Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Isaca CGEIT Practice Exam with Questions & Answers | Set: 3

Questions 31

A CIO has recently been made aware of a new regulatory requirement that may affect IT-enabled business activities. Which of the following should be the CIO s FIRST step in deciding the appropriate response to the new requirement?

Options:
A.

Revise initiatives that are active to reflect the new requirements.

B.

Confirm there are adequate resources to mitigate compliance requirements.

C.

Consult with legal and risk experts to understand the requirements.

D.

Consult with the board for guidance on the new requirements

Isaca CGEIT Premium Access
Questions 32

IT governance within an enterprise is attempting to drive a cultural shift to enhance compliance with IT security policies. The BEST way to support this objective is to ensure that enterprise IT policies are:

Options:
A.

communicated on a regular basis.

B.

acknowledged and signed by each employee.

C.

centrally posted and contain detailed instructions.

D.

integrated into individual performance objectives.

Questions 33

Which of the following is the BEST indication of an effective information governance model?

Options:
A.

Senior management ensures quality goals are defined for information.

B.

The CIO defines information accountability, quality criteria, and criticality.

C.

Enterprise architects define information protection attributes.

D.

Process owners determine which information assets will be managed.

Questions 34

When identifying improvements focused on the information asset life cycle, which of the following is CRITICAL for enabling data interoperability?

Options:
A.

Standardization

B.

Replication

C.

Segregation

D.

Sanitization

Questions 35

Which of the following BEST enables an enterprise to minimize the risks of intellectual property theft and loss of sensitive information when acquiring Internet of Things (IoT) hardware and software components?

Options:
A.

Review the data classification policy and relevant documentation

B.

Terminate contracts with suppliers from sanctioned regions of the world

C.

Require nondisclosure agreements (NDAs) from all suppliers

D.

Integrate supply chain cyber risk management processes

Questions 36

Which of the following is the PRIMARY reason to monitor data classification efforts?

Options:
A.

To identify and minimize data security breaches

B.

To identify deviations in the data that are outside risk thresholds

C.

TO ensure alignment with data protection regulations

D.

To ensure assets are protected appropriately

Questions 37

An IT value delivery framework PRIMARILY helps an enterprise:

Options:
A.

Improve value of successful IT projects.

B.

Increase transparency of value to the enterprise.

C.

Assist top management in approving IT projects.

D.

Optimize value to the enterprise.

Questions 38

An enterprise’s IT director is concerned that the chair of the IT steering committee is stealing confidential company information. Which of the following is the IT director’s BEST course of action?

Options:
A.

File a report with the local law enforcement agency.

B.

Report the concern to the ethics hotline.

C.

Discuss the concern with the chair directly.

D.

Conduct an investigation to substantiate the chair’s activities.

Questions 39

An enterprise is considering outsourcing non-core IT processes. Which of the following should be the FIRST step?

Options:
A.

Update resource allocation policies.

B.

Issue a formal request for proposal (RFP) to outsourcing vendors.

C.

Establish service-level metrics for outsourced activities.

D.

Conduct a cost-benefit analysis for outsourcing.

Questions 40

Which of the following is the FIRST step when developing an IT risk management framework?

Options:
A.

Promoting a culture of risk awareness

B.

Establishing a risk control library

C.

Aligning to enterprise risk management (ERM)

D.

Establishing risk appetite

Questions 41

When selecting a cloud provider, which of the following provides the MOST comprehensive information regarding the current status and effectiveness of the provider's controls?

Options:
A.

Globally recognized certification

B.

Third-party audit report

C.

Control self-assessment (CSA)

D.

Maturity assessment

Questions 42

Which of the following BEST helps to ensure that IT policies are

aligned with organizational strategies?

Options:
A.

The policies are approved by the board of directors.

B.

The policies are developed using a top-down approach.

C.

The policies are updated annually.

D.

The policies are periodically audited.

Questions 43

Which of the following is the BEST way to address the risk associated with new IT investments?

Options:
A.

Develop security best practices to protect applications.

B.

Integrate security requirements at the beginning of projects

C.

Establish an enterprise-wide incident response process.

D.

Implement an enterprise-wide security awareness program.

Questions 44

A CEO realizes the need to implement IT governance to support the strategic alignment of business and IT goals. Which of the following would BEST enable this initiative?

Options:
A.

A RACI chart

B.

An increased IT budget

C.

Well-trained IT staff

D.

Effective culture change

Questions 45

An enterprise is concerned that ongoing maintenance costs are not being considered when prioritizing IT-enabled business investments. Which of the following should be the enterprise's FIRST course of action?

Options:
A.

Implement a balanced scorecard for the IT project portfolio.

B.

Establish a portfolio manager role to monitor and control the IT projects.

C.

Require business cases to have product life cycle information.

D.

Mandate an enterprise architecture (EA) review with business stakeholders.

Isaca Free Exams

Isaca Free Exams
Examstrack offers comprehensive free resources and practice tests for Isaca exams.