Isaca CGEIT Practice Test Questions and Exam Dumps Part17 Q321-340

View Full Isaca CGEIT Exam Dumps and Practice Test Dumps.

 

Question 321

An enterprise is developing its annual IT strategy. Which activity should be performed to ensure that IT priorities remain aligned with business objectives?

  1. Review business objectives and map IT initiatives and capabilities to those objectives.
  2. Select projects based only on available technical skills.
  3. Prioritize projects according to the previous year’s spending.
  4. Allow each IT department to establish independent strategic priorities.

Correct Answer: 1

Explanation

IT strategy should directly support the organization’s business strategy and objectives. Reviewing business priorities and mapping proposed IT initiatives and capabilities to those objectives provides a structured way to confirm strategic alignment. Technical skills and historical spending may influence feasibility but should not independently determine strategic priorities. Allowing departments to create disconnected priorities can result in duplication, conflicting investments, and inefficient resource allocation. Governance should ensure that IT plans reflect enterprise goals, expected outcomes, risk considerations, and available resources. Regular alignment reviews also help identify changes in business direction and ensure technology investments continue to support the organization’s evolving strategic needs.

Question 322

A governance committee is considering two investments that provide similar benefits. One requires substantially more organizational resources than the other. What should governance consider when making the decision?

  1. Which investment has the most senior sponsor.
  2. Which project has the larger technical team.
  3. Relative benefits, costs, risks, dependencies, and resource requirements.
  4. Which project was submitted first.

Correct Answer: 3

Explanation

When investments offer similar benefits, governance should compare their overall value and feasibility. Relevant factors include expected benefits, total costs, risks, dependencies, resource requirements, strategic contribution, and implementation complexity. Executive sponsorship or submission order should not determine the outcome because these factors may have little relationship to enterprise value. A larger technical team may indicate greater complexity rather than greater value. Comparing investments using consistent criteria allows governance to allocate scarce resources objectively and transparently. This approach also helps identify whether one initiative provides comparable benefits with lower cost, risk, or resource consumption, supporting effective portfolio management and enterprise-wide value optimization.

Question 323

An organization is implementing a new enterprise application. Business stakeholders disagree about the expected benefits and success criteria. What should governance require?

  1. Allow the implementation team to define the benefits.
  2. Establish agreed business outcomes, measurable benefits, and accountable benefit owners.
  3. Delay all governance activities until implementation is complete.
  4. Define success only through technical performance.

Correct Answer: 2

Explanation

Benefits should be defined by the business because they depend on business outcomes rather than solely on technical implementation. Governance should require stakeholders to agree on expected outcomes, measurable benefits, targets, and accountable owners. This creates a basis for evaluating whether the investment delivers the value described in its business case. Allowing technical teams to define business benefits can result in inappropriate measures. Waiting until implementation ends removes opportunities to resolve disagreements before resources are committed. Technical performance is important but does not prove that business objectives were achieved. Clear benefit ownership and measurable criteria improve accountability and support effective post-implementation evaluation.

Question 324

A technology investment has been approved, but a major regulatory change occurs before implementation begins. What should governance do?

  1. Continue implementation without reviewing the new requirement.
  2. Cancel the investment immediately.
  3. Transfer the issue to the project manager.
  4. Reassess the investment’s requirements, risks, costs, and business case against the new regulation.

Correct Answer: 4

Explanation

Regulatory changes can materially affect an approved investment before implementation starts. Governance should reassess whether the investment’s requirements, controls, costs, risks, and expected benefits remain appropriate under the new regulatory environment. Immediate cancellation may be unnecessary if the investment can be adapted, while continuing without review could create compliance exposure. The project manager may manage implementation activities but should not independently determine enterprise-level regulatory implications. A governance reassessment provides decision-makers with current information and allows the investment to be modified, reprioritized, delayed, or stopped when appropriate. This ensures investment decisions remain aligned with legal obligations and enterprise risk expectations.

Question 325

An enterprise has multiple governance committees with overlapping responsibilities. What is the MOST appropriate action?

  1. Add another committee to coordinate the existing committees.
  2. Clarify responsibilities, decision rights, and escalation paths and eliminate unnecessary overlap.
  3. Require every committee to approve every IT decision.
  4. Allow committees to continue operating independently.

Correct Answer: 2

Explanation

Overlapping governance structures can create conflicting decisions, duplicated effort, delays, and unclear accountability. Governance should review the responsibilities and authority of each committee and clarify decision rights, escalation paths, and areas of accountability. Where unnecessary duplication exists, responsibilities should be consolidated or removed. Adding another committee may increase complexity rather than solve the problem. Requiring every committee to approve every decision would create excessive bureaucracy and slow decision-making. Independent operation can preserve conflicting responsibilities. A well-designed governance structure ensures that decisions are made at the appropriate level, with clear accountability and efficient escalation when issues cross organizational boundaries.

Question 326

A business unit requests funding for an IT project primarily because competitors have adopted similar technology. What should governance evaluate FIRST?

  1. Whether the technology directly supports identified business needs and strategic objectives.
  2. Whether competitors spent more money on the technology.
  3. Whether the vendor guarantees immediate market leadership.
  4. Whether the technology is currently receiving significant media attention.

Correct Answer: 1

Explanation

Competitive activity can be an important consideration, but it should not by itself justify an IT investment. Governance should first determine whether the proposed technology addresses a genuine business need and supports strategic objectives. The assessment should consider expected benefits, risks, costs, capabilities, organizational readiness, and alternatives. Competitor spending does not establish value for the organization, and vendor claims should not replace independent analysis. Media attention is also not a reliable investment criterion. A disciplined governance process prevents technology decisions from being driven solely by external trends and ensures investments are supported by a clear business rationale and appropriate enterprise-level evaluation.

Question 327

An enterprise wants to improve the quality of information used by its governance committee. Which measure is MOST useful?

  1. Number of pages in each governance report.
  2. Number of reports distributed each month.
  3. Timeliness, accuracy, relevance, and consistency of information provided for decisions.
  4. Number of employees producing governance reports.

Correct Answer: 3

Explanation

Governance decisions depend on information that is accurate, timely, relevant, and consistent. Measuring these qualities provides stronger evidence of reporting effectiveness than simply counting pages, reports, or staff. A long report may contain excessive information without supporting better decisions. Increasing reporting frequency can also create information overload if the content is not relevant. The number of employees involved in reporting measures effort rather than information quality. Governance should establish clear information requirements, definitions, ownership, validation procedures, and reporting standards. Evaluating information quality helps decision-makers receive the evidence needed to assess investments, risks, performance, compliance, and strategic alignment effectively.

Question 328

A critical business application is approaching the end of vendor support. What should governance consider?

  1. Ignore the issue until the vendor stops providing support.
  2. Evaluate lifecycle, security, operational, financial, and business continuity implications and determine an appropriate transition strategy.
  3. Replace the application immediately without assessing alternatives.
  4. Reduce monitoring because the application is already established.

Correct Answer: 2

Explanation

End-of-support conditions can increase security, operational, compliance, and continuity risks. Governance should evaluate the application’s lifecycle position, business criticality, available support, upgrade options, replacement alternatives, costs, dependencies, and transition risks. Waiting until support actually ends can reduce available options and increase exposure. Immediate replacement may also create unnecessary disruption if an upgrade or other mitigation is more appropriate. Reducing monitoring would increase risk rather than address the lifecycle concern. Governance should establish a strategy and timeline based on business requirements, risk tolerance, architecture considerations, and available resources. This supports sustainable technology management and reduces the likelihood of unplanned service disruption.

Question 329

A governance framework requires periodic review. Which event should most clearly trigger an additional review outside the normal schedule?

  1. A routine monthly status report.
  2. A minor administrative change.
  3. A significant change in business strategy, regulatory requirements, or organizational structure.
  4. Completion of an ordinary maintenance task.

Correct Answer: 3

Explanation

Governance frameworks should be reviewed periodically, but significant organizational changes can require additional review. Changes in business strategy, regulations, operating models, organizational structure, risk exposure, or major technology capabilities may alter decision rights, responsibilities, investment priorities, and governance requirements. Routine status reports and ordinary maintenance activities typically do not justify a comprehensive governance review. A minor administrative change may also be handled through normal processes. Trigger-based reviews help ensure that governance remains fit for purpose when the enterprise environment changes significantly. This approach complements scheduled assessments and supports continual alignment between governance structures and current organizational objectives.

Question 330

A governance committee must decide whether to continue an IT investment whose costs have increased significantly. Which information is MOST important?

  1. The original project schedule only.
  2. The number of developers assigned to the project.
  3. The vendor’s promotional materials.
  4. Updated costs, expected benefits, risks, dependencies, and alternatives.

Correct Answer: 4

Explanation

A significant cost increase may change the investment’s overall business case. Governance should therefore review updated costs alongside expected benefits, risks, dependencies, remaining work, and viable alternatives. The original schedule provides useful historical context but does not show whether the investment remains economically justified. Developer headcount does not directly establish value, and vendor promotional material is not sufficient evidence for an enterprise investment decision. Updated information enables governance to compare the investment’s current expected value with alternatives and determine whether to continue, modify, reprioritize, or terminate it. This supports disciplined portfolio management and helps prevent continued spending based on outdated assumptions.

Question 331

An enterprise is introducing a new governance policy for technology investments. What should be established to support effective implementation?

  1. Clear ownership, approval authority, communication requirements, and monitoring mechanisms.
  2. A requirement that every employee approve investments.
  3. Technical implementation procedures only.
  4. An informal verbal communication process.

Correct Answer: 1

Explanation

A governance policy is effective only when responsibilities and implementation mechanisms are clear. Investment governance should establish policy ownership, decision authority, approval thresholds, communication expectations, and monitoring requirements. These elements help employees understand how the policy operates and provide a mechanism for measuring compliance and effectiveness. Requiring every employee to approve investments is impractical and would create unnecessary delays. Technical procedures alone do not define governance authority or accountability. Informal communication can lead to inconsistent interpretation and weak auditability. Clear policy implementation structures help ensure investment decisions follow consistent criteria and remain aligned with enterprise objectives, risk appetite, and resource constraints.

Question 332

An enterprise’s governance committee has delegated certain low-risk technology decisions to management. What should governance ensure?

  1. Delegated decisions are unlimited and require no reporting.
  2. Decision thresholds, accountability, monitoring, and escalation requirements are clearly defined.
  3. Management can change enterprise risk appetite independently.
  4. All delegated decisions are transferred permanently from governance oversight.

Correct Answer: 2

Explanation

Delegation can improve decision efficiency when authority is assigned within clearly defined boundaries. Governance should establish thresholds, responsibilities, reporting requirements, monitoring arrangements, and escalation conditions for delegated decisions. This ensures management can act efficiently while significant or unusual matters are brought back to the appropriate governance level. Delegation does not mean that governance loses accountability for the framework or that management can independently change enterprise risk appetite. Permanent transfer of oversight would weaken governance. A controlled delegation model balances responsiveness with accountability and allows organizations to reserve higher-impact decisions for the appropriate authority while avoiding unnecessary escalation of routine, low-risk matters.

Question 333

A governance review identifies that several IT risks are repeatedly reported but never assigned accountable owners. What should be addressed FIRST?

  1. Increase the number of risk reports.
  2. Reduce the number of reported risks.
  3. Assign accountable risk owners with appropriate authority and responsibilities.
  4. Transfer all risks to internal audit.

Correct Answer: 3

Explanation

Risk identification without ownership does not provide effective risk management. Governance should ensure that significant risks are assigned to accountable owners who have the authority and resources to manage, monitor, mitigate, or escalate them. Increasing the number of reports does not solve the ownership gap. Reducing reported risks could hide important exposures, while internal audit should not assume management’s responsibility for owning operational or business risks. Clear risk ownership supports accountability and ensures that mitigation actions are tracked. Governance can then monitor whether risks remain within approved tolerance and whether escalation is required when exposures exceed established thresholds.

Question 334

A company is evaluating whether to centralize certain IT services that are currently managed independently by business units. What should governance evaluate?

  1. Only whether centralization reduces headcount.
  2. Business requirements, service value, costs, risks, standardization opportunities, and required decision rights.
  3. Whether all business units prefer centralization.
  4. Whether the central IT department has available office space.

Correct Answer: 2

Explanation

Centralization decisions should be based on enterprise value rather than a single cost or preference factor. Governance should evaluate business requirements, service quality, total costs, risk, scalability, standardization opportunities, local flexibility, and decision rights. Headcount reductions may be one potential benefit but do not capture the full impact. Business-unit preferences provide useful stakeholder input but should not be the sole decision criterion. Physical office capacity is largely irrelevant to the strategic question. A structured assessment can determine which services benefit from enterprise-wide standardization and which require local autonomy. Governance should also ensure that accountability and service expectations remain clear after any operating-model change.

Question 335

An IT governance committee wants to improve stakeholder engagement during investment decisions. Which practice is MOST effective?

  1. Involve relevant stakeholders early and provide clear information about objectives, options, risks, and expected outcomes.
  2. Inform stakeholders only after final approval.
  3. Limit participation to IT management.
  4. Allow stakeholders to approve investments without defined criteria.

Correct Answer: 1

Explanation

Early stakeholder engagement improves the quality and acceptance of investment decisions. Relevant stakeholders can provide business requirements, risk information, operational considerations, resource constraints, and perspectives on expected outcomes. Providing clear information about alternatives and trade-offs helps stakeholders participate meaningfully. Informing stakeholders only after approval limits their ability to influence requirements and may create resistance. Restricting participation to IT management can overlook business impacts, while allowing stakeholders to approve investments without criteria can produce inconsistent decisions. Effective governance defines who should participate, when they should participate, and what authority they have, supporting transparency, accountability, and alignment throughout the investment lifecycle.

Question 336

A governance body is reviewing an IT service that has strong performance metrics but poor user adoption. What should governance examine?

  1. Only infrastructure capacity.
  2. Whether the service is delivering intended business outcomes and whether adoption barriers need to be addressed.
  3. Whether service performance metrics should be deleted.
  4. Whether the service should automatically receive additional funding.

Correct Answer: 2

Explanation

High technical performance does not necessarily mean an IT service is delivering its intended business value. Poor user adoption can prevent expected benefits from being realized and may indicate issues with usability, training, communication, process alignment, incentives, or stakeholder involvement. Governance should examine these factors and determine whether corrective actions are needed. Infrastructure capacity may be relevant but does not explain adoption by itself. Removing performance metrics would reduce oversight, while additional funding should follow an assessment rather than occur automatically. Governance should evaluate both service performance and business outcomes so that investment and improvement decisions reflect actual enterprise value.

Question 337

A new IT policy is approved, but employees continue following outdated procedures. What governance action is MOST appropriate?

  1. Assume employees will eventually discover the change.
  2. Remove the new policy.
  3. Communicate the policy, update related procedures, provide appropriate guidance, and monitor adoption.
  4. Delegate policy communication to individual employees.

Correct Answer: 3

Explanation

Policy approval alone does not ensure implementation. Governance should ensure that the updated policy is communicated effectively and that related procedures, guidance, training, and operational documentation are aligned with the new requirements. Monitoring adoption can identify areas where additional clarification or corrective action is needed. Assuming employees will discover changes independently creates unnecessary compliance risk. Removing the policy avoids the implementation problem rather than addressing it. Informal communication by individual employees can result in inconsistent interpretations. Effective policy governance connects approval with communication, implementation, monitoring, and periodic review, ensuring employees understand their responsibilities and that the policy achieves its intended governance objective.

Question 338

An enterprise’s IT governance committee is receiving increasing numbers of exceptions to established standards. What should governance investigate?

  1. Whether the standards are appropriate and whether recurring exceptions indicate a systemic issue.
  2. Whether all standards should be eliminated.
  3. Whether every exception should be permanently approved.
  4. Whether exceptions should stop being documented.

Correct Answer: 1

Explanation

A high number of exceptions may indicate that standards are poorly designed, outdated, impractical, or misaligned with legitimate business requirements. Governance should analyze exception trends to determine whether there is a systemic problem. Recurring exceptions can provide valuable information for improving standards, architecture, policies, or processes. Eliminating standards would remove useful consistency and control, while permanently approving exceptions weakens governance. Stopping documentation would reduce transparency and prevent trend analysis. Governance should maintain a controlled exception process with appropriate authority and review. Exception data can then support continual improvement while ensuring deviations remain justified, risk-assessed, and appropriately monitored.

Question 339

An organization is assessing whether its IT governance structure supports effective risk escalation. Which evidence is MOST useful?

  1. Number of governance meetings conducted.
  2. Number of policies published.
  3. Number of IT employees with certifications.
  4. Evidence that risks exceeding defined thresholds are consistently escalated to authorized decision-makers.

Correct Answer: 4

Explanation

Effective risk escalation depends on clear thresholds, decision rights, and consistent execution. Evidence that risks exceeding defined tolerance or escalation thresholds are actually reported to authorized decision-makers provides direct insight into whether the governance process is working. Meeting counts and policy numbers measure activity rather than escalation effectiveness. Employee certifications may demonstrate capability but do not prove that risk escalation operates properly. Governance should establish documented thresholds and responsibilities and monitor whether significant risks are escalated promptly. Reviewing escalation records can reveal delays, unclear authority, or inconsistent application and can therefore support improvements to the enterprise risk governance framework.

Question 340

An enterprise wants to determine whether its IT governance framework continues to support business value after several organizational changes. What should governance perform?

  1. Compare the framework with current business objectives, decision rights, risks, capabilities, and value-delivery requirements.
  2. Replace the entire governance framework automatically.
  3. Focus only on technology infrastructure performance.
  4. Stop governance assessments until the organization becomes stable.

Correct Answer: 1

Explanation

Organizational changes can affect business objectives, responsibilities, decision rights, risk exposure, operating models, and technology requirements. Governance should therefore assess whether the existing framework remains appropriate for the current environment. Comparing governance arrangements with current objectives and value-delivery requirements helps identify gaps and determine targeted improvements. Automatically replacing the framework may create unnecessary disruption, while infrastructure performance alone does not measure governance effectiveness. Waiting for complete organizational stability may leave important gaps unresolved. A structured reassessment supports continual improvement and helps ensure governance remains aligned with business needs, appropriately manages risk, and enables effective technology-related decision-making as the enterprise evolves.