← All CMA Flashcard Decks

IT Environment and Governance Flashcards

7 cards from real CMA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 IT Environment and Governance flashcards as text
  1. Which standard provides guidance specifically on information security management systems (ISMS) and is frequently referenced in IT governance frameworks?

    Answer: ISO/IEC 27001

    ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an ISMS, making it central to IT security governance.

  2. In a multi-cloud governance strategy, what is the primary challenge that a master architect must address?

    Answer: Maintaining consistent security policies, visibility, and compliance across heterogeneous cloud environments

    Multi-cloud governance requires a unified control plane for policy enforcement, monitoring, and compliance across providers with different APIs and security models.

  3. What role does enterprise architecture (EA) play in IT governance?

    Answer: EA provides the structured framework for making and documenting IT investment and design decisions within governance processes

    Enterprise architecture provides the structured models, principles, and roadmaps that inform and constrain IT governance decisions, linking strategy to implementation.

  4. A master architect is reviewing a proposed microservices platform. Which governance concern is most critical to address at the architecture level?

    Answer: Defining service ownership, API contracts, and data governance boundaries between services

    Microservices governance requires clear service ownership, versioned API contracts, and defined data boundaries to prevent coupling and maintain system integrity.

  5. What is the purpose of an IT compliance audit in the context of IT governance?

    Answer: To verify that IT controls and practices conform to applicable laws, regulations, and internal policies

    Compliance audits provide independent assurance that IT systems and processes adhere to regulatory requirements and internal governance policies.

  6. Which of the following represents a 'governance anti-pattern' in IT environments?

    Answer: Allowing each business unit to independently procure and manage its own IT systems without enterprise oversight

    Decentralized, ungoverned IT procurement creates inconsistency, security gaps, and redundancy—this is a textbook governance anti-pattern.

  7. A master architect is implementing a data governance program. Which component ensures data quality and trustworthiness across the enterprise?

    Answer: A data stewardship model with defined ownership, quality standards, and lineage tracking

    Data stewardship assigns accountability for data quality, ensures policies are enforced, and maintains lineage so stakeholders can trust the data they consume.

IT Environment and Governance Flashcards — CMA Study Cards with Answers