Isaca CGEIT Practice Test Questions and Exam Dumps Part19 Q361-380

View Full Isaca CGEIT Exam Dumps and Practice Test Dumps.

 

Question 361

An enterprise is establishing governance requirements for a newly acquired subsidiary. What should be addressed FIRST?

  1. Replace the subsidiary’s entire IT department.
  2. Require immediate adoption of every corporate technology standard.
  3. Transfer all technology decisions to the parent organization’s operations team.
  4. Assess the subsidiary’s governance structure, risks, obligations, and alignment with enterprise requirements.

Correct Answer: 4

Explanation

When an organization acquires a subsidiary, governance should first establish an understanding of the subsidiary’s existing structure, technology environment, risks, regulatory obligations, decision rights, and business requirements. This assessment provides the foundation for determining which governance practices should be integrated, modified, or retained. Immediately replacing staff or imposing every corporate standard may create unnecessary disruption and overlook legitimate local requirements. Transferring all decisions to an operations team also does not address strategic governance needs. A structured assessment allows the parent organization to identify gaps and develop an appropriate integration approach while preserving accountability, managing risk, and maintaining alignment with enterprise objectives.

Question 362

An enterprise has limited cybersecurity resources and several competing IT initiatives. How should governance prioritize security investments?

  1. Fund every security request equally.
  2. Prioritize investments based on business criticality, risk exposure, regulatory requirements, and expected risk reduction.
  3. Fund only initiatives requested by IT operations.
  4. Prioritize the initiatives with the newest technologies.

Correct Answer: 2

Explanation

Security investment decisions should be based on enterprise risk and business priorities rather than equal distribution or technology novelty. Governance should consider the criticality of affected services and information, regulatory obligations, threat exposure, existing controls, potential business impact, and expected risk reduction. Funding every request equally may spread resources too thinly, while relying only on IT operations can overlook business and regulatory priorities. New technology is not necessarily the most effective security investment. A risk-based prioritization process allows limited resources to be directed toward areas where they can provide meaningful protection and support organizational objectives while keeping exposure within approved risk tolerance.

Question 363

A governance committee discovers that an investment’s expected benefits are being measured differently by different departments. What should governance do?

  1. Establish common benefit definitions, measures, targets, and ownership.
  2. Allow each department to use its preferred measurements.
  3. Remove nonfinancial benefits from the business case.
  4. Measure only project completion.

Correct Answer: 1

Explanation

Consistent benefit measurement is essential for determining whether an investment is achieving its approved outcomes. Different departmental definitions can make enterprise-level evaluation difficult and may create conflicting conclusions about value. Governance should establish common definitions, measurement methods, targets, data sources, and accountable benefit owners. Allowing every department to use different methods reduces comparability and transparency. Removing nonfinancial benefits can omit important outcomes such as customer experience, risk reduction, compliance, or employee productivity. Project completion measures delivery but does not establish value. Standardized benefit measurement allows governance to compare expected and actual results and identify corrective actions when outcomes fall below expectations.

Question 364

An organization is considering a major change to its enterprise architecture because several legacy platforms are limiting integration. What should governance evaluate?

  1. Only the cost of purchasing replacement software.
  2. Whether the architecture team supports the change.
  3. Business requirements, dependencies, risks, lifecycle considerations, and long-term value.
  4. Whether competitors have already replaced similar platforms.

Correct Answer: 3

Explanation

Enterprise architecture decisions should consider more than the immediate cost of replacement. Governance should evaluate business requirements, existing dependencies, technical debt, integration constraints, security and compliance risks, lifecycle considerations, transition complexity, and expected long-term value. Architecture-team support is important but does not replace enterprise-level evaluation. Competitor behavior can provide context but should not determine the organization’s architecture strategy. A comprehensive assessment helps governance understand the consequences of modernization and compare alternatives such as replacement, modernization, consolidation, or continued operation. This supports sustainable technology decisions and ensures architecture changes remain aligned with business objectives and resource capabilities.

Question 365

A critical IT investment is experiencing repeated scope changes requested by different stakeholders. What should governance ensure?

  1. All requested changes are automatically approved.
  2. The project manager alone decides whether scope changes are acceptable.
  3. Scope changes are ignored until implementation is complete.
  4. Material changes are evaluated for impact on value, cost, risk, resources, and strategic alignment.

Correct Answer: 4

Explanation

Frequent scope changes can affect the business case, schedule, cost, risk, resources, dependencies, and expected benefits of an investment. Governance should ensure that material changes are evaluated through an established change-control process. The assessment should determine whether the revised scope remains aligned with enterprise priorities and whether additional funding or resources are justified. Automatically approving changes can create uncontrolled scope expansion, while relying solely on the project manager may exceed delegated authority. Ignoring changes until completion prevents timely governance decisions. Effective change governance preserves investment discipline while allowing justified changes when they improve business value or respond to legitimate changes in requirements.

Question 366

A governance committee wants to reduce unnecessary duplication across technology platforms. Which activity would be MOST effective?

  1. Conduct an enterprise-wide capability and application portfolio assessment.
  2. Allow each business unit to select its own platforms independently.
  3. Approve new platforms only when requested by senior executives.
  4. Eliminate all applications older than five years.

Correct Answer: 1

Explanation

An enterprise-wide portfolio assessment provides visibility into applications, capabilities, functionality, costs, dependencies, risks, and business ownership. This enables governance to identify duplicate capabilities and determine opportunities for consolidation, reuse, modernization, or retirement. Independent business-unit selection can increase duplication, while executive sponsorship alone does not demonstrate enterprise value. Application age is not sufficient to determine whether a system should be retired because some older systems may remain critical and effective. Portfolio analysis supports evidence-based decisions and can reduce unnecessary costs, complexity, and technical debt while ensuring that technology capabilities continue to support business requirements.

Question 367

A business sponsor wants to continue funding an IT initiative even though its strategic alignment has weakened. What should governance require?

  1. Approval based solely on the sponsor’s commitment.
  2. A reassessment of the business case and strategic alignment before additional funding.
  3. Automatic cancellation of the initiative.
  4. Transfer of the initiative to operational spending.

Correct Answer: 2

Explanation

When strategic alignment weakens, continued funding should not be assumed. Governance should reassess the business case, expected benefits, risks, dependencies, and contribution to current enterprise objectives before authorizing additional resources. Sponsor commitment is valuable but does not replace enterprise-level evaluation. Automatic cancellation may eliminate an initiative that could still have value after modification, while transferring it to operational spending does not resolve the strategic concern. Reassessment enables governance to determine whether the initiative should continue, be modified, reprioritized, or terminated. This ensures scarce resources remain aligned with current organizational priorities and that investment decisions are based on updated information.

Question 368

An enterprise is creating governance requirements for a highly critical outsourced service. Which control is MOST important?

  1. Allow the provider to define its own performance criteria.
  2. Review the provider only when a major incident occurs.
  3. Establish contractual requirements, measurable service levels, risk controls, and ongoing performance monitoring.
  4. Transfer all accountability to the provider.

Correct Answer: 3

Explanation

Critical outsourced services require structured governance because external providers can create operational, security, compliance, continuity, and concentration risks. Contracts should establish measurable service levels, security obligations, reporting requirements, audit rights, incident responsibilities, continuity expectations, and appropriate remedies. Provider-defined criteria alone may not reflect enterprise requirements. Reviewing performance only after incidents is reactive and can allow problems to persist. Outsourcing activities does not transfer ultimate accountability for enterprise outcomes to the provider. Ongoing monitoring enables governance to verify that the provider continues to meet agreed requirements and that risks remain within acceptable limits throughout the relationship.

Question 369

An enterprise is planning a major transformation involving multiple IT programs. What should portfolio governance establish?

  1. Independent governance for every program with no enterprise coordination.
  2. Equal funding for all programs.
  3. Program schedules based only on technical dependencies.
  4. Enterprise-level priorities, dependencies, resource allocation, and benefit relationships across the programs.

Correct Answer: 4

Explanation

Large transformations often involve multiple interdependent programs whose combined outcomes determine enterprise value. Portfolio governance should establish priorities and coordinate dependencies, resources, funding, risks, and expected benefits across the programs. Independent governance without enterprise coordination can result in conflicting decisions or resource constraints. Equal funding does not account for differences in strategic importance, risk, or dependencies. Technical dependencies are important but do not capture business sequencing or benefit relationships. Portfolio-level oversight enables leadership to make trade-offs and ensure that individual programs collectively support strategic objectives rather than optimizing isolated initiatives.

Question 370

A governance body is reviewing a proposed IT service that would require significant ongoing operating costs. What should be included in the decision analysis?

  1. Only the implementation cost.
  2. Total lifecycle cost, expected value, risks, resource requirements, and sustainability.
  3. Only the vendor’s initial quotation.
  4. Only the expected technical performance.

Correct Answer: 2

Explanation

A technology service should be evaluated over its entire lifecycle rather than only its initial implementation cost. Governance should consider ongoing operating and maintenance costs, licensing, staffing, infrastructure, security, compliance, expected benefits, risks, dependencies, and long-term sustainability. Vendor quotations are useful inputs but may not represent total cost of ownership. Technical performance is also important but does not by itself demonstrate business value. A lifecycle-based analysis enables governance to compare alternatives and understand whether the proposed service remains economically and strategically appropriate over time. This supports responsible investment decisions and helps avoid situations where low initial costs lead to substantially higher long-term expenses.

Question 371

An organization has identified a recurring pattern of IT incidents associated with a specific business process. What should governance consider?

  1. Treat each incident independently.
  2. Increase incident reporting frequency only.
  3. Determine whether the underlying process, control, or governance weakness requires corrective action.
  4. Stop reporting incidents related to the process.

Correct Answer: 3

Explanation

Repeated incidents associated with the same business process may indicate a systemic weakness rather than isolated operational failures. Governance should consider whether underlying process design, controls, training, accountability, technology configuration, or risk management practices need improvement. Treating each incident independently can prevent identification of recurring root causes. Increasing reporting frequency alone does not address the underlying problem, while stopping reporting would reduce transparency and risk visibility. Governance should use incident trends as evidence for continual improvement and determine whether corrective actions, investment changes, policy updates, or risk escalation are required. This helps reduce recurring exposure and improve the reliability of critical business processes.

Question 372

An enterprise has established a governance framework, but responsibilities between business owners and IT service owners remain unclear. What should be done?

  1. Define and document roles, responsibilities, decision rights, and accountability for each service.
  2. Transfer all responsibility to IT.
  3. Allow responsibilities to be determined informally.
  4. Create a separate governance framework for every service.

Correct Answer: 1

Explanation

Clear accountability is essential for effective governance. Business owners and IT service owners may have different responsibilities, but these should be explicitly documented. Business owners may be accountable for business outcomes, priorities, and value, while service owners may manage service performance, operational requirements, and technical delivery. Transferring all responsibility to IT can weaken business ownership, while informal arrangements create ambiguity and inconsistent decisions. Creating separate governance frameworks for every service may introduce unnecessary complexity. A clear responsibility model should define decision rights, escalation paths, performance accountability, risk ownership, and benefit ownership. This helps ensure that important decisions are made by the appropriate individuals.

Question 373

A governance committee is evaluating an investment that depends on a major organizational change initiative. The change initiative has been delayed. What should governance do?

  1. Continue the IT investment unchanged because its technical work is progressing.
  2. Assess the dependency and determine its effect on the investment’s benefits, schedule, risks, and viability.
  3. Cancel the organizational change initiative.
  4. Increase IT funding automatically.

Correct Answer: 2

Explanation

When an IT investment depends on organizational change, delays in that change can materially affect the technology investment’s expected outcomes. Governance should assess the dependency and determine how the delay affects benefits realization, implementation timing, costs, risks, resources, and overall viability. Continuing unchanged may lead to technology being delivered before the organization is ready to use it effectively. Automatically increasing funding may not resolve the dependency, while canceling the change initiative could undermine the original business case. Portfolio governance should coordinate related initiatives and determine whether sequencing, scope, funding, or implementation plans need to be adjusted.

Question 374

A governance committee finds that an IT policy is technically compliant but creates unnecessary operational complexity. What should governance consider?

  1. Increasing the number of compliance checks.
  2. Expanding the policy to cover additional processes.
  3. Removing all policy requirements.
  4. Reviewing the policy’s objectives, risks, effectiveness, and opportunities to simplify implementation.

Correct Answer: 4

Explanation

Policies should achieve their intended governance objectives without creating unnecessary burden. If a compliant policy introduces excessive operational complexity, governance should review its purpose, risks addressed, effectiveness, and implementation costs. The goal should be to identify opportunities to simplify processes while preserving necessary controls and compliance requirements. Increasing compliance checks may increase administrative burden, while expanding the policy could make the problem worse. Removing all requirements could introduce unacceptable risk. A risk-based review helps determine whether controls are proportionate and whether alternative approaches can achieve the same objectives more efficiently. This supports continual improvement and encourages practical policy adoption.

Question 375

An enterprise is reviewing its governance reporting process after executives complain that reports arrive too late to support important decisions. What should governance improve?

  1. Add more information to each report.
  2. Increase the number of report reviewers.
  3. Establish reporting requirements that provide timely, relevant information before decision points.
  4. Eliminate executive reporting.

Correct Answer: 3

Explanation

Governance information must be available when decisions are being made. Reports that arrive after important decision points have limited value even if they contain accurate information. Governance should establish reporting schedules and requirements based on decision cycles, risk thresholds, investment milestones, and other relevant events. Adding more information can increase preparation time and worsen delays. Additional reviewers may also slow the process without improving timeliness. Eliminating executive reporting would remove an important governance mechanism. Effective reporting should provide concise, reliable, and relevant information early enough for decision-makers to evaluate alternatives, risks, performance, and required actions before commitments are made.

Question 376

A company wants to establish stronger oversight of enterprise information assets. Which governance practice is MOST appropriate?

  1. Define information ownership, classification, access responsibilities, retention requirements, and accountability.
  2. Allow each employee to determine information classification.
  3. Store all information under a single classification.
  4. Assign information governance entirely to infrastructure teams.

Correct Answer: 1

Explanation

Information governance requires clear ownership and accountability throughout the information lifecycle. Governance should define who owns information, how it is classified, who can access it, how long it should be retained, and how it should be protected and disposed of. Allowing individual employees to determine classifications can create inconsistent treatment and risk. Applying one classification to all information ignores differences in sensitivity and business value. Infrastructure teams can provide technical controls but should not independently own enterprise information governance. A structured information governance framework helps ensure that information is managed consistently and supports legal, regulatory, security, operational, and business requirements.

Question 377

An enterprise is considering reducing its IT governance committees to improve decision speed. What should be evaluated before making changes?

  1. Only the number of meetings currently held.
  2. Whether committee members prefer fewer meetings.
  3. Whether competitors have fewer governance committees.
  4. Decision coverage, accountability, authority, risk oversight, and potential gaps created by consolidation.

Correct Answer: 4

Explanation

Reducing governance committees can improve efficiency, but consolidation may also create gaps in accountability or risk oversight. Governance should first evaluate what decisions each committee currently handles, the authority it exercises, risks it oversees, and how responsibilities would be reassigned. Meeting frequency and member preferences do not fully demonstrate whether a committee is necessary. Competitor structures may differ because their business models and risks are different. A structured assessment can identify unnecessary duplication while preserving essential decision rights and oversight. The objective is to create an efficient governance structure that remains capable of making appropriate decisions, managing risk, and maintaining accountability.

Question 378

A major technology initiative is showing favorable financial results but increasing regulatory risk. What should governance do?

  1. Approve additional funding because financial performance is strong.
  2. Evaluate the regulatory exposure and determine whether mitigation or changes are required.
  3. Ignore the regulatory concern until implementation is complete.
  4. Remove regulatory metrics from governance reports.

Correct Answer: 2

Explanation

Strong financial performance does not override regulatory obligations or enterprise risk requirements. If an initiative increases regulatory exposure, governance should assess the nature and significance of the risk and determine whether additional controls, scope changes, process changes, or other mitigation measures are required. Funding decisions should consider the complete risk and value profile rather than financial performance alone. Ignoring regulatory concerns can create significant legal and operational consequences, while removing regulatory metrics reduces transparency. Governance should ensure that investments remain within approved risk tolerance and comply with applicable requirements while continuing to evaluate whether expected business benefits justify the resources and risks involved.

Question 379

An enterprise wants to improve governance after discovering repeated failures to follow approved IT standards. Which approach is MOST appropriate?

  1. Increase penalties without investigating the cause.
  2. Eliminate the standards.
  3. Analyze the causes of noncompliance, improve communication and training, and revise standards where necessary.
  4. Stop monitoring compliance.

Correct Answer: 3

Explanation

Repeated noncompliance may result from unclear standards, inadequate communication, insufficient training, impractical requirements, weak monitoring, or conflicting business needs. Governance should analyze the underlying causes before determining corrective actions. Communication and training can address awareness problems, while standards may need revision if they are outdated or impractical. Increasing penalties without understanding the cause may not resolve systemic issues. Eliminating standards would remove important governance controls, and stopping monitoring would reduce visibility. A continual-improvement approach uses compliance findings as evidence to strengthen policies, standards, processes, accountability, and communication while maintaining appropriate oversight of enterprise risk.

Question 380

A governance committee is reviewing whether its current IT investment approval process remains effective. Which evidence would provide the strongest basis for improvement?

  1. The number of approval meetings held.
  2. The number of investment proposals submitted.
  3. The length of investment approval documents.
  4. Analysis of decision quality, cycle time, investment outcomes, risk management, and stakeholder feedback.

Correct Answer: 4

Explanation

Evaluating governance effectiveness requires evidence about both process performance and decision outcomes. Decision quality, approval cycle time, investment benefits, risk management, compliance, and stakeholder feedback can reveal whether the approval process is achieving its objectives efficiently. Meeting counts and proposal volumes measure activity but do not demonstrate effectiveness. Document length also does not indicate whether decision-makers receive useful information. By analyzing multiple dimensions, governance can identify bottlenecks, unnecessary controls, information gaps, or weaknesses in investment evaluation. This evidence-based approach supports continual improvement and helps ensure the approval process remains proportionate, transparent, efficient, and aligned with enterprise objectives.