CGEIT - Certified in the Governance of Enterprise IT — Questions and Answers
Question 1: Which of the following is the BEST outcome measure to determine the effectiveness of IT risk management processes?
- Frequency of updates to the IT risk register
- Percentage of business users satisfied with the quality of risk training
- Number of events impacting business processes due to delays in responding to risks
- Time lag between when IT risk is identified and the enterprise's response (Correct answer)
Correct answer: Time lag between when IT risk is identified and the enterprise's response
Explanation: <br> This measure is crucial because it assesses the efficiency and effectiveness of the IT risk management process in addressing identified risks promptly. A shorter time lag indicates that risks are being promptly identified, assessed, and responded to, minimizing potential negative impacts on the organization. It reflects how well the organization can detect and react to risks before they escalate into issues that could affect business operations.
Question 2: In a mature IT governance model, responsibility for IT resource allocation decisions PRIMARILY rests with:
- External auditors who assess resource efficiency
- The CFO based on financial impact alone
- A governance structure that involves both IT and business leadership (Correct answer)
- Individual IT project managers
Correct answer: A governance structure that involves both IT and business leadership
Mature IT governance models use a shared governance structure involving both IT and business leaders to ensure resource allocation decisions reflect enterprise strategy.
Question 3: Integration middleware in enterprise IT architecture MOST supports governance by:
- Replacing the need for an enterprise architecture strategy
- Reducing the number of business applications in use
- Enabling controlled, monitored data exchange between disparate systems (Correct answer)
- Eliminating the need for data governance policies
Correct answer: Enabling controlled, monitored data exchange between disparate systems
Integration middleware provides governed, standardized pathways for systems to exchange data, enabling visibility and control over how information flows across the enterprise.
Question 4: A CGEIT-aligned IT asset management program should PRIMARILY focus on:
- Minimizing asset procurement costs through bulk purchasing
- Maintaining detailed technical specifications of all IT systems
- Tracking physical IT equipment for insurance purposes
- Maximizing asset utilization across the full lifecycle to deliver business value (Correct answer)
Correct answer: Maximizing asset utilization across the full lifecycle to deliver business value
IT asset management in governance focuses on maximizing utilization and value across the full asset lifecycle, not just procurement or tracking.
Question 5: A third-party SOC 2 report PRIMARILY provides assurance about a service provider's:
- Physical data center locations
- Controls over security, availability, processing integrity, confidentiality, and privacy (Correct answer)
- Financial performance and profitability
- Staff qualifications and training certifications
Correct answer: Controls over security, availability, processing integrity, confidentiality, and privacy
A SOC 2 report provides independent assurance that a service provider's controls meet the Trust Services Criteria covering security, availability, and related principles.
Question 6: A company implements a new ERP system but sees no improvement in operational efficiency. The MOST likely governance failure is:
- No benefits realization plan was established before deployment (Correct answer)
- The ERP vendor was not experienced enough
- The IT team lacked sufficient training
- The project exceeded its original budget
Correct answer: No benefits realization plan was established before deployment
Without a benefits realization plan, there is no structured approach to tracking and capturing the efficiency gains the investment was meant to deliver.
Question 7: Which US regulation MOST directly requires IT governance controls over financial reporting systems?
- Sarbanes-Oxley Act (SOX) (Correct answer)
- General Data Protection Regulation (GDPR)
- Health Insurance Portability and Accountability Act (HIPAA)
- Federal Information Security Management Act (FISMA)
Correct answer: Sarbanes-Oxley Act (SOX)
SOX Section 404 requires organizations to establish and certify internal controls over financial reporting, including IT systems that support those reports.
Question 8: The MAIN purpose of setting IT governance performance targets is to:
- Standardize performance expectations across all IT vendors
- Limit IT spending growth year over year
- Provide a clear standard against which actual performance can be evaluated (Correct answer)
- Satisfy external regulatory reporting requirements
Correct answer: Provide a clear standard against which actual performance can be evaluated
Performance targets give governance bodies a benchmark to assess whether IT activities are delivering at the required level.
Question 9: The TOGAF Architecture Development Method (ADM) is BEST described as:
- A one-time process to document current IT systems
- A compliance framework for financial reporting IT controls
- A vendor selection methodology for enterprise software
- An iterative cycle for developing and managing enterprise architecture (Correct answer)
Correct answer: An iterative cycle for developing and managing enterprise architecture
TOGAF ADM is an iterative, phased cycle that guides organizations through developing, implementing, and continually refining their enterprise architecture.
Question 10: Which governance role is MOST responsible for maintaining the enterprise architecture within an organization?
- Chief Architect or Enterprise Architecture function (Correct answer)
- IT helpdesk management
- External compliance auditor
- Chief Financial Officer
Correct answer: Chief Architect or Enterprise Architecture function
The Chief Architect or Enterprise Architecture function owns the ongoing development, maintenance, and governance of the enterprise architecture.
Question 11: IT integration governance PRIMARILY ensures that:
- Vendors deliver systems independently of each other
- All IT systems use identical technology platforms
- IT staff from different teams are merged into a single department
- Different IT systems work together seamlessly to deliver coherent business outcomes (Correct answer)
Correct answer: Different IT systems work together seamlessly to deliver coherent business outcomes
Integration governance ensures that disparate IT systems communicate and interoperate effectively so they collectively support business outcomes without silos.
Question 12: An IT governance board wants to improve benefits tracking. Which tool is MOST appropriate?
- Benefits realization register with periodic status updates (Correct answer)
- Vendor performance dashboard
- Network monitoring platform
- IT incident management system
Correct answer: Benefits realization register with periodic status updates
A benefits realization register provides a structured record of expected benefits, owners, timelines, and actual results for periodic review.
Question 13: HIPAA compliance MOST directly impacts IT governance in organizations that handle:
- Protected health information (PHI) stored or transmitted electronically (Correct answer)
- Consumer credit reporting data
- Federal government classified data
- Financial transaction data for public companies
Correct answer: Protected health information (PHI) stored or transmitted electronically
HIPAA's Security Rule specifically governs IT controls over electronic protected health information, requiring encryption, access controls, and audit trails.
Question 14: An IT governance portfolio review identifies several projects with low strategic value and high resource consumption. The BEST governance action is to:
- Continue all projects to avoid disrupting team commitments
- Transfer those projects to an external vendor
- Add more resources to accelerate the low-value projects
- Terminate or deprioritize those projects to reallocate resources to higher-value investments (Correct answer)
Correct answer: Terminate or deprioritize those projects to reallocate resources to higher-value investments
Good portfolio governance actively reallocates resources from low-value investments to higher-priority ones to maximize overall strategic return.
Question 15: A 'governance maturity model' is BEST used to:
- Compare IT budgets against industry benchmarks
- Assess the current state of governance practices and identify improvement areas (Correct answer)
- Map physical data center infrastructure
- Document software development lifecycle stages
Correct answer: Assess the current state of governance practices and identify improvement areas
A maturity model evaluates how developed and effective current governance practices are, and highlights where improvements will have the most impact.
Question 16: Which type of metric measures outcomes rather than activities in IT governance?
- Leading indicator
- Input metric
- Activity metric
- Lagging indicator (Correct answer)
Correct answer: Lagging indicator
Lagging indicators measure outcomes that have already occurred, such as business value realized, making them direct evidence of governance results.
Question 17: When legacy system replacement is being considered, enterprise architecture governance MOST helps by:
- Mandating immediate replacement of all systems older than 10 years
- Assessing dependencies, integration impacts, and alignment with the target architecture before a decision is made (Correct answer)
- Delegating the replacement decision entirely to the IT department
- Selecting the replacement system based solely on vendor reputation
Correct answer: Assessing dependencies, integration impacts, and alignment with the target architecture before a decision is made
EA governance ensures replacement decisions are informed by a clear understanding of system dependencies, integration requirements, and future architectural direction.
Question 18: When a new regulation affecting IT data retention is enacted, the FIRST governance action should be to:
- Wait for an external audit to identify specific gaps
- Delegate compliance entirely to the legal department
- Immediately rebuild all data storage systems
- Assess the regulation's impact on existing IT controls and data management practices (Correct answer)
Correct answer: Assess the regulation's impact on existing IT controls and data management practices
Impact assessment identifies which systems, data, and controls are affected by the new regulation so governance can plan a targeted and timely response.
Question 19: Which CGEIT concept describes the governance practice of regularly reviewing the IT investment portfolio against changing business priorities?
- Project scope creep management
- Portfolio rebalancing (Correct answer)
- IT change freeze
- Vendor contract renegotiation
Correct answer: Portfolio rebalancing
Portfolio rebalancing is the practice of periodically adjusting the mix of IT investments to reflect shifts in business strategy, emerging risks, or changing value expectations.
Question 20: Which IT resource management discipline MOST directly reduces the risk of vendor lock-in within an IT governance framework?
- Standardizing all IT services on a single vendor ecosystem
- Requiring vendors to use proprietary technology platforms
- Delegating vendor selection to individual project teams
- Establishing a multi-vendor sourcing strategy with clearly defined exit criteria (Correct answer)
Correct answer: Establishing a multi-vendor sourcing strategy with clearly defined exit criteria
A multi-vendor sourcing strategy with clear exit criteria reduces dependency on any single provider and manages the risk of vendor lock-in.
Question 21: Which of the following objectives can be the best coordinated with Human Resource Management?
- Satisfying the business needs (Correct answer)
- Rewarding employee fairly
- Focusing on business improvements
- Increasing the automation of the business processes
Correct answer: Satisfying the business needs
Explanation: <br> Satisfying the business needs is considered the best objective that can be coordinated with Human Resource Management (HRM), as it emphasizes the strategic alignment of HR practices with organizational objectives and operational requirements.
Question 22: Which EA framework is MOST widely recognized in US enterprises for structuring IT governance architecture?
- ITIL v4
- PMBOK
- TOGAF (The Open Group Architecture Framework) (Correct answer)
- Six Sigma
Correct answer: TOGAF (The Open Group Architecture Framework)
TOGAF is the most widely adopted enterprise architecture framework globally, providing a structured approach to designing and governing IT architecture.
Question 23: Which IT resource management practice best ensures that human capital investments align with enterprise IT governance objectives?
- Aligning IT workforce planning with strategic business goals and governance frameworks (Correct answer)
- Outsourcing all IT functions to reduce overhead costs
- Hiring IT staff based solely on technical certifications
- Limiting IT training to job-specific technical skills only
Correct answer: Aligning IT workforce planning with strategic business goals and governance frameworks
Aligning IT workforce planning with strategic business goals ensures that human capital decisions support governance objectives and organizational value.
Question 24: The PRIMARY reason IT value delivery governance requires executive sponsorship is that:
- Technology vendors insist on executive-level contract approval
- External auditors require executive signoff on all IT deliverables
- IT cannot manage its own projects without executive oversight
- Business outcomes require business authority to drive organizational changes beyond IT (Correct answer)
Correct answer: Business outcomes require business authority to drive organizational changes beyond IT
Realizing IT value often requires organizational changes — process redesign, behavior change, adoption — that only business executives have the authority to drive.
Question 25: Which IT resource management approach BEST supports enterprise agility within a governance framework?
- Centralizing all IT decision-making with the CIO
- Rigid long-term contracts with a single IT vendor
- Flexible resource models that can scale with changing business demands (Correct answer)
- Maintaining a fixed IT resource pool regardless of business cycles
Correct answer: Flexible resource models that can scale with changing business demands
Flexible resource models allow the enterprise to respond to changing business conditions while maintaining governance oversight and control.
Question 26: In IT governance, identifying stakeholders PRIMARILY helps an organization to:
- Assign technical tasks to appropriate teams
- Understand who has interests in and influence over IT decisions (Correct answer)
- Limit communication to senior executives only
- Reduce the number of people involved in IT projects
Correct answer: Understand who has interests in and influence over IT decisions
Stakeholder identification maps out who has interests or influence so governance structures can engage the right people in IT decisions.
Question 27: When an organization adopts a cloud-first strategy, its enterprise architecture governance MOST needs to address:
- Security, data sovereignty, vendor dependency, and integration with on-premise systems (Correct answer)
- Replacement of COBIT with a cloud-specific framework
- Elimination of all internal IT staff
- Reduction of governance committee membership
Correct answer: Security, data sovereignty, vendor dependency, and integration with on-premise systems
Cloud adoption introduces new governance challenges around data control, regulatory compliance, vendor lock-in, and integration that EA governance must explicitly address.
Question 28: An IT investment review board wants to ensure that IT will be able to support business initiatives. Each initiative is comprised of several interrelated IT projects. <br><br> Which of the following would help ensure that the initiatives meet their goals?
- Verification of initiatives against the architecture
- Establishment of portfolio management (Correct answer)
- Review of the business case for each initiative
- Review of project management methodology
Correct answer: Establishment of portfolio management
Explanation: <br> Portfolio management involves managing a collection of projects and initiatives as a portfolio to achieve strategic objectives. It helps ensure that each initiative aligns with business goals and objectives by providing oversight, prioritization, and resource allocation across interrelated IT projects. This approach enables the IT investment review board to effectively support business initiatives by coordinating efforts, managing risks, and optimizing resource utilization across the portfolio of initiatives.
Question 29: Which of the following examples are included in the general controls embedded in IT processes and services? Each correct answer represents a complete solution.
- Systems development (Correct answer)
- Completeness
- Change management (Correct answer)
- Accuracy
Correct answer: Systems development
Explanation: <br> General controls embedded in IT processes and services typically include: <br> - Change management: This involves processes and procedures for managing changes to IT systems, applications, and infrastructure. Change management ensures that changes are documented, assessed for impact, tested, and implemented in a controlled manner to maintain the integrity and reliability of IT services. <br> - Systems development: This encompasses the processes and methodologies used for developing, maintaining, and enhancing IT systems and applications. It includes activities such as requirements gathering, design, coding, testing, deployment, and maintenance of software systems.
Question 30: Which metric BEST measures the effectiveness of IT human resource management from a governance perspective?
- Number of IT certifications held by staff
- Alignment of IT competency profiles with current and future business capability requirements (Correct answer)
- IT staff-to-business-user ratio
- Average IT department tenure in years
Correct answer: Alignment of IT competency profiles with current and future business capability requirements
Aligning IT competency profiles with business capability requirements demonstrates that human resource management supports strategic governance objectives.
Question 31: An IT governance framework's effectiveness is BEST measured by:
- Reduction in IT department headcount
- Vendor contract renewal rates
- The number of governance policies published
- Stakeholder satisfaction and achievement of IT-business alignment outcomes (Correct answer)
Correct answer: Stakeholder satisfaction and achievement of IT-business alignment outcomes
Governance effectiveness is ultimately demonstrated through stakeholder satisfaction and whether IT and business goals are actually aligned and achieved.
Question 32: In CGEIT, an enterprise architecture gap analysis PRIMARILY identifies:
- The differences between current IT capabilities and what is needed to achieve future business goals (Correct answer)
- Budget overruns in active IT projects
- Employee skill shortages in the IT department
- Differences between two competing IT vendors
Correct answer: The differences between current IT capabilities and what is needed to achieve future business goals
A gap analysis compares the current IT capability state to the future target state required by business strategy, identifying what must be built, changed, or retired.
Question 33: A CGEIT practitioner identifies that benefits are being reported without independent verification. The BEST recommendation is to:
- Remove the benefits reporting requirement to reduce workload
- Implement an independent review or audit of reported benefit figures (Correct answer)
- Delay reviews until the next fiscal year
- Accept self-reported benefits from project teams as sufficient
Correct answer: Implement an independent review or audit of reported benefit figures
Independent verification of reported benefits ensures objectivity and prevents overstating achievements, supporting credible governance.
Question 34: Which activity is MOST essential when establishing a benefits realization framework for an IT investment?
- Scheduling quarterly technology audits
- Defining measurable business outcomes tied to strategic goals (Correct answer)
- Assigning all responsibility to the IT department
- Selecting the lowest-cost technology vendor
Correct answer: Defining measurable business outcomes tied to strategic goals
A benefits realization framework must link measurable outcomes directly to strategic goals so progress can be tracked and value confirmed.
Question 35: Which communication principle is MOST important when delivering negative IT governance news to stakeholders?
- Restricting disclosure to senior IT management only
- Delaying disclosure until the situation fully resolves
- Transparency and timeliness, accompanied by a remediation plan (Correct answer)
- Minimizing the scope of reported issues
Correct answer: Transparency and timeliness, accompanied by a remediation plan
Transparent and timely disclosure of governance issues, paired with a remediation plan, maintains stakeholder trust and enables corrective action.
Question 36: A 'control deficiency' identified during an IT audit MOST requires:
- A documented remediation plan with assigned ownership and target dates (Correct answer)
- Public disclosure to all stakeholders
- Transfer of responsibility to an external vendor
- Immediate shutdown of the affected IT system
Correct answer: A documented remediation plan with assigned ownership and target dates
A control deficiency requires a remediation plan with clear ownership and deadlines so the gap in controls is systematically closed.
Question 37: Which stakeholder group is MOST critical to engage when defining IT governance principles?
- External software vendors
- End users of business applications
- IT help desk staff
- Board of directors and senior executive leadership (Correct answer)
Correct answer: Board of directors and senior executive leadership
The board and senior executives set organizational direction and must own IT governance principles for them to carry authority and alignment with strategy.
Question 38: Which standard is MOST commonly used as a framework for IT controls assurance in US organizations?
- PMBOK (Project Management Body of Knowledge)
- TOGAF (The Open Group Architecture Framework)
- COBIT (Control Objectives for Information and Related Technologies) (Correct answer)
- ITIL (IT Infrastructure Library)
Correct answer: COBIT (Control Objectives for Information and Related Technologies)
COBIT is the primary globally recognized framework for IT governance and control objectives, widely used for assurance and compliance assessments in US organizations.
Question 39: In CGEIT, 'IT value delivery' encompasses which of the following?
- Ensuring all IT infrastructure is current and up to date
- Completing all IT projects before their deadlines
- Defining, delivering, measuring, and sustaining the benefits of IT investments over their lifecycle (Correct answer)
- Managing vendor relationships for optimal pricing
Correct answer: Defining, delivering, measuring, and sustaining the benefits of IT investments over their lifecycle
IT value delivery in CGEIT covers the full lifecycle — defining what value looks like, delivering it through IT, measuring whether it arrived, and sustaining it over time.
Question 40: A governance body reviewing IT resource management maturity would MOST value which of the following evidence?
- IT staff satisfaction survey results
- Documented processes linking resource decisions to strategic objectives with measurable outcomes (Correct answer)
- A complete inventory of all IT hardware assets
- Signed contracts with all current IT vendors
Correct answer: Documented processes linking resource decisions to strategic objectives with measurable outcomes
Documented processes that link resource decisions to strategic objectives with measurable outcomes demonstrate mature, value-driven IT resource governance.
Question 41: Which of the following resource categories includes skill sets, certifications, productivity, and morale?
- Partners
- Products
- Processes
- People (Correct answer)
Correct answer: People
Explanation: <br> The resource category that includes skill sets, certifications, productivity, and morale is "People." This category refers to the human resources within an organization, including their skills, qualifications, certifications, productivity levels, and morale. Effective management and development of people are crucial for achieving organizational objectives and maintaining competitive advantage.
Question 42: Enterprise Architecture (EA) PRIMARILY supports IT governance by:
- Providing a structured blueprint that aligns IT capabilities with business strategy (Correct answer)
- Tracking individual project milestones
- Managing IT vendor contracts and pricing
- Documenting all software bugs for remediation
Correct answer: Providing a structured blueprint that aligns IT capabilities with business strategy
Enterprise Architecture creates a holistic model of how IT capabilities, processes, and systems should be structured to support and enable business strategy.
Question 43: Which approach BEST supports ongoing stakeholder engagement in IT governance?
- Sending quarterly email updates without response options
- Regular governance forums with structured reporting and feedback mechanisms (Correct answer)
- Limiting governance communication to annual board reports
- Delegating all stakeholder communication to the IT helpdesk
Correct answer: Regular governance forums with structured reporting and feedback mechanisms
Regular forums with structured reporting and feedback create two-way engagement, keeping stakeholders informed and enabling them to influence governance.
Question 44: Which factor MOST determines the frequency of IT governance reporting to stakeholders?
- The age of the existing IT infrastructure
- The stakeholder's role, decision-making needs, and the volatility of the IT environment (Correct answer)
- The size of the IT department
- The number of IT vendors under contract
Correct answer: The stakeholder's role, decision-making needs, and the volatility of the IT environment
Reporting frequency should match how often stakeholders need information to make decisions, adjusted for how rapidly the IT environment is changing.
Question 45: Which practice BEST demonstrates effective IT value delivery governance?
- Delegating investment decisions to individual project managers
- Approving all projects submitted by the IT department
- Measuring success solely by project delivery speed
- Stage-gate reviews that confirm business value at each major phase before proceeding (Correct answer)
Correct answer: Stage-gate reviews that confirm business value at each major phase before proceeding
Stage-gate reviews create checkpoints where governance confirms that value is on track before committing further investment, preventing value erosion.
Question 46: An IT governance committee consistently has poor attendance from business leaders. The MOST effective remedy is to:
- Replace absent business leaders with IT staff
- Reduce meeting frequency to annual sessions
- Move all governance decisions to email approval
- Redesign meeting agendas to focus on business-relevant decisions and value (Correct answer)
Correct answer: Redesign meeting agendas to focus on business-relevant decisions and value
Business leaders attend when meetings are relevant to them — aligning governance agendas to business decisions increases meaningful participation.
Question 47: A 'governance heat map' is BEST used in stakeholder communication to:
- Map network infrastructure components
- Track individual employee performance
- Document software licensing agreements
- Visually display risk or performance status across IT domains (Correct answer)
Correct answer: Visually display risk or performance status across IT domains
A governance heat map uses color coding to communicate risk levels or performance status across governance domains in a format quickly understood by stakeholders.
Question 48: An IT organization is found to be SOX-compliant but experiences repeated data breaches. This MOST likely indicates:
- The organization needs to abandon its IT governance framework
- SOX requirements are too strict for practical implementation
- Compliance does not guarantee adequate security controls beyond regulatory minimums (Correct answer)
- Data breach responsibility lies entirely with the cybersecurity team
Correct answer: Compliance does not guarantee adequate security controls beyond regulatory minimums
SOX compliance addresses financial reporting controls, not comprehensive cybersecurity — meeting one compliance standard does not ensure security in all areas.
Question 49: A governance review reveals that a KPI has been stable for two years but the underlying business condition it measures has changed significantly. The BEST action is to:
- Continue tracking the KPI for historical continuity
- Increase the reporting frequency of the existing KPI
- Escalate the issue to the external auditor
- Retire or redesign the KPI to reflect the current business reality (Correct answer)
Correct answer: Retire or redesign the KPI to reflect the current business reality
A KPI that no longer reflects current business conditions provides misleading signals and should be redesigned or retired to maintain governance relevance.
Question 50: When IT governance metrics consistently meet targets, a governance board should FIRST:
- Immediately raise all targets by 20%
- Remove the metrics from the dashboard
- Reassign the IT team to other projects
- Verify that targets are appropriately challenging and not set too low (Correct answer)
Correct answer: Verify that targets are appropriately challenging and not set too low
Consistently met targets may indicate they are set too conservatively — verifying target difficulty ensures metrics continue to drive meaningful performance.
Question 51: In CGEIT, which of the following BEST describes the role of IT resource optimization within enterprise governance?
- Reducing IT headcount to minimize operational expenses
- Ensuring IT resources are acquired, deployed, and retired in a manner that maximizes value (Correct answer)
- Standardizing all IT resources to a single vendor platform
- Delegating all resource decisions to departmental IT managers
Correct answer: Ensuring IT resources are acquired, deployed, and retired in a manner that maximizes value
IT resource optimization in governance ensures resources are managed throughout their lifecycle to deliver maximum business value.
Question 52: The PRIMARY difference between IT compliance and IT assurance is that assurance:
- Provides independent confidence that controls are effective, beyond just checking conformance (Correct answer)
- Is performed exclusively by internal staff rather than external parties
- Replaces the need for formal compliance programs
- Focuses only on technical security controls
Correct answer: Provides independent confidence that controls are effective, beyond just checking conformance
Assurance goes beyond verifying that rules are followed; it independently validates that controls actually work and that stakeholders can rely on them.
Question 53: Which IT governance practice BEST demonstrates proactive compliance management?
- Responding to compliance findings only after an external audit
- Delegating all compliance responsibilities to IT staff
- Continuously monitoring regulatory changes and updating controls before deadlines (Correct answer)
- Conducting compliance assessments every three years
Correct answer: Continuously monitoring regulatory changes and updating controls before deadlines
Proactive compliance management means staying ahead of regulatory changes and updating controls before requirements take effect, not reacting after audits.
Question 54: Paul has been asked to complete a SWOT analysis for his solution scope. What does SWOT analysis mean?
- Strengths, Weaknesses, Opportunities, Threats (Correct answer)
- Stakeholder Weaknesses, Organizational Threats
- Strengths, Weaknesses, Opportunities, Time
- Stakeholders Weaknesses, Organization, Threats
Correct answer: Strengths, Weaknesses, Opportunities, Threats
Explanation: <br> SWOT analysis stands for Strengths, Weaknesses, Opportunities, and Threats. It is a strategic planning tool used to identify and evaluate the internal strengths and weaknesses of a project, product, or organization, as well as the external opportunities and threats in the environment. This analysis helps in understanding the current position and situation, assessing potential risks and advantages, and formulating strategies to leverage strengths and opportunities while mitigating weaknesses and threats.
Question 55: In benefits realization management, a 'benefits owner' is BEST described as:
- An IT lead who manages deployment timelines
- A finance analyst who tracks project spend
- A vendor representative who delivers the solution
- A business manager responsible for achieving a specific benefit (Correct answer)
Correct answer: A business manager responsible for achieving a specific benefit
A benefits owner is a named business manager accountable for ensuring a specific benefit is achieved after implementation.
Question 56: An IT compliance audit PRIMARILY evaluates whether:
- IT staff have completed mandatory training
- IT controls and practices conform to required standards, regulations, or policies (Correct answer)
- IT projects are delivered on time and within budget
- IT vendors are meeting their contractual obligations
Correct answer: IT controls and practices conform to required standards, regulations, or policies
An IT compliance audit assesses whether the organization's IT controls and practices conform to the applicable legal, regulatory, and policy requirements.
Question 57: Which of the following BEST represents an IT governance approach to managing IT financial resources?
- IT spending should be minimized across all categories regardless of strategic impact
- IT budgets should be managed independently from business unit budgets
- IT financial management should link expenditures directly to business outcomes and value delivery (Correct answer)
- Financial decisions should be delegated to the IT finance team without board involvement
Correct answer: IT financial management should link expenditures directly to business outcomes and value delivery
Linking IT expenditures to business outcomes ensures financial resources are governed in a way that supports value delivery and strategic alignment.
Question 58: A CGEIT candidate identifies that IT governance decisions are being made without input from business unit leaders. This MOST likely results in:
- IT investments misaligned with actual business needs (Correct answer)
- Faster IT project delivery timelines
- Reduced compliance exposure
- Lower IT operational costs
Correct answer: IT investments misaligned with actual business needs
Excluding business unit leaders from IT governance decisions leads to misalignment between IT investments and the actual needs of the business.
Question 59: An 'architecture review board' (ARB) in IT governance PRIMARILY serves to:
- Manage the IT department's annual budget
- Approve all IT vendor contracts
- Evaluate proposed IT changes for conformance with enterprise architecture standards (Correct answer)
- Conduct performance reviews for IT staff
Correct answer: Evaluate proposed IT changes for conformance with enterprise architecture standards
An ARB reviews proposed IT projects and changes to ensure they align with and comply with established enterprise architecture standards and principles.
Question 60: The PRIMARY reason IT governance communication plans fail is:
- They are not tailored to the needs and communication preferences of each stakeholder group (Correct answer)
- They include too much financial data
- They rely on external consultants
- They are updated too frequently
Correct answer: They are not tailored to the needs and communication preferences of each stakeholder group
A one-size-fits-all communication approach fails because different stakeholders need different levels of detail, formats, and frequencies.
Question 61: When an organization's IT resource demands exceed current capacity, the governance board should FIRST:
- Assess the situation against strategic priorities and available options before committing resources (Correct answer)
- Outsource the excess workload to the nearest available vendor
- Reduce IT project scope to fit within current resource limits
- Immediately approve additional IT headcount
Correct answer: Assess the situation against strategic priorities and available options before committing resources
Governance requires evaluating resource gaps against strategic priorities and available options before committing to a specific course of action.
Question 62: Which metric BEST reflects the overall performance of an IT investment portfolio?
- Total IT budget spent versus allocated
- Average project delivery time in weeks
- Percentage of portfolio investments achieving or exceeding their business case targets (Correct answer)
- Number of new IT projects initiated per quarter
Correct answer: Percentage of portfolio investments achieving or exceeding their business case targets
The proportion of investments achieving their business case targets directly measures whether the portfolio is delivering the value it was funded to create.
Question 63: Which of the following is PRIMARILY achieved through performance measurement?
- Process improvement (Correct answer)
- Cost efficiency
- Transparency
- Benefit realization
Correct answer: Process improvement
Explanation: <br> Performance measurement allows organizations to assess the effectiveness and efficiency of their processes. By measuring key performance indicators (KPIs), organizations can identify areas where processes can be optimized, streamlined, or redesigned to improve efficiency, reduce waste, and enhance overall effectiveness. Process improvement is directly facilitated by performance measurement because it provides the data and insights necessary to identify areas for improvement and track progress over time.
Question 64: When presenting IT governance results to a board of directors, the MOST appropriate format is:
- Vendor contract summaries
- Executive dashboard with KPIs, risks, and decisions required (Correct answer)
- Detailed technical architecture diagrams
- Line-by-line project budget spreadsheets
Correct answer: Executive dashboard with KPIs, risks, and decisions required
Boards need concise, strategic information including KPIs, key risks, and decisions they must make — not operational or technical detail.
Question 65: Which CGEIT concept BEST describes the practice of comparing IT governance performance against industry peers?
- Capability assessment
- Baselining
- Benchmarking (Correct answer)
- Variance analysis
Correct answer: Benchmarking
Benchmarking compares an organization's IT governance performance metrics against industry peers or best practices to identify gaps and improvement targets.
Question 66: An IT governance dashboard is MOST valuable when it:
- Tracks individual employee productivity metrics
- Lists all open IT projects with their technical specifications
- Documents compliance with specific IT standards
- Presents real-time KPIs that support executive decision-making (Correct answer)
Correct answer: Presents real-time KPIs that support executive decision-making
A governance dashboard's value is in providing current, relevant KPIs in a format that allows executives to make timely, informed governance decisions.
Question 67: Which CGEIT principle supports ongoing benefits realization after project closure?
- Transferring governance to the IT helpdesk
- Archiving all project documentation
- Post-implementation review linked to business case KPIs (Correct answer)
- Immediate reassignment of project resources
Correct answer: Post-implementation review linked to business case KPIs
Post-implementation reviews measure actual outcomes against the business case KPIs, confirming whether benefits have been realized.
Question 68: A stakeholder communication plan in IT governance PRIMARILY serves to:
- Minimize the number of governance meetings held
- Document all IT system changes for audit purposes
- Track vendor deliverables against contract terms
- Ensure the right information reaches the right stakeholders at the right time (Correct answer)
Correct answer: Ensure the right information reaches the right stakeholders at the right time
A communication plan systematically ensures stakeholders receive timely, relevant information that supports informed governance decisions and engagement.
Question 69: Which of the following is a process that occurs due to mergers, outsourcing, or changing business needs?
- Outplacement
- Involuntary exit (Correct answer)
- Voluntary exit
- Plant closing
Correct answer: Involuntary exit
Explanation: <br> Involuntary exit refers to the process where employees are terminated or laid off from their jobs due to reasons such as mergers, outsourcing, or changing business needs. This happens when the organization needs to reduce its workforce or restructure due to strategic changes, financial pressures, or shifts in business priorities. Involuntary exits are typically initiated by the employer rather than the employee, distinguishing them from voluntary exits where employees choose to leave on their own accord.
Question 70: Which practice BEST ensures IT governance metrics remain relevant over time?
- Periodically reviewing and updating metrics to reflect changes in business strategy (Correct answer)
- Keeping the same metrics indefinitely for trend comparison
- Delegating metric selection entirely to the IT department
- Adding more metrics each year to increase coverage
Correct answer: Periodically reviewing and updating metrics to reflect changes in business strategy
As business strategy evolves, governance metrics must be reviewed and updated to ensure they continue measuring what matters most to the organization.
Question 71: When an enterprise transitions an IT function from in-house to a managed service provider, the governance board is MOST responsible for:
- Selecting the specific technology platform to be used
- Managing day-to-day operations of the outsourced function
- Overseeing the transition to ensure strategic alignment and risk management (Correct answer)
- Negotiating individual contract clauses with the provider
Correct answer: Overseeing the transition to ensure strategic alignment and risk management
The governance board oversees the transition at a strategic level, ensuring it aligns with enterprise goals and that risks are properly managed.
Question 72: In CGEIT, 'informed stakeholders' in a RACI matrix are BEST described as those who:
- Are consulted before decisions are finalized
- Approve all major IT investment decisions
- Perform the hands-on technical work
- Receive updates on decisions and outcomes but do not participate in making them (Correct answer)
Correct answer: Receive updates on decisions and outcomes but do not participate in making them
Informed stakeholders are kept in the loop about outcomes and decisions but are not part of the decision-making or consultation process.
Question 73: Which IT governance body is MOST responsible for making IT portfolio investment decisions?
- IT Investment Committee or IT Steering Committee (Correct answer)
- The IT help desk leadership team
- Individual project managers
- External IT consultants
Correct answer: IT Investment Committee or IT Steering Committee
The IT Investment or Steering Committee provides governance-level oversight of IT investments, balancing risk, value, and strategic alignment across the portfolio.
Question 74: A governance 'architecture principle' MOST effectively guides IT decision-making by:
- Listing approved technology vendors for each IT category
- Setting maximum budget limits for IT investments
- Providing a stable rule that all IT decisions must respect regardless of project context (Correct answer)
- Documenting the preferences of individual IT project managers
Correct answer: Providing a stable rule that all IT decisions must respect regardless of project context
Architecture principles are enduring rules — like 'prefer reuse over rebuild' — that govern all IT decisions consistently, ensuring coherence across the enterprise.
Question 75: An organization's enterprise architecture lacks data architecture documentation. The MOST likely governance risk is:
- Failure to meet software delivery timelines
- Increased vendor negotiation complexity
- Data silos, inconsistent data quality, and poor decision-making across business units (Correct answer)
- Excessive IT infrastructure costs
Correct answer: Data silos, inconsistent data quality, and poor decision-making across business units
Without data architecture, organizations lack standards for how data is defined, stored, and shared, leading to silos and inconsistent data that undermines governance decisions.
Question 76: A benefit that reduces manual processing time by 30% is an example of:
- An intangible strategic benefit
- A tangible, measurable efficiency benefit (Correct answer)
- A vendor-reported performance gain
- A compliance-driven benefit
Correct answer: A tangible, measurable efficiency benefit
A 30% reduction in processing time is a concrete, quantifiable efficiency benefit that can be verified against baseline data.
Question 77: Which document BEST formalizes the expectations and responsibilities between an enterprise and an external IT service provider?
- Service Level Agreement (SLA) (Correct answer)
- IT strategic plan
- Risk register
- IT budget forecast
Correct answer: Service Level Agreement (SLA)
A Service Level Agreement formally defines performance expectations, responsibilities, and accountability measures between the enterprise and its IT service providers.
Question 78: In which of the following types of biases does the data collection itself interfere with the process it is measuring?
- Perception
- Interaction (Correct answer)
- Operational
- Nonresponse
Correct answer: Interaction
Explanation: <br> Interaction bias occurs when the process of data collection itself interferes with the process being measured. This interference can occur due to various factors, such as the presence of the data collectors influencing the behavior of the subjects or the environment, changes in conditions caused by the data collection process, or the data collection methods altering the natural state of the phenomenon being observed.
Question 79: The concept of 'IT assurance' BEST refers to:
- Automated monitoring of network uptime
- IT staff confidence in system performance
- Guarantees provided by IT vendors in service contracts
- Independent validation that IT controls are operating effectively and reliably (Correct answer)
Correct answer: Independent validation that IT controls are operating effectively and reliably
IT assurance is an independent evaluation that gives stakeholders confidence that IT controls are operating as intended and are reliable.
Question 80: Who holds ULTIMATE accountability for benefits realization in CGEIT governance?
- External auditor
- Project manager
- IT architect
- Business sponsor or executive owner (Correct answer)
Correct answer: Business sponsor or executive owner
The business sponsor or executive owner is ultimately accountable because they authorized the investment and are responsible for the business outcomes.
Question 81: A 'project portfolio' differs from a 'project' in that a portfolio:
- Comprises multiple projects managed collectively to optimize strategic value (Correct answer)
- Is a single large project broken into phases
- Contains only completed projects for historical reference
- Is managed by a single project manager
Correct answer: Comprises multiple projects managed collectively to optimize strategic value
A portfolio aggregates multiple projects and programs managed together so their combined investment delivers maximum strategic value.
Question 82: When realized benefits fall short of expectations, the BEST governance response is to:
- Conduct a root cause analysis and adjust the realization approach (Correct answer)
- Reduce the benefit targets retroactively
- Close the project and move to the next investment
- Transfer accountability to the IT department
Correct answer: Conduct a root cause analysis and adjust the realization approach
A root cause analysis identifies why benefits were not fully realized and informs corrective action to recover or adjust the approach.
Question 83: A 'RACI matrix' in IT governance is PRIMARILY used to:
- Clarify who is Responsible, Accountable, Consulted, and Informed for governance activities (Correct answer)
- Schedule IT maintenance windows
- Rank IT projects by return on investment
- Document the technical architecture of IT systems
Correct answer: Clarify who is Responsible, Accountable, Consulted, and Informed for governance activities
A RACI matrix defines roles and responsibilities for governance activities, preventing confusion about who makes decisions versus who provides input.
Question 84: Which document is the PRIMARY reference point for assessing whether IT benefits have been achieved?
- Original approved business case (Correct answer)
- IT budget variance report
- Project status reports
- Vendor service level agreement
Correct answer: Original approved business case
The original approved business case contains the benefit commitments against which actual outcomes are measured.
Question 85: A business has outsourced IT operations to several third-party providers, but service level agreements (SLAs) are not clearly defined in all cases. Which of the following is the GREATEST risk to the business?
- Third parties could provide overlapping services.
- The scope of work is not clearly defined.
- Costs are not measurable.
- Quality of services is not enforceable. (Correct answer)
Correct answer: Quality of services is not enforceable.
Explanation: <br> Without clearly defined SLAs, the business lacks a formal agreement specifying the expected level of service quality, performance metrics, and remedies for failure to meet these standards. This ambiguity can lead to inconsistent service delivery, disputes over service quality, and difficulties in holding the third-party providers accountable.
Question 86: Which outcome BEST indicates that an organization's IT governance communication is effective?
- Stakeholders make timely, informed IT-related decisions aligned with business strategy (Correct answer)
- Vendor satisfaction scores improve
- Governance meetings end ahead of schedule
- The IT department produces more governance reports
Correct answer: Stakeholders make timely, informed IT-related decisions aligned with business strategy
Effective governance communication is evidenced by stakeholders being able to make timely, strategy-aligned IT decisions using the information they receive.
Question 87: The MAIN benefit of an IT portfolio 'heat map' showing risk versus return is that it:
- Measures employee satisfaction with IT services
- Calculates the exact financial return of each IT investment
- Enables governance bodies to visually identify investments to prioritize, monitor, or exit (Correct answer)
- Documents technical specifications for all IT projects
Correct answer: Enables governance bodies to visually identify investments to prioritize, monitor, or exit
A risk-return heat map gives governance a visual tool to quickly assess which investments warrant more attention, accelerated pursuit, or discontinuation.
Question 88: An enterprise has decided to use third-party software for a business process which is hosted and supported by the same third party. The BEST way to provide quality of service oversight would be to establish a process:
- to qualify service providers. (Correct answer)
- for enterprise architecture updates.
- for robust change management.
- for periodic service provider audits.
Correct answer: to qualify service providers.
Explanation: <br> Qualifying service providers involves establishing criteria for selecting third-party vendors based on their capabilities, reputation, and ability to meet the enterprise's service requirements. By thoroughly vetting and qualifying service providers before engaging with them, the enterprise can ensure that they are capable of delivering high-quality services and support. This process helps mitigate risks associated with relying on third-party software and ensures that the enterprise selects a provider who can uphold the desired level of service quality.
Question 89: An IT governance scorecard shows strong financial performance but declining stakeholder satisfaction. The governance board should PRIMARILY focus on:
- Replacing the stakeholder satisfaction measurement with a financial metric
- Reducing IT spending to improve stakeholder perceptions
- Continuing current practices since financial results are strong
- Investigating and addressing the root causes of stakeholder dissatisfaction (Correct answer)
Correct answer: Investigating and addressing the root causes of stakeholder dissatisfaction
Stakeholder dissatisfaction is a leading indicator of future governance failure — it must be investigated even when financial results are positive.
Question 90: Following a major IT incident that resulted in a loss to the enterprise, a CIO is preparing for a meeting with the board of directors to discuss what may have failed internally. Which of the following should the CIO do FIRST to provide assurance to the board?
- Ensure IT and enterprise risk management alignment. (Correct answer)
- Verify continuous monitoring is being performed.
- Review the incident response policy.
- Review the IT control environment.
Correct answer: Ensure IT and enterprise risk management alignment.
Explanation: <br> Ensuring alignment between IT and enterprise risk management is critical because it demonstrates that the organization's IT risks are being managed in line with broader enterprise risk management objectives. This includes assessing how the incident occurred in relation to overall risk management strategies, identifying any gaps or inconsistencies, and ensuring that future risk mitigation efforts are aligned with enterprise goals. By establishing this alignment, the CIO can provide the board with assurance that IT risks are being managed comprehensively and that measures are in place to prevent similar incidents from occurring in the future.
Question 91: Dis-benefits in IT investments refer to:
- Benefits that arrive later than planned
- Budget overruns caused by scope creep
- Negative consequences or costs resulting from an IT change (Correct answer)
- IT costs that exceed vendor estimates
Correct answer: Negative consequences or costs resulting from an IT change
Dis-benefits are unintended negative outcomes of an IT investment, such as increased workload or disruption, that must also be tracked in the benefits realization plan.
Question 92: An IT governance board reviews an enterprise architecture roadmap PRIMARILY to ensure it:
- Matches the architecture of industry competitors
- Uses the latest available technology in all areas
- Eliminates all legacy systems within one year
- Supports the organization's strategic direction and investment priorities (Correct answer)
Correct answer: Supports the organization's strategic direction and investment priorities
The governance board reviews the EA roadmap to confirm that planned IT changes align with and enable the organization's strategic priorities.
Question 93: What is the PRIMARY governance concern when an organization relies heavily on contractors for critical IT functions?
- Knowledge transfer gaps and the potential loss of critical institutional knowledge (Correct answer)
- The administrative burden of contractor onboarding processes
- Contractors' unfamiliarity with enterprise IT tools
- The cost premium of contractor rates compared to permanent staff
Correct answer: Knowledge transfer gaps and the potential loss of critical institutional knowledge
Heavy reliance on contractors for critical functions creates governance risk through knowledge concentration outside the organization, threatening capability retention.
Question 94: A 'run vs. grow vs. transform' investment categorization in IT portfolio management MOST helps to:
- Balance spending between maintaining operations, enhancing capabilities, and driving innovation (Correct answer)
- Track vendor contract renewal cycles
- Measure IT project manager performance
- Compare IT spending across different business units
Correct answer: Balance spending between maintaining operations, enhancing capabilities, and driving innovation
Categorizing investments as run, grow, or transform enables governance bodies to deliberately balance maintaining the business, growing it, and transforming it.
Question 95: Which statement BEST describes the relationship between IT governance and benefits realization?
- IT governance focuses only on technical delivery timelines
- IT governance eliminates the need for a formal benefits realization process
- IT governance creates the accountability structures that ensure benefits are planned, tracked, and achieved (Correct answer)
- Benefits realization is exclusively a finance function, separate from governance
Correct answer: IT governance creates the accountability structures that ensure benefits are planned, tracked, and achieved
IT governance provides the oversight, accountability, and decision-making structures that make benefits realization systematic and enforceable.
Question 96: IT value delivery governance MOST requires that business cases include:
- Clearly defined benefits, costs, risks, and success metrics before approval (Correct answer)
- Vendor qualifications and pricing comparisons
- Historical data from similar projects at competitor organizations
- Only technical specifications and delivery timelines
Correct answer: Clearly defined benefits, costs, risks, and success metrics before approval
A complete business case with benefits, costs, risks, and success metrics gives governance bodies the information needed to make informed investment decisions.
Question 97: Stakeholder resistance to IT governance initiatives MOST often stems from:
- Insufficient IT budget allocation
- Overly complex technology selections
- Lack of clear communication about the purpose and benefits of governance (Correct answer)
- Inadequate vendor support contracts
Correct answer: Lack of clear communication about the purpose and benefits of governance
When stakeholders don't understand why governance exists or how it benefits them, resistance is a natural response to perceived bureaucracy.
Question 98: A 'leading indicator' in IT governance performance measurement BEST helps to:
- Compare actual costs to vendor quotes
- Audit completed IT projects for compliance
- Predict future governance outcomes so corrective action can be taken proactively (Correct answer)
- Report historical IT spending trends
Correct answer: Predict future governance outcomes so corrective action can be taken proactively
Leading indicators signal future performance, allowing governance bodies to intervene before problems fully materialize.
Question 99: A 'current state architecture' assessment in CGEIT PRIMARILY helps governance to:
- Negotiate better vendor pricing
- Create a new organizational chart for the IT department
- Document all open IT incidents
- Understand existing IT capabilities and identify gaps relative to strategic needs (Correct answer)
Correct answer: Understand existing IT capabilities and identify gaps relative to strategic needs
Current state assessment gives governance a clear picture of what IT capabilities exist today so gaps against future strategic needs can be identified and planned for.
Question 100: A newly established IT steering committee is concerned whether or not a system is meeting availability objectives. Which of the following will provide the BEST information to make an assessment?
- Performance indicators
- Critical success factors
- Balanced scorecard
- Capability maturity levels (Correct answer)
Correct answer: Capability maturity levels
Explanation: <br> Capability maturity levels, such as those defined in models like CMMI (Capability Maturity Model Integration), assess the maturity and effectiveness of an organization's processes, including those related to system availability. By evaluating the maturity level of processes related to system availability management, the IT steering committee can gain insights into how well the organization's practices align with best practices and standards. This assessment helps in understanding the organization's capability to consistently meet availability objectives over time.
Question 101: When evaluating IT vendor performance, which governance principle should guide the assessment process?
- Performance evaluation should focus solely on cost containment
- Vendor performance should be continuously measured against agreed SLAs and business outcomes (Correct answer)
- Vendors should be assessed only at contract renewal time
- Assessments should be delegated entirely to the procurement department
Correct answer: Vendor performance should be continuously measured against agreed SLAs and business outcomes
Continuous performance measurement against SLAs and business outcomes ensures vendors contribute to governance objectives and enables timely corrective action.
Question 102: Which role is MOST responsible for ensuring IT governance compliance with regulatory requirements?
- Chief Information Officer (CIO) and senior IT governance leadership (Correct answer)
- Network operations center staff
- Individual IT developers
- External auditors who conduct annual reviews
Correct answer: Chief Information Officer (CIO) and senior IT governance leadership
The CIO and senior IT governance leadership are accountable for ensuring IT practices meet regulatory requirements — they cannot delegate that accountability.
Question 103: A governance committee discovers that 40% of the IT portfolio is unaligned with current business strategy. The BEST immediate action is to:
- Conduct a strategic portfolio review and realign or exit misaligned investments (Correct answer)
- Continue all investments since they are already funded
- Transfer the misaligned investments to a separate budget
- Hire additional IT staff to accelerate all existing projects
Correct answer: Conduct a strategic portfolio review and realign or exit misaligned investments
A strategic portfolio review is required to assess each misaligned investment and decide whether to re-align, deprioritize, or exit, freeing resources for strategic work.
Question 104: In CGEIT, the MAIN reason IT governance requires an enterprise architecture capability is to:
- Select the cheapest available technology solutions
- Outsource architecture design to external consultants
- Reduce the authority of IT leadership in business decisions
- Ensure IT decisions are made with a complete, integrated view of the organization (Correct answer)
Correct answer: Ensure IT decisions are made with a complete, integrated view of the organization
EA gives governance bodies the holistic view of IT and business connections needed to make well-informed, integrated decisions rather than siloed ones.
Question 105: Which of the following should be the PRIMARY consideration for an enterprise when prioritizing IT projects?
- Process owner expectations based on operational benefits
- Impact on the business due to expected project outcomes (Correct answer)
- Results of IT performance benchmarks against competitors
- Technical capability of the enterprise to execute the projects
Correct answer: Impact on the business due to expected project outcomes
Explanation: <br> This choice emphasizes the importance of aligning IT projects with business objectives and ensuring that the expected outcomes contribute significantly to business goals and priorities. While all options are relevant factors in project prioritization, the impact on the business is typically the most critical factor as it directly ties project investments to business value and strategic objectives.
Question 106: The BEST way for a CIO to monitor the alignment between the business and IT strategy is to regularly review:
- IT services supporting business processes. (Correct answer)
- the risk register.
- the balanced scorecard.
- key risk indicators (KRIs).
Correct answer: IT services supporting business processes.
Explanation: <br> Regularly reviewing IT services that support business processes allows the CIO to directly assess how well IT operations and services are aligned with the needs and objectives of the business. This includes evaluating whether IT services are effectively enabling and enhancing business processes, contributing to operational efficiency, and supporting strategic goals. By monitoring this alignment, the CIO can identify areas where IT services may need to be adjusted or improved to better align with evolving business priorities.
Question 107: A Balanced Scorecard in IT governance PRIMARILY measures performance across which four perspectives?
- Financial, Customer, Internal Process, and Learning & Growth (Correct answer)
- Risk, Compliance, Strategy, and Operations
- Infrastructure, Applications, Data, and Security
- Budget, Schedule, Scope, and Quality
Correct answer: Financial, Customer, Internal Process, and Learning & Growth
The Balanced Scorecard measures IT governance performance across financial, customer, internal process, and learning & growth perspectives to provide a holistic view.
Question 108: An organization supports both programs and projects for various industries. What is a portfolio?
- A portfolio describes the organization of related projects, programs, and operations. (Correct answer)
- A portfolio is the total amount of funds that have been invested in programs, projects, and operations.
- A portfolio describes all of the monies that are invested in the organization.
- A portfolio describes any project or program within one industry or application area.
Correct answer: A portfolio describes the organization of related projects, programs, and operations.
Explanation: <br> In the context of project management and organizational management, a portfolio refers to a collection or grouping of related projects, programs, and operations that are managed as a group to achieve strategic objectives. A portfolio allows organizations to manage resources, risks, and priorities across a set of projects and programs to maximize benefits and achieve organizational goals.
Question 109: When balancing an IT investment portfolio, a governance board should PRIMARILY consider:
- Vendor market share and analyst rankings
- Historical IT project success rates only
- Individual project manager experience levels
- Strategic alignment, risk profile, expected return, and resource availability (Correct answer)
Correct answer: Strategic alignment, risk profile, expected return, and resource availability
Portfolio balance requires evaluating each investment's strategic fit, risk, expected return, and feasibility given available resources to optimize the total mix.
Question 110: Which metric BEST demonstrates that IT benefits have been realized?
- Completion of all project milestones on time
- Reduction in the number of help desk tickets
- Increase in the IT department headcount
- Improvement in a KPI directly linked to the business case (Correct answer)
Correct answer: Improvement in a KPI directly linked to the business case
A KPI directly tied to the original business case provides direct evidence that the promised benefit has materialized.
Question 111: Which stakeholder mapping technique categorizes stakeholders by their level of power and interest?
- SWOT Analysis
- Power-Interest Grid (Correct answer)
- Balanced Scorecard
- RACI Matrix
Correct answer: Power-Interest Grid
The Power-Interest Grid maps stakeholders into quadrants based on their influence and interest level, guiding how much engagement effort to invest in each group.
Question 112: In CGEIT, 'governance effectiveness' is BEST measured by assessing:
- The number of IT governance policies in place
- The ratio of IT staff to business users
- The speed at which IT incidents are resolved
- The degree to which IT outcomes align with defined business objectives (Correct answer)
Correct answer: The degree to which IT outcomes align with defined business objectives
Governance effectiveness is measured by outcomes — specifically whether IT results consistently align with and advance business objectives.
Question 113: Benefits realization is MOST closely aligned with which CGEIT domain?
- IT Governance Framework
- IT Risk Optimization
- IT Value Delivery (Correct answer)
- IT Resource Optimization
Correct answer: IT Value Delivery
IT Value Delivery is the domain focused on ensuring that IT investments produce the intended benefits and business value.
Question 114: A CGEIT practitioner discovers that IT governance decisions are not being cascaded to operational teams. The BEST corrective action is to:
- Increase the number of governance committee meetings
- Establish a structured communication cascade from governance bodies to operational levels (Correct answer)
- Restrict governance information to committee members only
- Outsource governance communication to a vendor
Correct answer: Establish a structured communication cascade from governance bodies to operational levels
A communication cascade ensures governance decisions are translated and communicated down to the operational teams who must act on them.
Question 115: An IT governance assurance review MOST commonly results in:
- Transfer of control ownership to the audit committee
- A report rating control effectiveness and recommending improvements (Correct answer)
- An immediate system shutdown if any gaps are found
- Suspension of all IT projects during the review period
Correct answer: A report rating control effectiveness and recommending improvements
Assurance reviews produce a rated assessment of how well controls are operating and prioritized recommendations for strengthening governance.
Question 116: An enterprise's board of directors can BEST manage enterprise risk by:
- ensuring the cost-effectiveness of the internal control system.
- requiring the establishment of an enterprise risk management (ERM) framework. (Correct answer)
- mandating board-approved enterprise risk management (ERM) modifications.
- requiring the establishment of an enterprise-wide program management office.
Correct answer: requiring the establishment of an enterprise risk management (ERM) framework.
Explanation: <br> Establishing an enterprise risk management (ERM) framework enables the board of directors to systematically identify, assess, manage, and monitor risks across the organization. This approach helps in aligning risk management practices with strategic objectives and ensures comprehensive oversight of risks affecting the enterprise.
Question 117: Which of the following BEST describes the purpose of an IT resource portfolio in enterprise governance?
- To track individual employee performance metrics
- To maintain a list of all IT vendors under contract
- To provide a consolidated view of IT resources enabling prioritization and value optimization decisions (Correct answer)
- To document the technical specifications of infrastructure components
Correct answer: To provide a consolidated view of IT resources enabling prioritization and value optimization decisions
An IT resource portfolio provides governance leaders with a consolidated view to make informed prioritization and value-optimization decisions across the enterprise.
Question 118: The 'demand management' function in IT portfolio governance PRIMARILY manages:
- Vendor service request queues
- The intake and prioritization of IT investment requests against strategic criteria (Correct answer)
- IT employee workload assignments
- Server capacity planning for peak business periods
Correct answer: The intake and prioritization of IT investment requests against strategic criteria
Demand management governs how IT investment requests are received, evaluated, and prioritized to ensure resources are applied to the highest-value work.
Question 119: An IT Governance Maturity Model (such as COBIT's PAM) rates governance processes on a scale that MOST commonly ranges from:
- 1 (Low) to 10 (High)
- D (Failing) to A+ (Excellent)
- Basic to Advanced to Expert
- 0 (Incomplete) to 5 (Optimizing) (Correct answer)
Correct answer: 0 (Incomplete) to 5 (Optimizing)
COBIT's Process Assessment Model and similar frameworks rate governance maturity from 0 (incomplete/ad hoc) to 5 (continuously optimizing).
Question 120: A benefits realization plan PRIMARILY ensures that:
- IT investments deliver intended business value over time (Correct answer)
- Vendor contracts are renegotiated annually
- IT budgets remain under projected costs
- Technology upgrades are completed on schedule
Correct answer: IT investments deliver intended business value over time
A benefits realization plan tracks whether IT investments produce the intended business value throughout and after implementation.
Question 121: An enterprise is implementing an IT governance framework and wants to ensure IT resource decisions support business continuity. The BEST approach is to:
- Classify IT resources by business criticality and allocate resources proportional to risk and impact (Correct answer)
- Establish a separate governance committee solely for business continuity
- Build redundant IT infrastructure for all systems regardless of criticality
- Defer all continuity decisions to the IT operations team
Correct answer: Classify IT resources by business criticality and allocate resources proportional to risk and impact
Classifying IT resources by business criticality and aligning resource allocation to risk and impact ensures continuity investments are proportionate and strategically sound.
Question 122: Which component of IT resource management MOST influences an organization's ability to sustain IT capabilities over the long term?
- Knowledge management and institutional IT expertise retention (Correct answer)
- Number of active IT projects at any given time
- Short-term vendor pricing agreements
- Frequency of IT infrastructure refresh cycles
Correct answer: Knowledge management and institutional IT expertise retention
Retaining and managing institutional IT knowledge ensures that critical capabilities are sustained even as staff turnover or technology evolves.
Question 123: In IT resource governance, a skills gap analysis is PRIMARILY used to:
- Identify differences between current IT competencies and those required to meet strategic objectives (Correct answer)
- Determine compensation benchmarks for IT roles
- Justify reducing the IT workforce
- Rank IT employees for performance review purposes
Correct answer: Identify differences between current IT competencies and those required to meet strategic objectives
A skills gap analysis identifies discrepancies between existing capabilities and those needed to meet strategic objectives, informing training and hiring decisions.
Question 124: A large enterprise has been experiencing a high turnover of skilled IT personnel, resulting in a significant loss of knowledge within the IT department. Which of the following should be done FIRST to address this problem?
- Develop an incentive scheme for IT employees.
- Revise the IT resource management plan.
- Update human resources policies and practices.
- Conduct a survey of current IT staff. (Correct answer)
Correct answer: Conduct a survey of current IT staff.
Explanation: <br> Conducting a survey of current IT staff will help gather insights into the reasons for turnover, understand their concerns, and identify areas where improvements are needed. This step is crucial for diagnosing the root causes of the turnover problem and informing subsequent actions effectively.
Question 125: Which technique BEST helps an organization prioritize IT investments based on expected benefits?
- Technology trend benchmarking against competitors
- Business case analysis with weighted benefit scoring (Correct answer)
- Lowest total cost of ownership comparison
- First-come, first-served project intake
Correct answer: Business case analysis with weighted benefit scoring
Business case analysis with weighted benefit scoring objectively compares investments based on their expected contribution to strategic goals.
Question 126: In a successful enterprise that is profitable in its marketplace and consistently growing in size, the non-IT workforce has grown by 50% in the last two years. The demand for IT staff in the marketplace is more than the supply, and the enterprise is losing staff to rival organizations. Due to the rapid growth, IT has struggled to keep up with the enterprise, and IT procedures and associated job roles are not well-defined. The MOST critical activity for reducing the impact caused by IT staff turnover is to:
- document processes and procedures. (Correct answer)
- hire temporary staff.
- outsource the IT operation.
- increase compensation for IT staff.
Correct answer: document processes and procedures.
Explanation: <br> Documenting processes and procedures is crucial because it ensures that knowledge is captured and transferred effectively within the IT department. This documentation helps new hires understand their roles, responsibilities, and how tasks should be performed, thereby reducing the learning curve and minimizing the disruption caused by turnover.
Question 127: An organization's IT governance framework should treat compliance MOST appropriately as:
- A task solely delegated to the legal department
- An obstacle that limits IT innovation
- A minimum baseline, with governance aiming to deliver additional value beyond compliance (Correct answer)
- The ultimate goal of IT governance efforts
Correct answer: A minimum baseline, with governance aiming to deliver additional value beyond compliance
Compliance represents the floor, not the ceiling — good IT governance meets compliance requirements while also driving value creation and strategic alignment.
Question 128: Which IT governance mechanism BEST prevents individual business units from making uncoordinated IT investments?
- Giving each business unit its own IT budget and approval authority
- Delegating all IT spending decisions to external auditors
- A centralized IT investment governance process with mandatory portfolio review (Correct answer)
- Requiring all IT projects to use the same software vendor
Correct answer: A centralized IT investment governance process with mandatory portfolio review
Centralized portfolio governance with mandatory review prevents duplicative, misaligned investments by coordinating IT spending across the enterprise.
Question 129: The PRIMARY measure of IT value delivery in a governance context is:
- The reduction in IT department headcount over time
- The extent to which IT investments achieve their intended business outcomes (Correct answer)
- The number of new technologies adopted in a fiscal year
- The percentage of IT projects completed on schedule
Correct answer: The extent to which IT investments achieve their intended business outcomes
Value delivery is measured by whether IT investments actually produce the business outcomes they were intended to enable — not by project metrics or technology adoption.
Question 130: A newly appointed CIO has issued a new IT strategic plan. Which of the following would be the MOST effective way for the CIO to ensure the IT management team is held accountable for the delivery of the plan?
- Revise the managers' performance goals to include key objectives. (Correct answer)
- Provide management training on IT strategic objectives.
- Enforce disciplinary action for managers if the plan is not delivered.
- Update the IT balanced scorecard with key objectives.
Correct answer: Revise the managers' performance goals to include key objectives.
Explanation: <br> By revising the managers' performance goals to include key objectives from the IT strategic plan, the CIO directly ties individual accountability to the achievement of strategic goals. This approach aligns the efforts of the IT management team with the overarching strategic direction of the organization, making it clear what is expected from each manager in terms of delivering specific outcomes outlined in the plan. It provides a structured framework for measuring performance and progress towards strategic objectives.
Question 131: An IT investment delivers on time and on budget but the business reports no improvement in outcomes. From a governance perspective, this investment was:
- Partially successful and should be considered adequate
- A vendor failure that should trigger contract penalties
- Unsuccessful, because value delivery — not project metrics — is the ultimate measure (Correct answer)
- Successful, because it met all project management criteria
Correct answer: Unsuccessful, because value delivery — not project metrics — is the ultimate measure
IT governance defines success by business outcomes, not project delivery metrics — an on-time, on-budget project that delivers no business value has failed its governance purpose.
Question 132: A Key Performance Indicator (KPI) in IT governance MUST be:
- Focused exclusively on IT cost reduction
- Specific, measurable, and directly linked to a governance objective (Correct answer)
- Easy to collect from any existing IT system
- Set by IT staff without business input
Correct answer: Specific, measurable, and directly linked to a governance objective
A valid KPI must be specific and measurable, and it must connect directly to a governance objective so it reflects meaningful progress.
Question 133: While assessing the feasibility of introducing new IT practices and standards into the IT governance framework, it is CRITICAL to understand an organization's:
- enterprise architecture. (Correct answer)
- level of outsourcing.
- culture.
- maturity of IT processes.
Correct answer: enterprise architecture.
Explanation: <br> Understanding an organization's enterprise architecture is indeed crucial when assessing the feasibility of introducing new IT practices and standards. Enterprise architecture provides a structured approach to aligning IT capabilities with business goals and requirements. It includes aspects such as the current IT infrastructure, systems, applications, data flows, and integration points across the organization. This understanding helps in evaluating how new IT practices and standards can be integrated into the existing architecture, identifying potential impacts, dependencies, and areas needing adaptation or enhancement.
Question 134: IT governance performance measurement MOST supports which COBIT principle?
- Standardizing all IT procurement processes
- Centralizing IT decision-making authority
- Separating IT management from business operations
- Meeting stakeholder needs through the delivery of measurable value (Correct answer)
Correct answer: Meeting stakeholder needs through the delivery of measurable value
COBIT's core principle of meeting stakeholder needs is directly supported by performance measurement, which verifies that IT is delivering the value stakeholders require.
Question 135: In IT governance, 'compliance' PRIMARILY refers to:
- Achieving the lowest possible IT operational cost
- Adherence to laws, regulations, standards, and internal policies applicable to IT (Correct answer)
- Maintaining uptime above a defined threshold
- Completing all IT projects on schedule
Correct answer: Adherence to laws, regulations, standards, and internal policies applicable to IT
IT compliance means conforming to the external regulatory requirements and internal policies that govern how IT systems and data must be managed.
Question 136: Which scenario BEST illustrates IT governance performance measurement working as intended?
- Annual financial reports show IT costs are within budget
- The IT department self-reports excellent performance with no independent verification
- A KPI trend showing declining customer satisfaction triggers a governance review that leads to a corrective action plan (Correct answer)
- All KPIs are green so the governance committee cancels its quarterly meeting
Correct answer: A KPI trend showing declining customer satisfaction triggers a governance review that leads to a corrective action plan
When a declining KPI triggers a structured governance review and corrective action, measurement is fulfilling its purpose of enabling proactive governance.
Question 137: Which control type BEST prevents unauthorized access to sensitive IT systems in a compliance context?
- Compensating control (e.g., manual approval process)
- Corrective control (e.g., incident response plan)
- Preventive control (e.g., role-based access control) (Correct answer)
- Detective control (e.g., access log review)
Correct answer: Preventive control (e.g., role-based access control)
Preventive controls like role-based access control stop unauthorized access from occurring in the first place, which is the most effective compliance posture.
Question 138: An organization measures IT governance effectiveness solely through financial metrics. The PRIMARY risk is:
- Producing reports that are too complex for executives
- Aligning too closely with external audit requirements
- Overspending on IT governance reporting tools
- Missing critical performance dimensions such as risk, customer value, and organizational learning (Correct answer)
Correct answer: Missing critical performance dimensions such as risk, customer value, and organizational learning
Financial-only metrics create blind spots in governance effectiveness because they ignore risk exposure, stakeholder value, and capability development dimensions.
Question 139: Which practice BEST supports IT resource capacity management within a governance structure?
- Delegating capacity decisions entirely to operational IT staff
- Purchasing maximum available capacity to avoid shortfalls
- Demand forecasting tied to business strategy and workload projections (Correct answer)
- Reactive procurement based on immediate operational needs
Correct answer: Demand forecasting tied to business strategy and workload projections
Demand forecasting linked to business strategy enables proactive and cost-effective capacity management aligned with governance principles.
Question 140: Which enterprise architecture domain governs the technical infrastructure that supports IT applications?
- Data Architecture
- Application Architecture
- Technology Architecture (Correct answer)
- Business Architecture
Correct answer: Technology Architecture
Technology Architecture covers the hardware, network, and infrastructure components that host and support business applications.
Question 141: An IT governance framework requires that IT infrastructure investments be prioritized based on:
- Business impact, risk exposure, and alignment with strategic objectives (Correct answer)
- Vendor discount levels and contractual incentives
- The preference of the CIO and IT architecture team
- Technical complexity and novelty of the technology
Correct answer: Business impact, risk exposure, and alignment with strategic objectives
Infrastructure investments should be prioritized based on their business impact, risk profile, and strategic alignment to ensure optimal resource allocation.
Question 142: Which layer of enterprise architecture DIRECTLY governs how business processes are structured and documented?
- Application Architecture
- Technology Architecture
- Business Architecture (Correct answer)
- Data Architecture
Correct answer: Business Architecture
Business Architecture maps business processes, capabilities, and value streams, directly governing how work is structured and connected to IT enablement.
Question 143: IT portfolio management in CGEIT PRIMARILY ensures that:
- IT spending is distributed equally across business units
- The collective set of IT investments optimally supports business strategy (Correct answer)
- Only proven technologies are included in IT investments
- All IT projects are delivered on time and within scope
Correct answer: The collective set of IT investments optimally supports business strategy
IT portfolio management takes a holistic view of all IT investments to ensure they collectively maximize strategic value rather than being managed in isolation.
Question 144: A 'compliance risk' in IT governance BEST refers to:
- The risk of choosing the wrong enterprise software platform
- The risk that IT projects will exceed their budgets
- The risk of failing to meet legal, regulatory, or policy obligations related to IT (Correct answer)
- The risk that IT staff will leave the organization
Correct answer: The risk of failing to meet legal, regulatory, or policy obligations related to IT
Compliance risk is the exposure to legal penalties, reputational harm, or operational disruption resulting from failure to meet applicable IT-related obligations.
Question 145: Which element is MOST important when designing a KPI for IT governance?
- Approval from the external IT auditor
- Alignment with the IT department's internal goals
- Selection of the most advanced data collection technology
- A clear baseline, target, and accountability owner (Correct answer)
Correct answer: A clear baseline, target, and accountability owner
A well-designed KPI needs a baseline to measure against, a target to aim for, and a named owner who is accountable for the result.
Question 146: When developing an IT sourcing strategy, a governance board should PRIMARILY consider:
- The preference of the IT department head
- The lowest available market price for IT services
- The strategic importance of capabilities and associated risks of each sourcing option (Correct answer)
- Current industry trends in IT outsourcing
Correct answer: The strategic importance of capabilities and associated risks of each sourcing option
Governance boards must evaluate strategic importance and risk of sourcing options to make decisions that support long-term enterprise objectives.
Question 147: In which of the following editions of COBIT was "Management Guidelines" added?
- The third edition
- The second edition (Correct answer)
- The first edition
- The fourth edition
Correct answer: The second edition
Explanation: <br> Management Guidelines were added in the second edition of COBIT (Control Objectives for Information and Related Technologies). This addition enhanced the framework by providing detailed guidance and management practices for implementing the control objectives outlined in COBIT.
Question 148: A continuous compliance monitoring program MOST benefits an organization by:
- Eliminating the need for annual external audits
- Detecting compliance gaps in real time rather than waiting for periodic audits (Correct answer)
- Reducing the number of IT controls required
- Automating all IT governance decision-making
Correct answer: Detecting compliance gaps in real time rather than waiting for periodic audits
Continuous monitoring provides real-time visibility into compliance status, enabling faster detection and remediation of gaps before they escalate.
Question 149: Which phase of the investment lifecycle is MOST critical for setting up successful benefits realization?
- Business case development and approval (Correct answer)
- Solution design and architecture
- Post-deployment support
- User acceptance testing
Correct answer: Business case development and approval
Benefits realization success depends on correctly defining and committing to expected outcomes during business case development before the investment begins.
Question 150: An organization's IT portfolio review reveals several projects with no defined success metrics. The FIRST corrective action should be:
- Transfer portfolio oversight to the finance department
- Increase project budgets to include a metrics workstream
- Cancel all projects lacking defined metrics immediately
- Establish benefit KPIs and assign benefits owners for each project (Correct answer)
Correct answer: Establish benefit KPIs and assign benefits owners for each project
Establishing KPIs and assigning benefits owners creates the accountability structure needed to track and realize benefits.
CGEIT - Certified in the Governance of Enterprise IT
The CGEIT certification, offered by ISACA, validates expertise in IT governance frameworks, risk optimization, benefits realization, and IT resource management for enterprise IT professionals.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds