IT Environment and Governance Flashcards
7 cards from real CMA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 IT Environment and Governance flashcards as text
What is the primary purpose of a Configuration Management Database (CMDB) in IT governance?
Answer: Tracking IT assets and their relationships to support change and incident management
A CMDB maintains records of IT configuration items (CIs) and their interdependencies, enabling informed change management, impact analysis, and incident resolution.
An enterprise has multiple disparate legacy systems. Which architectural approach best supports IT governance by providing a unified integration layer?
Answer: Enterprise Service Bus (ESB) or API management platform
An ESB or API management platform centralizes integration, enabling governance of data flows, versioning, and access control across heterogeneous systems.
Under SOX (Sarbanes-Oxley) compliance, what must a master architect ensure regarding financial IT systems?
Answer: Adequate internal controls over financial reporting processes are designed and documented
SOX Section 404 requires organizations to document and test internal controls over financial reporting, which includes the IT systems that process financial data.
Which IT governance practice directly reduces the risk of a single point of failure in critical enterprise systems?
Answer: Implementing high-availability and redundancy architectures
High-availability designs with redundancy (clustering, failover, load balancing) eliminate single points of failure and improve system resilience.
A master architect is asked to define IT risk appetite for the organization. What does 'risk appetite' mean in this context?
Answer: The level of risk the organization is willing to accept in pursuit of its objectives
Risk appetite defines how much risk an organization is willing to accept before taking action, guiding investment in controls and risk treatment decisions.
What is the difference between IT risk management and IT risk governance?
Answer: Risk management is operational execution; risk governance sets policies, oversight, and accountability structures
IT risk governance establishes the policies, roles, and oversight structures, while IT risk management involves the day-to-day identification, assessment, and treatment of risks.
Which of the following is a best practice for managing technical debt within an IT governance framework?
Answer: Tracking, prioritizing, and scheduling remediation of technical debt as part of the architecture roadmap
Effective governance treats technical debt as a managed liability, tracked in the architecture backlog and addressed through scheduled remediation efforts.