ISACA CGEIT Exam Prep
Certified in the Governance of Enterprise IT (Page 4 )

Updated On: 24-Aug-2026

The board of directors of an enterprise has approved a three-year IT strategic program to centralize the core business processes of its global entities into one core system.
Which of the following should be the ClO's NEXT step?

  1. Engage a team to perform a business impact analysis (BIA).
  2. Require the development of a risk management plan.
  3. Determine resource requirements for program implementation.
  4. Require the development of a program roadmap.

Answer(s): D

Explanation:

 A program roadmap is a strategic plan that outlines the vision, objectives, scope, deliverables, milestones, dependencies, risks, and benefits of a large-scale IT program. A program roadmap can help the CIO and other stakeholders to communicate, align, and monitor the progress and outcomes of the program. A program roadmap is essential for a complex and long-term IT program such as centralizing the core business processes of global entities into one core system. A program roadmap can help to ensure that the program is aligned with the IT strategy and the business goals, that the program has a clear and realistic scope and schedule, that the program has adequate resources and governance, and that the program delivers the expected value and benefits1234. Reference: How to Create an IT Strategy Roadmap. Definitive Guide to Developing an IT Strategy and Roadmap.
What is an IT Roadmap?. How To Develop a Strategy Roadmap in Six Steps.



Which of the following is the MOST important driver of IT governance?

  1. Effective internal controls
  2. Management transparency
  3. Quality measurement
  4. Technical excellence

Answer(s): B

Explanation:

 Management transparency is the most important driver of IT governance, because it enables the alignment of IT and business goals, the accountability of IT performance and value, the communication and collaboration among stakeholders, and the compliance with laws and regulations. Management transparency refers to the degree to which information about IT decisions, processes, outcomes, and risks is shared openly and honestly with relevant parties, such as the board of directors, senior management, business units, IT staff, customers, and regulators. Management transparency can help to build trust, confidence, and support for IT initiatives, as well as to identify and address any issues or gaps in IT governance12. Reference: What is IT governance? A formal way to align IT & business strategy. Definition of IT Governance (ITG) - IT Glossary | Gartner.



A global enterprise is experiencing an economic downturn and is rapidly losing market share. IT senior management is reassessing the core activities of the business, including IT, and the associated resource implications. Management has decided to focus on its local market and to close international operations. A critical issue from a resource management perspective is to retain the most capable staff. This is BEST achieved by:

  1. reviewing current goals-based performance appraisals across the enterprise.
  2. ranking employees across the enterprise based on their compensation.
  3. ranking employees across the enterprise based on length of service.
  4. retaining capable staff exclusively from the local market.

Answer(s): A

Explanation:

 Goals-based performance appraisals are a method of evaluating employees based on their achievement of specific and measurable objectives that are aligned with the organization’s strategy and vision. Goals-based performance appraisals can help to identify the most capable staff who have contributed to the organization’s success, demonstrated high performance and potential, and shown commitment and engagement. Reviewing current goals-based performance appraisals across the enterprise can help management to retain the most capable staff regardless of their location, compensation, or length of service12. Reference: Performance Appraisal Methods: Traditional and Modern Methods (with example). How to Conduct a Performance Appraisal.



An IT steering committee is presented with an audit finding that new software applications are delivered on time but consistently have unacceptable levels of defects.
Which of the following would be the BEST direction from the committee?

  1. Implement performance indicators.
  2. Evaluate the change management process.
  3. Establish code peer reviews.
  4. Evaluate the quality assurance process.

Answer(s): D

Explanation:

The quality assurance process is the set of activities that ensures that the software development process follows the defined standards and meets the customer requirements. The quality assurance process includes planning, designing, executing, and monitoring the tests, as well as reporting and resolving the defects. Evaluating the quality assurance process can help to identify and improve the root causes of software defects, such as inadequate testing techniques, tools, or resources, poor communication or collaboration among stakeholders, or lack of quality control or feedback mechanisms123. Reference: QA Process: A Complete Guide to QA Stages, Steps, & Tools.
What is Software Quality Assurance (SQA): A Guide for Beginners. Software Quality Assurance | Components | Standards | Techniques - EDUCBA.



A CIO is concerned with the potential of vendor system failures that could cause a large amount of unintended system downtime. To determine how to prepare for this concern, what is MOST important for the CIO to review?

  1. IT balanced scorecard
  2. Service-level metrics
  3. IT procurement policy
  4. Business impact analysis (BIA)

Answer(s): D

Explanation:

A business impact analysis (BIA) is a process of predicting the organizational and financial impact of business disruptions, such as vendor system failures. A BIA can help the CIO to prepare for this concern by identifying the critical business processes, the potential effects of disruption, and the recovery requirements and strategies. A BIA can also help the CIO to prioritize the resources and actions needed to restore the normal operations as quickly as possible1. A BIA is an essential component of business continuity planning (BCP) and disaster recovery planning (DRP)2.
An IT balanced scorecard is a tool that measures and monitors the performance of IT in relation to the strategic goals and objectives of the organization. An IT balanced scorecard can help the CIO to evaluate the effectiveness and efficiency of IT, but it does not address the impact of business disruptions or the recovery plans.
Service-level metrics are indicators that measure and report the quality and availability of IT services delivered to the customers or users. Service-level metrics can help the CIO to track and improve the service delivery, but they do not assess the impact of business disruptions or the recovery plans.
An IT procurement policy is a document that defines the rules and procedures for acquiring IT products and services from external vendors. An IT procurement policy can help the CIO to manage the vendor relationships, contracts, and risks, but it does not analyze the impact of business disruptions or the recovery plans. Reference: How To Conduct Business Impact Analysis in 8 Easy Steps. The Top 10 Vendor Risks & How to Manage Them.
What is FMEA? Failure Mode & Effects Analysis. Definition of Business Impact Analysis (BIA). [IT Balanced Scorecard: Definition, Frameworks, Examples]. [Service Level Metrics: Definition, Types, Examples]. [IT Procurement Policy: Definition, Components, Examples].



The BEST way to manage continuous improvement of governance-related processes is to:

  1. assess existing process resource capacities.
  2. define accountability based on roles and responsibilities.
  3. apply effective quality management practices.
  4. require third-party independent reviews.

Answer(s): C

Explanation:

 Quality management is the process of ensuring that the products and services delivered by an organization meet or exceed the expectations and requirements of the customers and stakeholders.
Quality management practices include planning, implementing, monitoring, and improving the quality standards and processes for an organization. Applying effective quality management practices can help to manage continuous improvement of governance-related processes, by ensuring that the processes are aligned with the organizational goals and objectives, that the processes are performed consistently and efficiently, that the processes are measured and evaluated for their effectiveness and value, and that the processes are continuously reviewed and enhanced for improvement123. Reference: What is Quality Management? Definition, Principles, Tools & Examples. Quality Management: The Importance of ISO. Continuous Improvement and a Business Process Governance Framework.



Which of the following would BEST enable business innovation through IT?

  1. Outsourcing of IT to a strategic business partner
  2. Business participation in IT strategy development
  3. Adoption of a standardized business development life cycle
  4. IT participation in business strategy development

Answer(s): D

Explanation:

Business innovation is the process of creating new or improved products, services, processes, or business models that create value for the organization and its customers. IT can enable business innovation by providing the tools, platforms, data, and capabilities that support the generation, implementation, and diffusion of innovative ideas. However, IT alone cannot drive business innovation; it requires a close collaboration and alignment between IT and business. Therefore, IT participation in business strategy development is the best way to enable business innovation through IT, because it can help to ensure that IT understands the business goals and needs, that IT contributes to the identification and evaluation of opportunities and challenges, that IT provides feasible and effective solutions and recommendations, and that IT supports the execution and monitoring of the innovation initiatives123. Reference: How to Drive Business Innovation Through IT. How to Enable Business Innovation with IT. Business Innovation: What It Is and How to Achieve It.



Acceptance of an enterprise's newly implemented IT governance initiatives has been resisted by a functional group requesting more autonomy over technology choices.
Which of the following is MOST important to accommodate this need for autonomy?

  1. Continuous improvement processes
  2. Documentation of key management practices
  3. An exception management process
  4. A change control process

Answer(s): C

Explanation:

An exception management process is a method for documenting and approving an exception to compliance with established IT governance policies, standards, and practices. An exception management process can accommodate the need for autonomy over technology choices by allowing a functional group to request and justify a deviation from the IT governance requirements, based on the business needs, risks, costs, and benefits. An exception management process can also help to ensure that the exceptions are reviewed and approved by the appropriate authorities, that the exceptions are monitored and reported, and that the exceptions are aligned with the IT strategy and objectives123. Reference: Exception Management Process Flow. IT/Information Security Exception Request Process. Strategies, Governance, Policies, Standards and Resources.



Viewing page 4 of 88
Viewing questions 25 - 32 out of 700 questions


Post your Comments and Discuss ISACA CGEIT exam prep with other Community members:

AI Tutor AI Tutor 👋 I’m here to help!