Pass the Isaca Isaca Certification CGEIT Questions and answers with CertsForce

Viewing page 2 out of 14 pages
Viewing questions 16-30 out of questions
Questions # 16:

An enterprise learns that some of its business divisions have been approaching technology vendors for cloud services, resulting in duplicate support contracts and underutilization of IT services. Which of the following should be done FIRST to address this issue?

Options:

A.

Review the enterprise IT procurement policy.


B.

Re-negotiate contracts with vendors to request discounts.


C.

Require updates to the IT procurement process.


D.

Conduct an audit to investigate utilization of cloud services.


Expert Solution
Questions # 17:

Which of the following is the BEST way for a CIO to assess the consistency of IT processes against industry benchmarks to determine where to focus improvement initiatives?

Options:

A.

Utilizing a capability maturity model


B.

Evaluating the current balanced scorecard


C.

Reviewing key performance measures


D.

Reviewing IT process audit results


Expert Solution
Questions # 18:

Which of the following should be the FIRST step to ensure IT resources have the appropriate skills and experience level to support enterprise objectives?

Options:

A.

Determining the required competencies.


B.

Providing training to IT personnel.


C.

Developing an IT skills matrix.


D.

Monitoring resource performance.


Expert Solution
Questions # 19:

Which of the following is the PRIMARY role of the governance function in enabling an enterprise to achieve its business objectives?

Options:

A.

Determining risk thresholds that the enterprise can sustain


B.

Preparing business continuity and resiliency plans


C.

Providing a means to effectively manage stakeholders


D.

Monitoring strategic plans to reach the desired target state


Expert Solution
Questions # 20:

Which of the following is the PRIMARY responsibility of a data steward at an enterprise with mature data management programs?

Options:

A.

Implementing processes for data collection and use


B.

Ensuring compliance with data privacy laws and regulations


C.

Establishing data quality requirements and metrics


D.

Developing data-related policies and procedures


Expert Solution
Questions # 21:

An enterprise has learned of a new regulation that may impact delivery of one of its core technology services. Which of the following should be done FIRST?

Options:

A.

Request an action plan from the risk team.


B.

Determine whether the board wants to comply with the regulation.


C.

Update the risk management framework.


D.

Assess the risk associated with the new regulation.


Expert Solution
Questions # 22:

An enterprise has an ongoing issue of corporate applications not delivering the expected benefits due to missing key functionality. As a result, many groups are using spreadsheets and databases instead of approved enterprise applications to store and manipulate information. Which of the following will BEST improve the success rate of future IT initiatives?

Options:

A.

Engage the business user community in acceptance testing Of acquired applications.


B.

Engage stakeholders to identify and validate business requirements.


C.

Establish a process for risk and value management.


D.

Prohibit the use of non-approved alternate software solutions.


Expert Solution
Questions # 23:

A global organization has noticed a significant decrease in the return on IT investments in a particular region. To enhance project governance in this region, the CEO should FIRST

Options:

A.

Perform a program benefit calculation and review the project selection methodology


B.

Suspend funding until project managers from better-performing regions can be assigned


C.

Perform an independent review of business cases for each current and proposed project in the region


D.

Work with the region's leadership to better understand why the situation has occurred


Expert Solution
Questions # 24:

An IT team is having difficulty meeting new demands placed on the department as a result of a major and radical shift in enterprise business strategy. Which of the following is the ClO's BEST course of action to address this situation?

Options:

A.

Utilize third parties for non-value-added processes.


B.

Align the business strategy with the IT strategy.


C.

Review the current IT strategy.


D.

Review the IT risk appetite.


Expert Solution
Questions # 25:

Which of the following is the BEST way to help ensure that IT human resources are skilled and available?

Options:

A.

Focus on outsourcing as an option for supplementing IT human resources.


B.

Integrate IT training requests with IT budget planning.


C.

Align IT human resource (HR) management processes with internal training.


D.

Align IT human resource (HR) management with business planning.


Expert Solution
Questions # 26:

When developing IT risk management policies and standards, it is MOST important to align them with:

Options:

A.

Best practices for IT risk management.


B.

The corporate risk culture.


C.

Enterprise goals and objectives.


D.

The enterprise risk management (ERM) framework.


Expert Solution
Questions # 27:

Which of the following is MOST important to effectively incorporate innovation and emerging technologies into an enterprise’s IT strategy?

Options:

A.

Implementing new technologies based on maturity roadmaps according to reputable consulting entities.


B.

Maintaining an IT strategy based on traditional technologies, supplemented by objectives for innovation.


C.

Establishing a formal innovation management process that involves IT and business stakeholders.


D.

Performing quarterly feedback reviews with focus groups representing the enterprise’s customer base.


Expert Solution
Questions # 28:

A large enterprise is implementing an information security policy exception process. The BEST way to ensure that security risk is properly addressed is to:

confirm process owners' acceptance of residual risk.

perform an internal and external network penetration test.

obtain IT security approval on security policy exceptions.

Options:

A.

benchmark policy against industry best practice.


Expert Solution
Questions # 29:

An enterprise recently approved a bring your own device (BYOD) policy. The IT steering committee has directed IT management to develop a communication plan to disseminate information regarding the associated technical risks. Which of the following is MOST important to include in this communication plan?

Options:

A.

A link on the corporate intranet to the BYOD policy


B.

Potential exposures and impacts using common terms


C.

Schedule and content for mandatory training


D.

Disciplinary actions for violation of the BYOD policy


Expert Solution
Questions # 30:

Which of the following is the BEST way for an IT steering committee to determine the benefits of an IT investment?

Options:

A.

Measure return on investment (ROI) during implementation.


B.

Measure net present value (NPV) during stage gate review.


C.

Measure planned versus actual spend on the project.


D.

Measure value creation throughout the economic life cycle.


Expert Solution
Viewing page 2 out of 14 pages
Viewing questions 16-30 out of questions