY element in sustaining an effective governance framework?
The board and senior management of a new enterprise recently met to formalize an IT governance framework. The board of directors' FIRST step in implementing IT governance is to ensure that:
An enterprise has decided to create its first mobile application. The IT director is concerned about the potential impact of this initiative. Which of the following is the MOST important input for managing the risk associated with this initiative?
Which of the following is MOST important to effectively initiate IT-enabled change?
A strategic systems project was implemented several months ago. Which of the following is the BEST reference for the IT steering committee as they evaluate its level of success?
A CIO believes that a recent mission-critical IT decision by the board of directors is not in the best financial interest of all stakeholders. Which of the following is the MOST ethical course of action?
An IT strategy committee wants to ensure that a risk program is successfully implemented throughout the enterprise. Which of the following would BEST support this goal?
An enterprise's information security function is making changes to its data retention and backup policies. Which of the following presents the GREATEST risk?
An IT steering committee wants the enterprise's mobile workforce to use cloud-based file storage to save non-sensitive corporate data, removing the need for remote access to that information. Before this change is implemented, what should be included in the data management policy?
Which of the following is the MOST effective way to manage risks within the enterprise?
Which of the following is the MOST important consideration for data classification to be successfully implemented?
While assessing the feasibility of introducing new IT practices and standards into the IT governance framework, it is CRITICAL to understand an organization's:
Which of the following is MOST critical for the successful implementation of an IT process?
An enterprise plans to implement a business intelligence (Bl) tool with data sources from various enterprise applications. Which of the following is the GREATEST challenge to implementation?
Prior to decommissioning an IT system, it is MOST important to:
It has been discovered that multiple business units across an enterprise are using duplicate IT applications and services to fulfill their individual needs. Which of the following would be MOST helpful to address this concern?
An enterprise is initiating efforts to improve system availability to mitigate IT risk to the business. Which of the following results would be MOST important to report to the CIO to measure progress?
Which of the following is the BEST method for making a strategic decision to invest in cloud services?
A multinational enterprise recently purchased a large company located in a different country. When introducing the concept of governance to the new acquisition, it is MOST important that executive management recognize:
An enterprise is planning to replace multiple enterprise resource planning (ERP) systems at various regions with one company-wide ERP system. The main objective of this change is to achieve economies of scale efficiencies resulting in cost reductions. To meet this objective, what is the BEST approach in the planning phase of the project?
A CIO has been asked to modify an organization's IT performance measurement system to reflect recent changes in technology, including the movement of some data processing to a cloud solution. Which of the following is the PRIMARY consideration when designing such a measurement system?
Which of the following would be MOST important to update if a decision is made to ban end user-owned devices in the workplace?
Senior management wants to expand offshoring to include IT services as other types of business offshoring have already resulted in significant financial benefits for the enterprise. The CIO is currently midway through a successful five-year strategy that relies heavily on internal IT resources. What should the CIO do NEXT?
Which of the following is the MOST effective means for IT management to report to executive management regarding the value of IT?
A marketing enterprise is considering procuring customer information to more accurately target customer communications and increase sales. The data has a very high cost to the enterprise. Which of the following would provide the MOST comprehensive view into the potential value to the organization?
Before an IT strategy committee can approve an IT risk assessment framework, which of the following is MOST important to have established?
The board of directors has mandated the use of geolocation software to track mobile assets assigned to employees who travel outside of their home country. To comply with this mandate, the IT steering committee should FIRST request