Free CGEIT Exam Braindumps (page: 56)

Page 55 of 119

An IT strategy committee has reviewed an audit report indicating sales employees are using personal smartphones to conduct corporate business. Although the committee appreciates the business benefits, it is also concerned with the security risk. To deliver the business benefit, the committee’s FIRST recommendation should be to:

  1. update the corporate security policy to include personal devices.
  2. document procedures for securing personal devices.
  3. improve training courses on securing corporate information.
  4. perform a risk assessment on personal device data protection.

Answer(s): D



Which of the following is the BEST way to implement effective IT risk management?

  1. Minimize the number of IT risk management decision points.
  2. Adopt risk management processes.
  3. Establish a risk management function.
  4. Align with business risk management processes.

Answer(s): B



Which of the following characteristics would BEST indicate that an IT process is a good candidate for outsourcing?

  1. Operational processes that are well-defined
  2. Non-strategic processes that are not documented
  3. Strategic processes that require expert professionals
  4. Processes with higher risk to the enterprise

Answer(s): B



Which of the following is the PRIMARY purpose of an effective set of key risk indicators (KRIs)?

  1. Identifying possible future adverse impacts on the enterprise
  2. Evaluating existing technology for risk monitoring capabilities
  3. Establishing executive level buy-in of the risk program
  4. Quantifying the productivity of the risk management team

Answer(s): C






Post your Comments and Discuss ISACA CGEIT exam with other Community members:

CGEIT Discussions & Posts