Free CGEIT Exam Braindumps (page: 19)

Page 18 of 119

Following a major IT incident that resulted in a loss to the enterprise, a CIO is preparing for a meeting with the board of directors to discuss what may have failed internally. Which of the following should the CIO do FIRST to provide assurance to the board?

  1. Review the IT control environment.
  2. Ensure IT and enterprise risk management alignment.
  3. Review the incident response policy.
  4. Verify continuous monitoring is being performed.

Answer(s): B



A newly appointed CIO has issued a new IT strategic plan. Which of the following would be the MOST
effective way for the CIO to ensure the IT management team is held accountable for the delivery of the plan?

  1. Provide management training on IT strategic objectives.
  2. Revise the managers' performance goals to include key objectives.
  3. Enforce disciplinary action for managers if the plan is not delivered.
  4. Update the IT balanced scorecard with key objectives.

Answer(s): B



Which of the following is the PRIMARY ongoing responsibility of the IT governance function related to risk?

  1. Responding to and controlling all IT risk events
  2. Verifying that all business units have staff skilled at assessing risk
  3. Communicating the enterprise risk management plan
  4. Ensuring IT risk management is aligned with business risk appetite

Answer(s): C



Which of the following is the BEST outcome measure to determine the effectiveness of IT risk management processes?

  1. Time lag between when IT risk is identified and the enterprise's response
  2. Percentage of business users satisfied with the quality of risk training
  3. Frequency of updates to the IT risk register
  4. Number of events impacting business processes due to delays in responding to risks

Answer(s): A






Post your Comments and Discuss ISACA CGEIT exam with other Community members:

CGEIT Discussions & Posts