
2025 Latest CGEIT dumps Exam Material with 680 Questions
ISACA CGEIT Questions and Answers Guarantee you Oass the Test Easily
NEW QUESTION # 364
After shifting from lease to purchase of IT infrastructure and software licenses, an enterprise has to pay for unexpected lease extensions causing significant cost overruns. The BEST direction for the IT steering committee would be to establish;
- A. a program to annually review financial policy on overruns.
- B. an end-of-life program to remove aging infrastructure from the environment.
- C. budget cuts to compensate for the cost overruns.
- D. a policy to consider total cost of ownership (TCO) in investment decisions.
Answer: B
NEW QUESTION # 365
Which of the following processes is responsible for low risk, frequently occurring low cost changes?
- A. Release Management
- B. Incident Management
- C. Request Fulfillment
- D. IT Facilities Management
Answer: C
NEW QUESTION # 366
Which of the following is an ADVANTAGE of using strategy mapping?
- A. It depicts the maturity levels of processes that support organizational strategy.
- B. It depicts the cause-and-effect linked relationships between strategic objectives.
- C. It provides effective indicators of productivity and growth.
- D. It identifies barriers to strategic alignment and links them to specific outcomes.
Answer: B
Explanation:
Strategy mapping is an advantage of using strategy mapping, as it helps to visualize and communicate how the enterprise can create value by achieving its strategic objectives. Strategy mapping also helps to align the IT goals and activities with the enterprise strategy, and to measure and monitor the IT performance and outcomes123. References := CGEIT Exam Content Outline, Domain 3, Subtopic A: Performance Management, Task 2: Ensure that IT performance measurement supports IT performance management by providing relevant, complete, reliable, timely and consistent information.
NEW QUESTION # 367
Which of the following is the PRIMARY purpose of an effective set of key risk indicators (KRIs)?
- A. Identifying possible future adverse impacts on the enterprise
- B. Establishing executive level buy-in of the risk program
- C. Quantifying the productivity of the risk management team
- D. Evaluating existing technology for risk monitoring capabilities
Answer: A
NEW QUESTION # 368
An enterprise has a zero-tolerance policy regarding security. This policy is causing a large number of email attachments to be blocked and is a disruption to enterprise. Which of the following should be the FIRST governance step to address this email issue?
- A. Direct the development of an email usage policy.
- B. Obtain senior management input based on identified risk.
- C. Recommend business sign-off on the zero-tolerance policy.
- D. Introduce an exception process.
Answer: B
Explanation:
According to the CGEIT certification guide, the first governance step to address the email issue caused by the zero-tolerance policy regarding security is to obtain senior management input based on identified risk. This is because senior management is ultimately responsible for setting the risk appetite and tolerance of the enterprise, and for balancing the security and business needs. The zero-tolerance policy may be too restrictive and may not align with the enterprise's risk profile and objectives. Therefore, senior management input is needed to review and adjust the policy according to the risk assessment and analysis1. The other options are less appropriate as the first governance step, as they do not involve senior management input or risk-based decision making. Reference:= CGEIT certification guide, domain 3: Risk Optimization, section 3.1: Risk Governance, page 87.
NEW QUESTION # 369
In which of the following situations is it MOST appropriate to use a quantitative risk assessment?
- A. The objectivity of the risk assessment is of primary importance.
- B. There is a lack of accurate and reliable past and present risk data.
- C. The risk assessment needs to be completed in a short period of time.
- D. The risk assessment is needed for an IT project business case.
Answer: A
NEW QUESTION # 370
Which volume provides guidance on clarification and prioritization of service-provider investments in services?
- A. Service Strategy
- B. Service Operation
- C. Service Management
- D. Service Design
Answer: A
NEW QUESTION # 371
Which of the following is the BEST way for a CIO to secure support for a strategy to achieve long-term IT objectives?
- A. Meet with stakeholders to explain the strategy and incorporate feedback.
- B. Develop a communication plan for distribution of information to staff.
- C. Develop tactics to implement the strategy and share with stakeholders.
- D. Make the necessary strategic decisions and notify staff accordingly.
Answer: A
NEW QUESTION # 372
The PRIMARY benefit of integrating IT resource planning into enterprise strategic planning is that it enables the enterprise to:
- A. develop tactical plans to achieve resource optimization.
- B. prioritize resource allocation based on sourcing strategy.
- C. allocate resources efficiently to achieve desired goals.
- D. adjust business goals depending upon resource availability.
Answer: C
Explanation:
Integrating IT resource planning into enterprise strategic planning enables the enterprise to allocate resources efficiently to achieve desired goals, as it ensures that IT resources are aligned with the enterprise vision, mission, and objectives. IT resource planning also helps to identify and prioritize the IT needs and demands of the enterprise, and to allocate the appropriate resources (such as people, processes, technology, and information) to meet them123. Reference:= CGEIT Exam Content Outline, Domain 2, Subtopic A: IT Resource Planning, Task 1: Ensure that IT resource planning is aligned with the enterprise strategic planning process.
NEW QUESTION # 373
Which of the following has the GREATEST influence on data quality assurance?
- A. Data encryption
- B. Data stewardship
- C. Data classification
- D. Data modeling
Answer: B
Explanation:
Data stewardship is the process of defining, implementing, and enforcing policies, standards, roles, and responsibilities for the quality, security, privacy, and usage of data within an enterprise1. Data stewardship has the greatest influence on data quality assurance, as it ensures that the data is accurate, complete, consistent, timely, and fit for its intended purpose1. Data stewardship also helps to identify and resolve data quality issues, monitor and measure data quality performance, and improve data quality over time1. The other options are not as influential as data stewardship, as they are specific aspects or techniques of data management, but not comprehensive processes. Data encryption is the process of transforming data into an unreadable format to protect it from unauthorized access or modification2. Data encryption can enhance data security and privacy, but it does not directly affect data quality assurance. Data classification is the process of categorizing data based on its value, sensitivity, and risk to the enterprise. Data classification can help to apply appropriate controls and policies for data protection and compliance, but it does not directly affect data quality assurance.
Data modeling is the process of creating a representation of the structure, relationships, and meaning of data within a specific domain or context. Data modeling can help to design and optimize databases and applications that use data, but it does not directly affect data quality assurance.
NEW QUESTION # 374
Which of the following essential elements of IT Portfolio Investment Management describes the ability to model the IT Portfolio with metrics most appropriate to the business such as ROI, Break- Even, Cost Avoidance, and Revenue Return?
- A. Highly Configurable
- B. Portfolio What-If Planning
- C. Integrated Dashboards and Scorecards
- D. Integrated Capability
Answer: A
NEW QUESTION # 375
Which of the following BEST enables the alignment of user access rights with business requirements?
- A. Data architecture model
- B. Maturity model
- C. System design
- D. Data classification policy
Answer: C
Explanation:
The alignment of user access rights with business requirements is most effectively achieved throughsystem design. During the design phase, systems are architected to incorporate role-based access controls, least privilege principles, and segregation of duties based on business needs. While data classification and architecture support information management, and maturity models help assess governance capability,system design operationalizes access controls directly in alignment with enterprise roles and responsibilities.
This is supported byCOBIT principlesthat emphasize embedding governance requirements into system design and implementation to ensure alignment, value delivery, and risk mitigation.
Reference:
CGEIT Review Manual (based on domain knowledge from Governance of Enterprise IT and COBIT design factors).
COBIT 2019 Design Guide: Aligning Governance System Components.
NEW QUESTION # 376
Which of the following quadrant analysis identifies the key issues of working well with other functions, IT value realization over time rather than-just cost, and being business process- focused but solution driven?
- A. High level role (strategic/transformational) and business market followers (riskaverse/mature)
- B. Low level role (tactical/utility) and business market leader (risk-taker/high growth)
- C. Low level role (tactical/utility) and business market followers (risk-averse/mature)
- D. High level role (strategic/transformational) and business market leader (risktaker/high growth)
Answer: A
Explanation:
Section: Volume C
NEW QUESTION # 377
When a shortfall of IT resources is identified, the FIRST course of action is to;
- A. perform a business impact analysis (BIA).
- B. reduce business requirements.
- C. reallocate the budget to close the gap in resources.
- D. negotiate best pricing for contracted resources.
Answer: A
NEW QUESTION # 378
Which of the following is the MOST effective means for IT management to report to executive management regarding the value of IT?
- A. Resource assessment
- B. Balanced scorecard
- C. Cost-benefit analysis
- D. IT process maturity level
Answer: D
NEW QUESTION # 379
Which of the following phases in SDLC transforms the detailed requirements into complete, detailed system design document?
- A. Initiation
- B. Planning
- C. Design
- D. Development
Answer: C
Explanation:
Section: Volume C
NEW QUESTION # 380
Which of the following is the MOST effective way to manage risks within the enterprise?
- A. Provide financial resources for risk management systems.
- B. Assign individuals responsibilities and accountabilities for management of risks.
- C. Document procedures and reporting processes.
- D. Make staff aware of the risks in their area and risk management techniques.
Answer: B
NEW QUESTION # 381
Which of the following MUST be established before implementing an information architecture that restricts access to data based on sensitivity?
- A. Security and privacy policies
- B. Risk and control frameworks
- C. Classification and ownership
- D. Probability and impact analysis
Answer: C
NEW QUESTION # 382
Which of the following would BEST help to ensure the appropriate allocation of IT resources to support an enterprise's mission?
- A. Prioritize program requirements based on existing resources.
- B. Implement resource planning for each IT project.
- C. Manage resources as part of the portfolio strategy.
- D. Develop a resource strategy as part of program management.
Answer: C
Explanation:
Managing resources as part of the portfolio strategy would best help to ensure the appropriate allocation of IT resources to support an enterprise's mission. This is because the portfolio strategy aligns the IT investments with the business goals and priorities, and ensures that the IT resources are allocated to the most valuable and strategic initiatives. By managing resources at the portfolio level, the enterprise can optimize the use of its IT resources across multiple programs and projects, and avoid resource conflicts, shortages, or wastages. A resource strategy as part of program management, prioritizing program requirements based on existing resources, and resource planning for each IT project are all useful practices, but they are not sufficient to ensure the appropriate allocation of IT resources at the enterprise level. They may only focus on the resource needs and constraints of specific programs or projects, and may not consider the overall alignment and optimization of IT resources with the enterprise's mission. Reference:= IT Portfolio Management: A Practitioner's Guide - ISACA, Resource Allocation Done Right: Best Practices for 2022 & Beyond, A Complete Guide to Resource Allocation in Projects - Float
NEW QUESTION # 383
......
The CGEIT certification exam is a valuable certification for professionals in the IT governance field. It demonstrates their knowledge and expertise, helps them stand out in the job market, and provides a framework for ongoing professional development.
Share Latest CGEIT DUMP Questions and Answers: https://dumpsninja.surepassexams.com/CGEIT-exam-bootcamp.html