CBM CBM Information Technology & Systems Management 1 — Questions and Answers
Question 1: Which IT governance framework is most widely used by US organizations to align IT strategy with business objectives?
- COBIT (Correct answer)
- ITIL
- ISO 27001
- TOGAF
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is the most widely adopted IT governance framework in US organizations for aligning IT with business goals.
Question 2: A business manager needs to evaluate a new ERP system investment. Which financial metric best measures the return on this technology investment?
- Return on Investment (ROI) (Correct answer)
- Gross Profit Margin
- Current Ratio
- Debt-to-Equity Ratio
Correct answer: Return on Investment (ROI)
ROI directly measures the net gain from a technology investment relative to its cost, making it the standard metric for evaluating ERP system expenditures.
Question 3: What is the primary purpose of a Service Level Agreement (SLA) in IT management?
- To define expected service performance standards between provider and customer (Correct answer)
- To outline employee compensation for IT roles
- To document software source code ownership
- To establish hardware procurement schedules
Correct answer: To define expected service performance standards between provider and customer
An SLA formally defines the expected performance metrics, uptime, and responsibilities between an IT service provider and the business customer.
Question 4: Which approach to software development uses short iterative cycles called sprints to deliver incremental value?
- Agile/Scrum (Correct answer)
- Waterfall
- Six Sigma
- Critical Path Method
Correct answer: Agile/Scrum
Agile/Scrum methodology divides development into time-boxed sprints, allowing teams to deliver working software incrementally and respond to changing requirements.
Question 5: A company experiences a major data breach. Under US law, which regulation primarily governs notification requirements for healthcare data breaches?
- HIPAA Breach Notification Rule (Correct answer)
- GDPR
- Sarbanes-Oxley Act
- FISMA
Correct answer: HIPAA Breach Notification Rule
The HIPAA Breach Notification Rule requires covered entities to notify affected individuals and the HHS Secretary when unsecured protected health information is breached.
Question 6: What does the concept of 'Total Cost of Ownership' (TCO) include when evaluating an IT system?
- Acquisition, implementation, maintenance, and disposal costs (Correct answer)
- Only the initial purchase price of hardware and software
- Annual licensing fees only
- Employee salaries for the IT department
Correct answer: Acquisition, implementation, maintenance, and disposal costs
TCO encompasses all direct and indirect costs throughout a system's lifecycle, including acquisition, deployment, operation, maintenance, and end-of-life disposal.
Which IT governance framework is most widely used by US organizations to align IT strategy with business objectives?