[Q133-Q153] Full CGEIT Practice Test and 565 Unique Questions, Get it Now!

Share

Full CGEIT Practice Test and 565 Unique Questions, Get it Now!

The Best CGEIT Exam Study Material Premium Files  and Preparation Tool


The CGEIT exam covers four key domains: Governance Frameworks, Strategic Management, Benefits Realization, and Risk Optimization. These domains cover a broad range of topics, including IT governance principles, frameworks, and models, strategic planning and alignment, performance measurement and management, risk management, and compliance frameworks.

 

NEW QUESTION # 133
Which of the following processes is responsible for low risk, frequently occurring low cost changes?

  • A. IT Facilities Management
  • B. Incident Management
  • C. Request Fulfillment
  • D. Release Management

Answer: C


NEW QUESTION # 134
A high-tech enterprise is concerned that leading competitors have been successfully recruiting top talent from the enterprise's research and development business unit.
What should the leadership team mandate FIRST?

  • A. A SWOT analysis
  • B. An aggressive talent acquisition program
  • C. A root cause analysis
  • D. An incentive and retention program

Answer: C

Explanation:
A root cause analysis is the first step to identify the factors that are causing the loss of top talent and to devise appropriate solutions. A SWOT analysis, an incentive and retention program, and an aggressive talent acquisition program are possible outcomes of a root cause analysis, but they are not the first action to take. References := CGEIT Review Manual, 7th Edition, page 103.


NEW QUESTION # 135
Which of the following is the PRIMARY purpose of an effective set of key risk indicators (KRIs)?

  • A. Establishing executive level buy-in of the risk program
  • B. Evaluating existing technology for risk monitoring capabilities
  • C. Quantifying the productivity of the risk management team
  • D. Identifying possible future adverse impacts on the enterprise

Answer: D

Explanation:
The PRIMARY purpose of an effective set of key risk indicators (KRIs) is to identify possible future adverse impacts on the enterprise. KRIs are metrics or indicators used by organizations to identify, assess, and monitor potential risks. KRIs show how risky a decision, activity, strategy, or plan may be for a business or company.
KRIs can be used to monitor operational, technological, financial and staff processes, such as security breaches, economic downturn and staff turnover rate. KRIs are like alarms that alert businesses of changes in the level of risk exposure1. By identifying possible future adverse impacts on the enterprise, KRIs can help to:
Prevent or mitigate the negative consequences of risks, such as financial loss, operational disruption, reputational damage, legal liability, etc.
Enhance the decision-making and planning processes by providing relevant and timely information on risks Align the risk management activities with the business objectives and expectations Communicate and report the risk status and performance to stakeholders and regulators Therefore, identifying possible future adverse impacts on the enterprise is the primary purpose of an effective set of KRIs.
1: Key Risk Indicators: Examples & Definitions - SolveXia


NEW QUESTION # 136
An enterprise wants to address the human factors of social engineering risk within the organization. From a governance perspective, which of the following is the BEST way to mitigate this risk?

  • A. Restrict access to social media.
  • B. Distribute the social media information security policy to staff.
  • C. Mandate security requirements be included in employee contracts.
  • D. Mandate annual security awareness training.

Answer: D

Explanation:
This is the best way to mitigate the human factors of social engineering risk within the organization from a governance perspective, as it helps to educate and empower the employees to recognize and prevent social engineering attacks. Social engineering attacks are malicious attacks that use deception and manipulation to exploit human behavior and trick people into revealing sensitive information, clicking malicious links, or opening malicious files1. These attacks can cause serious damage to the organization, such as financial loss, data breach, reputation harm, or legal liability1. Therefore, it is essential to address the human factors of social engineering risk, which are the psychological and emotional vulnerabilities that make people susceptible to these attacks, such as curiosity, greed, fear, urgency, or trust2. By mandating annual security awareness training, the organization can raise the level of knowledge and awareness among the employees about the common types, techniques, and indicators of social engineering attacks, as well as the best practices and policies to avoid them2. Security awareness training can also help to foster a culture of security and responsibility among the employees, and to reinforce their role and accountability in protecting the organization's assets and interests2. The other options are not as effective as mandating annual security awareness training, as they do not address the human factors of social engineering risk directly. Distributing the social media information security policy to staff may help to inform them about the rules and expectations for using social media platforms, but it does not ensure that they understand or follow them. Restricting access to social media may help to reduce the exposure to potential social engineering attacks, but it does not prevent them from occurring through other channels or mediums. Mandating security requirements be included in employee contracts may help to enforce compliance and deter violations, but it does not prevent them from happening due to ignorance or negligence.


NEW QUESTION # 137
Which of the following is a practice of forecasting possible risks to the organization and taking steps to mitigate their impact on operations?

  • A. Timekeeping
  • B. HR audit
  • C. Applicant tracking systems
  • D. Enterprise risk management

Answer: D


NEW QUESTION # 138
You are the project manager of the NHQ project for your company. You are working with your project team to complete a risk audit. A recent issue that your project team responded to, and management approved, was to increase the project schedule because there was risk surrounding the installation time of a new material. Your logic was that with the expanded schedule there would be time to complete the installation without affecting downstream project activities. What type of risk response is being audited in this scenario?

  • A. Avoidance
  • B. Parkinson's Law
  • C. Lag Time
  • D. Mitigation

Answer: A

Explanation:
Section: Volume A


NEW QUESTION # 139
What is the key output handed over to Service Transition within Service Design?

  • A. Service Portfolio Management
  • B. Service Design Package
  • C. ITIL Small-Scale Implementation
  • D. Business Perspective

Answer: B


NEW QUESTION # 140
Which of the following are the main objectives of the Performance measurement domain? Each correct answer represents a complete solution. Choose all that apply.

  • A. It defines value creation roles within IT.
  • B. It meets out the goals.
  • C. It statistically controls the process sequences.
  • D. It satisfies the customer's need.

Answer: B,C,D

Explanation:
Section: Volume A


NEW QUESTION # 141
When selecting a vendor to provide services associated with a critical application which of the following is the MOST important consideration with respect to business continuity planning (BCP)?

  • A. Testing the vendor's BCP and analyzing the results
  • B. Procuring a copy of the vendor's BCP during the contracting process
  • C. Obtaining independent audit reports of the vendor's BCP
  • D. Evaluating whether the vendor's BCP aligns with the enterprise's BCP

Answer: A


NEW QUESTION # 142
A rail transport company has the worst on-time arrival record in the industry due to an antiquated IT system that controls scheduling. Despite employee resistance, an initiative lo upgrade the technology and related processes has been approved. To maximize employee engagement throughout the project, which of the following should be in place prior to the start of the initiative?

  • A. Resource management plan
  • B. Organizational change management plan
  • C. Risk response plan
  • D. Procurement management plan

Answer: B

Explanation:
An organizational change management plan is the best option to have in place prior to the start of an initiative to upgrade the technology and related processes of a rail transport company that has the worst on-time arrival record in the industry due to an antiquated IT system that controls scheduling. An organizational change management plan is a document that outlines the strategy, approach, and actions for managing and implementing a change within an organization. It helps to prepare the organization and its stakeholders for the change, communicate the vision and benefits of the change, address the potential resistance and challenges of the change, and monitor and evaluate the progress and outcomes of the change. An organizational change management plan is especially important for a project that involves a significant technological and process change that may impact the culture, performance, and satisfaction of the employees. By having an organizational change management plan in place before the start of the initiative, the rail transport company can maximize employee engagement throughout the project, and ensure a smooth and successful transition to the new IT system and processes


NEW QUESTION # 143
A service provider guarantees for end-to-end network traffic performance to a customer.
Which of the following types of agreement is this?

  • A. NDA
  • B. SLA
  • C. VPN
  • D. LA

Answer: B


NEW QUESTION # 144
Which of the following essential elements of IT Portfolio Investment Management enables portfolio managers to include or exclude investments, change start and end dates, adjust budgets and reevaluate priorities?

  • A. Portfolio What-If Planning
  • B. Portfolio Management
  • C. Portfolio Planning Analysis
  • D. Integrated Capability

Answer: A


NEW QUESTION # 145
Which of the following BEST lowers costs and improves scalability from an IT enterprise architecture (EA) perspective?

  • A. Cost management
  • B. Standardization
  • C. IT strategic sourcing
  • D. Business agility

Answer: B


NEW QUESTION # 146
When conducting a risk assessment in support of a new regulatory requirement, the IT risk committee should FIRST consider the:

  • A. the risk cost burden to achieve compliance.
  • B. readiness of IT systems to address
  • C. disruption to normal business operations.
  • D. risk profile of the enterprise.

Answer: D

Explanation:
The risk profile of the enterprise is the most important thing to consider first when conducting a risk assessment in support of a new regulatory requirement, as it reflects the overall exposure and tolerance of the enterprise to various types of risks, such as strategic, operational, financial, or compliance risks. The risk profile of the enterprise can help determine the scope, objectives, and criteria of the risk assessment, as well as the prioritization and allocation of resources and efforts for risk identification, analysis, evaluation, and treatment. The risk profile of the enterprise can also help align the risk assessment with the enterprise's strategy, goals, and values, as well as ensure consistency and integration with other risk management activities or processes.
Disruption to normal business operations, readiness of IT systems to address the risk, and cost burden to achieve compliance are also important things to consider when conducting a risk assessment in support of a new regulatory requirement, but they are not the first thing to consider. Disruption to normal business operations is a potential consequence or impact of the risk on the enterprise's performance, productivity, or continuity. Disruption to normal business operations can be assessed and measured during the risk analysis or evaluation stage of the risk assessment, as well as mitigated or reduced during the risk treatment or response stage. Readiness of IT systems to address the risk is a factor that affects the capability or maturity of the enterprise's IT infrastructure, applications, or services to comply with or support the new regulatory requirement. Readiness of IT systems to address the risk can be assessed and improved during the risk treatment or response stage of the risk assessment, as well as monitored and reported during the risk communication or review stage. Cost burden to achieve compliance is a factor that affects the feasibility or affordability of the enterprise's actions or investments to comply with or support the new regulatory requirement. Cost burden to achieve compliance can be estimated and optimized during the risk treatment or response stage of the risk assessment, as well as balanced with the benefits or value of compliance.


NEW QUESTION # 147
Which of the following provides the BEST evidence of an IT risk-aware culture across an enterprise?

  • A. IT risks are communicated to the business.
  • B. IT risk-related policies are published.
  • C. The IT infrastructure is resilient.
  • D. Business staff report identified IT risks.

Answer: D


NEW QUESTION # 148
To successfully implement enterprise IT governance, which of the following should be the MAIN focus of IT policies?

  • A. Limiting IT costs
  • B. Providing business value
  • C. Optimizing operational benefits
  • D. Enhancing organizational capability

Answer: C


NEW QUESTION # 149
You are the project manager of a large construction project. You are evaluating the strengths, weaknesses, opportunities, and threats involved in a project. In which of the following processes are you on?

  • A. Identify Risks
  • B. Plan Risk Management
  • C. Define Scope
  • D. Plan Risk Responses

Answer: A

Explanation:
Section: Volume A


NEW QUESTION # 150
Which of the following methods is MOST likely to be used to assess plausible risk scenarios that could result in reputational risk to the enterprise?

  • A. Quantitative analysis
  • B. Controls gap analysis
  • C. SWOT analysis
  • D. Qualitative analysis

Answer: D

Explanation:
Qualitative analysis is a method that uses subjective judgments and opinions to assess plausible risk scenarios that could result in reputational risk to the enterprise. Qualitative analysis can help identify the sources, causes, and impacts of reputational risk, as well as the likelihood and severity of such risk. Qualitative analysis can also involve stakeholder feedback, surveys, interviews, focus groups, and expert opinions to evaluate the reputation of the enterprise and its IT functions.
The other options are not the most likely methods to assess plausible risk scenarios that could result in reputational risk to the enterprise. Controls gap analysis is a method that compares the existing controls with the required controls to identify any deficiencies or weaknesses that could expose the enterprise to risk.
Controls gap analysis can help improve the effectiveness and efficiency of IT processes and services, but it does not directly assess the reputational risk scenarios. Quantitative analysis is a method that uses numerical data and mathematical models to measure and evaluate risk scenarios. Quantitative analysis can help estimate the financial impact and probability of risk events, but it may not capture the intangible and subjective aspects of reputational risk. SWOT analysis is a method that evaluates the strengths, weaknesses, opportunities, and threats of an organization or a project. SWOT analysis can help identify the internal and external factors that affect the performance and success of the organization or the project, but it does not specifically assess the reputational risk scenarios.
For more information on qualitative analysis and reputational risk, you can refer to these web sources:
Qualitative Risk Analysis: What it is and how to implement it
Reputational Risk Management: A Framework for Measurement
Reputational Risk Management in IT Outsourcing: A Case Study


NEW QUESTION # 151
Which of the following systems come under the category of linking systems to connect an enterprise with its customers and supplier? Each correct answer represents a complete solution. Choose all that apply.

  • A. Website and portal
  • B. Office productivity
  • C. E-mail, smartphone, instant messaging
  • D. Electronic data interchange (EDI)/extensible markup language (XML) data transfer systems

Answer: A,C,D

Explanation:
Section: Volume C


NEW QUESTION # 152
What business analysis element tries to identify as many potential options as possible to meet the business objectives and fill identified gaps in capabilities?

  • A. Decision analysis
  • B. Ranking of approaches
  • C. Alternative generation
  • D. Documentation of assumptions and constraints

Answer: C


NEW QUESTION # 153
......

Get Instant Access to CGEIT Practice Exam Questions: https://www.torrentvce.com/CGEIT-valid-vce-collection.html

Reliable Study Materials & Testing Engine for CGEIT Exam Success!: https://drive.google.com/open?id=19Yf3sPSE1UWsR9UQfjxDAjkOgJ5TKs8P