Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Isaca Isaca Certification CGEIT Questions and answers with CertsForce

Viewing page 5 out of 14 pages
Viewing questions 61-75 out of questions
Questions # 61:

Which of the following would be MOST important to update if a decision is made to ban end user-owned devices in the workplace?

Options:

A.

Employee nondisclosure agreement


B.

Enterprise risk appetite statement


C.

Enterprise acceptable use policy


D.

Orientation training materials


Expert Solution
Questions # 62:

An enterprise is evaluating a possible strategic initiative for which IT would be the main driver. There are several risk scenarios associated with the initiative that have been identified. Which of the following should be done FIRST to facilitate a decision?

Options:

A.

Define the risk mitigation strategy.


B.

Assess the impact of each risk.


C.

Establish a baseline for each initiative.


D.

Select qualified personnel to manage the project.


Expert Solution
Questions # 63:

Which of the following should be the MAIN governance focus when implementing a newly approved bring your own device (BYOD) policy?

Options:

A.

Recommending mobile applications that will increase business productivity


B.

Training employees on the enterprise's chosen mobile device management system


C.

Educating employees on the increased IT security risk to the enterprise


D.

Understanding knowledge gaps of IT employees to support different mobile platforms


Expert Solution
Questions # 64:

Which of the following is the PRIMARY element in sustaining an effective governance framework?

Options:

A.

Identification of optimal business resources


B.

Establishment of a performance metric system


C.

Ranking of critical business risks


D.

Assurance of the execution of business controls


Expert Solution
Questions # 65:

The MOST important aspect of an IT governance framework to ensure that IT supports repeatable business processes is:

Options:

A.

earned value management.


B.

quality management,


C.

resource management.


D.

risk management


Expert Solution
Questions # 66:

An IT director is negotiating a contract with a vendor for application management services. There is concern by other departments that the outsourced services may not be delivered successfully. Which of the following is the BEST way for the IT director to address this concern?

Options:

A.

Implement a communication management plan.


B.

Develop a comprehensive vendor management plan.


C.

Review the IT service risk management plan.


D.

Establish a policy on operational level agreements with vendors.


Expert Solution
Questions # 67:

An enterprise decides to accept the IT risk of a subsidiary located in another country even though it exceeds the enterprise's risk appetite. Which of the following would be the BEST justification for this decision?

Options:

A.

Risk framework alignment


B.

Local market common practices


C.

Compliance with local regulations


D.

Technical gaps among subsidiaries


Expert Solution
Questions # 68:

The GREATEST benefit associated with a decision to implement performance metrics for key IT assets is the ability to:

Options:

A.

establish the span of control during the life cycle of IT assets.


B.

determine the average cost of controls for protection of IT assets.


C.

compare the performance Of IT assets against industry best practices.


D.

determine the contribution of IT assets in achievement of IT goals.


Expert Solution
Questions # 69:

Which of the following would be the PRIMARY impact on IT governance when a business strategy is changed?

Options:

A.

Performance outcomes of IT objectives


B.

IT governance structure


C.

Maturity level of IT processes


D.

Relationship level with IT outsourcers


Expert Solution
Questions # 70:

An IT audit report indicates that a lack of IT employee risk awareness is creating serious security issues in application design and configuration. Which of the following would be the BEST key risk indicator (KRI) to show progress in IT employee behavior?

Options:

A.

Number of IT employees attending security training sessions


B.

Results of application security testing


C.

Number of reported security incidents


D.

Results of application security awareness training quizzes


Expert Solution
Questions # 71:

Acceptance of an enterprise's newly implemented IT governance initiatives has been resisted by a functional group requesting more autonomy over technology choices. Which of the following is MOST important to accommodate this need for autonomy?

Options:

A.

Continuous improvement processes


B.

Documentation of key management practices


C.

An exception management process


D.

A change control process


Expert Solution
Questions # 72:

A business case indicates an enterprise would reduce costs by implementing a bring your own device (BYOD) program allowing employees to use personal devices for email. Which of the following should be the FIRST governance action?

Options:

A.

Assess the enterprise architecture (EA).


B.

Update the network infrastructure.


C.

Update the BYOD policy.


D.

Assess the BYOD risk.


Expert Solution
Questions # 73:

An enterprise is implementing a new IT governance program. Which of the following is the BEST way to increase the likelihood of its success?

Options:

A.

The IT steering committee approves the implementation efforts.


B.

The CIO communicates why IT governance is important to the enterprise.


C.

Implementation follows an IT audit recommendation.


D.

The CIO issues a mandate for adherence to the program.


Expert Solution
Questions # 74:

An IT director has become aware that a certain subset of data collected lawfully can be used to generate additional revenue. However, this particular use of the data is outside the original intention. What is the PRIMARY reason this situation should be escalated to the IT steering committee?

Options:

A.

Potential legal penalties


B.

Ethical concerns


C.

Regulatory requirements


D.

Data protection


Expert Solution
Questions # 75:

Senior management is reviewing the results of a recent security incident with significant business impact. Which of the following findings should be of GREATEST concern?

Options:

A.

Significant gaps are present m the incident documentation.


B.

The incident was not logged in the ticketing system.


C.

Response decisions were made without consulting the appropriate authority.


D.

Response efforts had to be outsourced due to insufficient internal resources.


Expert Solution
Viewing page 5 out of 14 pages
Viewing questions 61-75 out of questions