[Q131-Q148] Free CGEIT Exam Files Downloaded Instantly UPDATED [2024]

Share

Free CGEIT Exam Files Downloaded Instantly UPDATED [2024]

100% Pass Guaranteed Free CGEIT Exam Dumps


The CGEIT exam covers topics such as IT governance frameworks, strategic management, risk management, and IT resource management. Candidates must have a minimum of five years of experience in IT governance, including experience in one or more of the exam domains. CGEIT exam is four hours long and consists of 150 multiple-choice questions. Candidates must achieve a minimum score of 450 out of 800 to pass the exam.

 

NEW QUESTION # 131
Jane is the project manager of the GBB project for her company. In the current project a vendor has offered the project a ten percent discount based if they will order 100 units for the project. It is possible that the GBB Project may need the 100 units, but the cost of the units is not a top priority for the project. Jane documents the offer and tells the vendor that they will keep the offer in mind and continue with the project as planned.
What risk response has been given in this project?

  • A. Enhance
  • B. Exploiting
  • C. Acceptance
  • D. Sharing

Answer: C

Explanation:
Section: Volume B
Explanation/Reference:


NEW QUESTION # 132
Which of the following is the BEST indicator of the effectiveness of IT governance in an enterprise?

  • A. Project delivery
  • B. Residual risk
  • C. Value delivery
  • D. Resource utilization

Answer: C

Explanation:
Value delivery is the best indicator of the effectiveness of IT governance in an enterprise because it measures how well IT supports the business objectives and creates value for the stakeholders. The other options are important aspects of IT governance, but they are not as comprehensive as value delivery. References := ISACA, CGEIT Review Manual, 7th Edition, Chapter 1: Framework for the Governance of Enterprise IT, Section 1.2: Principles of IT Governance, p. 9.


NEW QUESTION # 133
To successfully implement enterprise IT governance, which of the following should be the MAIN focus of IT policies?

  • A. Limiting IT costs
  • B. Optimizing operational benefits
  • C. Enhancing organizational capability
  • D. Providing business value

Answer: D


NEW QUESTION # 134
Which of the following frameworks defines ERM as the discipline by which an organization in any industry assesses, controls, exploits, finances, and monitors risks from all sources for the purpose of increasing the organization's short- and long-term value to its stakeholders?

  • A. COBIT
  • B. Casualty Actuarial Society framework
  • C. COSO ERM framework
  • D. Val IT

Answer: B


NEW QUESTION # 135
Which of the following terms related to risk management represents the estimated frequency at which a threat is expected to occur?

  • A. Annualized Rate of Occurrence (ARO)
  • B. Single Loss Expectancy (SLE)
  • C. Exposure Factor (EF)
  • D. Safeguard

Answer: A


NEW QUESTION # 136
Which of the following concepts is used to reduce the errors produced during the manufacturing or service process, increase customer satisfaction, streamline supply chain management, aims for modernization of equipment and ensures workers have the highest level of training?

  • A. Balanced Scorecard (BSC)
  • B. Total Security Management
  • C. Total Quality Management
  • D. Six Sigma

Answer: C


NEW QUESTION # 137
Which of the following should be done FIRST when defining responsibilities for ownership of information and systems?

  • A. Ensure information is classified.
  • B. Require an information risk assessment.
  • C. Identify systems that are outsourced.
  • D. Require an inventory of information assets.

Answer: D


NEW QUESTION # 138
Which of the following areas tracks the project delivery, and monitors the IT services?

  • A. Performance measurement
  • B. Risk management
  • C. Value delivery
  • D. Strategic alignment

Answer: A

Explanation:
Section: Volume C


NEW QUESTION # 139
You are the project manager of the GHY Project and would like to perform a review of your project from several different characteristics. You would like to review what worked in the project and what needed improvement. What type of analysis would be most appropriate for the end of project review?

  • A. Business case study
  • B. SWOT analysis
  • C. Product breakdown
  • D. Feasibility study

Answer: B


NEW QUESTION # 140
Despite an adequate training budget. IT staff are not keeping skills current with emerging technologies critical to the business. Which of the following is the BEST way for the enterprise to address this situation?

  • A. Establish an agreed-upon skills development plan with each employee
  • B. Create a standard-setting center of excellence for IT.
  • C. Require human resources (HR) to recruit new talent using an established IT skills matrix.
  • D. Provide incentives for IT staff to attend outside conferences and training

Answer: A

Explanation:
The best way to address the issue of IT staff not keeping their skills current, despite an adequate training budget, is to establish an agreed-upon skills development plan with each employee. This personalized approach ensures that training and development activities are directly aligned with both the organization's needs and the individual's career goals, thereby increasing the likelihood of participation and the application of new skills. While providing incentives and creating centers of excellence can be supportive, a tailored development plan directly engages each staff member in their growth, ensuring relevance and commitment.


NEW QUESTION # 141
An internal audit of a large financial institution found that financial data is being managed in a way that will negatively impact the enterprise's ability to support regulatory reporting. Which of the following should be the FIRST strategic action in addressing this situation?

  • A. Assign data responsibilities through a RACI chart.
  • B. Review key risk indicators (KRIS) related to data management.
  • C. Update data management policies.
  • D. Establish a data governance framework.

Answer: C

Explanation:
Establishing a data governance framework is the first strategic action in addressing the situation where financial data is being managed in a way that will negatively impact the enterprise's ability to support regulatory reporting. This is because a data governance framework is a structured approach to managing and utilizing data in an organization. It includes policies, procedures, and standards that guide how data is collected, stored, managed, and used1. A data governance framework can help to:
* Improve data quality, accuracy, consistency, and completeness1
* Ensure data privacy, security, and compliance with regulatory requirements1
* Align data with business strategy, objectives, and priorities1
* Enhance data integration, accessibility, and usability1
* Define data roles and responsibilities and assign accountability1
By establishing a data governance framework, the enterprise can address the root cause of the problem, which is the lack of control and oversight over the financial data. A data governance framework can help to ensure that the financial data is properly managed and utilized to support regulatory reporting and other business needs.
The other options, assigning data responsibilities through a RACI chart, reviewing key risk indicators (KRIs) related to data management, and updating data management policies are not as effective as establishing a data governance framework for addressing the situation. They are more related to the implementation and execution of the data governance framework, rather than its design. They are also dependent on the existence of a data governance framework, as they require a clear understanding of the data landscape, goals, and standards of the organization.


NEW QUESTION # 142
The board of directors of an enterprise has approved a three-year IT strategic program to centralize the core business processes of its global entities into one core system. Which of the following should be the ClO's NEXT step?

  • A. Require the development of a risk management plan.
  • B. Determine resource requirements for program implementation.
  • C. Engage a team to perform a business impact analysis (BIA).
  • D. Require the development of a program roadmap.

Answer: D

Explanation:
A program roadmap is a strategic plan that outlines the vision, objectives, scope, deliverables, milestones, dependencies, risks, and benefits of a large-scale IT program. A program roadmap can help the CIO and other stakeholders to communicate, align, and monitor the progress and outcomes of the program. A program roadmap is essential for a complex and long-term IT program such as centralizing the core business processes of global entities into one core system. A program roadmap can help to ensure that the program is aligned with the IT strategy and the business goals, that the program has a clear and realistic scope and schedule, that the program has adequate resources and governance, and that the program delivers the expected value and benefits1234. References: How to Create an IT Strategy Roadmap. Definitive Guide to Developing an IT Strategy and Roadmap. What is an IT Roadmap?. How To Develop a Strategy Roadmap in Six Steps.


NEW QUESTION # 143
When an enterprise is evaluating potential IT service vendors, which of the following BEST enables a clear understanding of the vendor's capabilities that will be critical to the enterprise's strategy?
Due diligence process

  • A. Independent audit results
  • B. Historical service level agreements (SLAs)
  • C. Benchmarking analysis results

Answer: A

Explanation:
A due diligence process is the best way to enable a clear understanding of the vendor's capabilities that will be critical to the enterprise's strategy. A due diligence process is a systematic and comprehensive investigation and evaluation of the vendor's background, reputation, performance, quality, reliability, security, compliance, and suitability for the enterprise's needs and expectations. A due diligence process can help the enterprise:
Verify the vendor's claims and credentials, and validate the vendor's references and testimonials Assess the vendor's financial stability, legal status, and ethical standards Identify the vendor's strengths, weaknesses, opportunities, and threats Compare the vendor's offerings, capabilities, and prices with other vendors and market benchmarks Determine the risks and benefits of engaging with the vendor, and the mitigation and contingency plans Negotiate the terms and conditions of the contract, service level agreement (SLA), and key performance indicators (KPIs) References:
According to the CGEIT Review Manual 2022, "Due diligence is a comprehensive appraisal of a business undertaken by a prospective buyer or partner to establish its assets and liabilities and evaluate its commercial potential."1 According to the ISACA article on Third-Party Vendor Selection: If Done Right, It's a Win-Win2,
"Once you have identified which processes can be outsourced as well as their inherent risks, you can begin performing due diligence on potential vendors. The level of due diligence should be tailored to the significance of the relationship as well as the potential risks it poses." According to the Gartner article on How to Evaluate Technology Vendors in 4 Rigorous Steps1,
"Evaluating vendors requires detailed objectives, criteria, prioritization and monitoring. Here's help.
When it comes to choosing a vendor, enterprise tech buyer teams can easily become bogged down in the details and documentation provided by sales teams."


NEW QUESTION # 144
Gary is the project manager of the MMQ project for his company. He is working with his project team to plan the risk responses for his project. Sarah, a project team member, does not understand the process that Gary is using to plan the risk responses. Which approach is the preferred method to address project risks and the risk responses?

  • A. Risks in the project should be addressed by their impact for creating risk responses.
  • B. Risks in the project should be addressed by the organization's risk tolerance for creating risk responses.
  • C. Risks in the project should be addressed by their probability for creating risk responses.
  • D. Risks in the project should be addressed by their priority for creating risk responses.

Answer: D

Explanation:
Section: Volume B


NEW QUESTION # 145
Which of the following is the BEST outcome measure to determine the effectiveness of IT nsk management processes?

  • A. Frequency of updates to the IT risk register
  • B. Time lag between when IT risk is identified and the enterprise's response
  • C. Percentage of business users satisfied with the quality of risk training
  • D. Number of events impacting business processes due to delays in responding to risks

Answer: D

Explanation:
The number of events impacting business processes due to delays in responding to risks is the best outcome measure to determine the effectiveness of IT risk management processes, because it reflects the actual consequences and losses that result from inadequate or ineffective risk management. Outcome measures are metrics that evaluate the results and benefits of a process or activity, rather than the inputs or outputs1. Outcome measures help to assess whether the process or activity is achieving its objectives and delivering value to the organization1. The number of events impacting business processes due to delays in responding to risks is an outcome measure that indicates how well the IT risk management processes are able to identify, analyze, evaluate, treat, monitor, and communicate IT risks in a timely and appropriate manner. A high number of such events would suggest that the IT risk management processes are not effective, and that they need to be improved or revised. A low number of such events would suggest that the IT risk management processes are effective, and that they are reducing the likelihood and impact of IT risks on the organization.
References := How To Measure Risk Management KPI & Metrics - ERM Software


NEW QUESTION # 146
An IT strategy committee wants to evaluate how well the IT department supports the business strategy. Which of the following is the BEST method for making this determination?

  • A. Customer survey analysis
  • B. Capability maturity assessment
  • C. IT controls assurance program
  • D. IT balanced scorecard reporting

Answer: D

Explanation:
The BEST method for the IT strategy committee to evaluate how well the IT department supports the business strategy is to use IT balanced scorecard reporting. An IT balanced scorecard (BSC) is a strategic management tool that translates the IT vision and mission into measurable objectives, indicators, targets, and initiatives across four perspectives: financial, customer, internal process, and learning and growth1. An IT balanced scorecard reporting is a process of collecting, analyzing, and communicating the performance data and results of the IT department based on the IT BSC framework2. An IT balanced scorecard reporting can help to:
Align the IT objectives and activities with the business strategy and expectations3 Monitor and evaluate the efficiency, effectiveness, and value of the IT department Identify the strengths, weaknesses, opportunities, and threats of the IT department Communicate and demonstrate the contribution and impact of the IT department to the business outcomes Therefore, an IT balanced scorecard reporting is the most suitable method for the IT strategy committee to assess how well the IT department supports the business strategy.
The other options are not as good as option C. While it is useful to conduct a capability maturity assessment, a customer survey analysis, or an IT controls assurance program, these are not comprehensive enough to evaluate how well the IT department supports the business strategy. They are rather focused on specific aspects of the IT department, such as its processes, services, or controls. They do not necessarily cover all four perspectives of the IT BSC framework, which provide a holistic view of the IT performance and alignment with the business strategy. References The IT Balanced Scorecard (BSC) Explained - BMC Software1 What Is a Balanced Scorecard (BSC), How Is it Used in Business?2 How to Align Your Business Strategy with Your Technology Strategy ...3 How to Measure Your Strategic Plan's Success - dummies SWOT Analysis: What It Is and When to Use It - Business News Daily How to Communicate Strategy Effectively - ClearPoint Strategy


NEW QUESTION # 147
The PRIMARY reason for implementing an IT governance program in an enterprise is to

  • A. complies with regulatory requirements
  • B. decrease the scale of investment in information systems due to budgetary controls.
  • C. reduce risks due to improved compensating controls.
  • D. balance the demand for information and the ability to deliver.

Answer: D

Explanation:
IT governance is a formal framework that provides a structure for organizations to ensure that IT investments support business objectives. IT governance helps align IT and business strategies, manage IT risks and benefits, and deliver value to key stakeholders. One of the main objectives of IT governance is to balance the demand for information and the ability to deliver it in an effective and efficient manner. References :=
* CGEIT Review Manual 2023, Chapter 1: Framework for the Governance of Enterprise IT, page 8
* CGEIT Review Questions, Answers & Explanations Manual 2023, Question 277, page 65


NEW QUESTION # 148
......

Latest CGEIT dumps - Instant Download PDF: https://www.trainingdumps.com/CGEIT_exam-valid-dumps.html

Verified & Latest CGEIT Dump Q&As with Correct Answers: https://drive.google.com/open?id=1fISE_-IJe0BZmOZe9Qf66FiMR69E9kCR