ExamGecko
Home Home / Isaca / CGEIT

Isaca CGEIT Practice Test - Questions Answers, Page 49

Question list
Search
Search

List of questions

Search

Related questions











Which of the following BEST enables an enterprise to achieve the benefits of implementing new Internet of Things (loT) technology?

A.
IT project charter
A.
IT project charter
Answers
B.
Change management
B.
Change management
Answers
C.
Emerging technology roadmap
C.
Emerging technology roadmap
Answers
D.
Enterprise architecture (EA)
D.
Enterprise architecture (EA)
Answers
Suggested answer: D

A CIO was notified that a new employee was observed wearing a headset with an optical lens at the organization's data center. The individual was entering voice commands into the device. When approached, the employee explained the device is a new personal technology serving as a hands-free version of a smart phone. The CIO is concerned with potential security vulnerabilities of allowing such devices, and whether they should be banned from the facility. What should be the NEXT course of action in response to the ClO's concern?

A.
Define a risk mitigation strategy.
A.
Define a risk mitigation strategy.
Answers
B.
Update the acceptable use policy.
B.
Update the acceptable use policy.
Answers
C.
Research competitor usage of similar devices.
C.
Research competitor usage of similar devices.
Answers
D.
Assess the risk associated with the device.
D.
Assess the risk associated with the device.
Answers
Suggested answer: D

Which of the following is the BEST way for a CIO to ensure that the work of IT employees is aligned with approved IT directives?

A.
Mandate technical training related to the IT objectives.
A.
Mandate technical training related to the IT objectives.
Answers
B.
Have business leaders present their departments' objectives.
B.
Have business leaders present their departments' objectives.
Answers
C.
Include relevant IT goals in individual performance objectives.
C.
Include relevant IT goals in individual performance objectives.
Answers
D.
Request a progress review of IT objectives by internal audit.
D.
Request a progress review of IT objectives by internal audit.
Answers
Suggested answer: C

Which of the following would be MOST useful in developing IT strategic plans aligned with technological needs?

A.
Business impact analysis (BIA)
A.
Business impact analysis (BIA)
Answers
B.
Business case
B.
Business case
Answers
C.
Enterprise architecture (EA)
C.
Enterprise architecture (EA)
Answers
D.
Benchmark analysis
D.
Benchmark analysis
Answers
Suggested answer: C

Which of the following is the BEST indicator of the effectiveness of IT governance in an enterprise?

A.
Value delivery
A.
Value delivery
Answers
B.
Resource utilization
B.
Resource utilization
Answers
C.
Residual risk
C.
Residual risk
Answers
D.
Project delivery
D.
Project delivery
Answers
Suggested answer: A

An enterprise is assessing whether to utilize wearable technology. The enterprise has no prior experience with this technology and has asked the chief technology officer (CTO) to assess the impact to the enterprise. The CTO should FIRST:

A.
understand the enterprise's risk tolerance.
A.
understand the enterprise's risk tolerance.
Answers
B.
create an IT risk scorecard.
B.
create an IT risk scorecard.
Answers
C.
prioritize wearable technology risk.
C.
prioritize wearable technology risk.
Answers
Suggested answer: A

An internal auditor conducts an assessment of a two-year-old IT risk management program. Which of the following findings should be of MOST concern to the CIO?

A.
Organizational responsibility for IT risk management is not clearly defined.
A.
Organizational responsibility for IT risk management is not clearly defined.
Answers
B.
None of the members of the IT risk management team have risk management-related certifications.
B.
None of the members of the IT risk management team have risk management-related certifications.
Answers
C.
Only a few key risk indicators (KRIs) identified by the IT risk management team are being monitored and the rest will be on a phased schedule.
C.
Only a few key risk indicators (KRIs) identified by the IT risk management team are being monitored and the rest will be on a phased schedule.
Answers
Suggested answer: A

The accountability for a business continuity program for business-critical systems is BEST assigned to the:

A.
enterprise risk manager.
A.
enterprise risk manager.
Answers
B.
chief executive officer (CEO).
B.
chief executive officer (CEO).
Answers
C.
director of internal audit.
C.
director of internal audit.
Answers
D.
chief information officer (CIO).
D.
chief information officer (CIO).
Answers
Suggested answer: D

Explanation:

The accountability for a business continuity program for business-critical systems is bestassigned to the CIO, because the CIO is responsible for the IT strategy, operations, andresources that support the business objectives and continuity. The other options are not assuitable as the CIO, because they do not have the same level of authority, expertise, or
involvement in the IT function. The enterprise risk manager oversees the overall riskmanagement process, but does not have direct control over the IT resources and activities. TheCEO is ultimately accountable for the entire organization, but delegates the responsibility for ITto the CIO. The director of internal audit provides assurance and consulting services on theeffectiveness of governance, risk management, and control processes, but does not haveoperational responsibility for IT or business continuity.Reference:=Business Continuity ProgramRoles & Responsibilities,Who Should Manage the Business Continuity Program?

An enterprise plans to migrate its applications and data to an external cloud environment. Which of the following should be the ClO's PRIMARY focus before the migration?

A.
Reviewing the information governance framework
A.
Reviewing the information governance framework
Answers
B.
Selecting best-of-breed cloud offerings
B.
Selecting best-of-breed cloud offerings
Answers
C.
Updates the enterprise architecture (EA) repository
C.
Updates the enterprise architecture (EA) repository
Answers
D.
Conducting IT staff training to manage cloud workloads
D.
Conducting IT staff training to manage cloud workloads
Answers
Suggested answer: A

Which of the following is the MOST important consideration when integrating a new vendor with an enterprise resource planning (ERP) system?

A.
IT senior management selects the vendor.
A.
IT senior management selects the vendor.
Answers
B.
A vendor risk assessment is conducted
B.
A vendor risk assessment is conducted
Answers
C.
ERP data mapping is approved by the enterprise architect.
C.
ERP data mapping is approved by the enterprise architect.
Answers
D.
Procurement provides the terms of the contract.
D.
Procurement provides the terms of the contract.
Answers
Suggested answer: B
Total 577 questions
Go to page: of 58