Free CGEIT Exam Braindumps (page: 13)

Page 12 of 119

A business case indicates an enterprise would reduce costs by implementing a bring your own device (BYOD) program allowing employees to use personal devices for e-mail. Which of the following should be the FIRST governance action?

  1. Assess the enterprise architecture (EA).
  2. Update the BYOD policy.
  3. Update the network infrastructure.
  4. Assess the BYOD risk.

Answer(s): A



An enterprise has decided to implement an enterprise resource planning (ERP) system to achieve operating and cost efficiencies through global IT standardization. The business units are resistant because they are used to operating autonomously. The CEO has instructed the CIO to move quickly with the implementation to force acceptance with business unit leaders. Which of the following should be the CIO's FIRST step?

  1. Request funding from the CEO to hire ERP consultants.
  2. Ask the CEO to be the sponsor of the program.
  3. Engage a reluctant business unit to conduct a proof-of-concept pilot.
  4. Build a governance framework for identifying non-standard processes.

Answer(s): D



Which of the following is MOST critical to have in place before management can establish an IT risk assessment and response approach?

  1. A portfolio of IT investments
  2. Defined roles and responsibilities
  3. Historic data on risk events
  4. A balanced scorecard

Answer(s): B



An IT audit report indicates that a lack of IT employee risk awareness is creating serious security issues in application design and configuration. Which of the following would be the BEST key risk indicator (KRI) to show progress in IT employee behavior?

  1. Results of application security testing
  2. Results of application security awareness training quizzes
  3. Number of reported security incidents
  4. Number of IT employees attending security training sessions

Answer(s): C






Post your Comments and Discuss ISACA CGEIT exam with other Community members:

CGEIT Discussions & Posts