Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free Isaca CGEIT Practice Exam with Questions & Answers | Set: 9

Questions 121

A business unit is planning to replace an existing IT legacy solution with a hosted Software as a Service (SaaS) solution. However, business management is concerned that stored data will be at risk. Which of the following is the MOST effective way to reduce the risk associated with the SaaS solution?

Options:
A.

Research the technology and identify potential security threats.

B.

Include risk-related requirements in the SaaS contract.

C.

Create key risk indicators (KRls) for the SaaS solution.

D.

Redefine the risk appetite and risk tolerance.

Isaca CGEIT Premium Access
Questions 122

When selecting a vendor to provide services associated with a critical application which of the following is the MOST important consideration with respect to business continuity planning (BCP)?

Options:
A.

Procuring a copy of the vendor's BCP during the contracting process

B.

Testing the vendor's BCP and analyzing the results

C.

Obtaining independent audit reports of the vendor's BCP

D.

Evaluating whether the vendor's BCP aligns with the enterprise's BCP

Questions 123

Due to the recent introduction of personal data protection regulations, an enterprise is required to maintain its employee data in production systems only for a limited time. Which of the following is MOST important to review?

Options:
A.

Asset retention policies

B.

Information retention policies

C.

Data archival policies

D.

Data backup and restoration policies

Questions 124

An enterprise is considering outsourcing non-core IT processes Which of the following should be the FIRST step?

Options:
A.

Update resource allocation policies

B.

Conduct a cost-benefit analysis for outsourcing.

C.

Issue a formal request for proposal to outsourcing vendors.

D.

Establish service level metrics for outsourced activities

Questions 125

Which of the following provides the MOST comprehensive insight into the effectiveness of IT?

Options:
A.

IT balanced scorecard

B.

IT strategy

C.

Return on investment (ROI)

D.

Key risk indicators (KRIs)

Questions 126

A multinational enterprise is planning to migrate to cloud-based systems. Which of the following should be of MOST concern to the risk management committee?

Options:
A.

Cost considerations

B.

Regulatory compliance

C.

Resource alignment

D.

Security breaches

Questions 127

An enterprise has identified potential environmental disasters that could occur in the area where its data center is located. Which of the following should be done NEXT?

Options:
A.

Implement an early warning detection and notification system.

B.

Assess the likelihood and impact on the data center.

C.

Relocate the data center to minimize the threat.

D.

Assess how the data center is protected against the threat.

Questions 128

Which of the following BEST supports the implementation of an effective data classification policy?

Options:
A.

Monitoring with key performance indicators (KPIs)

B.

Implementation of data loss prevention (DLP) tools

C.

Clear guidelines adopted by the business

D.

Classification policy approval by the board

Questions 129

When establishing an enterprise data model, the BEST way to ensure the integrity of data is to:

Options:
A.

classify information using an agreed-upon schema.

B.

implement the highest level of protection to data across the enterprise.

C.

establish a privileged access management platform.

D.

implement a data loss prevention (DLP) program.

Questions 130

After shifting from lease to purchase of IT infrastructure and software licenses, an enterprise has to pay for unexpected lease extensions causing significant cost overruns. The BEST direction for the IT steering committee would be to establish;

Options:
A.

an end-of-life program to remove aging infrastructure from the environment.

B.

budget cuts to compensate for the cost overruns.

C.

a program to annually review financial policy on overruns.

D.

a policy to consider total cost of ownership (TCO) in investment decisions.

Questions 131

An organization requires updates to their IT infrastructure to meet business needs. Which of the following will provide the MOST useful information when planning for the necessary IT investments?

Options:
A.

Enterprise architecture (EA)

B.

Risk assessment report

C.

Business user satisfaction metrics

D.

Audit findings

Questions 132

An enterprise is assessing whether to utilize wearable technology. The enterprise has no prior experience with this technology and has asked the chief technology officer (CTO) to assess the impact to the enterprise. The CTO should FIRST:

Options:
A.

understand the enterprise’s risk tolerance.

B.

create an IT risk scorecard.

C.

prioritize wearable technology risk.

Questions 133

Which of the following would BEST enable an enterprise to ensure selected cloud vendors meet stringent regulatory requirements?

Options:
A.

Stage gate reviews

B.

Risk assessment

C.

Internal audit report

D.

Third-party audit reports

Questions 134

An interna! health organization has been notified that a data breach has resulted in patient records being published online. Which of the

following is MOST important consideration when determining the process for meeting the organization's legal and regulatory obligations?

Options:
A.

Organizational structure, including accountable partes

B.

Data classification and related security policy

C.

Context of the breach, including data ownership and location

D.

Details of how the breach occurred and related incident response efforts

Questions 135

Which of the following is the PRIMARY role of the governance function in enabling an enterprise to achieve its business objectives?

Options:
A.

Determining risk thresholds that the enterprise can sustain

B.

Preparing business continuity and resiliency plans

C.

Providing a means to effectively manage stakeholders

D.

Monitoring strategic plans to reach the desired target state

Isaca Free Exams

Isaca Free Exams
Examstrack offers comprehensive free resources and practice tests for Isaca exams.