
PDF Download Free of CGEIT Valid Practice Test Questions
CGEIT Test Engine files, CGEIT Dumps PDF
To be eligible for the CGEIT exam, candidates must have at least five years of experience in IT governance, risk management, and control, with a minimum of one year of experience in managing IT resources at an enterprise level. Candidates must also adhere to the ISACA Code of Professional Ethics and successfully pass the CGEIT exam. The exam consists of 150 multiple-choice questions and is four hours long. Overall, the CGEIT exam is a challenging but rewarding certification for professionals who want to advance their career in IT governance and management.
The CGEIT certification is intended for professionals responsible for governance and management of enterprise IT (EGIT) in their organizations. This includes C-level executives, IT managers, leaders, directors and other IT experts who perform a strategic role in the organization, such as developing, managing and auditing IT processes, policies, procedures, and practices. The certification empowers professionals with the essential knowledge and skills required to contribute significantly to the successful governance of an organization's IT assets.
To be eligible for the CGEIT certification exam, candidates must have at least five years of experience in IT governance, risk management, or compliance. Additionally, they must have completed at least 120 contact hours of CGEIT-related training or education. Candidates who pass the exam will earn the CGEIT certification, which is valid for three years.
NEW QUESTION # 139
Which of the following risk functions directs the Sarbanes-Oxley Section 302 and 404 assessments?
- A. Accounting / Financial compliance
- B. Compliance & Ethics
- C. Operational Quality Assurance
- D. Operations management
Answer: A
Explanation:
Section: Volume C
NEW QUESTION # 140
The use of an IT balanced scorecard enables the realization of business value of IT through:
- A. outcome measures and performance drivers.
- B. business value and control mechanisms.
- C. financial measures and investment management.
- D. vision and alignment with corporate programs.
Answer: A
NEW QUESTION # 141
Which of the following is MOST critical to have in place before management can establish an IT risk assessment and response approach?
- A. A portfolio of IT investments
- B. Historic data on risk events
- C. Defined roles and responsibilities
- D. A balanced scorecard
Answer: C
NEW QUESTION # 142
You work as a project manager for TechSoft Inc. You are working with the project stakeholders on the qualitative risk analysis process in your project. You have used all the tools to the qualitative risk analysis process in your project. Which of the following techniques is NOT used as a tool in qualitative risk analysis process?
- A. Risk Categorization
- B. Risk Reassessment
- C. Risk Data Quality Assessment
- D. Risk Urgency Assessment
Answer: B
Explanation:
Section: Volume A
NEW QUESTION # 143
Which conduct stakeholder analysis technique is useful for identifying shared characteristics of a stakeholder group?
- A. Interviews
- B. Scope modeling
- C. Brainstorming
- D. Surveys
Answer: D
Explanation:
Section: Volume A
NEW QUESTION # 144
The BEST way to ensure an IT steering committee meets enterprise objectives is to:
- A. have key business stakeholders represented on the committee.
- B. establish key performance indicators (KPIs).
- C. benchmark against industry best practices.
- D. require a member of the committee to have IT governance expertise.
Answer: A
NEW QUESTION # 145
A steering committee has been advised by the IT project management office that individual business units are building systems components that could be leveraged by other business units. Instead, identical components are being duplicated across the enterprise. Which of the following committee directives would be the BEST way to reduce the likelihood of this duplication?
- A. Review IT system release management practices.
- B. Establish an enterprise architecture.
- C. Implement stage gate reviews to assess systems.
- D. Perform an assessment of change management processes.
Answer: D
NEW QUESTION # 146
To reduce the risk of reputational damage through inappropriate use of social media by employees outside of the workplace, the enterprise approach regarding social media should PRIMARILY focus on;
- A. implementing a review of processes utilizing social media.
- B. implementing preventative controls.
- C. ensuring each use of social media is approved by management.
- D. developing policies on social media.
Answer: D
NEW QUESTION # 147
A business unit is planning to replace an existing IT legacy solution with a hosted Software as a Service (SaaS) solution. However, business management is concerned that stored data will be at risk. Which of the following would be the MOST effective way to reduce the risk associated with the SaaS solution?
- A. Include risk-related requirements in the SaaS contract.
- B. Research the technology and identify potential security threats.
- C. Create key risk indicators for the SaaS solution.
- D. Redefine the risk appetite and risk tolerance.
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION # 148
A service provider guarantees for end-to-end network traffic performance to a customer.
Which of the following types of agreement is this?
- A. LA
- B. NDA
- C. VPN
- D. SLA
Answer: D
NEW QUESTION # 149
Which of the following activity loops describes creation of new processes?
- A. Loop 4
- B. Loop 1
- C. Loop 3
- D. Loop 2
Answer: C
NEW QUESTION # 150
Fill in the blank with an appropriate phrase.
_______are activities that are dangerous to complete and manage such as construction, electrical work, or manufacturing.
Answer:
Explanation:
Pure risks
NEW QUESTION # 151
Which of the following terms includes performance objectives and criteria (POCs), performance indicators, and any other means that evaluate the success in achieving a specified goal?
- A. Performance Measurement System
- B. Precision
- C. Performance Measurement Category
- D. Performance Measure
Answer: D
NEW QUESTION # 152
Which of the following would be the BEST way to facilitate the adoption of strong IT governance practices throughout a multi-divisional enterprise?
- A. Documenting and communicating key management practices across divisions
- B. Ensuring divisional governance fosters continuous improvement processes
- C. Mandating data standardization across the distributed enterprise
- D. Ensuring each divisional policy is consistent with corporate policy
Answer: A
NEW QUESTION # 153
Stephen is the project manager of the GBB project. He has worked with two subject matter experts and his project team to complete the risk assessment technique. There are approximately 47 risks that have a low probability and a low impact on the project.
Which of the following answers best describes what Stephen should do with these risk events?
- A. The low probability and low impact risks should be added to the risk register.
- B. The low probability and low impact risks should be added to a watch list for future monitoring.
- C. Because they are low probability and low impact, Stephen should accept the risks.
- D. Because they are low probability and low impact, the risks can be dismissed.
Answer: B
NEW QUESTION # 154
Which of the following would be the BEST way for an IT steering committee to monitor the adoption of a new enterprise IT strategy?
- A. Implement service level agreements (SLAs)
- B. Establish key performance indicators (KPIs).
- C. Establish key risk indicators (KRIs).
- D. Schedule ongoing audit reviews.
Answer: B
NEW QUESTION # 155
Which of the following domains of COBIT covers the use of information & technology, and how best it can be used in a company to help achieve the company's goals and objectives?
- A. Monitor and Evaluate
- B. Deliver and Support
- C. Plan and Organize
- D. Acquire and Implement
Answer: C
NEW QUESTION # 156
Which of the following should be the CIO's GREATEST consideration when making changes to the IT strategy?
- A. Have key stakeholders been consulted?
- B. Has the impact to the enterprise architecture been assessed?
- C. Have IT risk metrics been adjusted?
- D. Has the investment portfolio been revised?
Answer: D
NEW QUESTION # 157
......
Pass Your Isaca Certificaton CGEIT Exam on May 03, 2023 with 409 Questions: https://actualtests.trainingquiz.com/CGEIT-training-materials.html

