CMA IT Environment and Governance 3 β Questions and Answers
Question 1: Which IT environment model uses a shared pool of configurable computing resources accessible over a network on demand?
- Distributed computing
- Cloud computing (Correct answer)
- Grid computing
- Peer-to-peer computing
Correct answer: Cloud computing
Cloud computing is defined by NIST as on-demand network access to a shared pool of configurable resources including servers, storage, and applications.
Question 2: A master architect must choose between a public, private, and hybrid cloud. For a financial institution requiring strict data sovereignty, which model is most appropriate?
- Public cloud only
- Private cloud or hybrid cloud with on-premises control (Correct answer)
- Community cloud shared with other financial institutions
- Multi-cloud with no private component
Correct answer: Private cloud or hybrid cloud with on-premises control
A private or hybrid cloud model gives financial institutions direct control over data residency, meeting regulatory data sovereignty requirements.
Question 3: In an IaaS (Infrastructure as a Service) model, which layer remains the customer's responsibility?
- Physical hardware maintenance
- Hypervisor management
- Operating system, middleware, and application stack (Correct answer)
- Network backbone infrastructure
Correct answer: Operating system, middleware, and application stack
In IaaS, the provider manages physical hardware and virtualization; the customer is responsible for OS, middleware, runtime, and applications.
Question 4: What is 'shadow IT' and why is it a governance concern?
- IT systems used only during night-time hours to reduce costs
- Technology deployed by business units without IT department approval or knowledge (Correct answer)
- A redundant IT environment used for disaster recovery
- IT resources allocated specifically to cybersecurity monitoring
Correct answer: Technology deployed by business units without IT department approval or knowledge
Shadow IT refers to systems deployed outside of IT governance, creating security, compliance, and integration risks unknown to the enterprise.
Question 5: Which metric best measures the effectiveness of an IT governance framework?
- Number of IT staff members
- Percentage of IT projects delivered on time
- Degree to which IT goals are aligned and measured against business outcomes (Correct answer)
- Total IT budget expenditure
Correct answer: Degree to which IT goals are aligned and measured against business outcomes
Effective IT governance is measured by how well IT outcomes align with and contribute to business objectives, not just operational efficiency.
Question 6: A master architect is evaluating a DevSecOps implementation. Which governance principle does this practice best embody?
- Separation of duties between development and security teams
- Integrating security controls into the development lifecycle from the start (Correct answer)
- Deferring security reviews until after deployment
- Outsourcing all security functions to a third party
Correct answer: Integrating security controls into the development lifecycle from the start
DevSecOps embeds security governance directly into CI/CD pipelines, making security a continuous, integrated activity rather than a post-development gate.
Question 7: Which of the following best describes the concept of 'zero trust' in IT environment governance?
- Trusting all users inside the corporate network perimeter
- Never trusting any user or device by default, requiring continuous verification (Correct answer)
- Eliminating all third-party vendor relationships
- Restricting IT governance to only the security team
Correct answer: Never trusting any user or device by default, requiring continuous verification
Zero trust architecture assumes no implicit trust based on network location and requires continuous verification of every user, device, and connection.
Which IT environment model uses a shared pool of configurable computing resources accessible over a network on demand?