Certified in the Governance of Enterprise IT Exam Questions and Answers
Acceptance of an enterprise's newly implemented IT governance initiatives has been resisted by a functional group requesting more autonomy over technology choices. Which of the following is MOST important to accommodate this need for autonomy?
Which of the following is PRIMARILY achieved through performance measurement?
Which of the following should be the MOST important consideration when defining an information architecture?
An enterprise is developing several consumer-based services using emerging technologies involving sensitive personal data. The CIO is under pressure to ensure the enterprise is first to market, but security scan results have not been adequately addressed. Reviewing which of the following will enable the CIO to make the BEST decision for the customers?
An enterprise has had the same IT governance framework in place for several years. Currently, large and small capital projects go through the same architectural governance reviews. Despite repeated requests to streamline the review process for small capital projects, business units have received no response from IT. The business units have recently escalated this issue to the newly appointed GO. Which of the following should be done FIRST to begin addressing business needs?
Which of the following is the MOST effective way of assessing enterprise risk?
Which of the following is the MOST effective approach to ensure senior management sponsorship of IT risk management?
The board and senior management of a new enterprise recently met to formalize an IT governance framework. The board of directors' FIRST step in implementing IT governance is to ensure that:
Prior to decommissioning an IT system, it is MOST important to:
In a large enterprise, which of the following is the MOST effective way to understand the business activities associated with the enterprise's information architecture?
The use of an IT balanced scorecard enables the realization of business value of IT through:
An enterprise has decided to utilize a cloud vendor for the first time to provide email as a service, eliminating in-house email capabilities. Which of the following IT strategic actions should be triggered by this decision?
A marketing enterprise is considering procuring customer information to more accurately target customer communications and increase sales. The data has a very high cost to the enterprise. Which of the following would provide the MOST comprehensive view into the potential value to the organization?
An IT strategy committee wants to ensure that a risk program is successfully implemented throughout the enterprise. Which of the following would BEST support this goal?
Which of the following MUST be established before implementing an information architecture that restricts access to data based on sensitivity?
An enterprise is planning to replace multiple enterprise resource planning (ERP) systems at various regions with one company-wide ERP system. The main objective of this change is to achieve economies of scale efficiencies resulting in cost reductions. To meet this objective, what is the BEST approach in the planning phase of the project?
An enterprise experiencing issues with data protection and least privilege is implementing enterprise-wide data encryption in response. Which of the following is the BEST approach to ensure all business units work toward remediating these issues?
An enterprise has decided to create its first mobile application. The IT director is concerned about the potential impact of this initiative. Which of the following is the MOST important input for managing the risk associated with this initiative?
Which of the following is MOST critical for the successful implementation of an IT process?
When evaluating benefits realization of IT process performance, the analysis MUST be based on;
An enterprise's information security function is making changes to its data retention and backup policies. Which of the following presents the GREATEST risk?
The board of directors has mandated the use of geolocation software to track mobile assets assigned to employees who travel outside of their home country. To comply with this mandate, the IT steering committee should FIRST request
The CIO in a large enterprise is seeking assurance that significant IT risk is being proactively monitored and does not exceed agreed risk tolerance levels. The BEST way to provide this ongoing assurance is to require the development of:
Which of the following would BEST help to improve an enterprise's ability to manage large IT investment projects?
A retail enterprise has cost reduction as its top priority. From a governance perspective, which of the following should be the MOST important consideration when evaluating different IT investment options?
An enterprise is implementing a new IT governance program. Which of the following is the BEST way to increase the likelihood of its success?
Which of the following is the BEST way to ensure new systems can be adequately supported once in production?
Which of the following would be the PRIMARY impact on IT governance when a business strategy is changed?
Senior management wants to promote investment in IT, but is uncertain that associated risks are being properly identified. The BEST way to address this concern is to:
Which of the following is MOST important to effectively initiate IT-enabled change?
An audit report has revealed that data scientists are analyzing sensitive "big data" files using an offsite cloud because corporate servers do not have the necessary processing capabilities. A review of policies indicates this practice is not prohibited. Which of the following should be the FIRST strategic action to address the report?
Which of the following roles has PRIMARY accountability for the security related to data assets?
Prior to setting IT objectives, an enterprise MUST have established its:
The MOST successful IT performance metrics are those that:
The use of new technology in an enterprise will require specific expertise and updated system development processes. There is concern that IT is not properly sourced. Which of the following should be the FIRST course of action?
While monitoring an enterprise's IT projects portfolio, it is discovered that a project is 75% complete, but all budgeted resources have been expended. Which of the following is the MOST important task to perform?
The CIO of an enterprise learns the payroll server of a competitor has been the victim of ransomware. To help plan for the possibility of ransomed corporate data, what should be the ClO's FIRST course of action?
Six months ago, an enterprise's CIO reorganized IT to improve service delivery to the business. Which of the following would BEST demonstrate the effectiveness of the reorganization?
Which of the following is the PRIMARY benefit of communicating the IT strategy across the enterprise?
An enterprise's CIO requires all IT processes within the enterprise to be clearly defined. Which of the following would be the MOST immediate outcome?
When implementing an IT governance framework, which of the following would BEST ensure acceptance of the framework?
It has been discovered that multiple business units across an enterprise are using duplicate IT applications and services to fulfill their individual needs. Which of the following would be MOST helpful to address this concern?
A multinational enterprise recently purchased a large company located in a different country. When introducing the concept of governance to the new acquisition, it is MOST important that executive management recognize:
An executive sponsor of a partially completed IT project has learned that the financial assumptions supporting the project have changed. Which of the following governance actions should be taken FIRST?
Best practice states that IT governance MUST:
Which of the following groups should approve the implementation of new technology?
Which of the following would BEST enable business innovation through IT?
Enterprise IT has overseen the implementation of an array of data services with overlapping functionality leading to business inefficiencies. Which of the following is the MOST likely cause of this situation?
The board of directors of an enterprise has approved a three-year IT strategic program to centralize the core business processes of its global entities into one core system. Which of the following should be the ClO's NEXT step?
A recent benchmarking analysis has indicated an IT organization is retaining more data and spending significantly more on data retention than its competitors. Which of the following would BEST ensure the optimization of retention costs?
Which of the following is the MOST comprehensive method to report on overall IT performance to the board of directors?
Which of the following MOST effectively prevents an IT system from becoming technologically obsolete before its planned return on investment (ROi)?
A financial institution with a highly regarded reputation for protecting customer interests has recently deployed a mobile payments program. Which of the following key risk indicators (KRIs) would be of MOST interest to the CIO?
A strategic systems project was implemented several months ago. Which of the following is the BEST reference for the IT steering committee as they evaluate its level of success?
A CIO has been asked to modify an organization's IT performance measurement system to reflect recent changes in technology, including the movement of some data processing to a cloud solution. Which of the following is the PRIMARY consideration when designing such a measurement system?
An enterprise considering implementing IT governance should FIRST develop the scope of the IT governance program and:
The BEST way to manage an outsourced vendor relationship is by:
A CIO of an enterprise is concerned that IT and the business have different priorities. Which of the following would BEST demonstrate the current state of strategic alignment?
Which of the following is the BEST justification for a procurement manager to agree to purchase IT equipment from a specific vendor during a sales promotion?
Which of the following will BEST enable an IT steering committee to monitor the achievement of overall IT objectives on a continuous basis?
Which of the following BEST supports the implementation of an effective data classification policy?
The board of directors of a large organization has directed IT senior management to improve IT governance within the organization. IT senior management's MOST important course of action should be to:
An enterprise has made the strategic decision to reduce operating costs for the next year and is taking advantage of cost reductions offered by an external cloud service provider. Which of the following should be the IT steering committee's PRIMARY concern?
To ensure that information can be traced to the originating event and accountable parties, an enterprise should FIRST:
Which of the following BEST enables an enterprise to determine how business expectations should be addressed in a governance program?
An IT strategy committee wants to evaluate how well the IT department supports the business strategy. Which of the following is the BEST method for making this determination?
Which of the following is MOST important for an enterprise to review when classifying information assets?
An airline wants to launch a new program involving the use of artificial intelligence (Al) and machine learning the mam objective of the program is to use customer behavior to determine new routes and markets Which of the following should be done NEXT?
Which of the following is the PRIMARY purpose of information governance?
The BEST time to identity metrics to measure the performance of an IT-enabled investment is during:
Which of the following should be established FIRST so that data owners can consistently assess the level of data protection needed across the enterprise?
The CEO of an organization is concerned that there are inconsistencies in the way information assets are classified across the enterprise. Which of the following is be the BEST way for the CIO to address these concerns?
A major data leakage incident at an enterprise has resulted in a mandate to strengthen and enforce current data governance practices. Which of the following should be done FIRST to achieve this objective?
Individual business units within an enterprise have been designing their own IT solutions without consulting the IT department. From a governance perspective, what is the GREATEST issue associated with this situation?
Which of the following should be the FIRST step for executive management to take in communicating what is considered acceptable use with regard to personally owned devices for company business?
The PRIMARY reason for periodically evaluating IT resource staffing requirements is to:
An IT department outsourced application support and negotiated service level agreements (SLAs) directly with the vendor Although the vendor met the SLAs business owner expectations are not met and senior management cancels the contract This situation can be avoided in the future by:
The CIO of a global technology company is considering introducing a bring your own device (BYOD) program. What should the CIO do FIRST?
Which of the following would be the BEST way for an IT steering committee to monitor the adoption of a new enterprise IT strategy?
Which of the following would be MOST helpful to an enterprise that wants to standardize how sensitive corporate data is handled?
To meet the growing demands of a newly established business unit, IT senior management has been tasked with changing the current IT organization model to
service-oriented. With significant growth expected of the IT organization, which of the following is the MOST important consideration when planning for long-term IT
service delivery?
Which of the following is the PRIMARY responsibility of a data steward?
Which of the following BEST supports an enterprise's ability to comply with privacy laws and regulations?
An enterprise is about to complete a major acquisition, and a decision has been made that both companies will be using the parent company's IT infrastructure. Which of the following should be done NEXT?
The board of directors of an enterprise has questioned whether the business is focused on optimizing value. The IT strategy committees’ BEST action to address the board's concern is to:
When developing a business case for an enterprise resource planning (ERP) implementation, which of the following, if overlooked, causes the GREATEST impact to the enterprise?
An enterprise is planning to outsource data processing for personally identifiable information (Pll). When is the MOST appropriate time to define the requirements for security and privacy of information?
Which of the following IT governance actions would be the BEST way to minimize the likelihood of IT failures jeopardizing the corporate value of an IT-dependent organization?
An enterprise incurred penalties for noncompliance with privacy regulations. Which of the following is MOST important to ensure appropriate ownership of access controls to address this deficiency?
The IT department has determined that problems with a business report are due to quality issues within a set of data to whom should IT refer the matter for resolution?
To minimize the potential mishandling of customer personal information in a system located in a country with strict privacy regulations which of the following is the BEST action to take?
Which of the following is the BEST outcome measure to determine the effectiveness of IT nsk management processes?
An enterprise is planning a transformation initiative by leveraging emerging technology that will have a significant impact on existing products and services Which of the following is the BEST way for IT to prepare for this change?
From an IT governance perspective, establishing performance measurements is PRIMARILY the responsibility of:
Which of the following would BEST support an enterprise's initiative to incorporate desired organizational behaviors into the IT governance framework?
Following a strategic planning session, new IT objectives were announced. Which of the following is the MOST effective way for the CIO to ensure these objectives are cascaded to IT personnel?
What is the BEST criterion for prioritizing IT risk remediation when resource requirements are equal?
An enterprise is concerned with the potential for data leakage as a result of increased use of social media in the workplace, and wishes to establish a social media strategy. Which of the following should be the MOST important consideration in developing this strategy?
An enterprise has decided to execute a risk self-assessment to identify improvement opportunities for current IT services. Which of the following is MOST important to address in the assessment?
Which of the following roles should be responsible for data normalization when it is found that a new system includes duplicates of data items?
Of the following, who is PRIMARILY responsible for applying frameworks for the governance of IT to balance the need for security controls with business requirements?
Which of the following is the BEST approach to assist an enterprise in planning for iT-enabled investments?
Which of the following is MOST important to include in IT governance reporting to the board of directors?
An enterprise's global IT program management office (PMO) has recently discovered that several IT projects are being run within a specific region without knowledge of the PMO. The projects are on time, on budget, and will deliver the proposed benefits to the specific region. Which of the following should be the PRIMARY concern of the PMO?
The BEST way for a CIO to monitor the alignment between the business and IT strategy is to regularly review
An enterprise has identified a number of plausible risk scenarios that could result in economic loss associated with major IT investments. Which of the following is the BEST method to assess the risk?
An IT governance committee is defining a risk management policy for a portfolio of IT-enabled investments Which of the following should be the PRIMARY consideration when developing the policy?
Following a re-prioritization of business objectives by management, which of the following should be performed FIRST to allocate resources to IT processes?
In a successful enterprise that is profitable in its marketplace and consistently growing in size, the non-IT workforce has grown by 50% in the last two years. The demand for IT staff in the marketplace is more than the supply, and the enterprise is losing staff to rival organizations. Due to the rapid growth. IT has struggled to keep up with the enterprise, and IT procedures and associated job roles are not well-defined. The MOST critical activity for reducing the impact caused by IT staff turnover is to:
Which of the following should be the PRIMARY consideration for an enterprise when prioritizing IT projects?
An organization is evaluating vendors to provide mobile device management (MDM) services. Which of the following is a KEY governance consideration for the IT steering committee?
Once the strategic vision has been established, which of the following would be the BEST activity for supporting the implementation of performance measures?
An enterprise wants to address the human factors of social engineering risk within the organization. From a governance perspective, which of the following is the BEST way to mitigate this risk?
In a large enterprise, which of the following should be responsible for the implementation of an IT balanced scorecard?
ACIO determines IT investment management processes are not fully realizing the benefits identified in business cases. Which of the following would be the BEST way to prevent this issue?
An enterprise plans to migrate its applications and data to an external cloud environment. Which of the following should be the ClO's PRIMARY focus before the migration?
An enterprise has launched a critical new IT initiative that is expected to produce substantial value. Which of the following would BEST facilitate the reporting of benefits realized by the IT investment to the board?
An enterprise has an ongoing issue of corporate applications not delivering the expected benefits due to missing key functionality. As a result, many groups are using spreadsheets and databases instead of approved enterprise applications to store and manipulate information. Which of the following will BEST improve the success rate of future IT initiatives?
Which of the following characteristics would BEST indicate that an IT process is a good candidate for outsourcing?
Which of the following would be the BEST way for an enterprise to address new legal and regulatory requirements applicable to IT?
An enterprise has a centralized IT function but also allows business units to have their own technology operations, resulting in duplicate technologies and conflicting priorities. Which of the following should be done FIRST to reduce the complexity of the IT landscape?
- Promote automation tools used by the business units.
Which of the following is the PRIMARY role of the CEO in IT governance?
An internal auditor conducts an assessment of a two-year-old IT risk management program. Which of the following findings should be of MOST concern to the CIO?
Which of the following BEST supports an IT strategy committee’s objective to align employee competencies with planned initiatives?
Which of the following is the MOST important consideration regarding IT measures as part of an IT strategic plan?
Which of the following is the BEST way for a CIO to assess the consistency of IT processes against industry benchmarks to determine where to focus improvement initiatives?
The BEST way for a CIO to manage the organizational impact of deploying a new enterprise-wide tool is to implement:
An IT governance committee is reviewing its current risk management policy in light of increased usage of social media within an enterprise. The FIRST task for the governance committee is to:
Which of the following is the BEST way for a CIO to ensure that the work of IT employees is aligned with approved IT directives?
An enterprise learns that some of its business divisions have been approaching technology vendors for cloud services, resulting in duplicate support contracts and underutilization of IT services. Which of the following should be done FIRST to address this issue?
Which of the following is a CIO's BEST approach to ensure IT executes against an approved strategy?
Which of the following is the PRIMARY consideration for an enterprise when deciding whether to adopt a qualitative risk assessment method?
- The method identifies areas to immediately address vulnerabilities.
- The method provides specific objective measurements of exposure.
- The method enables an analysis Of recommended controls.
A regulatory audit of an IT department has identified discrepancies between processes described in the procedures and what is actually done by system administrators.
The discrepancies were caused by recent IT application changes. Which of the following would be the BEST way to prevent the recurrence of similar findings in the future?
Within a governance structure for risk management, which of the following activities should be performed by the second line of defense?
Which of the following should a CIO review to obtain a holistic view of IT performance when identifying potential gaps in service delivery?
Which of the following would BEST help to prevent an IT system from becoming obsolete before its planned return on investment (ROI)?
An enterprise recently approved a bring your own device (BYOD) policy. The IT steering committee has directed IT management to develop a communication plan to disseminate information regarding the associated technical risks. Which of the following is MOST important to include in this communication plan?
An enterprise has made the strategic decision to begin a global expansion program which will require opening sales offices in countries across the world. Which of the following should be the FIRST consideration with regard to the IT service desk which will remain centralized?
- The effect of regional differences On service delivery
- Identification of IT service desk functions that can be outsourced
A CIO wants to make improvements to the enterprise's IT governance. Which of the following would BEST help to demonstrate the expected benefits from proposed changes?
An enterprise has decided to use third-party software for a business process which is hosted and supported by the same third party. The BEST way to provide quality of service oversight would be to establish a process:
Which of the following BEST facilitates the adoption of an IT governance program in an enterprise?
Which of the following is the BEST way for a CIO to ensure that IT-related training is taken seriously by the IT management team and direct employees?
When a shortfall of IT resources is identified, the FIRST course of action is to;
What should be an IT steering committee's FIRST course of action when an enterprise is considering establishing a virtual reality store to sell its products?
A CIO has recently been made aware of a new regulatory requirement that may affect IT-enabled business activities. Which of the following should be the CIO s FIRST step in deciding the appropriate response to the new requirement?
An enterprise's IT department has been operating independently without regard to business concerns, leading to misalignment between business and IT. The BEST way to establish alignment would be to require:
Which of the following is the GREATEST expected strategic organizational benefit from the standardization of technical platforms?
Which of the following is the PRIMARY benefit to an enterprise when risk management is practiced effectively throughout the organization?
Which of the following is the BEST way to address the risk associated with new IT investments?
An interna! health organization has been notified that a data breach has resulted in patient records being published online. Which of the
following is MOST important consideration when determining the process for meeting the organization's legal and regulatory obligations?
In a large enterprise, which of the following is the BEST approach to enable effective communication to senior management regarding the project status for a strategic enterprise resource management system implementation?
An internal audit of a large financial institution found that financial data is being managed in a way that will negatively impact the enterprise's ability to support regulatory reporting. Which of the following should be the FIRST strategic action in addressing this situation?
- Establish a data governance framework.
- Assign data responsibilities through a RACI chart.
- Review key risk indicators (KRIS) related to data management.
Which of the following BEST helps to ensure that IT policies are
aligned with organizational strategies?
Which of the following is the PRIMARY responsibility of a data steward at an enterprise with mature data management programs?
Which of the following would be an IT steering committee's BEST course of action upon learning business units have been independently procuring cloud services?
A CIO is planning to implement an enterprise resource planning (ERP) system at the request of the business. Of the following, who is accountable for providing sponsorship for the IT-enabled change across the enterprise?
Which of the following is the GREATEST consideration when evaluating whether to comply with the new carbon footprint regulations impacted by blockchain technology?
Which of the following BEST supports an IT staff restructure as part of an annual IT strategy review with senior management?
The MOST appropriate method for evaluating the capability of IT governance is through the use of:
Which of the following is the BEST indication that an implementation plan for a new governance initiative will be successful?
Which of the following is the BEST indication of an effective information governance model?
Which of the following is MOST important for a data steward to verify when a system's data is edited by an automated tool to fix an incident?
A CIO was notified that a new employee was observed wearing a headset with an optical lens at the organization's data center. The individual was entering voice commands into the device. When approached, the employee explained the device is a new personal technology serving as a hands-free version of a smart phone. The CIO is concerned with potential security vulnerabilities of allowing such devices, and whether they should be banned from the facility. What should be the NEXT course of action in response to the ClO's concern?
Which of the following is the PRIMARY reason to monitor data classification efforts?
Which of the following is the BEST way to encourage employees to raise ethics concerns in full confidence?
Which of the following would be MOST useful in developing IT strategic plans aligned with technological needs?
Which of the following is the BEST way to manage the risk associated with outsourcing critical IT services?
A small enterprise has just hired its first CIO, who has been tasked with making the IT department more efficient. What should be the CIO's NEXT step after identifying several new improvement initiatives?
Which of the following is MOST important for a CIO to ensure before signing a contract for a new cloud-based customer relationship management (CRM) system?
- The service provider has been audited for vulnerabilities and threats.
A large enterprise is implementing an information security policy exception process. The BEST way to ensure that security risk is properly addressed is to:
- confirm process owners' acceptance of residual risk.
- perform an internal and external network penetration test.
- obtain IT security approval on security policy exceptions.
Which of the following is the MOST efficient approach for using risk scenarios to evaluate a new business opportunity?