CGEIT IT Compliance and Assurance 1 — Questions and Answers
Question 1: In IT governance, 'compliance' PRIMARILY refers to:
- Adherence to laws, regulations, standards, and internal policies applicable to IT (Correct answer)
- Achieving the lowest possible IT operational cost
- Completing all IT projects on schedule
- Maintaining uptime above a defined threshold
Correct answer: Adherence to laws, regulations, standards, and internal policies applicable to IT
IT compliance means conforming to the external regulatory requirements and internal policies that govern how IT systems and data must be managed.
Question 2: Which US regulation MOST directly requires IT governance controls over financial reporting systems?
- Sarbanes-Oxley Act (SOX) (Correct answer)
- Health Insurance Portability and Accountability Act (HIPAA)
- General Data Protection Regulation (GDPR)
- Federal Information Security Management Act (FISMA)
Correct answer: Sarbanes-Oxley Act (SOX)
SOX Section 404 requires organizations to establish and certify internal controls over financial reporting, including IT systems that support those reports.
Question 3: An IT compliance audit PRIMARILY evaluates whether:
- IT controls and practices conform to required standards, regulations, or policies (Correct answer)
- IT projects are delivered on time and within budget
- IT vendors are meeting their contractual obligations
- IT staff have completed mandatory training
Correct answer: IT controls and practices conform to required standards, regulations, or policies
An IT compliance audit assesses whether the organization's IT controls and practices conform to the applicable legal, regulatory, and policy requirements.
Question 4: The concept of 'IT assurance' BEST refers to:
- Independent validation that IT controls are operating effectively and reliably (Correct answer)
- Guarantees provided by IT vendors in service contracts
- IT staff confidence in system performance
- Automated monitoring of network uptime
Correct answer: Independent validation that IT controls are operating effectively and reliably
IT assurance is an independent evaluation that gives stakeholders confidence that IT controls are operating as intended and are reliable.
Question 5: Which standard is MOST commonly used as a framework for IT controls assurance in US organizations?
- COBIT (Control Objectives for Information and Related Technologies) (Correct answer)
- ITIL (IT Infrastructure Library)
- TOGAF (The Open Group Architecture Framework)
- PMBOK (Project Management Body of Knowledge)
Correct answer: COBIT (Control Objectives for Information and Related Technologies)
COBIT is the primary globally recognized framework for IT governance and control objectives, widely used for assurance and compliance assessments in US organizations.
Question 6: A 'control deficiency' identified during an IT audit MOST requires:
- A documented remediation plan with assigned ownership and target dates (Correct answer)
- Immediate shutdown of the affected IT system
- Public disclosure to all stakeholders
- Transfer of responsibility to an external vendor
Correct answer: A documented remediation plan with assigned ownership and target dates
A control deficiency requires a remediation plan with clear ownership and deadlines so the gap in controls is systematically closed.
In IT governance, 'compliance' PRIMARILY refers to: