ISACA CGEIT Exam Prep
Certified in the Governance of Enterprise IT (Page 15 )

Updated On: 24-Aug-2026

IT has launched new portfolio management policies and processes to improve the alignment of IT projects with enterprise goals. The latest audit report indicates that no improvement has been made due to confusion in the decision-making process.
Which of the following is the BEST course of action for the CIO?

  1. Deliver prioritization and facilitation training.
  2. Implement a performance management framework.
  3. Create an IT portfolio management risk framework.
  4. Develop and communicate an accountability matrix.

Answer(s): D

Explanation:

The best course of action for the CIO is to develop and communicate an accountability matrix. An accountability matrix, also known as a responsibility assignment matrix, is a project management tool that defines the roles and responsibilities of different stakeholders in a project or process1 An accountability matrix can help to clarify who is responsible, accountable, consulted, and informed (RACI) for each task or deliverable, and avoid confusion and ambiguity in the decision-making process2 By developing and communicating an accountability matrix, the CIO can ensure that the IT portfolio management policies and processes are understood and followed by all the relevant parties, and that the IT projects are aligned with the enterprise goals. Reference: RACI Matrix: Responsibility Assignment Matrix Guide 20233, Responsibility assignment matrix -Wikipedia2, Accountability Matrix - Explained - The Business Professor, LLC1



Which of the following responsibilities should be retained within an enterprise when outsourcing a project management office (PMO) function?

  1. Selecting projects
  2. Managing projects
  3. Tracking project cost
  4. Defining project methodology

Answer(s): A

Explanation:

The responsibility that should be retained within an enterprise when outsourcing a project management office (PMO) function is selecting projects. This is because selecting projects is a strategic decision that involves aligning the project portfolio with the enterprise goals, vision, and mission. Selecting projects also requires understanding the business needs, priorities, and value proposition of each project, as well as the available resources, risks, and opportunities. These are aspects that the enterprise should have more knowledge and authority over than theoutsourced PMO provider. Outsourcing the project selection process may result in a loss of control, alignment, and accountability for the enterprise. Therefore, selecting projects is a responsibility that should be retained within an enterprise when outsourcing a PMO function.


Reference:

Build the Next Gen PMO by Outsourcing -Project Management Institute1, How to Outsource a PMO: Your Options and Which Will Suit Your Business -PM Majik2, What is an Outsourced PMO and How Does it Work? - PM Majik3



Which of the following should be the MOST important consideration when defining an information architecture?

  1. Frequency and quantity of information updates
  2. Information to justify business cases
  3. Incorporation of emerging technologies
  4. Access to and exchange of information

Answer(s): D

Explanation:

The most important consideration when defining an information architecture is access to and exchange of information. Information architecture (IA) is the process of guiding users through the site by organising and arranging all the relevant content in a clear, intuitive way1. The main purpose of IA is to help users find information and complete tasks2. To do this, IA needs to consider how users access and exchange information within the digital product or service, and how to make it easy, fast, and satisfying for them. Access to and exchange of information involves aspects such as:
Navigation systems: How users browse or move through information2. Navigation systems should be consistent, predictable, and visible, and should provide feedback and orientation cues to the users3.
Search systems: How users look for information2. Search systems should be accurate, relevant, and comprehensive, and should support different types of queries and filters4.
Labelling systems: How information is represented and classified2. Labelling systems should use clear, concise, and meaningful words that match the users’ expectations and vocabulary.
Information structure: How information is organised into categories, hierarchies, and relationships2. Information structure should reflect the users’ mental models and tasks, and should avoid unnecessary complexity or ambiguity.
By considering access to and exchange of information when defining an IA, the organization can ensure that the information assets are usable, findable, and accessible to the users, and that they support the user experience and the business goals. Reference:
Information Architecture Basics | Usability.gov1, What is information architecture? -UX Design Institute2, Navigation Design Basics: Tips & Best Practices -Adobe XD Ideas3, Search System Design: Best Practices & Tips-Adobe XD Ideas4, Labeling Systems: An Introduction to Information Architecture -Boxes …, Information Architecture 101: Techniques and Best Practices - Adobe …



Which of the following roles has PRIMARY accountability for the security related to data assets?

  1. Database administrator
  2. Data owner
  3. Data analyst
  4. Security architect

Answer(s): B

Explanation:

The role that has primary accountability for the security related to data assets is the data owner. A
data owner is a person who is generally in a senior company position, responsible for the categorization, protection, usage, and quality of one or more data sets1. The data owner must ensure that the information within their domain is correctly maintained across various platforms and business processes, and that it is secured from unauthorized access and misuse2. The data owner also has the authority to grant or revoke access rights to the data, and to define and enforce data security policies and standards3. Therefore, the data owner is the primary accountable role for the security related to data assets. Reference:
Data Owners vs. Data Stewards vs. Data Custodians - CPO Magazine2, CISSP domain 2: Asset security - Infosec Resources



Senior management is reviewing the results of a recent security incident with significant business impact.
Which of the following findings should be of GREATEST concern?

  1. Significant gaps are present m the incident documentation.
  2. The incident was not logged in the ticketing system.
  3. Response decisions were made without consulting the appropriate authority.
  4. Response efforts had to be outsourced due to insufficient internal resources.

Answer(s): C

Explanation:

The finding that should be of greatest concern to senior management is that response decisions were made without consulting the appropriate authority. This is because response decisions are critical actions that can affect the outcome and impact of a security incident, and they should be made by the designated authority who has the responsibility and accountability for the incident response. According to CISA, the Department of Justice, through the FBI and the NCIJTF, is thelead agency for threat response during a significant incident, with DHS’s investigative agencies—the Secret Service and ICE/HSI - playing a crucial role in criminal investigations1. If response decisions are made without consulting the appropriate authority, it may result in:
Legal or regulatory violations: The response actions may not comply with the applicable laws or regulations, such as data breach notification, evidence preservation, or privacy protection. This may expose the organization to legal or regulatory penalties, lawsuits, or reputational damage.
Ineffective or counterproductive actions: The response actions may not be aligned with the incident response plan, best practices, or standard operating procedures. This may cause more harm than good, such as escalating the incident, destroying evidence, or compromising recovery efforts.
Lack of coordination and communication: The response actions may not be coordinated or communicated with the relevant stakeholders, such as senior management, legal counsel, public relations, or external partners. This may lead to confusion, inconsistency, or mistrust among the parties involved in the incident response.
Therefore, senior management should be most concerned about the finding that response decisions were made without consulting the appropriate authority, and they should take corrective actions to prevent this from happening again in the future. Reference:
Cybersecurity Incident Response | CISA1



A large enterprise that is diversifying its business will be transitioning to a new software platform, which is expected to cause data changes.
Which of the following should be done FIRST when developing the related metadata management process?

  1. Require an update to enterprise data policies.
  2. Request an impact analysis.
  3. Review documented data interdependence.
  4. Validate against existing architecture.

Answer(s): B

Explanation:

The first thing that should be done when developing the metadata management process for the new software platform is to request an impact analysis. An impact analysis is a process of assessing the potential effects of a change on the existing system, processes, and stakeholders1. An impact analysis can help to identify the following aspects2:
The scope and objectives of the change: What are the expected benefits and outcomes of the new software platform? How does it align with the enterprise strategy and goals?
The current state and baseline: What are the existing data sources, formats, standards, and quality levels? How are they documented, stored, and accessed? Who are the data owners, stewards, and users?
The gaps and risks: What are the data changes that will occur due to the new software platform? How will they affect the data quality, security, privacy, and compliance? What are the potential challenges or issues that may arise during or after the transition?
The mitigation and contingency plans: How can the data changes be minimized or avoided? How can the data quality, security, privacy, and compliance be ensured or improved? What are the alternative solutions or fallback options in case of failure or disruption?
By requesting an impact analysis, the organization can gain a better understanding of the data environment and the implications of the new software platform. This can help to develop a metadata management process that is consistent, effective, and adaptable to the change. Reference:
Impact Analysis: A Key Aspect of Preventing Problems | Project …1, Impact Analysis: The Key to Successful Change Management2



An IT director has become aware that a certain subset of data collected lawfully can be used to generate additional revenue. However, this particular use of the data is outside the original intention.
What is the PRIMARY reason this situation should be escalated to the IT steering committee?

  1. Potential legal penalties
  2. Ethical concerns
  3. Regulatory requirements
  4. Data protection

Answer(s): B

Explanation:

The primary reason this situation should be escalated to the IT steering committee is B. Ethical concerns. This is because using data for a purpose that is outside the original intention may violate the principle of purpose limitation, which states that personal data should be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes1. Using data for a different purpose may also breach the trust and expectations of the individuals who provided the data, and may harm their rights and interests. Therefore, the IT director should consult the IT steering committee, which is a group of senior executives who are responsible for developing and enforcing the organization’s IT priorities and policies2, to determine whether the new use of data is ethical, lawful, and transparent. The IT steering committee should also consider the following aspects before making a decision:
The link between the original purpose and the new/upcoming purpose: How closely related are the two purposes? Is the new purpose compatible with the original purpose or does it contradict it?
The context in which the data was collected: What was the relationship between the organization and the individuals at the time of data collection? What did the individuals consent to or expect from the data processing?
The type and nature of the data: Is the data sensitive, personal, or confidential? Does it reveal any information about the individuals’ identity, preferences, behavior, or opinions?
The possible consequences of the intended further processing: How will the new use of data affect the individuals and the organization? Will it benefit or harm them? Will it create any risks or opportunities?
The existence of appropriate safeguards: What measures are in place to protect and manage the data according to the data protection principles and standards? How can the data quality, security, privacy, and compliance be ensured or improved?
By escalating this situation to the IT steering committee, the IT director can ensure that the ethical implications of using data for another purpose are properly assessed and addressed.



Of the following, who should approve the criteria for information quality within an enterprise?

  1. Information architect
  2. Information analyst
  3. Information steward
  4. Information owner

Answer(s): D

Explanation:

Information owners are responsible for defining the quality criteria for information within their domain, based on business requirements and stakeholder expectations. Information owners are also accountable for ensuring that information quality is maintained and improved. Reference := COBIT 5: Enabling Information, chapter 4, section 4.2.1



Viewing page 15 of 88
Viewing questions 113 - 120 out of 700 questions


Post your Comments and Discuss ISACA CGEIT exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!